From aa7112d6bc4621be487f887a691ad2569f05fe0c Mon Sep 17 00:00:00 2001
From: delgado-jacob <29643013+delgado-jacob@users.noreply.github.com>
Date: Tue, 21 Jan 2025 13:40:35 -0700
Subject: [PATCH 01/67] Add descriptions and mitre components to data sources
---
data_sources/asl_aws_cloudtrail.yml | 15 ++++++++++++++-
data_sources/aws_cloudfront.yml | 9 ++++++++-
data_sources/aws_cloudtrail.yml | 2 +-
.../aws_cloudtrail_assumerolewithsaml.yml | 10 +++++++++-
data_sources/aws_cloudtrail_consolelogin.yml | 9 ++++++++-
data_sources/aws_cloudtrail_copyobject.yml | 8 +++++++-
data_sources/aws_cloudtrail_createaccesskey.yml | 8 +++++++-
data_sources/aws_cloudtrail_createkey.yml | 8 +++++++-
.../aws_cloudtrail_createloginprofile.yml | 8 +++++++-
.../aws_cloudtrail_createnetworkaclentry.yml | 8 +++++++-
.../aws_cloudtrail_createpolicyversion.yml | 8 +++++++-
data_sources/aws_cloudtrail_createsnapshot.yml | 8 +++++++-
data_sources/aws_cloudtrail_createtask.yml | 8 +++++++-
.../aws_cloudtrail_createvirtualmfadevice.yml | 8 +++++++-
.../aws_cloudtrail_deactivatemfadevice.yml | 8 +++++++-
...aws_cloudtrail_deleteaccountpasswordpolicy.yml | 6 +++++-
data_sources/aws_cloudtrail_deletealarms.yml | 8 +++++++-
data_sources/aws_cloudtrail_deletedetector.yml | 8 +++++++-
data_sources/aws_cloudtrail_deletegroup.yml | 8 +++++++-
data_sources/aws_cloudtrail_deleteipset.yml | 7 ++++++-
data_sources/aws_cloudtrail_deleteloggroup.yml | 8 +++++++-
data_sources/aws_cloudtrail_deletelogstream.yml | 8 +++++++-
.../aws_cloudtrail_deletenetworkaclentry.yml | 7 ++++++-
data_sources/aws_cloudtrail_deletepolicy.yml | 6 +++++-
data_sources/aws_cloudtrail_deleterule.yml | 8 +++++++-
data_sources/aws_cloudtrail_deletesnapshot.yml | 8 +++++++-
data_sources/aws_cloudtrail_deletetrail.yml | 8 +++++++-
.../aws_cloudtrail_deletevirtualmfadevice.yml | 6 +++++-
data_sources/aws_cloudtrail_deletewebacl.yml | 6 +++++-
.../aws_cloudtrail_describeeventaggregates.yml | 6 +++++-
.../aws_cloudtrail_describeimagescanfindings.yml | 7 ++++++-
.../aws_cloudtrail_getaccountpasswordpolicy.yml | 6 +++++-
data_sources/aws_cloudtrail_getobject.yml | 7 ++++++-
data_sources/aws_cloudtrail_getpassworddata.yml | 6 +++++-
data_sources/aws_cloudtrail_jobcreated.yml | 6 +++++-
data_sources/aws_cloudtrail_modifydbinstance.yml | 7 ++++++-
.../aws_cloudtrail_modifyimageattribute.yml | 6 +++++-
.../aws_cloudtrail_modifysnapshotattribute.yml | 5 ++++-
data_sources/aws_cloudtrail_putbucketacl.yml | 6 +++++-
.../aws_cloudtrail_putbucketlifecycle.yml | 6 +++++-
.../aws_cloudtrail_putbucketreplication.yml | 5 ++++-
.../aws_cloudtrail_putbucketversioning.yml | 5 ++++-
data_sources/aws_cloudtrail_putimage.yml | 6 +++++-
data_sources/aws_cloudtrail_putkeypolicy.yml | 4 +++-
.../aws_cloudtrail_replacenetworkaclentry.yml | 6 +++++-
.../aws_cloudtrail_setdefaultpolicyversion.yml | 6 +++++-
data_sources/aws_cloudtrail_stoplogging.yml | 5 ++++-
...aws_cloudtrail_updateaccountpasswordpolicy.yml | 6 +++++-
.../aws_cloudtrail_updateloginprofile.yml | 6 +++++-
.../aws_cloudtrail_updatesamlprovider.yml | 7 ++++++-
data_sources/aws_cloudtrail_updatetrail.yml | 6 +++++-
data_sources/aws_cloudwatchlogs_vpcflow.yml | 6 ++++--
data_sources/aws_security_hub.yml | 7 ++++++-
data_sources/azure_active_directory.yml | 2 +-
...d_app_role_assignment_to_service_principal.yml | 9 +++++++--
.../azure_active_directory_add_member_to_role.yml | 8 +++++++-
..._active_directory_add_owner_to_application.yml | 8 +++++++-
...ure_active_directory_add_service_principal.yml | 8 +++++++-
...ure_active_directory_add_unverified_domain.yml | 8 +++++++-
...re_active_directory_consent_to_application.yml | 8 +++++++-
...ve_directory_disable_strong_authentication.yml | 7 ++++++-
.../azure_active_directory_enable_account.yml | 7 ++++++-
...zure_active_directory_invite_external_user.yml | 7 ++++++-
...active_directory_reset_password_(by_admin).yml | 7 ++++++-
...active_directory_set_domain_authentication.yml | 7 ++++++-
.../azure_active_directory_sign_in_activity.yml | 7 ++++++-
.../azure_active_directory_update_application.yml | 7 ++++++-
...tive_directory_update_authorization_policy.yml | 7 ++++++-
.../azure_active_directory_update_user.yml | 6 +++++-
...ve_directory_user_registered_security_info.yml | 7 +++++--
...eate_or_update_an_azure_automation_account.yml | 8 ++++++--
...eate_or_update_an_azure_automation_runbook.yml | 7 +++++--
...eate_or_update_an_azure_automation_webhook.yml | 8 ++++++--
data_sources/bro.yml | 9 ---------
data_sources/bro_conn.yml | 15 +++++++++++++++
data_sources/bro_dns.yml | 15 +++++++++++++++
data_sources/bro_files.yml | 15 +++++++++++++++
data_sources/bro_http.yml | 15 +++++++++++++++
data_sources/bro_loaded_scripts.yml | 14 ++++++++++++++
data_sources/bro_ntp.yml | 14 ++++++++++++++
data_sources/bro_ocsp.yml | 15 +++++++++++++++
data_sources/bro_ssl.yml | 15 +++++++++++++++
data_sources/bro_weird.yml | 15 +++++++++++++++
data_sources/bro_x509.yml | 15 +++++++++++++++
data_sources/circleci.yml | 8 +++++++-
data_sources/crowdstrike_processrollup2.yml | 9 ++++++++-
data_sources/crushftp.yml | 8 +++++++-
data_sources/g_suite_drive.yml | 8 +++++++-
data_sources/g_suite_gmail.yml | 7 ++++++-
data_sources/github.yml | 8 +++++++-
data_sources/google_workspace_login_failure.yml | 8 +++++++-
data_sources/google_workspace_login_success.yml | 8 +++++++-
data_sources/ivanti_vtm_audit.yml | 8 +++++++-
data_sources/kubernetes_audit.yml | 9 ++++++++-
data_sources/kubernetes_falco.yml | 9 ++++++++-
data_sources/linux_auditd_add_user.yml | 9 ++++++++-
data_sources/linux_auditd_execve.yml | 10 +++++++++-
data_sources/linux_auditd_path.yml | 10 +++++++++-
data_sources/linux_auditd_proctitle.yml | 9 ++++++++-
data_sources/linux_auditd_service_stop.yml | 9 ++++++++-
data_sources/linux_auditd_syscall.yml | 9 ++++++++-
data_sources/linux_secure.yml | 8 +++++++-
data_sources/ms365_defender_incident_alerts.yml | 8 +++++++-
data_sources/ms_defender_atp_alerts.yml | 8 +++++++-
data_sources/nginx_access.yml | 8 +++++++-
data_sources/o365.yml | 8 +++++++-
...365_add_app_role_assignment_grant_to_user_.yml | 8 +++++++-
..._app_role_assignment_to_service_principal_.yml | 8 +++++++-
data_sources/o365_add_mailboxpermission.yml | 8 +++++++-
data_sources/o365_add_member_to_role_.yml | 8 +++++++-
data_sources/o365_add_owner_to_application_.yml | 8 +++++++-
data_sources/o365_add_service_principal_.yml | 8 +++++++-
data_sources/o365_change_user_license_.yml | 8 +++++++-
data_sources/o365_consent_to_application_.yml | 8 +++++++-
.../o365_disable_strong_authentication_.yml | 8 +++++++-
data_sources/o365_mailitemsaccessed.yml | 8 +++++++-
data_sources/o365_modifyfolderpermissions.yml | 8 +++++++-
data_sources/o365_set_company_information_.yml | 8 +++++++-
data_sources/o365_set_mailbox.yml | 8 +++++++-
data_sources/o365_update_application_.yml | 8 +++++++-
.../o365_update_authorization_policy_.yml | 8 +++++++-
data_sources/o365_update_user_.yml | 8 +++++++-
data_sources/o365_userloggedin.yml | 8 +++++++-
data_sources/o365_userloginfailed.yml | 8 +++++++-
data_sources/okta.yml | 8 +++++++-
data_sources/osquery.yml | 8 +++++++-
data_sources/palo_alto_network_threat.yml | 8 +++++++-
data_sources/palo_alto_network_traffic.yml | 8 +++++++-
data_sources/pingid.yml | 8 +++++++-
data_sources/powershell_installed_iis_modules.yml | 7 ++++++-
.../powershell_script_block_logging_4104.yml | 10 +++++++++-
data_sources/powershell_sip_inventory.yml | 7 ++++++-
data_sources/splunk.yml | 8 +++++++-
data_sources/splunk_stream_http.yml | 8 +++++++-
data_sources/splunk_stream_ip.yml | 8 +++++++-
data_sources/splunk_stream_tcp.yml | 8 +++++++-
data_sources/suricata.yml | 8 +++++++-
data_sources/sysmon_eventid_1.yml | 8 +++++++-
data_sources/sysmon_eventid_10.yml | 8 +++++++-
data_sources/sysmon_eventid_11.yml | 9 ++++++++-
data_sources/sysmon_eventid_12.yml | 8 +++++++-
data_sources/sysmon_eventid_13.yml | 8 +++++++-
data_sources/sysmon_eventid_15.yml | 9 ++++++++-
data_sources/sysmon_eventid_17.yml | 5 ++++-
data_sources/sysmon_eventid_18.yml | 8 +++++++-
data_sources/sysmon_eventid_20.yml | 7 ++++++-
data_sources/sysmon_eventid_21.yml | 8 +++++++-
data_sources/sysmon_eventid_22.yml | 9 ++++++++-
data_sources/sysmon_eventid_23.yml | 9 ++++++++-
data_sources/sysmon_eventid_3.yml | 9 ++++++++-
data_sources/sysmon_eventid_5.yml | 8 +++++++-
data_sources/sysmon_eventid_6.yml | 8 +++++++-
data_sources/sysmon_eventid_7.yml | 9 ++++++++-
data_sources/sysmon_eventid_8.yml | 8 +++++++-
data_sources/sysmon_eventid_9.yml | 9 ++++++++-
data_sources/sysmon_for_linux_eventid_1.yml | 9 ++++++++-
data_sources/sysmon_for_linux_eventid_11.yml | 8 +++++++-
data_sources/windows_active_directory_admon.yml | 8 +++++++-
data_sources/windows_defender_alerts.yml | 8 +++++++-
.../windows_event_log_application_2282.yml | 7 ++++++-
.../windows_event_log_application_3000.yml | 8 +++++++-
data_sources/windows_event_log_capi2_70.yml | 9 ++++++++-
data_sources/windows_event_log_capi2_81.yml | 9 ++++++++-
...s_event_log_certificateservicesclient_1007.yml | 9 ++++++++-
data_sources/windows_event_log_defender_1121.yml | 7 ++++++-
data_sources/windows_event_log_defender_1122.yml | 7 ++++++-
data_sources/windows_event_log_defender_1129.yml | 7 ++++++-
data_sources/windows_event_log_defender_5007.yml | 5 ++++-
...ft_windows_terminalservices_rdpclient_1024.yml | 5 ++++-
.../windows_event_log_printservice_316.yml | 6 +++++-
.../windows_event_log_printservice_808.yml | 7 ++++++-
...ows_event_log_remoteconnectionmanager_1149.yml | 7 ++++++-
data_sources/windows_event_log_security_1100.yml | 6 +++++-
data_sources/windows_event_log_security_1102.yml | 7 ++++++-
data_sources/windows_event_log_security_4624.yml | 7 ++++++-
data_sources/windows_event_log_security_4625.yml | 6 +++++-
data_sources/windows_event_log_security_4627.yml | 7 ++++++-
data_sources/windows_event_log_security_4648.yml | 6 +++++-
data_sources/windows_event_log_security_4662.yml | 6 +++++-
data_sources/windows_event_log_security_4663.yml | 6 +++++-
data_sources/windows_event_log_security_4672.yml | 6 +++++-
data_sources/windows_event_log_security_4688.yml | 6 +++++-
data_sources/windows_event_log_security_4698.yml | 6 +++++-
data_sources/windows_event_log_security_4699.yml | 6 +++++-
data_sources/windows_event_log_security_4703.yml | 6 +++++-
data_sources/windows_event_log_security_4719.yml | 6 +++++-
data_sources/windows_event_log_security_4720.yml | 5 ++++-
data_sources/windows_event_log_security_4724.yml | 5 ++++-
data_sources/windows_event_log_security_4725.yml | 5 ++++-
data_sources/windows_event_log_security_4726.yml | 5 ++++-
data_sources/windows_event_log_security_4732.yml | 5 ++++-
data_sources/windows_event_log_security_4738.yml | 5 ++++-
data_sources/windows_event_log_security_4739.yml | 6 +++++-
data_sources/windows_event_log_security_4741.yml | 8 +++++++-
data_sources/windows_event_log_security_4742.yml | 7 ++++++-
data_sources/windows_event_log_security_4768.yml | 8 +++++++-
data_sources/windows_event_log_security_4769.yml | 8 +++++++-
data_sources/windows_event_log_security_4771.yml | 8 +++++++-
data_sources/windows_event_log_security_4776.yml | 8 +++++++-
data_sources/windows_event_log_security_4781.yml | 8 +++++++-
data_sources/windows_event_log_security_4794.yml | 8 +++++++-
data_sources/windows_event_log_security_4798.yml | 7 ++++++-
data_sources/windows_event_log_security_4876.yml | 8 +++++++-
data_sources/windows_event_log_security_4886.yml | 8 +++++++-
data_sources/windows_event_log_security_4887.yml | 8 +++++++-
data_sources/windows_event_log_security_5136.yml | 8 +++++++-
data_sources/windows_event_log_security_5137.yml | 8 +++++++-
data_sources/windows_event_log_security_5140.yml | 8 +++++++-
data_sources/windows_event_log_security_5141.yml | 8 +++++++-
data_sources/windows_event_log_security_5145.yml | 8 +++++++-
data_sources/windows_event_log_system_4720.yml | 8 +++++++-
data_sources/windows_event_log_system_4726.yml | 8 +++++++-
data_sources/windows_event_log_system_4728.yml | 8 +++++++-
data_sources/windows_event_log_system_7036.yml | 8 +++++++-
data_sources/windows_event_log_system_7040.yml | 8 +++++++-
data_sources/windows_event_log_system_7045.yml | 8 +++++++-
.../windows_event_log_taskscheduler_200.yml | 8 +++++++-
data_sources/windows_iis.yml | 7 ++++++-
data_sources/windows_iis_29.yml | 8 +++++++-
219 files changed, 1482 insertions(+), 223 deletions(-)
delete mode 100644 data_sources/bro.yml
create mode 100644 data_sources/bro_conn.yml
create mode 100644 data_sources/bro_dns.yml
create mode 100644 data_sources/bro_files.yml
create mode 100644 data_sources/bro_http.yml
create mode 100644 data_sources/bro_loaded_scripts.yml
create mode 100644 data_sources/bro_ntp.yml
create mode 100644 data_sources/bro_ocsp.yml
create mode 100644 data_sources/bro_ssl.yml
create mode 100644 data_sources/bro_weird.yml
create mode 100644 data_sources/bro_x509.yml
diff --git a/data_sources/asl_aws_cloudtrail.yml b/data_sources/asl_aws_cloudtrail.yml
index 743e34d3eb..8311be25cc 100644
--- a/data_sources/asl_aws_cloudtrail.yml
+++ b/data_sources/asl_aws_cloudtrail.yml
@@ -3,7 +3,20 @@ id: 1dcf9cfb-0e91-44c6-81b3-61b2574ec898
version: 1
date: '2025-01-14'
author: Patrick Bareiss, Splunk
-description: Data source object for ASL AWS CloudTrail
+description: Represents AWS API dataset data collection from Amazon Security Lake.
+mitre_components:
+- Cloud Service Metadata
+- Cloud Service Modification
+- Cloud Storage Access
+- Instance Creation
+- Instance Deletion
+- Instance Start
+- Instance Stop
+- Instance Modification
+- Cloud Storage Creation
+- Cloud Storage Deletion
+- Cloud Service Enumeration
+- Cloud Storage Enumeration
source: aws_asl
sourcetype: aws:asl
separator: api.operation
diff --git a/data_sources/aws_cloudfront.yml b/data_sources/aws_cloudfront.yml
index c4f146026d..bc4196951d 100644
--- a/data_sources/aws_cloudfront.yml
+++ b/data_sources/aws_cloudfront.yml
@@ -3,7 +3,14 @@ id: 780086dc-2384-45b6-ade7-56cb00105464
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS Cloudfront
+description: Logs requests made to AWS CloudFront distributions, including details on client access, response data, and performance metrics.
+mitre_components:
+- Network Traffic Content
+- Network Traffic Flow
+- Response Metadata
+- Response Content
+- Logon Session Metadata
+- Cloud Service Metadata
source: aws
sourcetype: aws:cloudfront:accesslogs
supported_TA:
diff --git a/data_sources/aws_cloudtrail.yml b/data_sources/aws_cloudtrail.yml
index af1afc59c0..1cdd7ac821 100644
--- a/data_sources/aws_cloudtrail.yml
+++ b/data_sources/aws_cloudtrail.yml
@@ -3,7 +3,7 @@ id: e8ace6db-1dbd-4c72-a1fb-334684619a38
version: 1
date: '2024-07-24'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail
+description: All AWS CloudTrail events
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
diff --git a/data_sources/aws_cloudtrail_assumerolewithsaml.yml b/data_sources/aws_cloudtrail_assumerolewithsaml.yml
index ef4041930f..acd5a6247f 100644
--- a/data_sources/aws_cloudtrail_assumerolewithsaml.yml
+++ b/data_sources/aws_cloudtrail_assumerolewithsaml.yml
@@ -3,10 +3,18 @@ id: 1e28f2a6-2db9-405f-b298-18734a293f77
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail AssumeRoleWithSAML
+description: Logs attempts to assume roles via SAML authentication in AWS, including
+ details of identity provider and role mapping.
+mitre_components:
+- User Account Authentication
+- Logon Session Creation
+- User Account Metadata
+- Cloud Service Metadata
+- Instance Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: AssumeRoleWithSAML
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_consolelogin.yml b/data_sources/aws_cloudtrail_consolelogin.yml
index 0ddc77ce93..934d502f32 100644
--- a/data_sources/aws_cloudtrail_consolelogin.yml
+++ b/data_sources/aws_cloudtrail_consolelogin.yml
@@ -3,10 +3,17 @@ id: b68b3f26-bd21-4fa8-b593-616fe75ac0ae
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail ConsoleLogin
+description: Logs attempts to sign in to the AWS Management Console, including successful and failed login events.
+mitre_components:
+- User Account Authentication
+- Logon Session Creation
+- User Account Metadata
+- Logon Session Metadata
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: ConsoleLogin
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_copyobject.yml b/data_sources/aws_cloudtrail_copyobject.yml
index 44fabed1bb..72a9c6af4b 100644
--- a/data_sources/aws_cloudtrail_copyobject.yml
+++ b/data_sources/aws_cloudtrail_copyobject.yml
@@ -3,10 +3,16 @@ id: 965083f4-64a8-403f-99cc-252e1a6bd3b6
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail CopyObject
+description: Logs operations that copy objects within or between AWS S3 buckets, including details of source and destination.
+mitre_components:
+- Cloud Storage Access
+- Cloud Storage Modification
+- Cloud Storage Metadata
+- Instance Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_values: CopyObject
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_createaccesskey.yml b/data_sources/aws_cloudtrail_createaccesskey.yml
index 4834e03b5d..6e95f8ab0f 100644
--- a/data_sources/aws_cloudtrail_createaccesskey.yml
+++ b/data_sources/aws_cloudtrail_createaccesskey.yml
@@ -3,10 +3,16 @@ id: 0460f7da-3254-4d90-b8c0-2ca657d0cea0
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail CreateAccessKey
+description: Logs the creation of new AWS access keys, including details of the associated user and permissions.
+mitre_components:
+- User Account Creation
+- User Account Metadata
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: CreateAccessKey
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_createkey.yml b/data_sources/aws_cloudtrail_createkey.yml
index 8c2aa289b1..655ce8762f 100644
--- a/data_sources/aws_cloudtrail_createkey.yml
+++ b/data_sources/aws_cloudtrail_createkey.yml
@@ -3,10 +3,16 @@ id: fcfc1593-b6b5-4a0f-91c5-3c395116a8b9
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail CreateKey
+description: Logs the creation of new AWS KMS keys, including details of key properties and associated metadata.
+mitre_components:
+- Cloud Service Creation
+- Cloud Service Metadata
+- Instance Creation
+- Volume Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: CreateKey
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_createloginprofile.yml b/data_sources/aws_cloudtrail_createloginprofile.yml
index 7f09482a94..7c272ab23f 100644
--- a/data_sources/aws_cloudtrail_createloginprofile.yml
+++ b/data_sources/aws_cloudtrail_createloginprofile.yml
@@ -3,10 +3,16 @@ id: 0024fdb1-0d62-4449-970a-746952cf80b6
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail CreateLoginProfile
+description: Logs the creation of login profiles for IAM users, including associated metadata and authentication settings.
+mitre_components:
+- User Account Creation
+- User Account Metadata
+- Logon Session Metadata
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: CreateLoginProfile
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_createnetworkaclentry.yml b/data_sources/aws_cloudtrail_createnetworkaclentry.yml
index b9eb2d9e66..65830e0d0c 100644
--- a/data_sources/aws_cloudtrail_createnetworkaclentry.yml
+++ b/data_sources/aws_cloudtrail_createnetworkaclentry.yml
@@ -3,10 +3,16 @@ id: 45934028-10ec-4ab5-a7b1-a6349b833e67
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail CreateNetworkAclEntry
+description: Logs the creation of new entries in a network ACL, including rules to allow or deny specific network traffic.
+mitre_components:
+- Firewall Rule Modification
+- Network Connection Creation
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: CreateNetworkAclEntry
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_createpolicyversion.yml b/data_sources/aws_cloudtrail_createpolicyversion.yml
index 49b4ea9e54..cc6b2d03f0 100644
--- a/data_sources/aws_cloudtrail_createpolicyversion.yml
+++ b/data_sources/aws_cloudtrail_createpolicyversion.yml
@@ -3,10 +3,16 @@ id: f9f0f3da-37ec-4164-9ea0-0ae46645a86b
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail CreatePolicyVersion
+description: Logs the creation of new versions of IAM policies, including changes to permissions and attached roles or resources.
+mitre_components:
+- Cloud Service Modification
+- Cloud Service Metadata
+- User Account Metadata
+- Group Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: CreatePolicyVersion
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_createsnapshot.yml b/data_sources/aws_cloudtrail_createsnapshot.yml
index d8140341e4..db7c828449 100644
--- a/data_sources/aws_cloudtrail_createsnapshot.yml
+++ b/data_sources/aws_cloudtrail_createsnapshot.yml
@@ -3,10 +3,16 @@ id: 514135a2-f4b2-4d32-8f31-d87824887f9f
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail CreateSnapshot
+description: Logs the creation of a new snapshot of a cloud resource, such as an Amazon EBS volume, including details about the snapshot ID and resource type.
+mitre_components:
+- Snapshot Creation
+- Snapshot Metadata
+- Volume Metadata
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: CreateSnapshot
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_createtask.yml b/data_sources/aws_cloudtrail_createtask.yml
index 64c885e902..ee7394b6e4 100644
--- a/data_sources/aws_cloudtrail_createtask.yml
+++ b/data_sources/aws_cloudtrail_createtask.yml
@@ -3,10 +3,16 @@ id: 6501e4fe-05b2-45f1-bd51-9e06a94fa7d9
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail CreateTask
+description: Logs the creation of a new task in AWS services, such as ECS, including details about the task definition and resource allocation.
+mitre_components:
+- Scheduled Job Creation
+- Scheduled Job Metadata
+- Cloud Service Metadata
+- Instance Creation
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_name: CreateTask
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml
index 579ea87956..ba978e3343 100644
--- a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml
+++ b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml
@@ -3,10 +3,16 @@ id: 13e6e952-0dad-4190-865c-fb5911725f7a
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail CreateVirtualMFADevice
+description: Logs the creation of a new virtual multi-factor authentication (MFA) device, including details about the associated user and configuration.
+mitre_components:
+- User Account Creation
+- User Account Metadata
+- Cloud Service Creation
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: CreateVirtualMFADevice
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_deactivatemfadevice.yml b/data_sources/aws_cloudtrail_deactivatemfadevice.yml
index bfef68070f..a62bdde87c 100644
--- a/data_sources/aws_cloudtrail_deactivatemfadevice.yml
+++ b/data_sources/aws_cloudtrail_deactivatemfadevice.yml
@@ -3,10 +3,16 @@ id: 7397a10b-1150-4de9-8062-a96454ae53b2
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail DeactivateMFADevice
+description: Logs the deactivation of a multi-factor authentication (MFA) device, including details about the associated user and the device.
+mitre_components:
+- User Account Modification
+- User Account Metadata
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: DeactivateMFADevice
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml
index 3998089a44..631ac8d253 100644
--- a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml
+++ b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml
@@ -3,10 +3,14 @@ id: b0730ac8-0992-4de8-b000-2c7d0fc7a67f
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail DeleteAccountPasswordPolicy
+description: Logs the deletion of an account-level password policy in AWS, including details about the account and policy being removed.
+mitre_components:
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: DeleteAccountPasswordPolicy
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_deletealarms.yml b/data_sources/aws_cloudtrail_deletealarms.yml
index d7b436d019..2fdf221e51 100644
--- a/data_sources/aws_cloudtrail_deletealarms.yml
+++ b/data_sources/aws_cloudtrail_deletealarms.yml
@@ -3,10 +3,16 @@ id: b0730ac8-0992-4de8-b000-2c7d0fc7a61f
version: 1
date: '2024-07-18'
author: Bhavin Patel, Splunk
-description: Data source object for AWS CloudTrail DeleteAlarms
+description: Logs the deletion of CloudWatch alarms, including details about the alarm names and associated monitoring configurations.
+mitre_components:
+- Cloud Service Modification
+- Cloud Service Metadata
+- Application Log Content
+- Host Status
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: DeleteAlarms
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_deletedetector.yml b/data_sources/aws_cloudtrail_deletedetector.yml
index df3b6cea4e..f467d9348d 100644
--- a/data_sources/aws_cloudtrail_deletedetector.yml
+++ b/data_sources/aws_cloudtrail_deletedetector.yml
@@ -3,10 +3,16 @@ id: 5d8bd475-c8bc-4447-b27f-efa508728b90
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail DeleteDetector
+description: Logs the deletion of an Amazon GuardDuty detector, including details about the detector ID and associated configurations.
+mitre_components:
+- Cloud Service Modification
+- Cloud Service Metadata
+- Host Status
+- Application Log Content
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: DeleteDetector
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_deletegroup.yml b/data_sources/aws_cloudtrail_deletegroup.yml
index f383f21440..a683fd2697 100644
--- a/data_sources/aws_cloudtrail_deletegroup.yml
+++ b/data_sources/aws_cloudtrail_deletegroup.yml
@@ -3,10 +3,16 @@ id: c95308a4-a943-42ca-b112-f90a05c21bd3
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail DeleteGroup
+description: Logs the deletion of an IAM group in AWS, including details about the group name and its associated policies or members.
+mitre_components:
+- Group Modification
+- Group Metadata
+- User Account Metadata
+- Cloud Service Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: DeleteGroup
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_deleteipset.yml b/data_sources/aws_cloudtrail_deleteipset.yml
index 9e70698a5f..4c8770dcb2 100644
--- a/data_sources/aws_cloudtrail_deleteipset.yml
+++ b/data_sources/aws_cloudtrail_deleteipset.yml
@@ -3,10 +3,15 @@ id: ebdeeb63-77a0-4808-a6fe-549956731377
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail DeleteIPSet
+description: Logs the deletion of an IP set in AWS WAF or GuardDuty, including details about the IP set ID and its associated configurations.
+mitre_components:
+- Cloud Service Modification
+- Cloud Service Metadata
+- Firewall Rule Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: DeleteIPSet
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_deleteloggroup.yml b/data_sources/aws_cloudtrail_deleteloggroup.yml
index 936f52788a..04895c5bab 100644
--- a/data_sources/aws_cloudtrail_deleteloggroup.yml
+++ b/data_sources/aws_cloudtrail_deleteloggroup.yml
@@ -3,10 +3,16 @@ id: 60cf6a69-fa43-4a6c-8808-e9fb46bf387f
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail DeleteLogGroup
+description: Logs the deletion of a CloudWatch log group, including details about the log group name and associated resources.
+mitre_components:
+- Cloud Service Modification
+- Cloud Service Metadata
+- Application Log Content
+- Host Status
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: DeleteLogGroup
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_deletelogstream.yml b/data_sources/aws_cloudtrail_deletelogstream.yml
index 591ea64693..998218f3d2 100644
--- a/data_sources/aws_cloudtrail_deletelogstream.yml
+++ b/data_sources/aws_cloudtrail_deletelogstream.yml
@@ -3,10 +3,16 @@ id: 6f8bb808-89f8-465e-a34d-229df2f46402
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail DeleteLogStream
+description: Logs the deletion of a log stream within a CloudWatch log group, including details about the stream name and associated log group.
+mitre_components:
+- Cloud Service Modification
+- Cloud Service Metadata
+- Application Log Content
+- Host Status
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: DeleteLogStream
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml
index 7c0003f08b..ce7ac268b0 100644
--- a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml
+++ b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml
@@ -3,10 +3,15 @@ id: a0dd0f10-cc03-425d-bd5a-e1e0d954b856
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail DeleteNetworkAclEntry
+description: Logs the deletion of a network ACL entry in AWS, including details about the rule number and associated network ACL.
+mitre_components:
+- Firewall Rule Modification
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: DeleteNetworkAclEntry
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_deletepolicy.yml b/data_sources/aws_cloudtrail_deletepolicy.yml
index 44cd10188c..fd3dbe18c2 100644
--- a/data_sources/aws_cloudtrail_deletepolicy.yml
+++ b/data_sources/aws_cloudtrail_deletepolicy.yml
@@ -3,10 +3,14 @@ id: d190d23a-2c59-4a0e-9c55-a53ebef28ee5
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail DeletePolicy
+description: Logs the deletion of an IAM policy in AWS, including details about the policy name and its associated roles or users.
+mitre_components:
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: DeletePolicy
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_deleterule.yml b/data_sources/aws_cloudtrail_deleterule.yml
index 545fbcec9a..b5bf81865b 100644
--- a/data_sources/aws_cloudtrail_deleterule.yml
+++ b/data_sources/aws_cloudtrail_deleterule.yml
@@ -3,10 +3,16 @@ id: b5760623-f3ca-492d-a372-d5c2b3567dfc
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail DeleteRule
+description: Logs the deletion of an event rule in AWS EventBridge, including details about the rule name and its associated targets or schedules.
+mitre_components:
+- Cloud Service Modification
+- Cloud Service Metadata
+- Scheduled Job Modification
+- Application Log Content
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: DeleteRule
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_deletesnapshot.yml b/data_sources/aws_cloudtrail_deletesnapshot.yml
index 6b586a2a3e..dc157cb6bd 100644
--- a/data_sources/aws_cloudtrail_deletesnapshot.yml
+++ b/data_sources/aws_cloudtrail_deletesnapshot.yml
@@ -3,10 +3,16 @@ id: b0731ac8-0992-4de8-b000-2c7d0fc2a61f
version: 1
date: '2024-07-18'
author: Bhavin Patel, Splunk
-description: Data source object for AWS CloudTrail DeleteSnapshot
+description: Logs the deletion of a cloud resource snapshot, such as an Amazon EBS snapshot, including details about the snapshot ID and associated resource.
+mitre_components:
+- Snapshot Deletion
+- Snapshot Metadata
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: DeleteSnapshot
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_deletetrail.yml b/data_sources/aws_cloudtrail_deletetrail.yml
index 1555fafdac..50d8ba5c17 100644
--- a/data_sources/aws_cloudtrail_deletetrail.yml
+++ b/data_sources/aws_cloudtrail_deletetrail.yml
@@ -3,10 +3,16 @@ id: a5af09ff-07b6-4df6-92a0-2146bfe402c8
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail DeleteTrail
+description: Logs the deletion of an AWS CloudTrail trail, including details about the trail name and its associated logging configurations.
+mitre_components:
+- Cloud Service Modification
+- Cloud Service Metadata
+- Application Log Content
+- Host Status
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: DeleteTrail
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml
index e03ef28b7d..64de0ba5eb 100644
--- a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml
+++ b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml
@@ -3,10 +3,14 @@ id: 84a08d6b-3d59-4260-8cab-84278ada262f
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail DeleteVirtualMFADevice
+description: Logs an event when a virtual Multi-Factor Authentication (MFA) device is deleted in AWS CloudTrail.
+mitre_components:
+- User Account Authentication
+- User Account Deletion
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: DeleteVirtualMFADevice
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_deletewebacl.yml b/data_sources/aws_cloudtrail_deletewebacl.yml
index 2368ae2314..8d9c4b1cb9 100644
--- a/data_sources/aws_cloudtrail_deletewebacl.yml
+++ b/data_sources/aws_cloudtrail_deletewebacl.yml
@@ -3,10 +3,14 @@ id: 90da5f08-7961-4c29-8de8-01364982aadf
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail DeleteWebACL
+description: Logs an event when a Web Access Control List (WebACL) is deleted in AWS CloudTrail.
+mitre_components:
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: DeleteWebACL
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_describeeventaggregates.yml b/data_sources/aws_cloudtrail_describeeventaggregates.yml
index ae72fb9931..68042cdaa6 100644
--- a/data_sources/aws_cloudtrail_describeeventaggregates.yml
+++ b/data_sources/aws_cloudtrail_describeeventaggregates.yml
@@ -3,10 +3,14 @@ id: 7efe4afe-62ae-4f96-81d1-76598ea37fc2
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail DescribeEventAggregates
+description: Logs an event when aggregate details about AWS events are queried, often for analysis.
+mitre_components:
+- Cloud Service Enumeration
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: DescribeEventAggregates
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_describeimagescanfindings.yml b/data_sources/aws_cloudtrail_describeimagescanfindings.yml
index 79696cbffc..d29dc3e798 100644
--- a/data_sources/aws_cloudtrail_describeimagescanfindings.yml
+++ b/data_sources/aws_cloudtrail_describeimagescanfindings.yml
@@ -3,10 +3,15 @@ id: 688ea789-9ba2-4970-90a2-17e541e273c9
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail DescribeImageScanFindings
+description: Logs an event when findings from an image vulnerability scan are described using the DescribeImageScanFindings operation in AWS CloudTrail.
+mitre_components:
+- Image Metadata
+- Image Modification
+- Malware Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: DescribeImageScanFindings
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml
index 376fecc828..d4abfd2473 100644
--- a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml
+++ b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml
@@ -3,10 +3,14 @@ id: 439bdc53-6e4b-4cd7-b326-86c7317fd396
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail GetAccountPasswordPolicy
+description: Logs an event when a request is made to get the account password policy in AWS CloudTrail.
+mitre_components:
+- User Account Authentication
+- User Account Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: GetAccountPasswordPolicy
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_getobject.yml b/data_sources/aws_cloudtrail_getobject.yml
index 27d29dea5d..3a3c9a6e10 100644
--- a/data_sources/aws_cloudtrail_getobject.yml
+++ b/data_sources/aws_cloudtrail_getobject.yml
@@ -3,10 +3,15 @@ id: 5063cb10-84c0-44af-ade4-ab9ecad11dfe
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail GetObject
+description: Logs an event when a request is made to access an object stored in an AWS S3 bucket.
+mitre_components:
+- Cloud Storage Access
+- Cloud Storage Metadata
+- Cloud Storage Enumeration
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: GetObject
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_getpassworddata.yml b/data_sources/aws_cloudtrail_getpassworddata.yml
index fc6857d804..7b86ddd0fe 100644
--- a/data_sources/aws_cloudtrail_getpassworddata.yml
+++ b/data_sources/aws_cloudtrail_getpassworddata.yml
@@ -3,10 +3,14 @@ id: 6ff2ce99-85b1-4c17-888a-56dbc3570671
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail GetPasswordData
+description: Logs an event when a request is made to retrieve the administrator password of an EC2 instance.
+mitre_components:
+- Instance Metadata
+- User Account Authentication
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: GetPasswordData
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_jobcreated.yml b/data_sources/aws_cloudtrail_jobcreated.yml
index b33710f139..fb86a52163 100644
--- a/data_sources/aws_cloudtrail_jobcreated.yml
+++ b/data_sources/aws_cloudtrail_jobcreated.yml
@@ -3,10 +3,14 @@ id: 6473289b-d097-4c86-a837-3cc5ae408155
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail JobCreated
+description: Logs an event when a new job is created in AWS CloudTrail.
+mitre_components:
+- Scheduled Job Creation
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: JobCreated
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_modifydbinstance.yml b/data_sources/aws_cloudtrail_modifydbinstance.yml
index 813b021c40..df5c25ffe5 100644
--- a/data_sources/aws_cloudtrail_modifydbinstance.yml
+++ b/data_sources/aws_cloudtrail_modifydbinstance.yml
@@ -3,10 +3,15 @@ id: bfa2912d-1a33-4b05-be46-543874d68241
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail ModifyDBInstance
+description: Logs an event when a modification is made to an AWS database instance, such as parameters or configurations.
+mitre_components:
+- Instance Modification
+- Cloud Service Modification
+- Instance Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: ModifyDBInstance
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_modifyimageattribute.yml b/data_sources/aws_cloudtrail_modifyimageattribute.yml
index e73a70ec35..3d415b44b9 100644
--- a/data_sources/aws_cloudtrail_modifyimageattribute.yml
+++ b/data_sources/aws_cloudtrail_modifyimageattribute.yml
@@ -3,10 +3,14 @@ id: 667c2115-8082-419e-b541-8150066bda4d
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail ModifyImageAttribute
+description: Logs an event when the attributes of an Amazon Machine Image (AMI) are modified.
+mitre_components:
+- Image Modification
+- Image Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: ModifyImageAttribute
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml
index 373a15ede9..211ccdf1dc 100644
--- a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml
+++ b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml
@@ -3,10 +3,13 @@ id: 7e5aa947-3a0d-4ee5-b800-0c10b555da05
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail ModifySnapshotAttribute
+description: Logs an event when modifications are made to the attributes of a snapshot in AWS CloudTrail.
+mitre_components:
+- Snapshot Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: ModifySnapshotAttribute
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_putbucketacl.yml b/data_sources/aws_cloudtrail_putbucketacl.yml
index 10765a8703..24be91aea5 100644
--- a/data_sources/aws_cloudtrail_putbucketacl.yml
+++ b/data_sources/aws_cloudtrail_putbucketacl.yml
@@ -3,10 +3,14 @@ id: 28fffbfd-d98d-4a42-990b-b04ab47422eb
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail PutBucketAcl
+description: Logs an event when an ACL is set or modified for an S3 bucket in AWS CloudTrail.
+mitre_components:
+- Cloud Storage Modification
+- Cloud Storage Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: PutBucketAcl
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_putbucketlifecycle.yml b/data_sources/aws_cloudtrail_putbucketlifecycle.yml
index c9d8491a16..a01d2b76d2 100644
--- a/data_sources/aws_cloudtrail_putbucketlifecycle.yml
+++ b/data_sources/aws_cloudtrail_putbucketlifecycle.yml
@@ -3,10 +3,14 @@ id: 1c73e954-87b6-4bd7-ac6a-5db7c4082b22
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail PutBucketLifecycle
+description: Logs an event when a lifecycle configuration is added to an S3 bucket in AWS CloudTrail.
+mitre_components:
+- Cloud Storage Modification
+- Cloud Storage Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: PutBucketLifecycle
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_putbucketreplication.yml b/data_sources/aws_cloudtrail_putbucketreplication.yml
index 50c9bb4051..b16eec7546 100644
--- a/data_sources/aws_cloudtrail_putbucketreplication.yml
+++ b/data_sources/aws_cloudtrail_putbucketreplication.yml
@@ -3,10 +3,13 @@ id: 0e1362eb-e592-419f-8fa5-556d3a122417
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail PutBucketReplication
+description: Logs an event when replication configurations are added or modified for an S3 bucket.
+mitre_components:
+- Cloud Storage Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: PutBucketReplication
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_putbucketversioning.yml b/data_sources/aws_cloudtrail_putbucketversioning.yml
index 4d928ee0d2..1fcc3c6668 100644
--- a/data_sources/aws_cloudtrail_putbucketversioning.yml
+++ b/data_sources/aws_cloudtrail_putbucketversioning.yml
@@ -3,10 +3,13 @@ id: 17b2fc7d-c8ce-487c-8815-f9a65a09e980
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail PutBucketVersioning
+description: Logs an event when the bucket versioning state is modified in an AWS S3 bucket.
+mitre_components:
+- Cloud Storage Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: PutBucketVersioning
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_putimage.yml b/data_sources/aws_cloudtrail_putimage.yml
index 707c03fcf6..263b630172 100644
--- a/data_sources/aws_cloudtrail_putimage.yml
+++ b/data_sources/aws_cloudtrail_putimage.yml
@@ -3,10 +3,14 @@ id: bb13f10d-0d8c-4fde-9136-b7cfd930e87c
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail PutImage
+description: Logs an event when a container image is uploaded to a repository in AWS CloudTrail.
+mitre_components:
+- Image Creation
+- Image Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: PutImage
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_putkeypolicy.yml b/data_sources/aws_cloudtrail_putkeypolicy.yml
index 9b2786fadb..edac5877b5 100644
--- a/data_sources/aws_cloudtrail_putkeypolicy.yml
+++ b/data_sources/aws_cloudtrail_putkeypolicy.yml
@@ -3,7 +3,7 @@ id: 9c54c86b-43b9-4bb8-915d-6838beb7f07c
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail PutKeyPolicy
+description: Logs changes made to AWS Key Management Service (KMS) key policies, including updates and permission assignments.
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
@@ -94,6 +94,8 @@ fields:
- vendor_account
- vendor_product
- vendor_region
+mitre_components:
+- Cloud Service Modification
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLK74OPBDR", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml
index 4ce1405960..af51b981b1 100644
--- a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml
+++ b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml
@@ -3,10 +3,14 @@ id: db0c240e-3754-40e4-86ef-cde018ee9f65
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail ReplaceNetworkAclEntry
+description: Logs an event when a network ACL entry is replaced within the AWS CloudTrail.
+mitre_components:
+- Firewall Rule Modification
+- Cloud Service Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: ReplaceNetworkAclEntry
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml
index 9797971379..df1e0b4657 100644
--- a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml
+++ b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml
@@ -3,10 +3,14 @@ id: 06e0b5a0-8d36-485e-befc-4ae79d77ef6c
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail SetDefaultPolicyVersion
+description: Logs an event when the default version of a resource policy in AWS is set or changed.
+mitre_components:
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: SetDefaultPolicyVersion
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_stoplogging.yml b/data_sources/aws_cloudtrail_stoplogging.yml
index f285ce143e..69859da19d 100644
--- a/data_sources/aws_cloudtrail_stoplogging.yml
+++ b/data_sources/aws_cloudtrail_stoplogging.yml
@@ -3,10 +3,13 @@ id: c5de7c54-4809-4659-bf9f-3bacf8bdfd35
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail StopLogging
+description: Logs an event when a cloud service in AWS, such as CloudTrail, is deactivated or stopped.
+mitre_components:
+- Cloud Service Disable
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: StopLogging
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml
index de90a002fe..3959397892 100644
--- a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml
+++ b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml
@@ -3,10 +3,14 @@ id: 35a8cc97-3600-40e1-a5d1-1c2ad5060be0
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail UpdateAccountPasswordPolicy
+description: Logs an event when an AWS account's password policy is updated.
+mitre_components:
+- User Account Modification
+- Cloud Service Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: UpdateAccountPasswordPolicy
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_updateloginprofile.yml b/data_sources/aws_cloudtrail_updateloginprofile.yml
index 6978637a08..e8d28c061a 100644
--- a/data_sources/aws_cloudtrail_updateloginprofile.yml
+++ b/data_sources/aws_cloudtrail_updateloginprofile.yml
@@ -3,10 +3,14 @@ id: 1db79158-e5d3-4d35-9d3c-586e44e09f1c
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail UpdateLoginProfile
+description: Logs an event when an IAM user's login profile is updated.
+mitre_components:
+- User Account Modification
+- User Account Authentication
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: UpdateLoginProfile
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_updatesamlprovider.yml b/data_sources/aws_cloudtrail_updatesamlprovider.yml
index 2f2cd5b188..9477d6a455 100644
--- a/data_sources/aws_cloudtrail_updatesamlprovider.yml
+++ b/data_sources/aws_cloudtrail_updatesamlprovider.yml
@@ -3,10 +3,15 @@ id: e5eb628d-711e-499c-87d9-8fa5dee419ec
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail UpdateSAMLProvider
+description: Logs an event when a SAML provider is updated in AWS.
+mitre_components:
+- Cloud Service Modification
+- User Account Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: UpdateSAMLProvider
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_updatetrail.yml b/data_sources/aws_cloudtrail_updatetrail.yml
index f22ec6b7ba..edc2d3ff2a 100644
--- a/data_sources/aws_cloudtrail_updatetrail.yml
+++ b/data_sources/aws_cloudtrail_updatetrail.yml
@@ -3,10 +3,14 @@ id: d5b7a1eb-711a-4c96-aa93-235fe3c8a939
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS CloudTrail UpdateTrail
+description: Logs an event when an AWS CloudTrail trail is updated, typically involving changes to settings or configuration.
+mitre_components:
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
+separator_value: UpdateTrail
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudwatchlogs_vpcflow.yml b/data_sources/aws_cloudwatchlogs_vpcflow.yml
index b20242046f..bec254d4fa 100644
--- a/data_sources/aws_cloudwatchlogs_vpcflow.yml
+++ b/data_sources/aws_cloudwatchlogs_vpcflow.yml
@@ -3,10 +3,12 @@ id: 38a34fc4-e128-4478-a8f4-7835d51d5135
version: 1
author: Bhavin Patel, Splunk
date: '2024-07-18'
-description: Data source object for AWS CloudWatchLogs VPCflow
+description: Logs an event when network traffic flow information such as source and destination IPs, ports, protocol, and action (allow/deny) is captured for VPC in AWS.
+mitre_components:
+- Network Traffic Flow
+- Network Connection Creation
source: aws_cloudwatchlogs_vpcflow
sourcetype: aws:cloudwatchlogs:vpcflow
-separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
version: 7.9.0
diff --git a/data_sources/aws_security_hub.yml b/data_sources/aws_security_hub.yml
index 5d4d52b2e7..5d72ddeb75 100644
--- a/data_sources/aws_security_hub.yml
+++ b/data_sources/aws_security_hub.yml
@@ -3,7 +3,12 @@ id: b02bfbf3-294f-478e-99a1-e24b8c692d7e
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for AWS Security Hub
+description: Logs an event when AWS Security Hub identifies potential security risks or deviations from configured best practices across AWS accounts.
+mitre_components:
+- Cloud Service Metadata
+- Cloud Service Enumeration
+- Cloud Service Modification
+- Cloud Service Disable
source: aws_securityhub_finding
sourcetype: aws:securityhub:finding
supported_TA:
diff --git a/data_sources/azure_active_directory.yml b/data_sources/azure_active_directory.yml
index 5acf9c76b5..20f8362da1 100644
--- a/data_sources/azure_active_directory.yml
+++ b/data_sources/azure_active_directory.yml
@@ -3,7 +3,7 @@ id: 51ca21e5-bda2-4652-bb29-27c7bc18a81c
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Active Directory
+description: All Azure Active Directory events
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
diff --git a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml
index 9db213655d..2afbd8e4ba 100644
--- a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml
+++ b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml
@@ -3,11 +3,16 @@ id: 8b2e84cd-6db0-47e9-badc-75c17df1995f
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Active Directory Add app role assignment
- to service principal
+description: Logs the addition of an application role assignment to a service principal in Azure Active Directory, including details about the role, service principal, and the user or process performing the action.
+mitre_components:
+- User Account Modification
+- Group Modification
+- Cloud Service Modification
+- Cloud Service Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
+separator_value: Add app role assignment to service principal
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
diff --git a/data_sources/azure_active_directory_add_member_to_role.yml b/data_sources/azure_active_directory_add_member_to_role.yml
index c62d91a8c2..c2dfa64ecb 100644
--- a/data_sources/azure_active_directory_add_member_to_role.yml
+++ b/data_sources/azure_active_directory_add_member_to_role.yml
@@ -3,10 +3,16 @@ id: 1660d196-127f-4678-81b2-472d51711b07
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Active Directory Add member to role
+description: Logs the addition of a member to a directory role in Azure Active Directory, including details about the role, the member added, and the user or process performing the action.
+mitre_components:
+- Group Modification
+- Group Metadata
+- User Account Metadata
+- Cloud Service Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
+separator_value: Add member to role
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
diff --git a/data_sources/azure_active_directory_add_owner_to_application.yml b/data_sources/azure_active_directory_add_owner_to_application.yml
index 6e3b00d39a..f174ee00b6 100644
--- a/data_sources/azure_active_directory_add_owner_to_application.yml
+++ b/data_sources/azure_active_directory_add_owner_to_application.yml
@@ -3,10 +3,16 @@ id: e895ed56-7be4-4b3a-b782-ecd0f594ec4c
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Active Directory Add owner to application
+description: Logs the addition of an owner to an application in Azure Active Directory, including details about the application, the owner added, and the user or process performing the action.
+mitre_components:
+- User Account Modification
+- Group Modification
+- Cloud Service Modification
+- Cloud Service Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
+separator_value: Add owner to application
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
diff --git a/data_sources/azure_active_directory_add_service_principal.yml b/data_sources/azure_active_directory_add_service_principal.yml
index 798a1dd0c9..d100855262 100644
--- a/data_sources/azure_active_directory_add_service_principal.yml
+++ b/data_sources/azure_active_directory_add_service_principal.yml
@@ -3,10 +3,16 @@ id: fd89d337-e4c0-4162-ad13-bca36f096fe6
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Active Directory Add service principal
+description: Logs the creation of a new service principal in Azure Active Directory, including details about the service principal, associated application, and the user or process performing the action.
+mitre_components:
+- Cloud Service Creation
+- Cloud Service Metadata
+- User Account Metadata
+- Active Directory Object Creation
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
+separator_value: Add service principal
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
diff --git a/data_sources/azure_active_directory_add_unverified_domain.yml b/data_sources/azure_active_directory_add_unverified_domain.yml
index 2cb8e93738..1b06002e40 100644
--- a/data_sources/azure_active_directory_add_unverified_domain.yml
+++ b/data_sources/azure_active_directory_add_unverified_domain.yml
@@ -3,10 +3,16 @@ id: d4c01fb1-3b88-46d3-bd12-9b9e256450f7
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Active Directory Add unverified domain
+description: Logs the addition of an unverified domain to Azure Active Directory, including details about the domain name and the user or process performing the action.
+mitre_components:
+- Domain Registration
+- Cloud Service Modification
+- Cloud Service Metadata
+- Configuration Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
+separator_value: Add unverified domain
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
diff --git a/data_sources/azure_active_directory_consent_to_application.yml b/data_sources/azure_active_directory_consent_to_application.yml
index 9464b69c7a..cc0ee34156 100644
--- a/data_sources/azure_active_directory_consent_to_application.yml
+++ b/data_sources/azure_active_directory_consent_to_application.yml
@@ -3,10 +3,16 @@ id: 4c5d6c49-53e3-4980-a4de-c63e26291ed0
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Active Directory Consent to application
+description: Logs user or admin consent to an application's permissions in Azure Active Directory, including details about the application, granted permissions, and the consenting user or process.
+mitre_components:
+- User Account Modification
+- Cloud Service Modification
+- Cloud Service Metadata
+- Configuration Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
+separator_value: Consent to application
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
diff --git a/data_sources/azure_active_directory_disable_strong_authentication.yml b/data_sources/azure_active_directory_disable_strong_authentication.yml
index 2b1fd79f79..c32bf6b639 100644
--- a/data_sources/azure_active_directory_disable_strong_authentication.yml
+++ b/data_sources/azure_active_directory_disable_strong_authentication.yml
@@ -3,10 +3,15 @@ id: 8f31966d-c496-496d-8837-f7fd11f31255
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Active Directory Disable Strong Authentication
+description: Logs an event when strong authentication methods are disabled in Azure Active Directory.
+mitre_components:
+- User Account Authentication
+- User Account Modification
+- Cloud Service Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
+separator_value: Disable Strong Authentication
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
diff --git a/data_sources/azure_active_directory_enable_account.yml b/data_sources/azure_active_directory_enable_account.yml
index 710007e9f8..d335c79ffc 100644
--- a/data_sources/azure_active_directory_enable_account.yml
+++ b/data_sources/azure_active_directory_enable_account.yml
@@ -3,10 +3,15 @@ id: cb49f3cd-04ad-415c-a5ed-9b27b2829fa7
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Active Directory Enable account
+description: Logs an event when an Azure Active Directory account is enabled.
+mitre_components:
+- User Account Modification
+- User Account Authentication
+- User Account Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
+separator_value: Enable account
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
diff --git a/data_sources/azure_active_directory_invite_external_user.yml b/data_sources/azure_active_directory_invite_external_user.yml
index ebb0a4dea9..d7cb59bbba 100644
--- a/data_sources/azure_active_directory_invite_external_user.yml
+++ b/data_sources/azure_active_directory_invite_external_user.yml
@@ -3,10 +3,15 @@ id: d3818bd5-f283-4518-8b67-df19240c3e40
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Active Directory Invite external user
+description: Logs an event when an external user is invited to join an Azure Active Directory tenant.
+mitre_components:
+- Active Directory Object Creation
+- User Account Creation
+- User Account Authentication
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
+separator_value: Invite external user
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
diff --git a/data_sources/azure_active_directory_reset_password_(by_admin).yml b/data_sources/azure_active_directory_reset_password_(by_admin).yml
index 1247baa3b5..9c4db01f1f 100644
--- a/data_sources/azure_active_directory_reset_password_(by_admin).yml
+++ b/data_sources/azure_active_directory_reset_password_(by_admin).yml
@@ -3,10 +3,15 @@ id: dcd0e4dc-68f8-4b77-a66f-89c57b3afa6b
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Active Directory Reset password (by admin)
+description: Logs an event when an admin resets a user's password in Azure Active Directory.
+mitre_components:
+- User Account Authentication
+- User Account Modification
+- Active Directory Object Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
+separator_value: Reset password (by admin)
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
diff --git a/data_sources/azure_active_directory_set_domain_authentication.yml b/data_sources/azure_active_directory_set_domain_authentication.yml
index 07fbd4945f..c20d10043c 100644
--- a/data_sources/azure_active_directory_set_domain_authentication.yml
+++ b/data_sources/azure_active_directory_set_domain_authentication.yml
@@ -3,10 +3,15 @@ id: e7bcdab9-908c-40ab-ba38-5db54fa87750
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Active Directory Set domain authentication
+description: Logs an event when the authentication method for a domain in Azure Active Directory is set or modified.
+mitre_components:
+- Active Directory Object Modification
+- User Account Authentication
+- Cloud Service Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
+separator_value: Set domain authentication
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
diff --git a/data_sources/azure_active_directory_sign_in_activity.yml b/data_sources/azure_active_directory_sign_in_activity.yml
index 71e28dc986..3fca810c95 100644
--- a/data_sources/azure_active_directory_sign_in_activity.yml
+++ b/data_sources/azure_active_directory_sign_in_activity.yml
@@ -3,10 +3,15 @@ id: f9ed0a3a-9e20-4198-a035-d0a29593fbe0
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Active Directory Sign-in activity
+description: Logs an event when a user attempts to sign into Azure Active Directory, capturing authentication details and outcomes.
+mitre_components:
+- User Account Authentication
+- Logon Session Creation
+- User Account Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
+separator_value: Sign-in activity
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
diff --git a/data_sources/azure_active_directory_update_application.yml b/data_sources/azure_active_directory_update_application.yml
index 821d432ecf..cc9da95340 100644
--- a/data_sources/azure_active_directory_update_application.yml
+++ b/data_sources/azure_active_directory_update_application.yml
@@ -3,10 +3,15 @@ id: 2c08188a-ba25-496e-87c7-803cf28b6c90
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Active Directory Update application
+description: Logs an event when an application in Azure Active Directory is updated, such as changes to its settings or permissions.
+mitre_components:
+- Service Modification
+- User Account Modification
+- Cloud Service Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
+separator_value: Update application
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
diff --git a/data_sources/azure_active_directory_update_authorization_policy.yml b/data_sources/azure_active_directory_update_authorization_policy.yml
index 6d43b471e6..37b2c7c4be 100644
--- a/data_sources/azure_active_directory_update_authorization_policy.yml
+++ b/data_sources/azure_active_directory_update_authorization_policy.yml
@@ -3,10 +3,15 @@ id: c5b7ffcd-73d8-4fe5-afd8-b1218d715c0c
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Active Directory Update authorization policy
+description: Logs an event when an authorization policy is updated in Azure Active Directory.
+mitre_components:
+- User Account Modification
+- Group Modification
+- Active Directory Object Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
+separator_value: Update authorization policy
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
diff --git a/data_sources/azure_active_directory_update_user.yml b/data_sources/azure_active_directory_update_user.yml
index 4efa2a3816..a37a792233 100644
--- a/data_sources/azure_active_directory_update_user.yml
+++ b/data_sources/azure_active_directory_update_user.yml
@@ -3,10 +3,14 @@ id: 5495c90a-047c-4b8e-b2fe-1db6282d3872
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Active Directory Update user
+description: Logs an event when a user account is updated in Azure Active Directory.
+mitre_components:
+- User Account Modification
+- User Account Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
+separator_value: Update user
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
diff --git a/data_sources/azure_active_directory_user_registered_security_info.yml b/data_sources/azure_active_directory_user_registered_security_info.yml
index f7bef825fe..ae651e960d 100644
--- a/data_sources/azure_active_directory_user_registered_security_info.yml
+++ b/data_sources/azure_active_directory_user_registered_security_info.yml
@@ -3,11 +3,14 @@ id: b63240de-8a01-4ba8-8987-89d18d4b375d
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Active Directory User registered security
- info
+description: Logs an event when a user registers or updates their security information in Azure Active Directory.
+mitre_components:
+- User Account Modification
+- User Account Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
+separator_value: User registered security info
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml
index 8e30686b23..290688b816 100644
--- a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml
+++ b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml
@@ -3,11 +3,15 @@ id: 2ab182e7-feda-4249-9418-32710b55a885
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Audit Create or Update an Azure Automation
- account
+description: Logs an event when an Azure Automation account is created or updated.
+mitre_components:
+- Cloud Service Creation
+- Cloud Service Modification
+- Cloud Service Metadata
source: mscs:azure:audit
sourcetype: mscs:azure:audit
separator: operationName.localizedValue
+separator_value: Create or Update an Azure Automation account
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml
index 024427c038..e7ee46661a 100644
--- a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml
+++ b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml
@@ -3,11 +3,14 @@ id: 2bd83221-7a8b-436f-9b2b-efa1d44d009e
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Audit Create or Update an Azure Automation
- Runbook
+description: Logs an event when a new Azure Automation Runbook is created or an existing one is updated.
+mitre_components:
+- Scheduled Job Modification
+- Scheduled Job Creation
source: mscs:azure:audit
sourcetype: mscs:azure:audit
separator: operationName.localizedValue
+separator_value: Create or Update an Azure Automation Runbook
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml
index 35fccd817e..584e44aaff 100644
--- a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml
+++ b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml
@@ -3,11 +3,15 @@ id: 575faeb2-09d0-4849-b1f6-eae241f26ff2
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Azure Audit Create or Update an Azure Automation
- webhook
+description: Logs an event when a webhook is created or updated in Azure Automation.
+mitre_components:
+- Scheduled Job Modification
+- Cloud Service Modification
+- Scheduled Job Metadata
source: mscs:azure:audit
sourcetype: mscs:azure:audit
separator: operationName.localizedValue
+separator_value: Create or Update an Azure Automation webhook
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
diff --git a/data_sources/bro.yml b/data_sources/bro.yml
deleted file mode 100644
index 72d2cd5415..0000000000
--- a/data_sources/bro.yml
+++ /dev/null
@@ -1,9 +0,0 @@
-name: Bro
-id: c5d9612b-0ffd-44d3-8247-3cf3486ec5e2
-version: 1
-date: '2024-07-18'
-author: Patrick Bareiss, Splunk
-description: Data source object for Bro
-source: bro:http:json
-sourcetype: bro:http:json
-supported_TA: []
diff --git a/data_sources/bro_conn.yml b/data_sources/bro_conn.yml
new file mode 100644
index 0000000000..d4ed14b382
--- /dev/null
+++ b/data_sources/bro_conn.yml
@@ -0,0 +1,15 @@
+name: Bro conn
+id: c5a7e93b-2172-45a7-a7e9-3b217255a7f5
+version: 1
+date: '2025-20-01'
+author: Jacob Delgado, SnapAttack
+description: Logs network connection metadata captured by Zeek (formerly Bro), including details such as source and destination IPs, ports, connection state, and protocol.
+mitre_components:
+- Network Connection Creation
+- Network Traffic Flow
+- Response Metadata
+- Application Log Content
+source: bro:conn:json
+sourcetype: bro:conn:json
+supported_TA: []
+
diff --git a/data_sources/bro_dns.yml b/data_sources/bro_dns.yml
new file mode 100644
index 0000000000..2b7cf87568
--- /dev/null
+++ b/data_sources/bro_dns.yml
@@ -0,0 +1,15 @@
+name: Bro dns
+id: a4576cbf-06cc-4ed0-976c-bf06ccaed011
+version: 1
+date: '2025-20-01'
+author: Jacob Delgado, SnapAttack
+description: Logs DNS queries and responses captured by Zeek (formerly Bro), including details such as queried domains, resolved IPs, query types, and response codes.
+mitre_components:
+- Active DNS
+- Passive DNS
+- Network Traffic Content
+- Network Traffic Flow
+- Response Metadata
+source: bro:dns:json
+sourcetype: bro:dns:json
+supported_TA: []
diff --git a/data_sources/bro_files.yml b/data_sources/bro_files.yml
new file mode 100644
index 0000000000..b8b0f83dc8
--- /dev/null
+++ b/data_sources/bro_files.yml
@@ -0,0 +1,15 @@
+name: Bro files
+id: f72d34d0-3495-4826-ad34-d03495782633
+version: 1
+date: '2025-20-01'
+author: Jacob Delgado, SnapAttack
+description: Logs metadata about files transferred over the network captured by Zeek (formerly Bro), including details such as file names, hashes, MIME types, and transfer protocols.
+mitre_components:
+- File Metadata
+- Network Traffic Content
+- Network Traffic Flow
+- Response Metadata
+- Application Log Content
+source: bro:files:json
+sourcetype: bro:files:json
+supported_TA: []
diff --git a/data_sources/bro_http.yml b/data_sources/bro_http.yml
new file mode 100644
index 0000000000..f0e879954e
--- /dev/null
+++ b/data_sources/bro_http.yml
@@ -0,0 +1,15 @@
+name: Bro http
+id: c5d9612b-0ffd-44d3-8247-3cf3486ec5e2
+version: 2
+date: '2024-07-18'
+author: Patrick Bareiss, Splunk
+description: Logs HTTP traffic analyzed by Zeek (formerly Bro), including details such as request methods, URLs, user agents, response codes, and headers.
+mitre_components:
+- Network Traffic Content
+- Network Traffic Flow
+- Response Content
+- Response Metadata
+- Application Log Content
+source: bro:http:json
+sourcetype: bro:http:json
+supported_TA: []
diff --git a/data_sources/bro_loaded_scripts.yml b/data_sources/bro_loaded_scripts.yml
new file mode 100644
index 0000000000..e6f2764604
--- /dev/null
+++ b/data_sources/bro_loaded_scripts.yml
@@ -0,0 +1,14 @@
+name: Bro loaded_scripts
+id: 81e08a21-a735-42b1-a08a-21a73582b1bf
+version: 1
+date: '2025-20-01'
+author: Jacob Delgado, SnapAttack
+description: Logs details about the scripts loaded by Zeek (formerly Bro) during initialization, including script names and paths.
+mitre_components:
+- Application Log Content
+- Configuration Modification
+- Script Execution
+- OS API Execution
+source: bro:loaded_scripts:json
+sourcetype: bro:loaded_scripts:json
+supported_TA: []
diff --git a/data_sources/bro_ntp.yml b/data_sources/bro_ntp.yml
new file mode 100644
index 0000000000..15ea709585
--- /dev/null
+++ b/data_sources/bro_ntp.yml
@@ -0,0 +1,14 @@
+name: Bro ntp
+id: 3f64a544-47a4-4958-a4a5-4447a47958df
+version: 1
+date: '2025-20-01'
+author: Jacob Delgado, SnapAttack
+description: Logs Network Time Protocol (NTP) activity captured by Zeek (formerly Bro), including details such as NTP requests, responses, and server metadata.
+mitre_components:
+- Network Traffic Flow
+- Network Traffic Content
+- Response Metadata
+- Application Log Content
+source: bro:ntp:json
+sourcetype: bro:ntp:json
+supported_TA: []
diff --git a/data_sources/bro_ocsp.yml b/data_sources/bro_ocsp.yml
new file mode 100644
index 0000000000..c0da63d49e
--- /dev/null
+++ b/data_sources/bro_ocsp.yml
@@ -0,0 +1,15 @@
+name: Bro ocsp
+id: d20909ab-70be-409a-8909-ab70be609af1
+version: 1
+date: '2025-20-01'
+author: Jacob Delgado, SnapAttack
+description: Logs Online Certificate Status Protocol (OCSP) activity captured by Zeek (formerly Bro), including details such as certificate validation requests and responses.
+mitre_components:
+- Certificate Registration
+- Network Traffic Flow
+- Network Traffic Content
+- Response Metadata
+- Application Log Content
+source: bro:ocsp:json
+sourcetype: bro:ocsp:json
+supported_TA: []
\ No newline at end of file
diff --git a/data_sources/bro_ssl.yml b/data_sources/bro_ssl.yml
new file mode 100644
index 0000000000..2616ce8186
--- /dev/null
+++ b/data_sources/bro_ssl.yml
@@ -0,0 +1,15 @@
+name: Bro ssl
+id: 22c637eb-f62e-41f0-8637-ebf62e11f0a8
+version: 1
+date: '2025-20-01'
+author: Jacob Delgado, SnapAttack
+description: Logs SSL/TLS handshake and session details captured by Zeek (formerly Bro), including certificates, cipher suites, and session information.
+mitre_components:
+- Certificate Registration
+- Network Traffic Flow
+- Network Traffic Content
+- Response Metadata
+- Application Log Content
+source: bro:ssl:json
+sourcetype: bro:ssl:json
+supported_TA: []
\ No newline at end of file
diff --git a/data_sources/bro_weird.yml b/data_sources/bro_weird.yml
new file mode 100644
index 0000000000..346236e53d
--- /dev/null
+++ b/data_sources/bro_weird.yml
@@ -0,0 +1,15 @@
+name: Bro weird
+id: e03762c5-c4b8-44e3-b762-c5c4b8e4e3b6
+version: 1
+date: '2025-20-01'
+author: Jacob Delgado, SnapAttack
+description: Logs anomalous or unexpected network behaviors identified by Zeek (formerly Bro), including protocol violations and unusual traffic patterns.
+mitre_components:
+- Network Traffic Flow
+- Network Traffic Content
+- Response Metadata
+- Application Log Content
+- Host Status
+source: bro:weird:json
+sourcetype: bro:weird:json
+supported_TA: []
diff --git a/data_sources/bro_x509.yml b/data_sources/bro_x509.yml
new file mode 100644
index 0000000000..8c41ee6ac1
--- /dev/null
+++ b/data_sources/bro_x509.yml
@@ -0,0 +1,15 @@
+name: Bro x509
+id: e8792367-64b0-47e9-b923-6764b0f7e936
+version: 1
+date: '2025-20-01'
+author: Jacob Delgado, SnapAttack
+description: Logs details about X.509 certificates observed in network traffic captured by Zeek (formerly Bro), including certificate fields, validity periods, and issuers.
+mitre_components:
+- Certificate Registration
+- Network Traffic Content
+- Response Metadata
+- Application Log Content
+- Host Status
+source: bro:x509:json
+sourcetype: bro:x509:json
+supported_TA: []
\ No newline at end of file
diff --git a/data_sources/circleci.yml b/data_sources/circleci.yml
index 9dfcb06b20..6cf9ff1092 100644
--- a/data_sources/circleci.yml
+++ b/data_sources/circleci.yml
@@ -3,7 +3,13 @@ id: 34ad06fc-a296-4ab5-8315-2f07714948e3
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for CircleCI
+description: Logs activities related to CI/CD pipelines executed in CircleCI, including job execution, workflow progress, and configuration changes.
+mitre_components:
+- Scheduled Job Execution
+- Scheduled Job Metadata
+- Application Log Content
+- Configuration Modification
+- Host Status
source: circleci
sourcetype: circleci
supported_TA:
diff --git a/data_sources/crowdstrike_processrollup2.yml b/data_sources/crowdstrike_processrollup2.yml
index 83b05821b9..e9074afdd5 100644
--- a/data_sources/crowdstrike_processrollup2.yml
+++ b/data_sources/crowdstrike_processrollup2.yml
@@ -3,10 +3,17 @@ id: cbb06880-9dd9-4542-ac60-bd6e5d3c3e4e
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for CrowdStrike ProcessRollup2
+description: Logs process-related activities captured by CrowdStrike, including process creation, termination, and metadata such as hashes, parent processes, and command-line arguments.
+mitre_components:
+- Process Creation
+- Process Termination
+- Process Metadata
+- Command Execution
+- OS API Execution
source: crowdstrike
sourcetype: crowdstrike:events:sensor
separator: event_simpleName
+separator_value: ProcessRollup2
supported_TA:
- name: Splunk Add-on for CrowdStrike FDR
url: https://splunkbase.splunk.com/app/5579
diff --git a/data_sources/crushftp.yml b/data_sources/crushftp.yml
index 7c3f19a528..04a5b0827c 100644
--- a/data_sources/crushftp.yml
+++ b/data_sources/crushftp.yml
@@ -3,7 +3,13 @@ id: 8a42ace5-e4c8-4653-80cf-1b8e7e6024ef
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for CrushFTP
+description: Logs activities related to file transfers and user interactions in CrushFTP, including file uploads, downloads, user authentication, and session details.
+mitre_components:
+- File Access
+- File Metadata
+- User Account Authentication
+- Logon Session Metadata
+- Network Traffic Content
source: crushftp
sourcetype: crushftp:sessionlogs
supported_TA: []
diff --git a/data_sources/g_suite_drive.yml b/data_sources/g_suite_drive.yml
index 0b3b02e79e..a07ee5cd8c 100644
--- a/data_sources/g_suite_drive.yml
+++ b/data_sources/g_suite_drive.yml
@@ -3,7 +3,13 @@ id: 5f79120f-a235-4468-bd0d-55203758ac22
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for G Suite Drive
+description: Logs activities related to Google Drive in G Suite, including file creation, modification, sharing, and access details.
+mitre_components:
+- File Access
+- File Creation
+- File Modification
+- Cloud Storage Access
+- Cloud Storage Metadata
source: http:gsuite
sourcetype: gsuite:drive:json
supported_TA:
diff --git a/data_sources/g_suite_gmail.yml b/data_sources/g_suite_gmail.yml
index 7f628c7174..0a6ddc9596 100644
--- a/data_sources/g_suite_gmail.yml
+++ b/data_sources/g_suite_gmail.yml
@@ -3,7 +3,12 @@ id: 706c3978-41de-406b-b6e0-75bd01e12a5d
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for G Suite Gmail
+description: Logs Gmail activities in G Suite, including email sending, receiving, and access details, as well as potential security-related events.
+mitre_components:
+- Application Log Content
+- User Account Metadata
+- Email Metadata
+- Cloud Service Metadata
source: http:gsuite
sourcetype: gsuite:gmail:bigquery
supported_TA:
diff --git a/data_sources/github.yml b/data_sources/github.yml
index 2c5c88084d..e9125f7f07 100644
--- a/data_sources/github.yml
+++ b/data_sources/github.yml
@@ -3,7 +3,13 @@ id: 88aa4632-3c3e-43f6-a00a-998d71f558e3
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for GitHub
+description: Logs activities on GitHub repositories, including push events, pull requests, issue creation, and user authentication events.
+mitre_components:
+- User Account Authentication
+- Configuration Modification
+- Application Log Content
+- User Account Metadata
+- Scheduled Job Metadata
source: github
sourcetype: aws:firehose:json
supported_TA:
diff --git a/data_sources/google_workspace_login_failure.yml b/data_sources/google_workspace_login_failure.yml
index 11f79d2ad5..4f49e2a565 100644
--- a/data_sources/google_workspace_login_failure.yml
+++ b/data_sources/google_workspace_login_failure.yml
@@ -3,10 +3,16 @@ id: cabec7cf-4008-4899-b47e-39c34a9a1255
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Google Workspace login_failure
+description: Logs failed login attempts to Google Workspace accounts, including details about the user, IP address, and reason for failure.
+mitre_components:
+- User Account Authentication
+- Logon Session Metadata
+- User Account Metadata
+- Application Log Content
source: gws:reports:admin
sourcetype: gws:reports:admin
separator: event.name
+separator_value: login_failure
supported_TA:
- name: Splunk Add-on for Google Workspace
url: https://splunkbase.splunk.com/app/5556
diff --git a/data_sources/google_workspace_login_success.yml b/data_sources/google_workspace_login_success.yml
index 4a2bd0308c..723b1b2724 100644
--- a/data_sources/google_workspace_login_success.yml
+++ b/data_sources/google_workspace_login_success.yml
@@ -3,10 +3,16 @@ id: bffe8013-9cdf-4fe6-9c1b-6784391a4951
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Google Workspace login_success
+description: Logs successful login attempts to Google Workspace accounts, including details about the user, IP address, and session metadata.
+mitre_components:
+- User Account Authentication
+- Logon Session Creation
+- User Account Metadata
+- Logon Session Metadata
source: gws:reports:admin
sourcetype: gws:reports:admin
separator: event.name
+separator_value: login_success
supported_TA:
- name: Splunk Add-on for Google Workspace
url: https://splunkbase.splunk.com/app/5556
diff --git a/data_sources/ivanti_vtm_audit.yml b/data_sources/ivanti_vtm_audit.yml
index 0bdb54223a..a10ae34f02 100644
--- a/data_sources/ivanti_vtm_audit.yml
+++ b/data_sources/ivanti_vtm_audit.yml
@@ -3,7 +3,13 @@ id: b04be6e5-2002-4a49-8722-52285635b8f5
version: 1
date: '2024-08-19'
author: Michael Haag, Splunk
-description: Data source object for Ivanti Virtual Traffic Manager (vTM)
+description: Logs administrative and operational activities in Ivanti Virtual Traffic Manager (VTM), including configuration changes, user actions, and system events.
+mitre_components:
+- Configuration Modification
+- Application Log Content
+- User Account Metadata
+- Host Status
+- Service Modification
source: ivanti_vtm
sourcetype: ivanti_vtm_audit
supported_TA: []
diff --git a/data_sources/kubernetes_audit.yml b/data_sources/kubernetes_audit.yml
index 9ca3815448..9035f6c381 100644
--- a/data_sources/kubernetes_audit.yml
+++ b/data_sources/kubernetes_audit.yml
@@ -3,7 +3,14 @@ id: 6c25181a-0c07-4aaf-90e6-77ab1f0e6699
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Kubernetes Audit
+description: Logs activities within a Kubernetes cluster, including API server requests, resource access, configuration changes, and user authentication events.
+mitre_components:
+- Pod Metadata
+- Pod Modification
+- Cluster Metadata
+- User Account Authentication
+- Configuration Modification
+- Application Log Content
source: kubernetes
sourcetype: _json
supported_TA: []
diff --git a/data_sources/kubernetes_falco.yml b/data_sources/kubernetes_falco.yml
index 568d4be771..6b21e39781 100644
--- a/data_sources/kubernetes_falco.yml
+++ b/data_sources/kubernetes_falco.yml
@@ -3,7 +3,14 @@ id: 23c0eeed-840a-4711-a41b-6819c1ffbba5
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Kubernetes Falco
+description: Logs suspicious or anomalous activities within a Kubernetes environment detected by Falco, including system calls, file access, and network activity.
+mitre_components:
+- File Access
+- Network Traffic Content
+- Process Creation
+- Process Modification
+- Application Log Content
+- Host Status
source: kubernetes
sourcetype: kube:container:falco
supported_TA: []
diff --git a/data_sources/linux_auditd_add_user.yml b/data_sources/linux_auditd_add_user.yml
index c1d4736a2e..1b6bb6ba17 100644
--- a/data_sources/linux_auditd_add_user.yml
+++ b/data_sources/linux_auditd_add_user.yml
@@ -3,9 +3,16 @@ id: 30f79353-e1d2-4585-8735-1e0359559f3f
version: 1
date: '2024-08-08'
author: Teoderick Contreras, Splunk
-description: Data source object for Linux Auditd Add User Type
+description: Logs activities related to the addition of a new user account on a Linux system, including details about the username, UID, and the process initiating the action.
+mitre_components:
+- User Account Creation
+- User Account Metadata
+- OS API Execution
+- Application Log Content
source: /var/log/audit/audit.log
sourcetype: linux:audit
+separator: type
+separator_value: ADD_USER
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
- name: Splunk Add-on for Unix and Linux
diff --git a/data_sources/linux_auditd_execve.yml b/data_sources/linux_auditd_execve.yml
index 0752725a0f..f70b98a8f9 100644
--- a/data_sources/linux_auditd_execve.yml
+++ b/data_sources/linux_auditd_execve.yml
@@ -3,9 +3,17 @@ id: 9ef6364d-cc67-480e-8448-3306829a6a24
version: 1
date: '2024-08-08'
author: Teoderick Contreras, Splunk
-description: Data source object for Linux Auditd Execve Type
+description: Logs the execution of processes on a Linux system, including details about the executed command, arguments, and the initiating process.
+mitre_components:
+- Command Execution
+- Process Creation
+- Process Metadata
+- OS API Execution
+- Application Log Content
source: /var/log/audit/audit.log
sourcetype: linux:audit
+separator: type
+separator_value: EXECVE
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
- name: Splunk Add-on for Unix and Linux
diff --git a/data_sources/linux_auditd_path.yml b/data_sources/linux_auditd_path.yml
index 03703ad47b..3dd0c9d22a 100644
--- a/data_sources/linux_auditd_path.yml
+++ b/data_sources/linux_auditd_path.yml
@@ -3,9 +3,17 @@ id: 3d86125c-0496-4a5a-aae3-0d355a4f3d7d
version: 1
date: '2024-08-08'
author: Teoderick Contreras, Splunk
-description: Data source object for Linux Auditd Path Type
+description: Logs file system access events on a Linux system, including details about file paths, permissions, and associated processes.
+mitre_components:
+- File Access
+- File Metadata
+- Process Metadata
+- OS API Execution
+- Application Log Content
source: /var/log/audit/audit.log
sourcetype: linux:audit
+separator: type
+separator_value: PATH
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
- name: Splunk Add-on for Unix and Linux
diff --git a/data_sources/linux_auditd_proctitle.yml b/data_sources/linux_auditd_proctitle.yml
index 4831ba4585..e0038b6a94 100644
--- a/data_sources/linux_auditd_proctitle.yml
+++ b/data_sources/linux_auditd_proctitle.yml
@@ -3,7 +3,14 @@ id: 5a25984a-2789-400a-858b-d75c923e06b1
version: 1
date: '2024-08-08'
author: Teoderick Contreras, Splunk
-description: Data source object for Linux Auditd Proctitle Type
+description: Logs the full command-line arguments of a process execution on a Linux system, providing visibility into the executed command and its parameters.
+mitre_components:
+- Command Execution
+- Process Metadata
+- OS API Execution
+- Application Log Content
+separator: type
+separator_value: PROCTITLE
source: /var/log/audit/audit.log
sourcetype: linux:audit
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
diff --git a/data_sources/linux_auditd_service_stop.yml b/data_sources/linux_auditd_service_stop.yml
index 151da0bdca..3c4f41bcbf 100644
--- a/data_sources/linux_auditd_service_stop.yml
+++ b/data_sources/linux_auditd_service_stop.yml
@@ -3,7 +3,14 @@ id: 0643483c-bc62-455c-8d6e-1630e5f0e00d
version: 1
date: '2024-08-08'
author: Teoderick Contreras, Splunk
-description: Data source object for Linux Auditd Service Stop Type
+description: Logs events related to the stoppage of a service on a Linux system, including details about the service name, the process initiating the stop, and associated timestamps.
+mitre_components:
+- Service Modification
+- Service Metadata
+- OS API Execution
+- Application Log Content
+separator: type
+separator_value: SERVICE_STOP
source: /var/log/audit/audit.log
sourcetype: linux:audit
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
diff --git a/data_sources/linux_auditd_syscall.yml b/data_sources/linux_auditd_syscall.yml
index 73a300e2be..46f043e357 100644
--- a/data_sources/linux_auditd_syscall.yml
+++ b/data_sources/linux_auditd_syscall.yml
@@ -3,9 +3,16 @@ id: 4dff7047-0d43-4096-bb3f-b756c889bbad
version: 1
date: '2024-08-08'
author: Teoderick Contreras, Splunk
-description: Data source object for Linux Auditd Syscall Type
+description: Logs system calls made by processes on a Linux system, including details about the syscall number, arguments, return values, and associated process metadata.
+mitre_components:
+- OS API Execution
+- Process Metadata
+- Application Log Content
+- Host Status
source: /var/log/audit/audit.log
sourcetype: linux:audit
+separator: type
+separator_value: syscall
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
- name: Splunk Add-on for Unix and Linux
diff --git a/data_sources/linux_secure.yml b/data_sources/linux_secure.yml
index cd08575aa2..1f1c1917e3 100644
--- a/data_sources/linux_secure.yml
+++ b/data_sources/linux_secure.yml
@@ -3,7 +3,13 @@ id: 9a47d88b-1b17-49ce-a0ef-b440ddbd98bb
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Linux Secure
+description: Logs authentication and authorization events on a Linux system, including login attempts, SSH connections, and privilege escalation activities.
+mitre_components:
+- User Account Authentication
+- Logon Session Creation
+- Logon Session Metadata
+- User Account Metadata
+- Application Log Content
source: /var/log/secure
sourcetype: linux_secure
supported_TA: []
diff --git a/data_sources/ms365_defender_incident_alerts.yml b/data_sources/ms365_defender_incident_alerts.yml
index 3fd9ba4555..d8114c0151 100644
--- a/data_sources/ms365_defender_incident_alerts.yml
+++ b/data_sources/ms365_defender_incident_alerts.yml
@@ -3,7 +3,13 @@ id: 12345678-90ab-cdef-1234-567890abcdef
version: 1
date: '2024-07-18'
author: Bhavin Patel, Splunk
-description: Data source object for MS365 Defender Incident Alerts
+description: Logs security incidents and correlated alerts in Microsoft 365 Defender, including details about affected assets, threat types, and remediation steps.
+mitre_components:
+- Host Status
+- User Account Metadata
+- Application Log Content
+- Malware Metadata
+- Active Directory Object Access
source: ms365_defender_incident_alerts
sourcetype: ms365:defender:incident:alerts
supported_TA:
diff --git a/data_sources/ms_defender_atp_alerts.yml b/data_sources/ms_defender_atp_alerts.yml
index 92d4452143..09026a67d5 100644
--- a/data_sources/ms_defender_atp_alerts.yml
+++ b/data_sources/ms_defender_atp_alerts.yml
@@ -3,7 +3,13 @@ id: 38f034ed-1598-46c8-95e8-14edf01fdf5d
version: 1
date: '2024-10-30'
author: Bryan Pluta, Bhavin Patel, Splunk
-description: Data source object for Microsoft Defender ATP Alerts
+description: Logs security alerts generated by Microsoft Defender for Endpoint, including information about detected threats, impacted devices, and recommended actions.
+mitre_components:
+- Host Status
+- Malware Metadata
+- Process Metadata
+- User Account Metadata
+- Application Log Content
source: ms_defender_atp_alerts
sourcetype: ms:defender:atp:alerts
supported_TA:
diff --git a/data_sources/nginx_access.yml b/data_sources/nginx_access.yml
index 87238e5c67..052bfc81e4 100644
--- a/data_sources/nginx_access.yml
+++ b/data_sources/nginx_access.yml
@@ -3,7 +3,13 @@ id: c716a418-eab3-4df5-9dff-5420174e3068
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Nginx Access
+description: Logs HTTP/S access events on an Nginx server, including details such as client IP, request method, URI, response status, and user agent.
+mitre_components:
+- Network Traffic Content
+- Network Traffic Flow
+- Response Metadata
+- Application Log Content
+- User Account Metadata
source: /var/log/nginx/access.log
sourcetype: nginx:plus:kv
supported_TA: []
diff --git a/data_sources/o365.yml b/data_sources/o365.yml
index 8102ea7c9f..efbfc3ee05 100644
--- a/data_sources/o365.yml
+++ b/data_sources/o365.yml
@@ -3,7 +3,13 @@ id: b32de97d-0074-4cca-853c-db22c392b6c0
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for O365.
+description: Logs management activities in Microsoft 365, including administrative actions, user activities, and configuration changes across various services.
+mitre_components:
+- User Account Metadata
+- Cloud Service Modification
+- Application Log Content
+- Configuration Modification
+- Active Directory Object Modification
source: o365
sourcetype: o365:management:activity
separator: Operation
diff --git a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml
index 89ececa0d0..4c64614e57 100644
--- a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml
+++ b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml
@@ -3,10 +3,16 @@ id: ce1d7849-a1d2-47fd-b6eb-d7ef854a860c
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for O365 Add app role assignment grant to user.
+description: Logs the assignment of an application role grant to a user in Microsoft 365, including details about the role, user, and application involved.
+mitre_components:
+- User Account Modification
+- Group Modification
+- Cloud Service Modification
+- Cloud Service Metadata
source: o365
sourcetype: o365:management:activity
separator: Operation
+separator_value: Add app role assignment grant to user.
supported_TA:
- name: Splunk Add-on for Microsoft Office 365
url: https://splunkbase.splunk.com/app/4055
diff --git a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml
index 365604ba84..1549f8b091 100644
--- a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml
+++ b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml
@@ -3,10 +3,16 @@ id: 785ba57a-ba7b-474e-97c8-9474e6e00b3a
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for O365 Add app role assignment to service principal.
+description: Logs the assignment of an application role to a service principal in Microsoft 365, including details about the role, service principal, and application involved.
+mitre_components:
+- Cloud Service Modification
+- Cloud Service Metadata
+- User Account Metadata
+- Group Modification
source: o365
sourcetype: o365:management:activity
separator: Operation
+separator_value: Add app role assignment to service principal.
supported_TA:
- name: Splunk Add-on for Microsoft Office 365
url: https://splunkbase.splunk.com/app/4055
diff --git a/data_sources/o365_add_mailboxpermission.yml b/data_sources/o365_add_mailboxpermission.yml
index c4869abc7a..e98765f07b 100644
--- a/data_sources/o365_add_mailboxpermission.yml
+++ b/data_sources/o365_add_mailboxpermission.yml
@@ -3,10 +3,16 @@ id: 9c0babdb-bb15-449e-abba-0a9cdb3fc061
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for O365 Add-MailboxPermission
+description: Logs the addition of mailbox permissions in Microsoft 365, including details about the mailbox, granted permissions, and the user or administrator performing the action.
+mitre_components:
+- User Account Modification
+- User Account Metadata
+- Active Directory Object Modification
+- Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
+separator_value: Add-MailboxPermission
supported_TA:
- name: Splunk Add-on for Microsoft Office 365
url: https://splunkbase.splunk.com/app/4055
diff --git a/data_sources/o365_add_member_to_role_.yml b/data_sources/o365_add_member_to_role_.yml
index c2403e0b25..3fc466dba1 100644
--- a/data_sources/o365_add_member_to_role_.yml
+++ b/data_sources/o365_add_member_to_role_.yml
@@ -3,10 +3,16 @@ id: 8b949f7c-4b5d-404f-9694-d7403c4ec096
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for O365 Add member to role.
+description: Logs the addition of a member to a role in Microsoft 365, including details about the role, the added member, and the user or administrator performing the action.
+mitre_components:
+- Group Modification
+- Group Metadata
+- User Account Metadata
+- Cloud Service Modification
source: o365
sourcetype: o365:management:activity
separator: Operation
+separator_value: Add member to role.
supported_TA:
- name: Splunk Add-on for Microsoft Office 365
url: https://splunkbase.splunk.com/app/4055
diff --git a/data_sources/o365_add_owner_to_application_.yml b/data_sources/o365_add_owner_to_application_.yml
index fdeccc791b..71caf3f806 100644
--- a/data_sources/o365_add_owner_to_application_.yml
+++ b/data_sources/o365_add_owner_to_application_.yml
@@ -3,10 +3,16 @@ id: da012cbf-af6e-40ee-a1ba-32a5f8da8f8a
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for O365 Add owner to application.
+description: Logs the addition of an owner to an application in Microsoft 365, including details about the application, the new owner, and the user or administrator performing the action.
+mitre_components:
+- User Account Modification
+- Group Modification
+- Cloud Service Modification
+- Cloud Service Metadata
source: o365
sourcetype: o365:management:activity
separator: Operation
+separator_value: Add owner to application.
supported_TA:
- name: Splunk Add-on for Microsoft Office 365
url: https://splunkbase.splunk.com/app/4055
diff --git a/data_sources/o365_add_service_principal_.yml b/data_sources/o365_add_service_principal_.yml
index ae338dcc71..8511ac4c76 100644
--- a/data_sources/o365_add_service_principal_.yml
+++ b/data_sources/o365_add_service_principal_.yml
@@ -3,10 +3,16 @@ id: 9c1ef9f5-bc30-4a47-a1bd-cb34484ee778
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for O365 Add service principal.
+description: Logs the addition of a new service principal in Microsoft 365, including details about the associated application and the action initiator.
+mitre_components:
+- Cloud Service Creation
+- Cloud Service Metadata
+- User Account Metadata
+- Active Directory Object Creation
source: o365
sourcetype: o365:management:activity
separator: Operation
+separator_value: Add service principal.
supported_TA:
- name: Splunk Add-on for Microsoft Office 365
url: https://splunkbase.splunk.com/app/4055
diff --git a/data_sources/o365_change_user_license_.yml b/data_sources/o365_change_user_license_.yml
index 17222c9261..2cceff2f8a 100644
--- a/data_sources/o365_change_user_license_.yml
+++ b/data_sources/o365_change_user_license_.yml
@@ -3,10 +3,16 @@ id: 1029a20d-3d0d-4fb9-b5e2-22ac5380b20a
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for O365 Change user license.
+description: Logs changes to user licenses in Microsoft 365, including additions, removals, or updates to service plans associated with a user account.
+mitre_components:
+- User Account Modification
+- User Account Metadata
+- Cloud Service Modification
+- Configuration Modification
source: o365
sourcetype: o365:management:activity
separator: Operation
+separator_value: Change user license.
supported_TA:
- name: Splunk Add-on for Microsoft Office 365
url: https://splunkbase.splunk.com/app/4055
diff --git a/data_sources/o365_consent_to_application_.yml b/data_sources/o365_consent_to_application_.yml
index 4b96c68d96..a5df3bc9f2 100644
--- a/data_sources/o365_consent_to_application_.yml
+++ b/data_sources/o365_consent_to_application_.yml
@@ -3,10 +3,16 @@ id: 0a15a464-ef51-4614-9a07-a216eb9817db
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for O365 Consent to application.
+description: Logs user or administrator consent to an application's permissions in Microsoft 365, including details about the application, granted permissions, and the consenting user or process.
+mitre_components:
+- User Account Modification
+- Cloud Service Modification
+- Cloud Service Metadata
+- Configuration Modification
source: o365
sourcetype: o365:management:activity
separator: Operation
+separator_value: Consent to application.
supported_TA:
- name: Splunk Add-on for Microsoft Office 365
url: https://splunkbase.splunk.com/app/4055
diff --git a/data_sources/o365_disable_strong_authentication_.yml b/data_sources/o365_disable_strong_authentication_.yml
index 53f37fa0ab..ea3fb70491 100644
--- a/data_sources/o365_disable_strong_authentication_.yml
+++ b/data_sources/o365_disable_strong_authentication_.yml
@@ -3,10 +3,16 @@ id: 235381c4-382a-4183-b818-a51c3ce12187
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for O365 Disable Strong Authentication.
+description: Logs the disabling of strong authentication (e.g., multi-factor authentication) for a user or group in Microsoft 365, including details about the affected accounts and the action initiator.
+mitre_components:
+- User Account Modification
+- Group Modification
+- Configuration Modification
+- Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
+separator_value: Disable Strong Authentication.
supported_TA:
- name: Splunk Add-on for Microsoft Office 365
url: https://splunkbase.splunk.com/app/4055
diff --git a/data_sources/o365_mailitemsaccessed.yml b/data_sources/o365_mailitemsaccessed.yml
index d2bad265dc..bc03fd713a 100644
--- a/data_sources/o365_mailitemsaccessed.yml
+++ b/data_sources/o365_mailitemsaccessed.yml
@@ -3,10 +3,16 @@ id: 3d5188eb-341a-4b46-9caa-aade4047d027
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for O365 MailItemsAccessed
+description: Logs access to mailbox items in Microsoft 365, including details about the user accessing the items, the accessed content, and the method of access.
+mitre_components:
+- File Access
+- User Account Metadata
+- Application Log Content
+- Active Directory Object Access
source: o365
sourcetype: o365:management:activity
separator: Operation
+separator_value: MailItemsAccessed
supported_TA:
- name: Splunk Add-on for Microsoft Office 365
url: https://splunkbase.splunk.com/app/4055
diff --git a/data_sources/o365_modifyfolderpermissions.yml b/data_sources/o365_modifyfolderpermissions.yml
index bf6d9f1855..76c4e10d20 100644
--- a/data_sources/o365_modifyfolderpermissions.yml
+++ b/data_sources/o365_modifyfolderpermissions.yml
@@ -3,10 +3,16 @@ id: 0a8c1080-68c2-46d7-8324-2e7d97bb6e2f
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for O365 ModifyFolderPermissions
+description: Logs modifications to folder permissions in Microsoft 365, including updates to access levels, user assignments, and sharing settings.
+mitre_components:
+- User Account Modification
+- File Access
+- Active Directory Object Modification
+- Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
+separator_value: ModifyFolderPermissions
supported_TA:
- name: Splunk Add-on for Microsoft Office 365
url: https://splunkbase.splunk.com/app/4055
diff --git a/data_sources/o365_set_company_information_.yml b/data_sources/o365_set_company_information_.yml
index d40cca2fcb..5fab124138 100644
--- a/data_sources/o365_set_company_information_.yml
+++ b/data_sources/o365_set_company_information_.yml
@@ -3,10 +3,16 @@ id: 06c6d576-f032-41e3-b15d-80a434ce13d8
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for O365 Set Company Information.
+description: Logs updates to organizational settings and company information in Microsoft 365, including changes to contact details, branding, and configuration policies.
+mitre_components:
+- Cloud Service Modification
+- Configuration Modification
+- Cloud Service Metadata
+- Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
+separator_value: Set Company Information.
supported_TA:
- name: Splunk Add-on for Microsoft Office 365
url: https://splunkbase.splunk.com/app/4055
diff --git a/data_sources/o365_set_mailbox.yml b/data_sources/o365_set_mailbox.yml
index 30ebad4b33..6849ce100a 100644
--- a/data_sources/o365_set_mailbox.yml
+++ b/data_sources/o365_set_mailbox.yml
@@ -3,10 +3,16 @@ id: db798c5c-928c-4972-bb42-e5f90e35865f
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for O365 Set-Mailbox
+description: Logs changes to mailbox properties in Microsoft 365, including updates to permissions, storage quotas, and configuration settings.
+mitre_components:
+- User Account Modification
+- Active Directory Object Modification
+- User Account Metadata
+- Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
+separator_value: Set-Mailbox
supported_TA:
- name: Splunk Add-on for Microsoft Office 365
url: https://splunkbase.splunk.com/app/4055
diff --git a/data_sources/o365_update_application_.yml b/data_sources/o365_update_application_.yml
index f78faf1948..155f1353ca 100644
--- a/data_sources/o365_update_application_.yml
+++ b/data_sources/o365_update_application_.yml
@@ -3,10 +3,16 @@ id: 62159133-911b-4c63-9e30-a6a8c89195ca
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for O365 Update application.
+description: Logs updates made to applications in Microsoft 365, including changes to configurations, permissions, and role assignments.
+mitre_components:
+- Cloud Service Modification
+- Configuration Modification
+- Cloud Service Metadata
+- Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
+separator_value: Update application.
supported_TA:
- name: Splunk Add-on for Microsoft Office 365
url: https://splunkbase.splunk.com/app/4055
diff --git a/data_sources/o365_update_authorization_policy_.yml b/data_sources/o365_update_authorization_policy_.yml
index b53bce2417..2438a25b16 100644
--- a/data_sources/o365_update_authorization_policy_.yml
+++ b/data_sources/o365_update_authorization_policy_.yml
@@ -3,10 +3,16 @@ id: d40e6a20-4d64-404c-8351-2caae8228d34
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for O365 Update authorization policy.
+description: Logs changes to authorization policies in Microsoft 365, including updates to access controls, permissions, and security settings.
+mitre_components:
+- Cloud Service Modification
+- Configuration Modification
+- User Account Metadata
+- Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
+separator_value: Update authorization policy.
supported_TA:
- name: Splunk Add-on for Microsoft Office 365
url: https://splunkbase.splunk.com/app/4055
diff --git a/data_sources/o365_update_user_.yml b/data_sources/o365_update_user_.yml
index 5497544e68..308a4ac7a4 100644
--- a/data_sources/o365_update_user_.yml
+++ b/data_sources/o365_update_user_.yml
@@ -3,10 +3,16 @@ id: a05fd01e-34d9-4233-9089-11272416b531
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for O365 Update user.
+description: Logs updates to user account properties in Microsoft 365, including changes to roles, permissions, and profile information.
+mitre_components:
+- User Account Modification
+- User Account Metadata
+- Active Directory Object Modification
+- Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
+separator_value: Update user.
supported_TA:
- name: Splunk Add-on for Microsoft Office 365
url: https://splunkbase.splunk.com/app/4055
diff --git a/data_sources/o365_userloggedin.yml b/data_sources/o365_userloggedin.yml
index 540450b496..3296cb188a 100644
--- a/data_sources/o365_userloggedin.yml
+++ b/data_sources/o365_userloggedin.yml
@@ -3,10 +3,16 @@ id: ed29c8c4-4053-419c-b133-16abf2a1c4c9
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for O365 UserLoggedIn
+description: Logs successful login events by users in Microsoft 365, including details about the user account, IP address, and session metadata.
+mitre_components:
+- User Account Authentication
+- Logon Session Creation
+- User Account Metadata
+- Logon Session Metadata
source: o365
sourcetype: o365:management:activity
separator: Operation
+separator_value: UserLoggedIn
supported_TA:
- name: Splunk Add-on for Microsoft Office 365
url: https://splunkbase.splunk.com/app/4055
diff --git a/data_sources/o365_userloginfailed.yml b/data_sources/o365_userloginfailed.yml
index b03d5032ae..dfea247775 100644
--- a/data_sources/o365_userloginfailed.yml
+++ b/data_sources/o365_userloginfailed.yml
@@ -3,10 +3,16 @@ id: 6099b33d-d581-43ed-8401-911862590361
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for O365 UserLoginFailed
+description: Logs failed login attempts by users in Microsoft 365, including details about the user account, IP address, and reason for failure.
+mitre_components:
+- User Account Authentication
+- Logon Session Metadata
+- User Account Metadata
+- Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
+separator_value: UserLoginFailed
supported_TA:
- name: Splunk Add-on for Microsoft Office 365
url: https://splunkbase.splunk.com/app/4055
diff --git a/data_sources/okta.yml b/data_sources/okta.yml
index 816d155e23..27417c8961 100644
--- a/data_sources/okta.yml
+++ b/data_sources/okta.yml
@@ -3,7 +3,13 @@ id: ec26febe-e760-4981-bbee-72e107c7b9d2
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Okta
+description: Logs authentication and administrative activities captured by Okta, including user login attempts, session management, and configuration changes.
+mitre_components:
+- User Account Authentication
+- Logon Session Creation
+- User Account Metadata
+- Configuration Modification
+- Application Log Content
source: Okta
sourcetype: OktaIM2:log
supported_TA:
diff --git a/data_sources/osquery.yml b/data_sources/osquery.yml
index 7244b5e8ce..bd8cb58790 100644
--- a/data_sources/osquery.yml
+++ b/data_sources/osquery.yml
@@ -3,7 +3,13 @@ id: 7ec4d7c8-c1d0-423a-9169-261f6adb74c0
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for osquery
+description: Logs system queries performed using osquery, including details about processes, file access, network activity, and system configurations.
+mitre_components:
+- Process Metadata
+- File Access
+- Network Traffic Content
+- Host Status
+- Application Log Content
source: osquery
sourcetype: osquery:results
supported_TA: []
diff --git a/data_sources/palo_alto_network_threat.yml b/data_sources/palo_alto_network_threat.yml
index 37d07f372d..d9c2937be9 100644
--- a/data_sources/palo_alto_network_threat.yml
+++ b/data_sources/palo_alto_network_threat.yml
@@ -3,7 +3,13 @@ id: 375c2b0e-d216-41ad-9406-200464595209
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Palo Alto Network Threat
+description: Logs detected threats identified by Palo Alto Networks devices, including details about malware, intrusion attempts, and malicious network activity.
+mitre_components:
+- Malware Metadata
+- Network Traffic Content
+- Network Traffic Flow
+- Application Log Content
+- Host Status
source: pan:threat
sourcetype: pan:threat
supported_TA:
diff --git a/data_sources/palo_alto_network_traffic.yml b/data_sources/palo_alto_network_traffic.yml
index 7f42b934b2..02afe2d863 100644
--- a/data_sources/palo_alto_network_traffic.yml
+++ b/data_sources/palo_alto_network_traffic.yml
@@ -3,7 +3,13 @@ id: 182a83bc-c31a-4817-8c7a-263744cec52a
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Palo Alto Network Traffic
+description: Logs network traffic events captured by Palo Alto Networks devices, including details about sessions, protocols, and source and destination IPs.
+mitre_components:
+- Network Traffic Content
+- Network Traffic Flow
+- Network Connection Creation
+- Response Metadata
+- Application Log Content
source: screenconnect_palo_traffic
sourcetype: pan:traffic
supported_TA:
diff --git a/data_sources/pingid.yml b/data_sources/pingid.yml
index 1342a8c5d5..2b77686143 100644
--- a/data_sources/pingid.yml
+++ b/data_sources/pingid.yml
@@ -3,7 +3,13 @@ id: 17890675-61c1-40bd-a88e-6a8e9e246b43
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for PingID
+description: Logs authentication and multi-factor authentication (MFA) events managed by PingID, including user logins, device enrollments, and MFA challenges.
+mitre_components:
+- User Account Authentication
+- Logon Session Metadata
+- User Account Metadata
+- Application Log Content
+- Host Status
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
supported_TA: []
diff --git a/data_sources/powershell_installed_iis_modules.yml b/data_sources/powershell_installed_iis_modules.yml
index a27822830a..cf0b592d7b 100644
--- a/data_sources/powershell_installed_iis_modules.yml
+++ b/data_sources/powershell_installed_iis_modules.yml
@@ -3,7 +3,12 @@ id: 4f2ccf42-3503-4417-a684-bfccf7f0d7b4
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Powershell Installed IIS Modules
+description: Logs the list of installed IIS modules retrieved using PowerShell, including details about their names and statuses.
+mitre_components:
+- Service Metadata
+- Configuration Modification
+- OS API Execution
+- Application Log Content
source: powershell://AppCmdModules
sourcetype: Pwsh:InstalledIISModules
supported_TA: []
diff --git a/data_sources/powershell_script_block_logging_4104.yml b/data_sources/powershell_script_block_logging_4104.yml
index 8333b3c4b2..b5aba9d7f7 100644
--- a/data_sources/powershell_script_block_logging_4104.yml
+++ b/data_sources/powershell_script_block_logging_4104.yml
@@ -3,9 +3,17 @@ id: 5cfd0c72-d989-47a0-92f9-6edc6f8d3564
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Powershell Script Block Logging 4104
+description: Logs detailed content of PowerShell script blocks as they are executed, including the full command text and context for the execution.
+mitre_components:
+- Script Execution
+- Command Execution
+- Process Metadata
+- OS API Execution
+- Application Log Content
source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
sourcetype: xmlwineventlog
+separator: EventID
+separator_value: 4104
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/powershell_sip_inventory.yml b/data_sources/powershell_sip_inventory.yml
index dc02c04217..3d87d08359 100644
--- a/data_sources/powershell_sip_inventory.yml
+++ b/data_sources/powershell_sip_inventory.yml
@@ -3,7 +3,12 @@ id: 5ef5cb5d-1fa8-4567-b48f-27317662cd73
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Powershell SIP Inventory
+description: Logs the inventory of System Integrity Policies (SIP) on a system retrieved via PowerShell, including details about policy configurations and statuses.
+mitre_components:
+- Configuration Modification
+- Host Status
+- Application Log Content
+- OS API Execution
source: powershell://SubjectInterfacePackage
sourcetype: PwSh:SubjectInterfacePackage
supported_TA: []
diff --git a/data_sources/splunk.yml b/data_sources/splunk.yml
index 59728f1060..fdd3c93db4 100644
--- a/data_sources/splunk.yml
+++ b/data_sources/splunk.yml
@@ -3,7 +3,13 @@ id: d8a2c791-460b-4756-a8e5-ecade77b21e3
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Splunk
+description: Logs user interface access events for Splunk, including details about user actions, accessed resources, and authentication information.
+mitre_components:
+- User Account Authentication
+- User Account Metadata
+- Application Log Content
+- Configuration Modification
+- Logon Session Metadata
source: splunkd_ui_access.log
sourcetype: splunkd_ui_access
supported_TA: []
diff --git a/data_sources/splunk_stream_http.yml b/data_sources/splunk_stream_http.yml
index 29db818262..7db141fc5f 100644
--- a/data_sources/splunk_stream_http.yml
+++ b/data_sources/splunk_stream_http.yml
@@ -3,7 +3,13 @@ id: b0070a33-92ed-49e5-8f38-576cdf300710
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Splunk Stream HTTP
+description: Logs HTTP traffic captured by Splunk Stream, including details such as request methods, URLs, headers, response codes, and client-server interactions.
+mitre_components:
+- Network Traffic Content
+- Network Traffic Flow
+- Response Content
+- Response Metadata
+- Application Log Content
source: stream:http
sourcetype: stream:http
supported_TA:
diff --git a/data_sources/splunk_stream_ip.yml b/data_sources/splunk_stream_ip.yml
index d722002f17..9460dfccac 100644
--- a/data_sources/splunk_stream_ip.yml
+++ b/data_sources/splunk_stream_ip.yml
@@ -3,7 +3,13 @@ id: c96f5906-f601-4f32-a26c-482535159bc2
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Splunk Stream IP
+description: Logs IP traffic captured by Splunk Stream, including details about source and destination IPs, protocols, and packet metadata.
+mitre_components:
+- Network Traffic Content
+- Network Traffic Flow
+- Network Connection Creation
+- Response Metadata
+- Application Log Content
source: stream:ip
sourcetype: stream:ip
supported_TA:
diff --git a/data_sources/splunk_stream_tcp.yml b/data_sources/splunk_stream_tcp.yml
index 685c0f6931..e1488a0873 100644
--- a/data_sources/splunk_stream_tcp.yml
+++ b/data_sources/splunk_stream_tcp.yml
@@ -3,7 +3,13 @@ id: 4b1233d1-f80a-4da1-ab27-a5b10ea8a4ce
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Splunk Stream TCP
+description: Logs TCP traffic captured by Splunk Stream, including details about source and destination IPs, ports, connection states, and packet-level metadata.
+mitre_components:
+- Network Traffic Content
+- Network Traffic Flow
+- Network Connection Creation
+- Response Metadata
+- Application Log Content
source: stream:tcp
sourcetype: stream:tcp
supported_TA:
diff --git a/data_sources/suricata.yml b/data_sources/suricata.yml
index 6ad1b8e80c..389920b743 100644
--- a/data_sources/suricata.yml
+++ b/data_sources/suricata.yml
@@ -3,7 +3,13 @@ id: 64b245d4-a4d1-4865-a718-c83d3b939f2e
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Suricata
+description: Logs network traffic and security events detected by Suricata, including details about connections, protocol metadata, and potential threats.
+mitre_components:
+- Network Traffic Content
+- Network Traffic Flow
+- Network Connection Creation
+- Malware Metadata
+- Application Log Content
source: suricata
sourcetype: suricata
supported_TA: []
diff --git a/data_sources/sysmon_eventid_1.yml b/data_sources/sysmon_eventid_1.yml
index 80284e88ac..9af0398f6a 100644
--- a/data_sources/sysmon_eventid_1.yml
+++ b/data_sources/sysmon_eventid_1.yml
@@ -3,10 +3,16 @@ id: b375f4d1-d7ca-4bc0-9103-294825c0af17
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon EventID 1
+description: Logs the creation of a new process, including details such as process ID, parent process, command line arguments, and hashes of the executable.
+mitre_components:
+- Process Creation
+- Process Metadata
+- Command Execution
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
+separator_value: 1
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_10.yml b/data_sources/sysmon_eventid_10.yml
index be7121e719..80713f8dc3 100644
--- a/data_sources/sysmon_eventid_10.yml
+++ b/data_sources/sysmon_eventid_10.yml
@@ -3,10 +3,16 @@ id: 659cd5a8-148a-4c59-ade1-05f41ac1b096
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon EventID 10
+description: Logs events where one process accesses another process, typically for memory reads or injections, including details about the source and target processes.
+mitre_components:
+- Process Access
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
+separator_value: 10
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_11.yml b/data_sources/sysmon_eventid_11.yml
index e206bee06f..ecf23fc755 100644
--- a/data_sources/sysmon_eventid_11.yml
+++ b/data_sources/sysmon_eventid_11.yml
@@ -3,10 +3,17 @@ id: f3db9179-f4f5-416d-bc03-39f4d4ff699e
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon EventID 11
+description: Logs the creation of a new file, including details about the file path, hash information, and associated process metadata.
+mitre_components:
+- File Creation
+- File Metadata
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
+separator_value: 11
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_12.yml b/data_sources/sysmon_eventid_12.yml
index 232ca47a23..665a69a98e 100644
--- a/data_sources/sysmon_eventid_12.yml
+++ b/data_sources/sysmon_eventid_12.yml
@@ -3,10 +3,16 @@ id: 3ef28798-8eaa-4fd2-b074-6f36d08a1b33
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon EventID 12
+description: Logs the creation of a new registry key, including details about the key name, registry path, and associated process metadata.
+mitre_components:
+- Windows Registry Key Creation
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
+separator_value: 12
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_13.yml b/data_sources/sysmon_eventid_13.yml
index ff0aa0690b..d7ed659f74 100644
--- a/data_sources/sysmon_eventid_13.yml
+++ b/data_sources/sysmon_eventid_13.yml
@@ -3,10 +3,16 @@ id: 19cd00ee-f65f-48ca-bb08-64aac28638ce
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon EventID 13
+description: Logs changes to a registry key, including details about the modified key, value, and associated process.
+mitre_components:
+- Windows Registry Key Modification
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
+separator_value: 13
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_15.yml b/data_sources/sysmon_eventid_15.yml
index 335042f192..8ffed5fe5c 100644
--- a/data_sources/sysmon_eventid_15.yml
+++ b/data_sources/sysmon_eventid_15.yml
@@ -3,10 +3,17 @@ id: 95785e02-93b4-47e2-81f1-be326295348e
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon EventID 15
+description: Logs the creation of a new file stream, including details about the file stream's hash, path, and associated process metadata.
+mitre_components:
+- File Creation
+- File Metadata
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
+separator_value: 15
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_17.yml b/data_sources/sysmon_eventid_17.yml
index b1125bf4d3..221feadee2 100644
--- a/data_sources/sysmon_eventid_17.yml
+++ b/data_sources/sysmon_eventid_17.yml
@@ -3,10 +3,13 @@ id: 08924246-c8e8-4c95-a9fc-633c43cc82df
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon EventID 17
+description: Sysmon EventID 17 logs details about the detection of a named pipe.
+mitre_components:
+- Named Pipe Metadata
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
+separator_value: 17
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_18.yml b/data_sources/sysmon_eventid_18.yml
index a1204b64f7..d776df79ee 100644
--- a/data_sources/sysmon_eventid_18.yml
+++ b/data_sources/sysmon_eventid_18.yml
@@ -3,10 +3,16 @@ id: 37eb3554-214e-4e66-af10-c3ffc5b8ca82
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon EventID 18
+description: Logs the connection to a named pipe, including details about the pipe name, source and destination processes, and communication direction.
+mitre_components:
+- Named Pipe Metadata
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
+separator_value: 18
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_20.yml b/data_sources/sysmon_eventid_20.yml
index dfcc795a12..07720a1a9e 100644
--- a/data_sources/sysmon_eventid_20.yml
+++ b/data_sources/sysmon_eventid_20.yml
@@ -3,7 +3,12 @@ id: aeee5374-3203-4286-b744-a8cc4ad1cd7e
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon EventID 20
+description: Logs WMI (Windows Management Instrumentation) consumer activity, including details about the WMI event consumer, associated process, and event data.
+mitre_components:
+- WMI Creation
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
diff --git a/data_sources/sysmon_eventid_21.yml b/data_sources/sysmon_eventid_21.yml
index 89de93b9dc..4fb0386039 100644
--- a/data_sources/sysmon_eventid_21.yml
+++ b/data_sources/sysmon_eventid_21.yml
@@ -3,10 +3,16 @@ id: 304384bc-715e-4958-988b-a8051a91349a
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon EventID 21
+description: Logs activity related to the association of a WMI event consumer with a filter, including details about the consumer, filter, and associated process.
+mitre_components:
+- WMI Creation
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
+separator_value: 21
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_22.yml b/data_sources/sysmon_eventid_22.yml
index eee550143e..5ed15373d4 100644
--- a/data_sources/sysmon_eventid_22.yml
+++ b/data_sources/sysmon_eventid_22.yml
@@ -3,10 +3,17 @@ id: 911538b2-eba7-4d3e-85e8-d82d380c37bf
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon EventID 22
+description: Logs DNS query events, including details about the queried domain, source IP, query type, and response data.
+mitre_components:
+- Passive DNS
+- Active DNS
+- Network Traffic Content
+- Network Traffic Flow
+- Application Log Content
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
+separator_value: 22
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_23.yml b/data_sources/sysmon_eventid_23.yml
index ee91eb49d2..dfcd344c24 100644
--- a/data_sources/sysmon_eventid_23.yml
+++ b/data_sources/sysmon_eventid_23.yml
@@ -3,10 +3,17 @@ id: 5ea2721d-f60c-4f48-a047-47d514e327c3
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon EventID 23
+description: Logs the deletion of a file, including details about the file path, associated process, and the time of deletion.
+mitre_components:
+- File Deletion
+- File Metadata
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
+separator_value: 23
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_3.yml b/data_sources/sysmon_eventid_3.yml
index 4a92e3fcd3..36d5299c6b 100644
--- a/data_sources/sysmon_eventid_3.yml
+++ b/data_sources/sysmon_eventid_3.yml
@@ -3,10 +3,17 @@ id: 01d84dff-4e26-422c-9389-6a579ee6e75b
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon EventID 3
+description: Logs details of network connections initiated by processes, including source and destination IPs, ports, protocols, and the associated process metadata.
+mitre_components:
+- Network Connection Creation
+- Network Traffic Flow
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
+separator_value: 3
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_5.yml b/data_sources/sysmon_eventid_5.yml
index 2e8f6f0ab7..06cf9d15a3 100644
--- a/data_sources/sysmon_eventid_5.yml
+++ b/data_sources/sysmon_eventid_5.yml
@@ -3,10 +3,16 @@ id: 556471bf-44fa-44e6-97e2-eb25416aeb6d
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon EventID 5
+description: Logs the termination of a process, including details about the process name, process ID, parent process, and associated metadata.
+mitre_components:
+- Process Termination
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
+separator_value: 5
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_6.yml b/data_sources/sysmon_eventid_6.yml
index 33345ac58b..9cf7db46b6 100644
--- a/data_sources/sysmon_eventid_6.yml
+++ b/data_sources/sysmon_eventid_6.yml
@@ -3,10 +3,16 @@ id: eadc297a-c20c-45a1-8fac-74ad54019767
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon EventID 6
+description: Logs the loading of a driver into the kernel or user mode, including details about the driver name, file path, and associated process metadata.
+mitre_components:
+- Driver Load
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
+separator_value: 6
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_7.yml b/data_sources/sysmon_eventid_7.yml
index 2efd35e16d..24d4800817 100644
--- a/data_sources/sysmon_eventid_7.yml
+++ b/data_sources/sysmon_eventid_7.yml
@@ -3,10 +3,17 @@ id: 45512fa5-4d55-4088-9d51-f4dedc16fdff
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon EventID 7
+description: Logs the loading of an image (module) into a process, including details about the image name, file path, and hash information.
+mitre_components:
+- Module Load
+- Process Metadata
+- File Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
+separator_value: 7
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_8.yml b/data_sources/sysmon_eventid_8.yml
index 5fc772500d..ff4dd0f046 100644
--- a/data_sources/sysmon_eventid_8.yml
+++ b/data_sources/sysmon_eventid_8.yml
@@ -3,10 +3,16 @@ id: df7a786c-ade0-48f0-8596-26f10d169f7d
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon EventID 8
+description: Logs the creation of a new thread in a process, including details about the thread ID, start address, and source process.
+mitre_components:
+- Process Modification
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
+separator_value: 8
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_9.yml b/data_sources/sysmon_eventid_9.yml
index b93f6051cb..8d3731938b 100644
--- a/data_sources/sysmon_eventid_9.yml
+++ b/data_sources/sysmon_eventid_9.yml
@@ -3,10 +3,17 @@ id: ae4a6a24-9b8c-4386-a7ac-677d7ad5bf09
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon EventID 9
+description: Logs the access of raw disk data by a process, including details about the disk name, process ID, and process metadata.
+mitre_components:
+- Drive Access
+- File Metadata
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
+separator_value: 9
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_for_linux_eventid_1.yml b/data_sources/sysmon_for_linux_eventid_1.yml
index 9ee369f5b8..ac395956a2 100644
--- a/data_sources/sysmon_for_linux_eventid_1.yml
+++ b/data_sources/sysmon_for_linux_eventid_1.yml
@@ -3,10 +3,17 @@ id: 93643652-30fe-4941-a1f7-6454f2948660
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon for Linux EventID 1
+description: Logs process creation events on Linux systems, including details about the process name, process ID, command line arguments, and parent process ID.
+mitre_components:
+- Process Creation
+- Command Execution
+- Process Metadata
+- OS API Execution
+- Application Log Content
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon:linux
separator: EventID
+separator_value: 1
supported_TA:
- name: Splunk Add-on for Sysmon for Linux
url: https://splunkbase.splunk.com/app/6652
diff --git a/data_sources/sysmon_for_linux_eventid_11.yml b/data_sources/sysmon_for_linux_eventid_11.yml
index 8276870f8a..96020a1d91 100644
--- a/data_sources/sysmon_for_linux_eventid_11.yml
+++ b/data_sources/sysmon_for_linux_eventid_11.yml
@@ -3,7 +3,13 @@ id: 14672fed-235a-411f-8062-ace9696fb2af
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Sysmon for Linux EventID 11
+description: Logs the creation of a new file on a Linux system, including details about the file path, file type, and associated process.
+mitre_components:
+- File Creation
+- File Metadata
+- Process Metadata
+- OS API Execution
+- Application Log Content
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon:linux
separator: EventID
diff --git a/data_sources/windows_active_directory_admon.yml b/data_sources/windows_active_directory_admon.yml
index cfeb4c831e..7e660bb3e7 100644
--- a/data_sources/windows_active_directory_admon.yml
+++ b/data_sources/windows_active_directory_admon.yml
@@ -3,7 +3,13 @@ id: 22bbf4e4-d313-43c1-98ee-808b8775519d
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Active Directory Admon
+description: Logs administrative actions within Active Directory, including user and group modifications, permission changes, and policy updates.
+mitre_components:
+- Active Directory Object Modification
+- Group Modification
+- User Account Modification
+- Configuration Modification
+- Application Log Content
source: ActiveDirectory
sourcetype: ActiveDirectory
supported_TA:
diff --git a/data_sources/windows_defender_alerts.yml b/data_sources/windows_defender_alerts.yml
index 83a470bf4b..7a4de96d5d 100644
--- a/data_sources/windows_defender_alerts.yml
+++ b/data_sources/windows_defender_alerts.yml
@@ -3,7 +3,13 @@ id: 91738e9e-d112-41c9-b91b-e5868d8993d7
version: 1
date: '2024-09-24'
author: Gowthamaraj Rajendran
-description: Data source object for Windows Defender alerts
+description: Logs security alerts generated by Windows Defender, including details about detected threats, impacted files, and recommended actions for remediation.
+mitre_components:
+- Malware Metadata
+- File Access
+- Process Metadata
+- Application Log Content
+- Host Status
source: eventhub://windowsdefenderlogs
sourcetype: mscs:azure:eventhub:defender:advancedhunting
separator: AlertId
diff --git a/data_sources/windows_event_log_application_2282.yml b/data_sources/windows_event_log_application_2282.yml
index eb6fc6d136..af675f03ca 100644
--- a/data_sources/windows_event_log_application_2282.yml
+++ b/data_sources/windows_event_log_application_2282.yml
@@ -3,7 +3,12 @@ id: 4490537e-5e0c-46f7-9209-f56f852aa237
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Application 2282
+description: Logs an event in IIS when a module DLL fails to load due to a configuration issue, including details about the module and error message.
+mitre_components:
+- Service Modification
+- Configuration Modification
+- Application Log Content
+- Service Metadata
source: XmlWinEventLog:Application
sourcetype: XmlWinEventLog
separator: EventCode
diff --git a/data_sources/windows_event_log_application_3000.yml b/data_sources/windows_event_log_application_3000.yml
index 87b847e9bc..9ec681c407 100644
--- a/data_sources/windows_event_log_application_3000.yml
+++ b/data_sources/windows_event_log_application_3000.yml
@@ -3,10 +3,16 @@ id: 3911945d-9222-408d-b851-9b1bce4c2d24
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Application 3000
+description: Logs the termination of a process, including details about the process, its termination code, and timestamp.
+mitre_components:
+- Process Termination
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Application
sourcetype: XmlWinEventLog
separator: EventCode
+separator_value: 3000
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_capi2_70.yml b/data_sources/windows_event_log_capi2_70.yml
index b604bbe548..0ac0455e60 100644
--- a/data_sources/windows_event_log_capi2_70.yml
+++ b/data_sources/windows_event_log_capi2_70.yml
@@ -3,10 +3,17 @@ id: 821de0a6-c5b4-491b-a27e-187552792817
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log CAPI2 70
+description: This event log records events related to cryptographic operations, including the deletion and export of certificates.
+mitre_components:
+- Certificate Registration
+- Process Metadata
+- Application Log Content
+- OS API Execution
+- Host Status
source: XmlWinEventLog:Microsoft-Windows-CAPI2/Operational
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 70
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_capi2_81.yml b/data_sources/windows_event_log_capi2_81.yml
index 376d347618..5d677ef6c5 100644
--- a/data_sources/windows_event_log_capi2_81.yml
+++ b/data_sources/windows_event_log_capi2_81.yml
@@ -3,10 +3,17 @@ id: 463ff898-8135-4c0e-811e-f8629dfc5027
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log CAPI2 81
+description: Logs an error when attempting to verify the digital signature of a file, including details about the file path, signature failure, and the process involved.
+mitre_components:
+- File Access
+- File Metadata
+- Malware Metadata
+- Application Log Content
+- Process Metadata
source: XmlWinEventLog:Microsoft-Windows-CAPI2/Operational
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 81
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_certificateservicesclient_1007.yml b/data_sources/windows_event_log_certificateservicesclient_1007.yml
index aecc0bf864..0399196d64 100644
--- a/data_sources/windows_event_log_certificateservicesclient_1007.yml
+++ b/data_sources/windows_event_log_certificateservicesclient_1007.yml
@@ -3,10 +3,17 @@ id: c51444e3-479d-4c4a-b111-e8276a3acf39
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log CertificateServicesClient 1007
+description: Logs the export of a certificate from the local certificate store, including details about the certificate thumbprint, subject names, and the process involved.
+mitre_components:
+- Certificate Registration
+- Certificate Metadata
+- Process Metadata
+- Application Log Content
+- User Account Metadata
source: XmlWinEventLog:Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational
sourcetype: XmlWinEventLog
separator: EventCode
+separator_value: 1007
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_defender_1121.yml b/data_sources/windows_event_log_defender_1121.yml
index e06fcfddca..4ff6962a3c 100644
--- a/data_sources/windows_event_log_defender_1121.yml
+++ b/data_sources/windows_event_log_defender_1121.yml
@@ -3,10 +3,15 @@ id: 84a254c5-7900-4b52-a324-a176adb7c11d
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Defender 1121
+description: Logs an event when a Windows Defender attack surface reduction rule fires in block mode.
+mitre_components:
+- Application Log Content
+- Host Status
+- Process Creation
source: WinEventLog:Microsoft-Windows-Windows Defender/Operational
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 1121
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_defender_1122.yml b/data_sources/windows_event_log_defender_1122.yml
index 669bbb0047..bc1fe7c3eb 100644
--- a/data_sources/windows_event_log_defender_1122.yml
+++ b/data_sources/windows_event_log_defender_1122.yml
@@ -3,10 +3,15 @@ id: 4a2d0499-f489-4557-82f4-f357025cf3e7
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Defender 1122
+description: Logs an event when a process attempts to load a DLL that is blocked by an attack surface reduction rule.
+mitre_components:
+- Application Log Content
+- Process Creation
+- Module Load
source: WinEventLog:Microsoft-Windows-Windows Defender/Operational
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 1122
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_defender_1129.yml b/data_sources/windows_event_log_defender_1129.yml
index 1227f6efa2..d2572d00c0 100644
--- a/data_sources/windows_event_log_defender_1129.yml
+++ b/data_sources/windows_event_log_defender_1129.yml
@@ -3,10 +3,15 @@ id: 0572e119-a48a-4c70-bc58-90e453edacd2
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Defender 1129
+description: Logs an event when a user overrides a security policy set by an Attack Surface Reduction rule in Microsoft Defender.
+mitre_components:
+- User Account Authentication
+- Security Policy Modification
+- Application Log Content
source: WinEventLog:Microsoft-Windows-Windows Defender/Operational
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 1129
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_defender_5007.yml b/data_sources/windows_event_log_defender_5007.yml
index 598ccc1740..80df5e2faa 100644
--- a/data_sources/windows_event_log_defender_5007.yml
+++ b/data_sources/windows_event_log_defender_5007.yml
@@ -3,7 +3,10 @@ id: 27f18792-8d95-4871-8853-874b7faf023f
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Defender 5007
+description: Logs an event when Windows Defender antimalware settings are modified.
+mitre_components:
+- Service Modification
+- Service Metadata
source: WinEventLog:Microsoft-Windows-Windows Defender/Operational
sourcetype: xmlwineventlog
separator: EventCode
diff --git a/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml b/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml
index d17981dc1f..22e591d7a7 100644
--- a/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml
+++ b/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml
@@ -3,7 +3,10 @@ id: 2490537e-5e0c-46f7-9209-f56f852aa217
version: 1
date: '2024-11-21'
author: Michael Haag, Splunk
-description: Data source object for Windows Event Microsoft Windows TerminalServices RDPClient 1024
+description: Logs an event when a Remote Desktop Protocol (RDP) client successfully connects to a remote host.
+mitre_components:
+- Network Connection Creation
+- Logon Session Creation
source: WinEventLog:Microsoft-Windows-TerminalServices-RDPClient/Operational
sourcetype: WinEventLog
separator: EventCode
diff --git a/data_sources/windows_event_log_printservice_316.yml b/data_sources/windows_event_log_printservice_316.yml
index 66896969fe..507a925e5d 100644
--- a/data_sources/windows_event_log_printservice_316.yml
+++ b/data_sources/windows_event_log_printservice_316.yml
@@ -3,10 +3,14 @@ id: 12f0be8b-22c0-4fdf-9468-b7ccca824d1d
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Printservice 316
+description: Logs an event when printer drivers are installed or updated on the system.
+mitre_components:
+- Driver Load
+- Driver Metadata
source: WinEventLog:Microsoft-Windows-PrintService/Admin
sourcetype: WinEventLog
separator: EventCode
+separator_value: 316
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_printservice_808.yml b/data_sources/windows_event_log_printservice_808.yml
index bc9a09f66d..ef717b2d20 100644
--- a/data_sources/windows_event_log_printservice_808.yml
+++ b/data_sources/windows_event_log_printservice_808.yml
@@ -3,10 +3,15 @@ id: e3a26785-4389-4830-8d7b-3dad4252719e
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Printservice 808
+description: Logs an event when the print spooler service fails to load a printer plug-in module.
+mitre_components:
+- Module Load
+- Application Log Content
+- Service Metadata
source: WinEventLog:Microsoft-Windows-PrintService/Admin
sourcetype: WinEventLog
separator: EventCode
+separator_value: 808
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml
index 1081028aa2..14c3a6bc1a 100644
--- a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml
+++ b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml
@@ -3,10 +3,15 @@ id: 08f9edb4-f95f-40be-b1dd-bc3a1cd95aaf
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log RemoteConnectionManager 1149
+description: Logs an event when a Remote Desktop Service session is initialized.
+mitre_components:
+- Network Connection Creation
+- Logon Session Creation
+- Logon Session Metadata
source: WinEventLog:Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational
sourcetype: wineventlog
separator: EventCode
+separator_value: 1149
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_1100.yml b/data_sources/windows_event_log_security_1100.yml
index 1e2404f690..41e0c3fced 100644
--- a/data_sources/windows_event_log_security_1100.yml
+++ b/data_sources/windows_event_log_security_1100.yml
@@ -3,10 +3,14 @@ id: 2a25dafa-691e-4cb2-ae59-07a48867ed9a
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 1100
+description: Logs an event when the event logging service has shut down.
+mitre_components:
+- Host Status
+- System Configuration Changes
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 1100
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_1102.yml b/data_sources/windows_event_log_security_1102.yml
index 0646f5ad48..50bcf53f6b 100644
--- a/data_sources/windows_event_log_security_1102.yml
+++ b/data_sources/windows_event_log_security_1102.yml
@@ -3,10 +3,15 @@ id: 8db7b91a-6d7a-40e7-bfac-06f8e901a9cb
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 1102
+description: Logs an event when the audit log is cleared.
+mitre_components:
+- User Account Modification
+- Logon Session Metadata
+- File Deletion
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 1102
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4624.yml b/data_sources/windows_event_log_security_4624.yml
index 4f02eeb290..0faba24352 100644
--- a/data_sources/windows_event_log_security_4624.yml
+++ b/data_sources/windows_event_log_security_4624.yml
@@ -3,10 +3,15 @@ id: 08682968-0366-4882-9559-fe4fe018a846
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4624
+description: Logs an event when an account successfully logs on to a system.
+mitre_components:
+- Logon Session Creation
+- User Account Authentication
+- Logon Session Metadata
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4624
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4625.yml b/data_sources/windows_event_log_security_4625.yml
index 3928d3b9d6..5f58a8d248 100644
--- a/data_sources/windows_event_log_security_4625.yml
+++ b/data_sources/windows_event_log_security_4625.yml
@@ -3,10 +3,14 @@ id: 365a02c2-7d18-4baf-b76e-d90c20bbe6ed
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4625
+description: Logs an event when an account fails to log on to a system.
+mitre_components:
+- User Account Authentication
+- Logon Session Metadata
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4625
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4627.yml b/data_sources/windows_event_log_security_4627.yml
index dbb7cc5c55..d91715f957 100644
--- a/data_sources/windows_event_log_security_4627.yml
+++ b/data_sources/windows_event_log_security_4627.yml
@@ -3,10 +3,15 @@ id: e35c7b9a-b451-4084-95a5-43b7f8965cac
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4627
+description: Logs an event when a successful account logon occurs and displays the list of groups the logged-on account belongs to.
+mitre_components:
+- Logon Session Creation
+- Group Metadata
+- User Account Authentication
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4627
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4648.yml b/data_sources/windows_event_log_security_4648.yml
index 26445ed64d..ade1d81ce9 100644
--- a/data_sources/windows_event_log_security_4648.yml
+++ b/data_sources/windows_event_log_security_4648.yml
@@ -3,10 +3,14 @@ id: 6a367f8b-1ee0-463d-94a7-029757c6cd02
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4648
+description: Logged when an account logon is attempted by a process by explicitly specifying the credentials of that account
+mitre_components:
+- User Account Authentication
+- Logon Session Creation
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4648
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4662.yml b/data_sources/windows_event_log_security_4662.yml
index 1970056294..f55185240e 100644
--- a/data_sources/windows_event_log_security_4662.yml
+++ b/data_sources/windows_event_log_security_4662.yml
@@ -3,10 +3,14 @@ id: f3c2cd64-0b5f-4013-8201-35dc03828ec6
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4662
+description: Logs an event when a user accessed an object within the Active Directory, such as creating, modifying, or deleting it
+mitre_components:
+- Active Directory Object Access
+- Active Directory Object Modification
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4662
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4663.yml b/data_sources/windows_event_log_security_4663.yml
index 78a84369d9..addcc024d9 100644
--- a/data_sources/windows_event_log_security_4663.yml
+++ b/data_sources/windows_event_log_security_4663.yml
@@ -3,10 +3,14 @@ id: 5d6dca8c-dad9-494f-a321-ef2b0b92fbf4
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4663
+description: Logs an event when a user or process tried to access a file, directory, registry key, or other system object on the computer
+mitre_components:
+- File Access
+- File Modification
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4663
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4672.yml b/data_sources/windows_event_log_security_4672.yml
index 69d9996108..71facef2ee 100644
--- a/data_sources/windows_event_log_security_4672.yml
+++ b/data_sources/windows_event_log_security_4672.yml
@@ -3,10 +3,14 @@ id: 43f189b6-369d-4a32-a34c-57e0d38d92f1
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4672
+description: Logs an event when a user with administrative privileges logs on to a system.
+mitre_components:
+- Logon Session Creation
+- User Account Authentication
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4672
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4688.yml b/data_sources/windows_event_log_security_4688.yml
index 8f0a3e3a57..082bce7da0 100644
--- a/data_sources/windows_event_log_security_4688.yml
+++ b/data_sources/windows_event_log_security_4688.yml
@@ -3,10 +3,14 @@ id: d195eb26-a81c-45ed-aeb3-25792e8a985a
version: 2
date: '2024-09-26'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4688
+description: Logs the creation of a new process
+mitre_components:
+- Process Creation
+- Command Execution
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4688
configuration: Enabling Windows event log process command line logging via group policy
object https://lantern.splunk.com/Security/Product_Tips/Enterprise_Security/Enabling_Windows_event_log_process_command_line_logging_via_group_policy_object
supported_TA:
diff --git a/data_sources/windows_event_log_security_4698.yml b/data_sources/windows_event_log_security_4698.yml
index 0aa1b8ab6a..9f863f1161 100644
--- a/data_sources/windows_event_log_security_4698.yml
+++ b/data_sources/windows_event_log_security_4698.yml
@@ -3,10 +3,14 @@ id: 32c06703-02d3-47ec-8856-b0dc3045866c
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4698
+description: Logs an event when a new scheduled task is created
+mitre_components:
+- Scheduled Job Creation
+- Scheduled Job Metadata
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4698
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4699.yml b/data_sources/windows_event_log_security_4699.yml
index a0184e87ef..764795adec 100644
--- a/data_sources/windows_event_log_security_4699.yml
+++ b/data_sources/windows_event_log_security_4699.yml
@@ -3,10 +3,14 @@ id: 4727dead-d063-4333-9ddd-59823a416aff
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4699
+description: Logs an event when a scheduled task is deleted from the system.
+mitre_components:
+- Scheduled Job Metadata
+- Scheduled Job Modification
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4699
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4703.yml b/data_sources/windows_event_log_security_4703.yml
index 6d914bbc8c..a776196575 100644
--- a/data_sources/windows_event_log_security_4703.yml
+++ b/data_sources/windows_event_log_security_4703.yml
@@ -3,10 +3,14 @@ id: e256673b-16e8-4b74-b7aa-9eed6ce67072
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4703
+description: Logs an event when a token right is adjusted on a Windows system.
+mitre_components:
+- User Account Modification
+- Process Modification
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4703
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4719.yml b/data_sources/windows_event_log_security_4719.yml
index 07f7261f0d..a5305e46f7 100644
--- a/data_sources/windows_event_log_security_4719.yml
+++ b/data_sources/windows_event_log_security_4719.yml
@@ -3,10 +3,14 @@ id: 954033e6-dd05-4775-a1f2-1f19632f4420
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4719
+description: Logs an event when a system audit policy is modified on a Windows system.
+mitre_components:
+- Service Modification
+- User Account Modification
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4719
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4720.yml b/data_sources/windows_event_log_security_4720.yml
index bbed05f0b9..390bcae55a 100644
--- a/data_sources/windows_event_log_security_4720.yml
+++ b/data_sources/windows_event_log_security_4720.yml
@@ -3,10 +3,13 @@ id: 7ef1c9e5-691b-48c2-811b-eba91d2d2f1d
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4720
+description: Logs an event when a new user account is created on a Windows system.
+mitre_components:
+- User Account Creation
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4720
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4724.yml b/data_sources/windows_event_log_security_4724.yml
index 1960e64264..2a42ca008c 100644
--- a/data_sources/windows_event_log_security_4724.yml
+++ b/data_sources/windows_event_log_security_4724.yml
@@ -3,10 +3,13 @@ id: 117fe51f-93f8-4589-8e8b-c6b7b7154c7d
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4724
+description: Logs an event when an attempt is made to reset an account's password, whether successful or not.
+mitre_components:
+- User Account Modification
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4724
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4725.yml b/data_sources/windows_event_log_security_4725.yml
index 62a49da0e5..a70b371aa9 100644
--- a/data_sources/windows_event_log_security_4725.yml
+++ b/data_sources/windows_event_log_security_4725.yml
@@ -3,10 +3,13 @@ id: 31fd887d-0d14-44cc-bb64-80063a9f2968
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4725
+description: Logs an event when a user account has been disabled in Active Directory.
+mitre_components:
+- User Account Modification
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4725
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4726.yml b/data_sources/windows_event_log_security_4726.yml
index feb818c007..c6bcdb5ef2 100644
--- a/data_sources/windows_event_log_security_4726.yml
+++ b/data_sources/windows_event_log_security_4726.yml
@@ -3,10 +3,13 @@ id: 0b56dcd7-0f72-4a05-9226-d6059781737b
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4726
+description: Logs an event when a user account is deleted from Active Directory.
+mitre_components:
+- User Account Deletion
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4726
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4732.yml b/data_sources/windows_event_log_security_4732.yml
index 574c3dd7aa..4cf35ee519 100644
--- a/data_sources/windows_event_log_security_4732.yml
+++ b/data_sources/windows_event_log_security_4732.yml
@@ -3,10 +3,13 @@ id: b0d61c5d-aefe-486a-9152-de45cc10fbb4
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4732
+description: Logs an event when a member is added to a security-enabled local group on a Windows system.
+mitre_components:
+- Group Modification
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4732
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4738.yml b/data_sources/windows_event_log_security_4738.yml
index 7ee6af3b45..7298903e0b 100644
--- a/data_sources/windows_event_log_security_4738.yml
+++ b/data_sources/windows_event_log_security_4738.yml
@@ -3,10 +3,13 @@ id: cb85709b-101e-41a9-bb60-d2108f79dfbd
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4738
+description: Logs an event when a user account's properties, such as permissions or memberships, are modified on a Windows system.
+mitre_components:
+- User Account Modification
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4738
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4739.yml b/data_sources/windows_event_log_security_4739.yml
index 4ac66f85a9..3642e4b93e 100644
--- a/data_sources/windows_event_log_security_4739.yml
+++ b/data_sources/windows_event_log_security_4739.yml
@@ -3,10 +3,14 @@ id: c1e0442a-8a97-405d-baf2-057c5d68cd9a
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4739
+description: Logs an event when a domain policy, such as account or lockout policy, is modified in Active Directory or local security settings.
+mitre_components:
+- Group Modification
+- Active Directory Object Modification
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4739
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4741.yml b/data_sources/windows_event_log_security_4741.yml
index 2d112fb492..7d4b9f3150 100644
--- a/data_sources/windows_event_log_security_4741.yml
+++ b/data_sources/windows_event_log_security_4741.yml
@@ -3,10 +3,16 @@ id: ef87257f-e7d1-4856-abae-097b2cfdcdb4
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4741
+description: Logs the creation of a new computer account in Active Directory, including details about the account name, domain, and the user performing the action.
+mitre_components:
+- Active Directory Object Creation
+- User Account Metadata
+- Application Log Content
+- Configuration Modification
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4741
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4742.yml b/data_sources/windows_event_log_security_4742.yml
index 042c75ef93..8668a87cdd 100644
--- a/data_sources/windows_event_log_security_4742.yml
+++ b/data_sources/windows_event_log_security_4742.yml
@@ -3,7 +3,12 @@ id: ea830adf-5450-489a-bcdc-fb8d2cbe674c
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4742
+description: Logs changes to the properties of a computer account in Active Directory, including details about the modified attributes and the user performing the action.
+mitre_components:
+- Active Directory Object Modification
+- User Account Metadata
+- Application Log Content
+- Configuration Modification
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
diff --git a/data_sources/windows_event_log_security_4768.yml b/data_sources/windows_event_log_security_4768.yml
index 474534451e..bee4afe853 100644
--- a/data_sources/windows_event_log_security_4768.yml
+++ b/data_sources/windows_event_log_security_4768.yml
@@ -3,10 +3,16 @@ id: 4a5fd6ed-66bd-4f34-bc74-51c00c73c298
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4768
+description: Logs Kerberos pre-authentication requests, including details about the user account, authentication type, and client IP address.
+mitre_components:
+- User Account Authentication
+- Active Directory Credential Request
+- Logon Session Metadata
+- User Account Metadata
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4768
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4769.yml b/data_sources/windows_event_log_security_4769.yml
index d8694a1dea..ce9343c3c8 100644
--- a/data_sources/windows_event_log_security_4769.yml
+++ b/data_sources/windows_event_log_security_4769.yml
@@ -3,10 +3,16 @@ id: 358d5520-f40b-4fa2-b799-966c030cb731
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4769
+description: Logs Kerberos service ticket requests, including details about the requesting user, target service, and client IP address.
+mitre_components:
+- Active Directory Credential Request
+- User Account Authentication
+- Logon Session Metadata
+- User Account Metadata
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4769
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4771.yml b/data_sources/windows_event_log_security_4771.yml
index f31e4b50fe..b4db6f6ec1 100644
--- a/data_sources/windows_event_log_security_4771.yml
+++ b/data_sources/windows_event_log_security_4771.yml
@@ -3,10 +3,16 @@ id: 418debbb-adf3-48ec-9efd-59d45f8861e5
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4771
+description: Logs failed Kerberos pre-authentication attempts, including details about the user account, client IP, and failure reason.
+mitre_components:
+- User Account Authentication
+- Logon Session Metadata
+- User Account Metadata
+- Application Log Content
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4771
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4776.yml b/data_sources/windows_event_log_security_4776.yml
index e6ea80b2c5..fb3ebc5cac 100644
--- a/data_sources/windows_event_log_security_4776.yml
+++ b/data_sources/windows_event_log_security_4776.yml
@@ -3,10 +3,16 @@ id: 1da9092a-c795-4a26-ace8-d43855524e96
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4776
+description: Logs NTLM authentication attempts, including details about the account name, authentication status, and the originating workstation.
+mitre_components:
+- User Account Authentication
+- Logon Session Metadata
+- User Account Metadata
+- Application Log Content
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4776
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4781.yml b/data_sources/windows_event_log_security_4781.yml
index b807a5a1d9..453217cdd0 100644
--- a/data_sources/windows_event_log_security_4781.yml
+++ b/data_sources/windows_event_log_security_4781.yml
@@ -3,10 +3,16 @@ id: 9732ffe7-ebce-4557-865c-1725a0f633cb
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4781
+description: Logs changes made to the name of a computer account, including the old and new names and the user performing the action.
+mitre_components:
+- User Account Modification
+- User Account Metadata
+- Active Directory Object Modification
+- Application Log Content
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4781
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4794.yml b/data_sources/windows_event_log_security_4794.yml
index f3ea14b1c1..bc7d30320b 100644
--- a/data_sources/windows_event_log_security_4794.yml
+++ b/data_sources/windows_event_log_security_4794.yml
@@ -3,10 +3,16 @@ id: ec7da74f-274a-4bde-aa0e-15c68aca0426
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4794
+description: Logs attempts to set the Directory Services Restore Mode (DSRM) administrator password, including details about the account name and the user performing the action.
+mitre_components:
+- User Account Modification
+- User Account Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value:
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4798.yml b/data_sources/windows_event_log_security_4798.yml
index 0d64c1b297..ff04d051f0 100644
--- a/data_sources/windows_event_log_security_4798.yml
+++ b/data_sources/windows_event_log_security_4798.yml
@@ -3,7 +3,12 @@ id: 29e97f72-eb2e-400e-b0c9-81277547e43b
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4798
+description: Logs an enumeration of local group membership on a system, including details about the groups queried and the account performing the action.
+mitre_components:
+- Group Enumeration
+- Group Metadata
+- User Account Metadata
+- Application Log Content
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
diff --git a/data_sources/windows_event_log_security_4876.yml b/data_sources/windows_event_log_security_4876.yml
index 4d978151e4..b44884ed9a 100644
--- a/data_sources/windows_event_log_security_4876.yml
+++ b/data_sources/windows_event_log_security_4876.yml
@@ -3,10 +3,16 @@ id: 4a78722a-9cd9-44e8-b010-dffad5c7f170
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4876
+description: Logs the result of a cryptographic operation, including details about the key, algorithm used, and whether the operation succeeded or failed.
+mitre_components:
+- Certificate Registration
+- User Account Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4876
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4886.yml b/data_sources/windows_event_log_security_4886.yml
index 3c82a3eb85..dd50c8c278 100644
--- a/data_sources/windows_event_log_security_4886.yml
+++ b/data_sources/windows_event_log_security_4886.yml
@@ -3,10 +3,16 @@ id: c5abd97d-b468-451f-bd65-b4f97efa4ecc
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4886
+description: Logs the deletion of a cryptographic key container, including details about the key container name and the user performing the action.
+mitre_components:
+- Certificate Registration
+- User Account Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4886
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4887.yml b/data_sources/windows_event_log_security_4887.yml
index 39f5cbb7cc..80ac4f9763 100644
--- a/data_sources/windows_event_log_security_4887.yml
+++ b/data_sources/windows_event_log_security_4887.yml
@@ -3,10 +3,16 @@ id: 994c7b19-a623-4231-9818-f00e453b9a75
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 4887
+description: Logs cryptographic operations performed by a Windows system, including details about the certificate or key used and the operation type.
+mitre_components:
+- Certificate Registration
+- User Account Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4887
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_5136.yml b/data_sources/windows_event_log_security_5136.yml
index 9e685b1960..f2494cadc9 100644
--- a/data_sources/windows_event_log_security_5136.yml
+++ b/data_sources/windows_event_log_security_5136.yml
@@ -3,10 +3,16 @@ id: 7ba3737e-231e-455d-824e-cd077749f835
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 5136
+description: Logs modifications made to an Active Directory object, including details about the object name, type, and the changes applied.
+mitre_components:
+- Active Directory Object Modification
+- Active Directory Object Access
+- User Account Metadata
+- Application Log Content
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 5136
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_5137.yml b/data_sources/windows_event_log_security_5137.yml
index aef4beca13..8787969fa8 100644
--- a/data_sources/windows_event_log_security_5137.yml
+++ b/data_sources/windows_event_log_security_5137.yml
@@ -3,10 +3,16 @@ id: 64ed7bb1-9c3c-4355-ac08-b506ec3b053e
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 5137
+description: Logs the creation of a new Active Directory object, including details about the object name, type, and the user performing the action.
+mitre_components:
+- Active Directory Object Creation
+- Active Directory Object Modification
+- User Account Metadata
+- Application Log Content
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 5137
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_5140.yml b/data_sources/windows_event_log_security_5140.yml
index 0687f2ebb5..8d1883d26c 100644
--- a/data_sources/windows_event_log_security_5140.yml
+++ b/data_sources/windows_event_log_security_5140.yml
@@ -3,10 +3,16 @@ id: 93e0ca09-e4b8-4da6-872a-d0127c4d2b22
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 5140
+description: Logs access to a network share, including details about the user, share path, and the access type.
+mitre_components:
+- Network Share Access
+- File Access
+- User Account Metadata
+- Application Log Content
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 5140
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_5141.yml b/data_sources/windows_event_log_security_5141.yml
index 07f144b980..713a598abe 100644
--- a/data_sources/windows_event_log_security_5141.yml
+++ b/data_sources/windows_event_log_security_5141.yml
@@ -3,10 +3,16 @@ id: eafb35fa-f034-4be3-8508-d9173a73c0a1
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 5141
+description: Logs the deletion of an Active Directory object, including details about the object name, type, and the user performing the action.
+mitre_components:
+- Active Directory Object Deletion
+- Active Directory Object Modification
+- User Account Metadata
+- Application Log Content
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 5141
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_5145.yml b/data_sources/windows_event_log_security_5145.yml
index 1d6560e36e..70a22f8d7c 100644
--- a/data_sources/windows_event_log_security_5145.yml
+++ b/data_sources/windows_event_log_security_5145.yml
@@ -3,10 +3,16 @@ id: 0746479b-7b82-4d7e-8811-0b35da00f798
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log Security 5145
+description: Logs detailed information about access to a network share, including the user, share path, accessed file, and access permissions.
+mitre_components:
+- Network Share Access
+- File Access
+- User Account Metadata
+- Application Log Content
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 5145
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_system_4720.yml b/data_sources/windows_event_log_system_4720.yml
index d930d69759..a2b9a2e197 100644
--- a/data_sources/windows_event_log_system_4720.yml
+++ b/data_sources/windows_event_log_system_4720.yml
@@ -3,10 +3,16 @@ id: f01d4758-05c8-4ac4-a9a5-33500dd5eb6c
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log System 4720
+description: Logs the creation of a new user account, including details about the account name, associated domain, and the account performing the action.
+mitre_components:
+- User Account Creation
+- User Account Metadata
+- Active Directory Object Creation
+- Application Log Content
source: XmlWinEventLog:System
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4720
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_system_4726.yml b/data_sources/windows_event_log_system_4726.yml
index 706432fb4e..a94f1b82e5 100644
--- a/data_sources/windows_event_log_system_4726.yml
+++ b/data_sources/windows_event_log_system_4726.yml
@@ -3,10 +3,16 @@ id: 05e6b2df-b50e-441b-8ac8-565f2e80d62f
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log System 4726
+description: Logs the deletion of a user account, including details about the account name, associated domain, and the account performing the action.
+mitre_components:
+- User Account Deletion
+- User Account Metadata
+- Active Directory Object Modification
+- Application Log Content
source: XmlWinEventLog:System
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4726
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_system_4728.yml b/data_sources/windows_event_log_system_4728.yml
index 906b7cd67d..9d5380f3ca 100644
--- a/data_sources/windows_event_log_system_4728.yml
+++ b/data_sources/windows_event_log_system_4728.yml
@@ -3,10 +3,16 @@ id: 4549f0ac-3df9-4bfb-bea5-1459690c8040
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log System 4728
+description: Logs the addition of a user to a security-enabled group, including details about the group name, user account, and associated domain.
+mitre_components:
+- Group Modification
+- Group Metadata
+- User Account Metadata
+- Active Directory Object Modification
source: XmlWinEventLog:System
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 4728
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_system_7036.yml b/data_sources/windows_event_log_system_7036.yml
index 2b5c6845fa..4079da5408 100644
--- a/data_sources/windows_event_log_system_7036.yml
+++ b/data_sources/windows_event_log_system_7036.yml
@@ -3,10 +3,16 @@ id: a6e9b34f-1507-4fa1-a4ba-684d1b676a34
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log System 7036
+description: Logs state changes of a Windows service, including details about the service name and its new state (e.g., started or stopped).
+mitre_components:
+- Service Metadata
+- OS API Execution
+- Application Log Content
+- Host Status
source: XmlWinEventLog:System
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 7036
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_system_7040.yml b/data_sources/windows_event_log_system_7040.yml
index 9a669d6262..e1d08e67e4 100644
--- a/data_sources/windows_event_log_system_7040.yml
+++ b/data_sources/windows_event_log_system_7040.yml
@@ -3,10 +3,16 @@ id: 91738e9e-d112-41c9-b91b-e5868d8993d9
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log System 7040
+description: Logs changes to the start type of a Windows service, including details about the service name, old start type, and new start type.
+mitre_components:
+- Service Modification
+- Service Metadata
+- OS API Execution
+- Application Log Content
source: XmlWinEventLog:System
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 7040
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_system_7045.yml b/data_sources/windows_event_log_system_7045.yml
index 335efef1a8..b7e8511470 100644
--- a/data_sources/windows_event_log_system_7045.yml
+++ b/data_sources/windows_event_log_system_7045.yml
@@ -3,10 +3,16 @@ id: 614dedc8-8a14-4393-ba9b-6f093cbcd293
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log System 7045
+description: Logs the successful installation of a new Windows service, including details about the service name, executable path, and service type.
+mitre_components:
+- Service Creation
+- Service Metadata
+- OS API Execution
+- Process Metadata
source: XmlWinEventLog:System
sourcetype: xmlwineventlog
separator: EventCode
+separator_value: 7045
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_taskscheduler_200.yml b/data_sources/windows_event_log_taskscheduler_200.yml
index 979e053f1d..c7af8fd33b 100644
--- a/data_sources/windows_event_log_taskscheduler_200.yml
+++ b/data_sources/windows_event_log_taskscheduler_200.yml
@@ -3,10 +3,16 @@ id: f8c777f8-e88a-4bba-ae8a-79b250212f23
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows Event Log TaskScheduler 200
+description: Logs the successful registration of a new scheduled task in Windows Task Scheduler, including task details and configurations.
+mitre_components:
+- Scheduled Job Creation
+- Scheduled Job Metadata
+- Service Creation
+- OS API Execution
source: WinEventLog:Microsoft-Windows-TaskScheduler/Operational
sourcetype: wineventlog
separator: EventCode
+separator_value: 200
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_iis.yml b/data_sources/windows_iis.yml
index a78d2107dd..0aa47abd32 100644
--- a/data_sources/windows_iis.yml
+++ b/data_sources/windows_iis.yml
@@ -3,7 +3,12 @@ id: 469335b3-b6ad-49e2-bbe6-47e15c1464a7
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows IIS
+description: Logs changes to IIS server configuration, including updates to settings, modules, authentication methods, and site bindings.
+mitre_components:
+- Service Modification
+- Cloud Service Modification
+- Configuration Modification
+- Application Log Content
source: IIS:Configuration:Operational
sourcetype: IIS:Configuration:Operational
separator: EventID
diff --git a/data_sources/windows_iis_29.yml b/data_sources/windows_iis_29.yml
index 7657e0c52c..26d05e774f 100644
--- a/data_sources/windows_iis_29.yml
+++ b/data_sources/windows_iis_29.yml
@@ -3,10 +3,16 @@ id: 1d99ddd7-7fec-4dea-bf4f-1f4906142328
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
-description: Data source object for Windows IIS 29
+description: Logs modifications to IIS server authentication settings, including updates to client certificate requirements and authentication methods.
+mitre_components:
+- Service Modification
+- Configuration Modification
+- Certificate Registration
+- Application Log Content
source: IIS:Configuration:Operational
sourcetype: IIS:Configuration:Operational
separator: EventID
+separator_value: 29
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
From cbac872e4109835bbe9998d867423347ad653cc3 Mon Sep 17 00:00:00 2001
From: delgado-jacob <29643013+delgado-jacob@users.noreply.github.com>
Date: Thu, 23 Jan 2025 09:38:13 -0700
Subject: [PATCH 02/67] Update version and modified date. Fix reference in
detection.
---
data_sources/asl_aws_cloudtrail.yml | 34 +-
data_sources/aws_cloudfront.yml | 183 +-
.../aws_cloudtrail_assumerolewithsaml.yml | 198 +-
data_sources/aws_cloudtrail_consolelogin.yml | 177 +-
data_sources/aws_cloudtrail_copyobject.yml | 187 +-
.../aws_cloudtrail_createaccesskey.yml | 175 +-
data_sources/aws_cloudtrail_createkey.yml | 211 +-
.../aws_cloudtrail_createloginprofile.yml | 173 +-
.../aws_cloudtrail_createnetworkaclentry.yml | 205 +-
.../aws_cloudtrail_createpolicyversion.yml | 175 +-
.../aws_cloudtrail_createsnapshot.yml | 193 +-
data_sources/aws_cloudtrail_createtask.yml | 191 +-
.../aws_cloudtrail_createvirtualmfadevice.yml | 171 +-
.../aws_cloudtrail_deactivatemfadevice.yml | 171 +-
...cloudtrail_deleteaccountpasswordpolicy.yml | 169 +-
data_sources/aws_cloudtrail_deletealarms.yml | 239 +--
.../aws_cloudtrail_deletedetector.yml | 165 +-
data_sources/aws_cloudtrail_deletegroup.yml | 175 +-
data_sources/aws_cloudtrail_deleteipset.yml | 165 +-
.../aws_cloudtrail_deleteloggroup.yml | 169 +-
.../aws_cloudtrail_deletelogstream.yml | 171 +-
.../aws_cloudtrail_deletenetworkaclentry.yml | 183 +-
data_sources/aws_cloudtrail_deletepolicy.yml | 171 +-
data_sources/aws_cloudtrail_deleterule.yml | 171 +-
.../aws_cloudtrail_deletesnapshot.yml | 253 +--
data_sources/aws_cloudtrail_deletetrail.yml | 167 +-
.../aws_cloudtrail_deletevirtualmfadevice.yml | 167 +-
data_sources/aws_cloudtrail_deletewebacl.yml | 167 +-
...aws_cloudtrail_describeeventaggregates.yml | 159 +-
...s_cloudtrail_describeimagescanfindings.yml | 1831 +++++++++--------
...ws_cloudtrail_getaccountpasswordpolicy.yml | 165 +-
data_sources/aws_cloudtrail_getobject.yml | 183 +-
.../aws_cloudtrail_getpassworddata.yml | 185 +-
data_sources/aws_cloudtrail_jobcreated.yml | 134 +-
.../aws_cloudtrail_modifydbinstance.yml | 283 +--
.../aws_cloudtrail_modifyimageattribute.yml | 173 +-
...aws_cloudtrail_modifysnapshotattribute.yml | 163 +-
data_sources/aws_cloudtrail_putbucketacl.yml | 191 +-
.../aws_cloudtrail_putbucketlifecycle.yml | 193 +-
.../aws_cloudtrail_putbucketreplication.yml | 217 +-
.../aws_cloudtrail_putbucketversioning.yml | 199 +-
data_sources/aws_cloudtrail_putimage.yml | 179 +-
data_sources/aws_cloudtrail_putkeypolicy.yml | 179 +-
.../aws_cloudtrail_replacenetworkaclentry.yml | 192 +-
...aws_cloudtrail_setdefaultpolicyversion.yml | 165 +-
data_sources/aws_cloudtrail_stoplogging.yml | 155 +-
...cloudtrail_updateaccountpasswordpolicy.yml | 176 +-
.../aws_cloudtrail_updateloginprofile.yml | 160 +-
.../aws_cloudtrail_updatesamlprovider.yml | 343 +--
data_sources/aws_cloudtrail_updatetrail.yml | 173 +-
data_sources/aws_cloudwatchlogs_vpcflow.yml | 124 +-
data_sources/aws_security_hub.yml | 227 +-
...p_role_assignment_to_service_principal.yml | 170 +-
...re_active_directory_add_member_to_role.yml | 122 +-
...ive_directory_add_owner_to_application.yml | 132 +-
...active_directory_add_service_principal.yml | 122 +-
...active_directory_add_unverified_domain.yml | 121 +-
...ctive_directory_consent_to_application.yml | 132 +-
...irectory_disable_strong_authentication.yml | 117 +-
.../azure_active_directory_enable_account.yml | 116 +-
..._active_directory_invite_external_user.yml | 117 +-
...ve_directory_reset_password_(by_admin).yml | 119 +-
...ve_directory_set_domain_authentication.yml | 119 +-
...zure_active_directory_sign_in_activity.yml | 219 +-
...re_active_directory_update_application.yml | 119 +-
..._directory_update_authorization_policy.yml | 121 +-
.../azure_active_directory_update_user.yml | 118 +-
...irectory_user_registered_security_info.yml | 113 +-
..._or_update_an_azure_automation_account.yml | 192 +-
..._or_update_an_azure_automation_runbook.yml | 193 +-
..._or_update_an_azure_automation_webhook.yml | 210 +-
data_sources/bro_conn.yml | 15 +-
data_sources/bro_dns.yml | 17 +-
data_sources/bro_files.yml | 18 +-
data_sources/bro_http.yml | 17 +-
data_sources/bro_loaded_scripts.yml | 15 +-
data_sources/bro_ntp.yml | 15 +-
data_sources/bro_ocsp.yml | 19 +-
data_sources/bro_ssl.yml | 19 +-
data_sources/bro_weird.yml | 17 +-
data_sources/bro_x509.yml | 19 +-
data_sources/circleci.yml | 127 +-
data_sources/crowdstrike_processrollup2.yml | 200 +-
data_sources/crushftp.yml | 21 +-
data_sources/g_suite_drive.yml | 85 +-
data_sources/g_suite_gmail.yml | 161 +-
data_sources/github.yml | 401 ++--
.../google_workspace_login_failure.yml | 91 +-
.../google_workspace_login_success.yml | 87 +-
data_sources/ivanti_vtm_audit.yml | 36 +-
data_sources/kubernetes_audit.yml | 111 +-
data_sources/kubernetes_falco.yml | 87 +-
data_sources/linux_auditd_add_user.yml | 62 +-
data_sources/linux_auditd_execve.yml | 34 +-
data_sources/linux_auditd_path.yml | 63 +-
data_sources/linux_auditd_proctitle.yml | 27 +-
data_sources/linux_auditd_service_stop.yml | 58 +-
data_sources/linux_auditd_syscall.yml | 106 +-
data_sources/linux_secure.yml | 87 +-
.../ms365_defender_incident_alerts.yml | 414 ++--
data_sources/ms_defender_atp_alerts.yml | 691 ++++---
data_sources/nginx_access.yml | 135 +-
data_sources/o365.yml | 23 +-
...add_app_role_assignment_grant_to_user_.yml | 159 +-
..._role_assignment_to_service_principal_.yml | 158 +-
data_sources/o365_add_mailboxpermission.yml | 142 +-
data_sources/o365_add_member_to_role_.yml | 163 +-
.../o365_add_owner_to_application_.yml | 168 +-
data_sources/o365_add_service_principal_.yml | 167 +-
data_sources/o365_change_user_license_.yml | 159 +-
data_sources/o365_consent_to_application_.yml | 152 +-
.../o365_disable_strong_authentication_.yml | 154 +-
data_sources/o365_mailitemsaccessed.yml | 145 +-
data_sources/o365_modifyfolderpermissions.yml | 181 +-
.../o365_set_company_information_.yml | 169 +-
data_sources/o365_set_mailbox.yml | 161 +-
data_sources/o365_update_application_.yml | 167 +-
.../o365_update_authorization_policy_.yml | 151 +-
data_sources/o365_update_user_.yml | 165 +-
data_sources/o365_userloggedin.yml | 165 +-
data_sources/o365_userloginfailed.yml | 183 +-
data_sources/okta.yml | 23 +-
data_sources/osquery.yml | 123 +-
data_sources/palo_alto_network_threat.yml | 62 +-
data_sources/palo_alto_network_traffic.yml | 65 +-
data_sources/pingid.yml | 71 +-
.../powershell_installed_iis_modules.yml | 35 +-
.../powershell_script_block_logging_4104.yml | 162 +-
data_sources/powershell_sip_inventory.yml | 15 +-
data_sources/splunk.yml | 63 +-
data_sources/splunk_stream_http.yml | 113 +-
data_sources/splunk_stream_ip.yml | 146 +-
data_sources/splunk_stream_tcp.yml | 23 +-
data_sources/suricata.yml | 109 +-
data_sources/sysmon_eventid_1.yml | 333 +--
data_sources/sysmon_eventid_10.yml | 183 +-
data_sources/sysmon_eventid_11.yml | 188 +-
data_sources/sysmon_eventid_12.yml | 178 +-
data_sources/sysmon_eventid_13.yml | 205 +-
data_sources/sysmon_eventid_15.yml | 184 +-
data_sources/sysmon_eventid_17.yml | 156 +-
data_sources/sysmon_eventid_18.yml | 165 +-
data_sources/sysmon_eventid_20.yml | 171 +-
data_sources/sysmon_eventid_21.yml | 175 +-
data_sources/sysmon_eventid_22.yml | 163 +-
data_sources/sysmon_eventid_23.yml | 187 +-
data_sources/sysmon_eventid_3.yml | 215 +-
data_sources/sysmon_eventid_5.yml | 159 +-
data_sources/sysmon_eventid_6.yml | 166 +-
data_sources/sysmon_eventid_7.yml | 206 +-
data_sources/sysmon_eventid_8.yml | 187 +-
data_sources/sysmon_eventid_9.yml | 161 +-
data_sources/sysmon_for_linux_eventid_1.yml | 205 +-
data_sources/sysmon_for_linux_eventid_11.yml | 161 +-
.../windows_active_directory_admon.yml | 103 +-
data_sources/windows_defender_alerts.yml | 44 +-
.../windows_event_log_application_2282.yml | 130 +-
.../windows_event_log_application_3000.yml | 115 +-
data_sources/windows_event_log_capi2_70.yml | 123 +-
data_sources/windows_event_log_capi2_81.yml | 129 +-
...ent_log_certificateservicesclient_1007.yml | 125 +-
.../windows_event_log_defender_1121.yml | 132 +-
.../windows_event_log_defender_1122.yml | 126 +-
.../windows_event_log_defender_1129.yml | 111 +-
.../windows_event_log_defender_5007.yml | 101 +-
...indows_terminalservices_rdpclient_1024.yml | 101 +-
.../windows_event_log_printservice_316.yml | 102 +-
.../windows_event_log_printservice_808.yml | 113 +-
...event_log_remoteconnectionmanager_1149.yml | 103 +-
.../windows_event_log_security_1100.yml | 142 +-
.../windows_event_log_security_1102.yml | 154 +-
.../windows_event_log_security_4624.yml | 227 +-
.../windows_event_log_security_4625.yml | 217 +-
.../windows_event_log_security_4627.yml | 178 +-
.../windows_event_log_security_4648.yml | 204 +-
.../windows_event_log_security_4662.yml | 178 +-
.../windows_event_log_security_4663.yml | 191 +-
.../windows_event_log_security_4672.yml | 158 +-
.../windows_event_log_security_4688.yml | 239 +--
.../windows_event_log_security_4698.yml | 158 +-
.../windows_event_log_security_4699.yml | 156 +-
.../windows_event_log_security_4703.yml | 196 +-
.../windows_event_log_security_4719.yml | 167 +-
.../windows_event_log_security_4720.yml | 202 +-
.../windows_event_log_security_4724.yml | 189 +-
.../windows_event_log_security_4725.yml | 186 +-
.../windows_event_log_security_4726.yml | 188 +-
.../windows_event_log_security_4732.yml | 181 +-
.../windows_event_log_security_4738.yml | 229 ++-
.../windows_event_log_security_4739.yml | 205 +-
.../windows_event_log_security_4741.yml | 231 ++-
.../windows_event_log_security_4742.yml | 233 +--
.../windows_event_log_security_4768.yml | 193 +-
.../windows_event_log_security_4769.yml | 193 +-
.../windows_event_log_security_4771.yml | 181 +-
.../windows_event_log_security_4776.yml | 163 +-
.../windows_event_log_security_4781.yml | 194 +-
.../windows_event_log_security_4794.yml | 178 +-
.../windows_event_log_security_4798.yml | 174 +-
.../windows_event_log_security_4876.yml | 162 +-
.../windows_event_log_security_4886.yml | 146 +-
.../windows_event_log_security_4887.yml | 152 +-
.../windows_event_log_security_5136.yml | 185 +-
.../windows_event_log_security_5137.yml | 178 +-
.../windows_event_log_security_5140.yml | 213 +-
.../windows_event_log_security_5141.yml | 174 +-
.../windows_event_log_security_5145.yml | 253 +--
.../windows_event_log_system_4720.yml | 211 +-
.../windows_event_log_system_4726.yml | 191 +-
.../windows_event_log_system_4728.yml | 191 +-
.../windows_event_log_system_7036.yml | 142 +-
.../windows_event_log_system_7040.yml | 147 +-
.../windows_event_log_system_7045.yml | 147 +-
.../windows_event_log_taskscheduler_200.yml | 140 +-
data_sources/windows_iis.yml | 21 +-
data_sources/windows_iis_29.yml | 53 +-
.../network/detect_outbound_ldap_traffic.yml | 9 +-
217 files changed, 17727 insertions(+), 17073 deletions(-)
diff --git a/data_sources/asl_aws_cloudtrail.yml b/data_sources/asl_aws_cloudtrail.yml
index 8311be25cc..05767f098b 100644
--- a/data_sources/asl_aws_cloudtrail.yml
+++ b/data_sources/asl_aws_cloudtrail.yml
@@ -1,26 +1,26 @@
name: ASL AWS CloudTrail
id: 1dcf9cfb-0e91-44c6-81b3-61b2574ec898
-version: 1
-date: '2025-01-14'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Represents AWS API dataset data collection from Amazon Security Lake.
mitre_components:
-- Cloud Service Metadata
-- Cloud Service Modification
-- Cloud Storage Access
-- Instance Creation
-- Instance Deletion
-- Instance Start
-- Instance Stop
-- Instance Modification
-- Cloud Storage Creation
-- Cloud Storage Deletion
-- Cloud Service Enumeration
-- Cloud Storage Enumeration
+ - Cloud Service Metadata
+ - Cloud Service Modification
+ - Cloud Storage Access
+ - Instance Creation
+ - Instance Deletion
+ - Instance Start
+ - Instance Stop
+ - Instance Modification
+ - Cloud Storage Creation
+ - Cloud Storage Deletion
+ - Cloud Service Enumeration
+ - Cloud Storage Enumeration
source: aws_asl
sourcetype: aws:asl
separator: api.operation
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
diff --git a/data_sources/aws_cloudfront.yml b/data_sources/aws_cloudfront.yml
index bc4196951d..b8eb8a416b 100644
--- a/data_sources/aws_cloudfront.yml
+++ b/data_sources/aws_cloudfront.yml
@@ -1,102 +1,103 @@
name: AWS Cloudfront
id: 780086dc-2384-45b6-ade7-56cb00105464
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs requests made to AWS CloudFront distributions, including details on client access, response data, and performance metrics.
+description: Logs requests made to AWS CloudFront distributions, including details
+ on client access, response data, and performance metrics.
mitre_components:
-- Network Traffic Content
-- Network Traffic Flow
-- Response Metadata
-- Response Content
-- Logon Session Metadata
-- Cloud Service Metadata
+ - Network Traffic Content
+ - Network Traffic Flow
+ - Response Metadata
+ - Response Content
+ - Logon Session Metadata
+ - Cloud Service Metadata
source: aws
sourcetype: aws:cloudfront:accesslogs
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- bytes
-- bytes_in
-- bytes_out
-- c_ip
-- c_port
-- cached
-- category
-- client_ip
-- cs_bytes
-- cs_cookie
-- cs_host
-- cs_method
-- cs_protocol
-- cs_protocol_version
-- cs_referer
-- cs_uri_query
-- cs_uri_stem
-- cs_user_agent
-- date
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- duration
-- edge_location_name
-- eventtype
-- fle_encrypted_fields
-- fle_status
-- host
-- http_content_type
-- http_method
-- http_user_agent
-- http_user_agent_length
-- index
-- linecount
-- punct
-- response_time
-- sc_bytes
-- sc_content_len
-- sc_content_type
-- sc_range_end
-- sc_range_start
-- sc_status
-- source
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- src_port
-- ssl_cipher
-- ssl_protocol
-- status
-- tag
-- tag::eventtype
-- time
-- time_taken
-- time_to_first_byte
-- timeendpos
-- timestartpos
-- uri_path
-- url
-- url_domain
-- url_length
-- vendor_product
-- x_edge_detail_result_type
-- x_edge_location
-- x_edge_request_id
-- x_edge_response_result_type
-- x_edge_result_type
-- x_forwarded_for
-- x_host_header
+ - _time
+ - action
+ - app
+ - bytes
+ - bytes_in
+ - bytes_out
+ - c_ip
+ - c_port
+ - cached
+ - category
+ - client_ip
+ - cs_bytes
+ - cs_cookie
+ - cs_host
+ - cs_method
+ - cs_protocol
+ - cs_protocol_version
+ - cs_referer
+ - cs_uri_query
+ - cs_uri_stem
+ - cs_user_agent
+ - date
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - duration
+ - edge_location_name
+ - eventtype
+ - fle_encrypted_fields
+ - fle_status
+ - host
+ - http_content_type
+ - http_method
+ - http_user_agent
+ - http_user_agent_length
+ - index
+ - linecount
+ - punct
+ - response_time
+ - sc_bytes
+ - sc_content_len
+ - sc_content_type
+ - sc_range_end
+ - sc_range_start
+ - sc_status
+ - source
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - src_port
+ - ssl_cipher
+ - ssl_protocol
+ - status
+ - tag
+ - tag::eventtype
+ - time
+ - time_taken
+ - time_to_first_byte
+ - timeendpos
+ - timestartpos
+ - uri_path
+ - url
+ - url_domain
+ - url_length
+ - vendor_product
+ - x_edge_detail_result_type
+ - x_edge_location
+ - x_edge_request_id
+ - x_edge_response_result_type
+ - x_edge_result_type
+ - x_forwarded_for
+ - x_host_header
example_log: "2023-11-07\t16:58:21\tIAD55-P5\t921\t44.192.78.55\tGET\td3u5aue66f5ui4.cloudfront.net\t\
/plugins/servlet/com.jsos.shell/ShellServlet\t200\t-\tSlackbot-LinkExpanding%201.0%20(+https://api.slack.com/robots)\t\
-\t-\tLambdaGeneratedResponse\tsGwvFCkFU4qlMxatCoJRgW87P7Ee8bKQor3U6lRt6I6jaFvLC7vcPA==\t\
diff --git a/data_sources/aws_cloudtrail_assumerolewithsaml.yml b/data_sources/aws_cloudtrail_assumerolewithsaml.yml
index acd5a6247f..c9823cd2d7 100644
--- a/data_sources/aws_cloudtrail_assumerolewithsaml.yml
+++ b/data_sources/aws_cloudtrail_assumerolewithsaml.yml
@@ -1,114 +1,114 @@
name: AWS CloudTrail AssumeRoleWithSAML
id: 1e28f2a6-2db9-405f-b298-18734a293f77
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs attempts to assume roles via SAML authentication in AWS, including
details of identity provider and role mapping.
mitre_components:
-- User Account Authentication
-- Logon Session Creation
-- User Account Metadata
-- Cloud Service Metadata
-- Instance Modification
+ - User Account Authentication
+ - Logon Session Creation
+ - User Account Metadata
+ - Cloud Service Metadata
+ - Instance Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: AssumeRoleWithSAML
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- awsRegion
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.durationSeconds
-- requestParameters.principalArn
-- requestParameters.roleArn
-- requestParameters.roleSessionName
-- requestParameters.sAMLAssertionID
-- resources{}.ARN
-- resources{}.accountId
-- resources{}.type
-- responseElements.assumedRoleUser.arn
-- responseElements.assumedRoleUser.assumedRoleId
-- responseElements.audience
-- responseElements.credentials.accessKeyId
-- responseElements.credentials.expiration
-- responseElements.credentials.sessionToken
-- responseElements.issuer
-- responseElements.nameQualifier
-- responseElements.subject
-- responseElements.subjectType
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- src_user
-- src_user_id
-- src_user_type
-- start_time
-- status
-- tag
-- tag::action
-- tag::eventtype
-- temp_access_key
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.identityProvider
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- user_agent
-- user_arn
-- user_id
-- user_name
-- user_role
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - app
+ - awsRegion
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.durationSeconds
+ - requestParameters.principalArn
+ - requestParameters.roleArn
+ - requestParameters.roleSessionName
+ - requestParameters.sAMLAssertionID
+ - resources{}.ARN
+ - resources{}.accountId
+ - resources{}.type
+ - responseElements.assumedRoleUser.arn
+ - responseElements.assumedRoleUser.assumedRoleId
+ - responseElements.audience
+ - responseElements.credentials.accessKeyId
+ - responseElements.credentials.expiration
+ - responseElements.credentials.sessionToken
+ - responseElements.issuer
+ - responseElements.nameQualifier
+ - responseElements.subject
+ - responseElements.subjectType
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - src_user
+ - src_user_id
+ - src_user_type
+ - start_time
+ - status
+ - tag
+ - tag::action
+ - tag::eventtype
+ - temp_access_key
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.identityProvider
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - user_agent
+ - user_arn
+ - user_id
+ - user_name
+ - user_role
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "SAMLUser", "principalId":
"ZRu9MRAjiG9tvi1QBNfdI664G5A=:rodsoto@rodsoto.onmicrosoft.com", "userName": "rodsoto@rodsoto.onmicrosoft.com",
"identityProvider": "ZRu9MRAjiG9tvi1QBNfdI664G5A="}, "eventTime": "2021-01-22T03:44:16Z",
diff --git a/data_sources/aws_cloudtrail_consolelogin.yml b/data_sources/aws_cloudtrail_consolelogin.yml
index 934d502f32..0d05cff28d 100644
--- a/data_sources/aws_cloudtrail_consolelogin.yml
+++ b/data_sources/aws_cloudtrail_consolelogin.yml
@@ -1,101 +1,102 @@
name: AWS CloudTrail ConsoleLogin
id: b68b3f26-bd21-4fa8-b593-616fe75ac0ae
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs attempts to sign in to the AWS Management Console, including successful and failed login events.
+description: Logs attempts to sign in to the AWS Management Console, including successful
+ and failed login events.
mitre_components:
-- User Account Authentication
-- Logon Session Creation
-- User Account Metadata
-- Logon Session Metadata
-- Cloud Service Metadata
+ - User Account Authentication
+ - Logon Session Creation
+ - User Account Metadata
+ - Logon Session Metadata
+ - Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: ConsoleLogin
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- additionalEventData.LoginTo
-- additionalEventData.MFAUsed
-- additionalEventData.MobileVersion
-- app
-- authentication_method
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- desc
-- dest
-- dvc
-- errorCode
-- errorMessage
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- reason
-- recipientAccountId
-- region
-- requestParameters
-- responseElements.ConsoleLogin
-- result
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- status
-- tag
-- tag::action
-- tag::eventtype
-- timeendpos
-- timestartpos
-- tlsDetails.cipherSuite
-- tlsDetails.clientProvidedHostHeader
-- tlsDetails.tlsVersion
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.type
-- userIdentity.userName
-- user_access_key
-- user_agent
-- user_group_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - additionalEventData.LoginTo
+ - additionalEventData.MFAUsed
+ - additionalEventData.MobileVersion
+ - app
+ - authentication_method
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - desc
+ - dest
+ - dvc
+ - errorCode
+ - errorMessage
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - reason
+ - recipientAccountId
+ - region
+ - requestParameters
+ - responseElements.ConsoleLogin
+ - result
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - status
+ - tag
+ - tag::action
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - tlsDetails.cipherSuite
+ - tlsDetails.clientProvidedHostHeader
+ - tlsDetails.tlsVersion
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.type
+ - userIdentity.userName
+ - user_access_key
+ - user_agent
+ - user_group_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "accountId":
"140429656527", "accessKeyId": "", "userName": "HIDDEN_DUE_TO_SECURITY_REASONS"},
"eventTime": "2022-10-19T20:33:38Z", "eventSource": "signin.amazonaws.com", "eventName":
diff --git a/data_sources/aws_cloudtrail_copyobject.yml b/data_sources/aws_cloudtrail_copyobject.yml
index 72a9c6af4b..9edd40bb4d 100644
--- a/data_sources/aws_cloudtrail_copyobject.yml
+++ b/data_sources/aws_cloudtrail_copyobject.yml
@@ -1,106 +1,107 @@
name: AWS CloudTrail CopyObject
id: 965083f4-64a8-403f-99cc-252e1a6bd3b6
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs operations that copy objects within or between AWS S3 buckets, including details of source and destination.
+description: Logs operations that copy objects within or between AWS S3 buckets, including
+ details of source and destination.
mitre_components:
-- Cloud Storage Access
-- Cloud Storage Modification
-- Cloud Storage Metadata
-- Instance Modification
+ - Cloud Storage Access
+ - Cloud Storage Modification
+ - Cloud Storage Metadata
+ - Instance Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_values: CopyObject
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- additionalEventData.AuthenticationMethod
-- additionalEventData.CipherSuite
-- additionalEventData.SSEApplied
-- additionalEventData.SignatureVersion
-- additionalEventData.bytesTransferredIn
-- additionalEventData.bytesTransferredOut
-- additionalEventData.x-amz-id-2
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.Host
-- requestParameters.bucketName
-- requestParameters.key
-- requestParameters.x-amz-copy-source
-- requestParameters.x-amz-server-side-encryption
-- requestParameters.x-amz-server-side-encryption-aws-kms-key-id
-- resources{}.ARN
-- resources{}.accountId
-- resources{}.type
-- responseElements.x-amz-server-side-encryption
-- responseElements.x-amz-server-side-encryption-aws-kms-key-id
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - additionalEventData.AuthenticationMethod
+ - additionalEventData.CipherSuite
+ - additionalEventData.SSEApplied
+ - additionalEventData.SignatureVersion
+ - additionalEventData.bytesTransferredIn
+ - additionalEventData.bytesTransferredOut
+ - additionalEventData.x-amz-id-2
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.Host
+ - requestParameters.bucketName
+ - requestParameters.key
+ - requestParameters.x-amz-copy-source
+ - requestParameters.x-amz-server-side-encryption
+ - requestParameters.x-amz-server-side-encryption-aws-kms-key-id
+ - resources{}.ARN
+ - resources{}.accountId
+ - resources{}.type
+ - responseElements.x-amz-server-side-encryption
+ - responseElements.x-amz-server-side-encryption-aws-kms-key-id
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLNALZHZ6KX", "arn": "arn:aws:iam::111111111111:user/patrick_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLJ2OYSF6E", "userName": "patrick_cli"},
diff --git a/data_sources/aws_cloudtrail_createaccesskey.yml b/data_sources/aws_cloudtrail_createaccesskey.yml
index 6e95f8ab0f..d72354f779 100644
--- a/data_sources/aws_cloudtrail_createaccesskey.yml
+++ b/data_sources/aws_cloudtrail_createaccesskey.yml
@@ -1,100 +1,101 @@
name: AWS CloudTrail CreateAccessKey
id: 0460f7da-3254-4d90-b8c0-2ca657d0cea0
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the creation of new AWS access keys, including details of the associated user and permissions.
+description: Logs the creation of new AWS access keys, including details of the associated
+ user and permissions.
mitre_components:
-- User Account Creation
-- User Account Metadata
-- Cloud Service Modification
-- Cloud Service Metadata
+ - User Account Creation
+ - User Account Metadata
+ - Cloud Service Modification
+ - Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreateAccessKey
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.userName
-- responseElements.accessKey.accessKeyId
-- responseElements.accessKey.createDate
-- responseElements.accessKey.status
-- responseElements.accessKey.userName
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- src_user_name
-- start_time
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.userName
+ - responseElements.accessKey.accessKeyId
+ - responseElements.accessKey.createDate
+ - responseElements.accessKey.status
+ - responseElements.accessKey.userName
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - src_user_name
+ - start_time
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::121521347698:user/bhavin_cli", "accountId":
"121521347698", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
diff --git a/data_sources/aws_cloudtrail_createkey.yml b/data_sources/aws_cloudtrail_createkey.yml
index 655ce8762f..293ecba3cd 100644
--- a/data_sources/aws_cloudtrail_createkey.yml
+++ b/data_sources/aws_cloudtrail_createkey.yml
@@ -1,118 +1,119 @@
name: AWS CloudTrail CreateKey
id: fcfc1593-b6b5-4a0f-91c5-3c395116a8b9
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the creation of new AWS KMS keys, including details of key properties and associated metadata.
+description: Logs the creation of new AWS KMS keys, including details of key properties
+ and associated metadata.
mitre_components:
-- Cloud Service Creation
-- Cloud Service Metadata
-- Instance Creation
-- Volume Metadata
+ - Cloud Service Creation
+ - Cloud Service Metadata
+ - Instance Creation
+ - Volume Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreateKey
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.bypassPolicyLockoutSafetyCheck
-- requestParameters.customerMasterKeySpec
-- requestParameters.description
-- requestParameters.keyUsage
-- requestParameters.origin
-- requestParameters.policy
-- resources{}.ARN
-- resources{}.accountId
-- resources{}.type
-- responseElements.keyMetadata.aWSAccountId
-- responseElements.keyMetadata.arn
-- responseElements.keyMetadata.creationDate
-- responseElements.keyMetadata.customerMasterKeySpec
-- responseElements.keyMetadata.description
-- responseElements.keyMetadata.enabled
-- responseElements.keyMetadata.encryptionAlgorithms{}
-- responseElements.keyMetadata.keyId
-- responseElements.keyMetadata.keyManager
-- responseElements.keyMetadata.keyState
-- responseElements.keyMetadata.keyUsage
-- responseElements.keyMetadata.origin
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.sessionContext.sessionIssuer.accountId
-- userIdentity.sessionContext.sessionIssuer.arn
-- userIdentity.sessionContext.sessionIssuer.principalId
-- userIdentity.sessionContext.sessionIssuer.type
-- userIdentity.sessionContext.sessionIssuer.userName
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.bypassPolicyLockoutSafetyCheck
+ - requestParameters.customerMasterKeySpec
+ - requestParameters.description
+ - requestParameters.keyUsage
+ - requestParameters.origin
+ - requestParameters.policy
+ - resources{}.ARN
+ - resources{}.accountId
+ - resources{}.type
+ - responseElements.keyMetadata.aWSAccountId
+ - responseElements.keyMetadata.arn
+ - responseElements.keyMetadata.creationDate
+ - responseElements.keyMetadata.customerMasterKeySpec
+ - responseElements.keyMetadata.description
+ - responseElements.keyMetadata.enabled
+ - responseElements.keyMetadata.encryptionAlgorithms{}
+ - responseElements.keyMetadata.keyId
+ - responseElements.keyMetadata.keyManager
+ - responseElements.keyMetadata.keyState
+ - responseElements.keyMetadata.keyUsage
+ - responseElements.keyMetadata.origin
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.sessionContext.sessionIssuer.accountId
+ - userIdentity.sessionContext.sessionIssuer.arn
+ - userIdentity.sessionContext.sessionIssuer.principalId
+ - userIdentity.sessionContext.sessionIssuer.type
+ - userIdentity.sessionContext.sessionIssuer.userName
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLK74OPBDR", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_createloginprofile.yml b/data_sources/aws_cloudtrail_createloginprofile.yml
index 7c272ab23f..df6b04e40d 100644
--- a/data_sources/aws_cloudtrail_createloginprofile.yml
+++ b/data_sources/aws_cloudtrail_createloginprofile.yml
@@ -1,99 +1,100 @@
name: AWS CloudTrail CreateLoginProfile
id: 0024fdb1-0d62-4449-970a-746952cf80b6
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the creation of login profiles for IAM users, including associated metadata and authentication settings.
+description: Logs the creation of login profiles for IAM users, including associated
+ metadata and authentication settings.
mitre_components:
-- User Account Creation
-- User Account Metadata
-- Logon Session Metadata
-- Cloud Service Metadata
+ - User Account Creation
+ - User Account Metadata
+ - Logon Session Metadata
+ - Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreateLoginProfile
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.passwordResetRequired
-- requestParameters.userName
-- responseElements.loginProfile.createDate
-- responseElements.loginProfile.passwordResetRequired
-- responseElements.loginProfile.userName
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.passwordResetRequired
+ - requestParameters.userName
+ - responseElements.loginProfile.createDate
+ - responseElements.loginProfile.passwordResetRequired
+ - responseElements.loginProfile.userName
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
diff --git a/data_sources/aws_cloudtrail_createnetworkaclentry.yml b/data_sources/aws_cloudtrail_createnetworkaclentry.yml
index 65830e0d0c..993b03197a 100644
--- a/data_sources/aws_cloudtrail_createnetworkaclentry.yml
+++ b/data_sources/aws_cloudtrail_createnetworkaclentry.yml
@@ -1,115 +1,116 @@
name: AWS CloudTrail CreateNetworkAclEntry
id: 45934028-10ec-4ab5-a7b1-a6349b833e67
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the creation of new entries in a network ACL, including rules to allow or deny specific network traffic.
+description: Logs the creation of new entries in a network ACL, including rules to
+ allow or deny specific network traffic.
mitre_components:
-- Firewall Rule Modification
-- Network Connection Creation
-- Cloud Service Modification
-- Cloud Service Metadata
+ - Firewall Rule Modification
+ - Network Connection Creation
+ - Cloud Service Modification
+ - Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreateNetworkAclEntry
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- direction
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object
-- object_category
-- object_id
-- product
-- protocol
-- protocol_code
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.aclProtocol
-- requestParameters.cidrBlock
-- requestParameters.egress
-- requestParameters.networkAclId
-- requestParameters.ruleAction
-- requestParameters.ruleNumber
-- responseElements._return
-- responseElements.requestId
-- rule_action
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- src_ip_range
-- start_time
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.sessionContext.sessionIssuer.accountId
-- userIdentity.sessionContext.sessionIssuer.arn
-- userIdentity.sessionContext.sessionIssuer.principalId
-- userIdentity.sessionContext.sessionIssuer.type
-- userIdentity.sessionContext.sessionIssuer.userName
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - direction
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object
+ - object_category
+ - object_id
+ - product
+ - protocol
+ - protocol_code
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.aclProtocol
+ - requestParameters.cidrBlock
+ - requestParameters.egress
+ - requestParameters.networkAclId
+ - requestParameters.ruleAction
+ - requestParameters.ruleNumber
+ - responseElements._return
+ - responseElements.requestId
+ - rule_action
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - src_ip_range
+ - start_time
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.sessionContext.sessionIssuer.accountId
+ - userIdentity.sessionContext.sessionIssuer.arn
+ - userIdentity.sessionContext.sessionIssuer.principalId
+ - userIdentity.sessionContext.sessionIssuer.type
+ - userIdentity.sessionContext.sessionIssuer.userName
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_createpolicyversion.yml b/data_sources/aws_cloudtrail_createpolicyversion.yml
index cc6b2d03f0..2973c651b0 100644
--- a/data_sources/aws_cloudtrail_createpolicyversion.yml
+++ b/data_sources/aws_cloudtrail_createpolicyversion.yml
@@ -1,100 +1,101 @@
name: AWS CloudTrail CreatePolicyVersion
id: f9f0f3da-37ec-4164-9ea0-0ae46645a86b
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the creation of new versions of IAM policies, including changes to permissions and attached roles or resources.
+description: Logs the creation of new versions of IAM policies, including changes
+ to permissions and attached roles or resources.
mitre_components:
-- Cloud Service Modification
-- Cloud Service Metadata
-- User Account Metadata
-- Group Modification
+ - Cloud Service Modification
+ - Cloud Service Metadata
+ - User Account Metadata
+ - Group Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreatePolicyVersion
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.policyArn
-- requestParameters.policyDocument
-- requestParameters.setAsDefault
-- responseElements.policyVersion.createDate
-- responseElements.policyVersion.isDefaultVersion
-- responseElements.policyVersion.versionId
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.policyArn
+ - requestParameters.policyDocument
+ - requestParameters.setAsDefault
+ - responseElements.policyVersion.createDate
+ - responseElements.policyVersion.isDefaultVersion
+ - responseElements.policyVersion.versionId
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLNMCDVJZAY", "arn": "arn:aws:iam::111111111111:user/rhino_escalate",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLHSQZPZFZ", "userName":
diff --git a/data_sources/aws_cloudtrail_createsnapshot.yml b/data_sources/aws_cloudtrail_createsnapshot.yml
index db7c828449..ae5c392552 100644
--- a/data_sources/aws_cloudtrail_createsnapshot.yml
+++ b/data_sources/aws_cloudtrail_createsnapshot.yml
@@ -1,109 +1,110 @@
name: AWS CloudTrail CreateSnapshot
id: 514135a2-f4b2-4d32-8f31-d87824887f9f
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the creation of a new snapshot of a cloud resource, such as an Amazon EBS volume, including details about the snapshot ID and resource type.
+description: Logs the creation of a new snapshot of a cloud resource, such as an Amazon
+ EBS volume, including details about the snapshot ID and resource type.
mitre_components:
-- Snapshot Creation
-- Snapshot Metadata
-- Volume Metadata
-- Cloud Service Metadata
+ - Snapshot Creation
+ - Snapshot Metadata
+ - Volume Metadata
+ - Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreateSnapshot
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.tagSpecificationSet.items{}.resourceType
-- requestParameters.tagSpecificationSet.items{}.tags{}.key
-- requestParameters.tagSpecificationSet.items{}.tags{}.value
-- requestParameters.volumeId
-- responseElements.encrypted
-- responseElements.ownerId
-- responseElements.requestId
-- responseElements.snapshotId
-- responseElements.startTime
-- responseElements.status
-- responseElements.tagSet.items{}.key
-- responseElements.tagSet.items{}.value
-- responseElements.volumeId
-- responseElements.volumeSize
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- tlsDetails.cipherSuite
-- tlsDetails.clientProvidedHostHeader
-- tlsDetails.tlsVersion
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.tagSpecificationSet.items{}.resourceType
+ - requestParameters.tagSpecificationSet.items{}.tags{}.key
+ - requestParameters.tagSpecificationSet.items{}.tags{}.value
+ - requestParameters.volumeId
+ - responseElements.encrypted
+ - responseElements.ownerId
+ - responseElements.requestId
+ - responseElements.snapshotId
+ - responseElements.startTime
+ - responseElements.status
+ - responseElements.tagSet.items{}.key
+ - responseElements.tagSet.items{}.value
+ - responseElements.volumeId
+ - responseElements.volumeSize
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - tlsDetails.cipherSuite
+ - tlsDetails.clientProvidedHostHeader
+ - tlsDetails.tlsVersion
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/bhavin_console",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName":
diff --git a/data_sources/aws_cloudtrail_createtask.yml b/data_sources/aws_cloudtrail_createtask.yml
index ee7394b6e4..7808c2b9cc 100644
--- a/data_sources/aws_cloudtrail_createtask.yml
+++ b/data_sources/aws_cloudtrail_createtask.yml
@@ -1,108 +1,109 @@
name: AWS CloudTrail CreateTask
id: 6501e4fe-05b2-45f1-bd51-9e06a94fa7d9
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the creation of a new task in AWS services, such as ECS, including details about the task definition and resource allocation.
+description: Logs the creation of a new task in AWS services, such as ECS, including
+ details about the task definition and resource allocation.
mitre_components:
-- Scheduled Job Creation
-- Scheduled Job Metadata
-- Cloud Service Metadata
-- Instance Creation
+ - Scheduled Job Creation
+ - Scheduled Job Metadata
+ - Cloud Service Metadata
+ - Instance Creation
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_name: CreateTask
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.cloudWatchLogGroupArn
-- requestParameters.destinationLocationArn
-- requestParameters.options.logLevel
-- requestParameters.options.verifyMode
-- requestParameters.schedule.scheduleExpression
-- requestParameters.sourceLocationArn
-- responseElements.taskArn
-- sessionCredentialFromConsole
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- tlsDetails.cipherSuite
-- tlsDetails.clientProvidedHostHeader
-- tlsDetails.tlsVersion
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.sessionContext.sessionIssuer.accountId
-- userIdentity.sessionContext.sessionIssuer.arn
-- userIdentity.sessionContext.sessionIssuer.principalId
-- userIdentity.sessionContext.sessionIssuer.type
-- userIdentity.sessionContext.sessionIssuer.userName
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.cloudWatchLogGroupArn
+ - requestParameters.destinationLocationArn
+ - requestParameters.options.logLevel
+ - requestParameters.options.verifyMode
+ - requestParameters.schedule.scheduleExpression
+ - requestParameters.sourceLocationArn
+ - responseElements.taskArn
+ - sessionCredentialFromConsole
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - tlsDetails.cipherSuite
+ - tlsDetails.clientProvidedHostHeader
+ - tlsDetails.tlsVersion
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.sessionContext.sessionIssuer.accountId
+ - userIdentity.sessionContext.sessionIssuer.arn
+ - userIdentity.sessionContext.sessionIssuer.principalId
+ - userIdentity.sessionContext.sessionIssuer.type
+ - userIdentity.sessionContext.sessionIssuer.userName
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLDF6WQQQQQ:abc@acme.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/abc@acme.com",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLOB2GM111", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml
index ba978e3343..7b6b181672 100644
--- a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml
+++ b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml
@@ -1,98 +1,99 @@
name: AWS CloudTrail CreateVirtualMFADevice
id: 13e6e952-0dad-4190-865c-fb5911725f7a
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the creation of a new virtual multi-factor authentication (MFA) device, including details about the associated user and configuration.
+description: Logs the creation of a new virtual multi-factor authentication (MFA)
+ device, including details about the associated user and configuration.
mitre_components:
-- User Account Creation
-- User Account Metadata
-- Cloud Service Creation
-- Cloud Service Metadata
+ - User Account Creation
+ - User Account Metadata
+ - Cloud Service Creation
+ - Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreateVirtualMFADevice
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.path
-- requestParameters.virtualMFADeviceName
-- responseElements.virtualMFADevice.serialNumber
-- sessionCredentialFromConsole
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.path
+ - requestParameters.virtualMFADeviceName
+ - responseElements.virtualMFADevice.serialNumber
+ - sessionCredentialFromConsole
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
"140429656527", "arn": "arn:aws:iam::140429656527:root", "accountId": "140429656527",
"accessKeyId": "ASIASBMSCQHH2YXNXJBU", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
diff --git a/data_sources/aws_cloudtrail_deactivatemfadevice.yml b/data_sources/aws_cloudtrail_deactivatemfadevice.yml
index a62bdde87c..e53018b544 100644
--- a/data_sources/aws_cloudtrail_deactivatemfadevice.yml
+++ b/data_sources/aws_cloudtrail_deactivatemfadevice.yml
@@ -1,98 +1,99 @@
name: AWS CloudTrail DeactivateMFADevice
id: 7397a10b-1150-4de9-8062-a96454ae53b2
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the deactivation of a multi-factor authentication (MFA) device, including details about the associated user and the device.
+description: Logs the deactivation of a multi-factor authentication (MFA) device,
+ including details about the associated user and the device.
mitre_components:
-- User Account Modification
-- User Account Metadata
-- Cloud Service Modification
-- Cloud Service Metadata
+ - User Account Modification
+ - User Account Metadata
+ - Cloud Service Modification
+ - Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeactivateMFADevice
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.serialNumber
-- requestParameters.userName
-- responseElements
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.serialNumber
+ - requestParameters.userName
+ - responseElements
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
"111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111",
"accessKeyId": "ASIASBMSCQHHWAIHMHUX", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
diff --git a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml
index 631ac8d253..9d10c7443a 100644
--- a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml
+++ b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml
@@ -1,97 +1,98 @@
name: AWS CloudTrail DeleteAccountPasswordPolicy
id: b0730ac8-0992-4de8-b000-2c7d0fc7a67f
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the deletion of an account-level password policy in AWS, including details about the account and policy being removed.
+description: Logs the deletion of an account-level password policy in AWS, including
+ details about the account and policy being removed.
mitre_components:
-- Cloud Service Modification
-- Cloud Service Metadata
+ - Cloud Service Modification
+ - Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteAccountPasswordPolicy
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- desc
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters
-- responseElements
-- sessionCredentialFromConsole
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - desc
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters
+ - responseElements
+ - sessionCredentialFromConsole
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
"111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111",
"accessKeyId": "ASIASBMSCQHHWMDJXSE6", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
diff --git a/data_sources/aws_cloudtrail_deletealarms.yml b/data_sources/aws_cloudtrail_deletealarms.yml
index 2fdf221e51..7babfa595c 100644
--- a/data_sources/aws_cloudtrail_deletealarms.yml
+++ b/data_sources/aws_cloudtrail_deletealarms.yml
@@ -1,132 +1,133 @@
name: AWS CloudTrail DeleteAlarms
id: b0730ac8-0992-4de8-b000-2c7d0fc7a61f
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Bhavin Patel, Splunk
-description: Logs the deletion of CloudWatch alarms, including details about the alarm names and associated monitoring configurations.
+description: Logs the deletion of CloudWatch alarms, including details about the alarm
+ names and associated monitoring configurations.
mitre_components:
-- Cloud Service Modification
-- Cloud Service Metadata
-- Application Log Content
-- Host Status
+ - Cloud Service Modification
+ - Cloud Service Metadata
+ - Application Log Content
+ - Host Status
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteAlarms
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- authentication_method
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- desc
-- dest
-- dest_ip_range
-- dest_port_range
-- direction
-- dvc
-- errorCode
-- errorMessage
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- image_id
-- index
-- instance_type
-- linecount
-- managementEvent
-- msg
-- object
-- object_attrs
-- object_category
-- object_id
-- product
-- protocol
-- protocol_code
-- punct
-- readOnly
-- reason
-- recipientAccountId
-- region
-- requestID
-- requestParameters.alarmNames{}
-- responseElements
-- result
-- result_id
-- rule_action
-- sessionCredentialFromConsole
-- signature
-- source
-- sourceIPAddress
-- splunk_server
-- splunk_server_group
-- src
-- src_ip
-- src_ip_range
-- src_port_range
-- src_user
-- src_user_id
-- src_user_name
-- src_user_role
-- src_user_type
-- start_time
-- status
-- tag
-- tag::action
-- tag::eventtype
-- tag::object_category
-- temp_access_key
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.invokedBy
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.sessionContext.sessionIssuer.accountId
-- userIdentity.sessionContext.sessionIssuer.arn
-- userIdentity.sessionContext.sessionIssuer.principalId
-- userIdentity.sessionContext.sessionIssuer.type
-- userIdentity.sessionContext.sessionIssuer.userName
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_role
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - app
+ - authentication_method
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - desc
+ - dest
+ - dest_ip_range
+ - dest_port_range
+ - direction
+ - dvc
+ - errorCode
+ - errorMessage
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - image_id
+ - index
+ - instance_type
+ - linecount
+ - managementEvent
+ - msg
+ - object
+ - object_attrs
+ - object_category
+ - object_id
+ - product
+ - protocol
+ - protocol_code
+ - punct
+ - readOnly
+ - reason
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.alarmNames{}
+ - responseElements
+ - result
+ - result_id
+ - rule_action
+ - sessionCredentialFromConsole
+ - signature
+ - source
+ - sourceIPAddress
+ - splunk_server
+ - splunk_server_group
+ - src
+ - src_ip
+ - src_ip_range
+ - src_port_range
+ - src_user
+ - src_user_id
+ - src_user_name
+ - src_user_role
+ - src_user_type
+ - start_time
+ - status
+ - tag
+ - tag::action
+ - tag::eventtype
+ - tag::object_category
+ - temp_access_key
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.invokedBy
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.sessionContext.sessionIssuer.accountId
+ - userIdentity.sessionContext.sessionIssuer.arn
+ - userIdentity.sessionContext.sessionIssuer.principalId
+ - userIdentity.sessionContext.sessionIssuer.type
+ - userIdentity.sessionContext.sessionIssuer.userName
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_role
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLKZK7JIDWN:AutoScaling-ManageAlarms", "arn": "arn:aws:sts::111111111111:assumed-role/AWSServiceRoleForApplicationAutoScaling_DynamoDBTable/AutoScaling-ManageAlarms",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLJ7ZZZZZZZ", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_deletedetector.yml b/data_sources/aws_cloudtrail_deletedetector.yml
index f467d9348d..f20cba230e 100644
--- a/data_sources/aws_cloudtrail_deletedetector.yml
+++ b/data_sources/aws_cloudtrail_deletedetector.yml
@@ -1,95 +1,96 @@
name: AWS CloudTrail DeleteDetector
id: 5d8bd475-c8bc-4447-b27f-efa508728b90
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the deletion of an Amazon GuardDuty detector, including details about the detector ID and associated configurations.
+description: Logs the deletion of an Amazon GuardDuty detector, including details
+ about the detector ID and associated configurations.
mitre_components:
-- Cloud Service Modification
-- Cloud Service Metadata
-- Host Status
-- Application Log Content
+ - Cloud Service Modification
+ - Cloud Service Metadata
+ - Host Status
+ - Application Log Content
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteDetector
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.detectorId
-- responseElements.__type
-- responseElements.message
-- result_id
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.detectorId
+ - responseElements.__type
+ - responseElements.message
+ - result_id
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
diff --git a/data_sources/aws_cloudtrail_deletegroup.yml b/data_sources/aws_cloudtrail_deletegroup.yml
index a683fd2697..e2bd256da6 100644
--- a/data_sources/aws_cloudtrail_deletegroup.yml
+++ b/data_sources/aws_cloudtrail_deletegroup.yml
@@ -1,100 +1,101 @@
name: AWS CloudTrail DeleteGroup
id: c95308a4-a943-42ca-b112-f90a05c21bd3
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the deletion of an IAM group in AWS, including details about the group name and its associated policies or members.
+description: Logs the deletion of an IAM group in AWS, including details about the
+ group name and its associated policies or members.
mitre_components:
-- Group Modification
-- Group Metadata
-- User Account Metadata
-- Cloud Service Modification
+ - Group Modification
+ - Group Metadata
+ - User Account Metadata
+ - Cloud Service Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteGroup
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- errorMessage
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- reason
-- recipientAccountId
-- region
-- requestID
-- requestParameters.groupName
-- responseElements
-- result
-- result_id
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - errorMessage
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - reason
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.groupName
+ - responseElements
+ - result
+ - result_id
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::121522247101:user/bhavin_cli", "accountId":
"121522247101", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
diff --git a/data_sources/aws_cloudtrail_deleteipset.yml b/data_sources/aws_cloudtrail_deleteipset.yml
index 4c8770dcb2..ce670c3006 100644
--- a/data_sources/aws_cloudtrail_deleteipset.yml
+++ b/data_sources/aws_cloudtrail_deleteipset.yml
@@ -1,95 +1,96 @@
name: AWS CloudTrail DeleteIPSet
id: ebdeeb63-77a0-4808-a6fe-549956731377
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the deletion of an IP set in AWS WAF or GuardDuty, including details about the IP set ID and its associated configurations.
+description: Logs the deletion of an IP set in AWS WAF or GuardDuty, including details
+ about the IP set ID and its associated configurations.
mitre_components:
-- Cloud Service Modification
-- Cloud Service Metadata
-- Firewall Rule Modification
+ - Cloud Service Modification
+ - Cloud Service Metadata
+ - Firewall Rule Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteIPSet
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.detectorId
-- requestParameters.ipSetId
-- responseElements.__type
-- responseElements.message
-- result_id
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.detectorId
+ - requestParameters.ipSetId
+ - responseElements.__type
+ - responseElements.message
+ - result_id
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"},
diff --git a/data_sources/aws_cloudtrail_deleteloggroup.yml b/data_sources/aws_cloudtrail_deleteloggroup.yml
index 04895c5bab..3aafeff30a 100644
--- a/data_sources/aws_cloudtrail_deleteloggroup.yml
+++ b/data_sources/aws_cloudtrail_deleteloggroup.yml
@@ -1,97 +1,98 @@
name: AWS CloudTrail DeleteLogGroup
id: 60cf6a69-fa43-4a6c-8808-e9fb46bf387f
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the deletion of a CloudWatch log group, including details about the log group name and associated resources.
+description: Logs the deletion of a CloudWatch log group, including details about
+ the log group name and associated resources.
mitre_components:
-- Cloud Service Modification
-- Cloud Service Metadata
-- Application Log Content
-- Host Status
+ - Cloud Service Modification
+ - Cloud Service Metadata
+ - Application Log Content
+ - Host Status
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteLogGroup
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- apiVersion
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.logGroupName
-- responseElements
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- tlsDetails.cipherSuite
-- tlsDetails.clientProvidedHostHeader
-- tlsDetails.tlsVersion
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - apiVersion
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.logGroupName
+ - responseElements
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - tlsDetails.cipherSuite
+ - tlsDetails.clientProvidedHostHeader
+ - tlsDetails.tlsVersion
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
diff --git a/data_sources/aws_cloudtrail_deletelogstream.yml b/data_sources/aws_cloudtrail_deletelogstream.yml
index 998218f3d2..7f4805833e 100644
--- a/data_sources/aws_cloudtrail_deletelogstream.yml
+++ b/data_sources/aws_cloudtrail_deletelogstream.yml
@@ -1,98 +1,99 @@
name: AWS CloudTrail DeleteLogStream
id: 6f8bb808-89f8-465e-a34d-229df2f46402
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the deletion of a log stream within a CloudWatch log group, including details about the stream name and associated log group.
+description: Logs the deletion of a log stream within a CloudWatch log group, including
+ details about the stream name and associated log group.
mitre_components:
-- Cloud Service Modification
-- Cloud Service Metadata
-- Application Log Content
-- Host Status
+ - Cloud Service Modification
+ - Cloud Service Metadata
+ - Application Log Content
+ - Host Status
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteLogStream
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- apiVersion
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.logGroupName
-- requestParameters.logStreamName
-- responseElements
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- tlsDetails.cipherSuite
-- tlsDetails.clientProvidedHostHeader
-- tlsDetails.tlsVersion
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - apiVersion
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.logGroupName
+ - requestParameters.logStreamName
+ - responseElements
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - tlsDetails.cipherSuite
+ - tlsDetails.clientProvidedHostHeader
+ - tlsDetails.tlsVersion
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
diff --git a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml
index ce7ac268b0..deca786012 100644
--- a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml
+++ b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml
@@ -1,104 +1,105 @@
name: AWS CloudTrail DeleteNetworkAclEntry
id: a0dd0f10-cc03-425d-bd5a-e1e0d954b856
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the deletion of a network ACL entry in AWS, including details about the rule number and associated network ACL.
+description: Logs the deletion of a network ACL entry in AWS, including details about
+ the rule number and associated network ACL.
mitre_components:
-- Firewall Rule Modification
-- Cloud Service Modification
-- Cloud Service Metadata
+ - Firewall Rule Modification
+ - Cloud Service Modification
+ - Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteNetworkAclEntry
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- direction
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.egress
-- requestParameters.networkAclId
-- requestParameters.ruleNumber
-- responseElements._return
-- responseElements.requestId
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.sessionContext.sessionIssuer.accountId
-- userIdentity.sessionContext.sessionIssuer.arn
-- userIdentity.sessionContext.sessionIssuer.principalId
-- userIdentity.sessionContext.sessionIssuer.type
-- userIdentity.sessionContext.sessionIssuer.userName
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - direction
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.egress
+ - requestParameters.networkAclId
+ - requestParameters.ruleNumber
+ - responseElements._return
+ - responseElements.requestId
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.sessionContext.sessionIssuer.accountId
+ - userIdentity.sessionContext.sessionIssuer.arn
+ - userIdentity.sessionContext.sessionIssuer.principalId
+ - userIdentity.sessionContext.sessionIssuer.type
+ - userIdentity.sessionContext.sessionIssuer.userName
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_deletepolicy.yml b/data_sources/aws_cloudtrail_deletepolicy.yml
index fd3dbe18c2..62fa46bbd0 100644
--- a/data_sources/aws_cloudtrail_deletepolicy.yml
+++ b/data_sources/aws_cloudtrail_deletepolicy.yml
@@ -1,98 +1,99 @@
name: AWS CloudTrail DeletePolicy
id: d190d23a-2c59-4a0e-9c55-a53ebef28ee5
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the deletion of an IAM policy in AWS, including details about the policy name and its associated roles or users.
+description: Logs the deletion of an IAM policy in AWS, including details about the
+ policy name and its associated roles or users.
mitre_components:
-- Cloud Service Modification
-- Cloud Service Metadata
+ - Cloud Service Modification
+ - Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeletePolicy
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- errorMessage
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- reason
-- recipientAccountId
-- region
-- requestID
-- requestParameters.policyArn
-- responseElements
-- result
-- result_id
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - errorMessage
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - reason
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.policyArn
+ - responseElements
+ - result
+ - result_id
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::151521547504:user/bhavin_cli", "accountId":
"151521547504", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
diff --git a/data_sources/aws_cloudtrail_deleterule.yml b/data_sources/aws_cloudtrail_deleterule.yml
index b5bf81865b..b5f3c819fa 100644
--- a/data_sources/aws_cloudtrail_deleterule.yml
+++ b/data_sources/aws_cloudtrail_deleterule.yml
@@ -1,98 +1,99 @@
name: AWS CloudTrail DeleteRule
id: b5760623-f3ca-492d-a372-d5c2b3567dfc
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the deletion of an event rule in AWS EventBridge, including details about the rule name and its associated targets or schedules.
+description: Logs the deletion of an event rule in AWS EventBridge, including details
+ about the rule name and its associated targets or schedules.
mitre_components:
-- Cloud Service Modification
-- Cloud Service Metadata
-- Scheduled Job Modification
-- Application Log Content
+ - Cloud Service Modification
+ - Cloud Service Metadata
+ - Scheduled Job Modification
+ - Application Log Content
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteRule
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- apiVersion
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.changeToken
-- requestParameters.ruleId
-- responseElements.changeToken
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- tlsDetails.cipherSuite
-- tlsDetails.clientProvidedHostHeader
-- tlsDetails.tlsVersion
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - apiVersion
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.changeToken
+ - requestParameters.ruleId
+ - responseElements.changeToken
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - tlsDetails.cipherSuite
+ - tlsDetails.clientProvidedHostHeader
+ - tlsDetails.tlsVersion
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
diff --git a/data_sources/aws_cloudtrail_deletesnapshot.yml b/data_sources/aws_cloudtrail_deletesnapshot.yml
index dc157cb6bd..62a075237d 100644
--- a/data_sources/aws_cloudtrail_deletesnapshot.yml
+++ b/data_sources/aws_cloudtrail_deletesnapshot.yml
@@ -1,139 +1,140 @@
name: AWS CloudTrail DeleteSnapshot
id: b0731ac8-0992-4de8-b000-2c7d0fc2a61f
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Bhavin Patel, Splunk
-description: Logs the deletion of a cloud resource snapshot, such as an Amazon EBS snapshot, including details about the snapshot ID and associated resource.
+description: Logs the deletion of a cloud resource snapshot, such as an Amazon EBS
+ snapshot, including details about the snapshot ID and associated resource.
mitre_components:
-- Snapshot Deletion
-- Snapshot Metadata
-- Cloud Service Modification
-- Cloud Service Metadata
+ - Snapshot Deletion
+ - Snapshot Metadata
+ - Cloud Service Modification
+ - Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteSnapshot
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- authentication_method
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- desc
-- dest
-- dest_ip_range
-- dest_port_range
-- direction
-- dvc
-- errorCode
-- errorMessage
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- image_id
-- index
-- instance_type
-- linecount
-- managementEvent
-- msg
-- object
-- object_attrs
-- object_category
-- object_id
-- product
-- protocol
-- protocol_code
-- punct
-- readOnly
-- reason
-- recipientAccountId
-- region
-- requestID
-- requestParameters.force
-- requestParameters.snapshotId
-- responseElements
-- responseElements._return
-- responseElements.requestId
-- result
-- result_id
-- rule_action
-- sessionCredentialFromConsole
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- splunk_server_group
-- src
-- src_ip
-- src_ip_range
-- src_port_range
-- src_user
-- src_user_id
-- src_user_name
-- src_user_role
-- src_user_type
-- start_time
-- status
-- tag
-- tag::action
-- tag::eventtype
-- tag::object_category
-- temp_access_key
-- timeendpos
-- timestartpos
-- tlsDetails.cipherSuite
-- tlsDetails.clientProvidedHostHeader
-- tlsDetails.tlsVersion
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.sessionContext.sessionIssuer.accountId
-- userIdentity.sessionContext.sessionIssuer.arn
-- userIdentity.sessionContext.sessionIssuer.principalId
-- userIdentity.sessionContext.sessionIssuer.type
-- userIdentity.sessionContext.sessionIssuer.userName
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_role
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - app
+ - authentication_method
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - desc
+ - dest
+ - dest_ip_range
+ - dest_port_range
+ - direction
+ - dvc
+ - errorCode
+ - errorMessage
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - image_id
+ - index
+ - instance_type
+ - linecount
+ - managementEvent
+ - msg
+ - object
+ - object_attrs
+ - object_category
+ - object_id
+ - product
+ - protocol
+ - protocol_code
+ - punct
+ - readOnly
+ - reason
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.force
+ - requestParameters.snapshotId
+ - responseElements
+ - responseElements._return
+ - responseElements.requestId
+ - result
+ - result_id
+ - rule_action
+ - sessionCredentialFromConsole
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - splunk_server_group
+ - src
+ - src_ip
+ - src_ip_range
+ - src_port_range
+ - src_user
+ - src_user_id
+ - src_user_name
+ - src_user_role
+ - src_user_type
+ - start_time
+ - status
+ - tag
+ - tag::action
+ - tag::eventtype
+ - tag::object_category
+ - temp_access_key
+ - timeendpos
+ - timestartpos
+ - tlsDetails.cipherSuite
+ - tlsDetails.clientProvidedHostHeader
+ - tlsDetails.tlsVersion
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.sessionContext.sessionIssuer.accountId
+ - userIdentity.sessionContext.sessionIssuer.arn
+ - userIdentity.sessionContext.sessionIssuer.principalId
+ - userIdentity.sessionContext.sessionIssuer.type
+ - userIdentity.sessionContext.sessionIssuer.userName
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_role
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.09", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLDF6WPXXXX:daftpunk@splunk.com", "arn": "arn:aws:sts::11111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/daftpunk@splunk.com",
"accountId": "11111111111111", "accessKeyId": "AAAAAAAAAAAAAAAAAA", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_deletetrail.yml b/data_sources/aws_cloudtrail_deletetrail.yml
index 50d8ba5c17..2d077d3400 100644
--- a/data_sources/aws_cloudtrail_deletetrail.yml
+++ b/data_sources/aws_cloudtrail_deletetrail.yml
@@ -1,96 +1,97 @@
name: AWS CloudTrail DeleteTrail
id: a5af09ff-07b6-4df6-92a0-2146bfe402c8
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the deletion of an AWS CloudTrail trail, including details about the trail name and its associated logging configurations.
+description: Logs the deletion of an AWS CloudTrail trail, including details about
+ the trail name and its associated logging configurations.
mitre_components:
-- Cloud Service Modification
-- Cloud Service Metadata
-- Application Log Content
-- Host Status
+ - Cloud Service Modification
+ - Cloud Service Metadata
+ - Application Log Content
+ - Host Status
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteTrail
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.name
-- responseElements
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- tlsDetails.cipherSuite
-- tlsDetails.clientProvidedHostHeader
-- tlsDetails.tlsVersion
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.name
+ - responseElements
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - tlsDetails.cipherSuite
+ - tlsDetails.clientProvidedHostHeader
+ - tlsDetails.tlsVersion
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"},
diff --git a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml
index 64de0ba5eb..ba7bd9f0b0 100644
--- a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml
+++ b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml
@@ -1,96 +1,97 @@
name: AWS CloudTrail DeleteVirtualMFADevice
id: 84a08d6b-3d59-4260-8cab-84278ada262f
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when a virtual Multi-Factor Authentication (MFA) device is deleted in AWS CloudTrail.
+description: Logs an event when a virtual Multi-Factor Authentication (MFA) device
+ is deleted in AWS CloudTrail.
mitre_components:
-- User Account Authentication
-- User Account Deletion
+ - User Account Authentication
+ - User Account Deletion
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteVirtualMFADevice
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.serialNumber
-- responseElements
-- sessionCredentialFromConsole
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.serialNumber
+ - responseElements
+ - sessionCredentialFromConsole
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
"111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111",
"accessKeyId": "ASIASBMSCQHHWAIHMHUX", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
diff --git a/data_sources/aws_cloudtrail_deletewebacl.yml b/data_sources/aws_cloudtrail_deletewebacl.yml
index 8d9c4b1cb9..dad7353b3b 100644
--- a/data_sources/aws_cloudtrail_deletewebacl.yml
+++ b/data_sources/aws_cloudtrail_deletewebacl.yml
@@ -1,96 +1,97 @@
name: AWS CloudTrail DeleteWebACL
id: 90da5f08-7961-4c29-8de8-01364982aadf
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when a Web Access Control List (WebACL) is deleted in AWS CloudTrail.
+description: Logs an event when a Web Access Control List (WebACL) is deleted in AWS
+ CloudTrail.
mitre_components:
-- Cloud Service Modification
-- Cloud Service Metadata
+ - Cloud Service Modification
+ - Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteWebACL
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- apiVersion
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.changeToken
-- requestParameters.webACLId
-- responseElements.changeToken
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- tlsDetails.cipherSuite
-- tlsDetails.clientProvidedHostHeader
-- tlsDetails.tlsVersion
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - apiVersion
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.changeToken
+ - requestParameters.webACLId
+ - responseElements.changeToken
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - tlsDetails.cipherSuite
+ - tlsDetails.clientProvidedHostHeader
+ - tlsDetails.tlsVersion
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
diff --git a/data_sources/aws_cloudtrail_describeeventaggregates.yml b/data_sources/aws_cloudtrail_describeeventaggregates.yml
index 68042cdaa6..51c3b5464a 100644
--- a/data_sources/aws_cloudtrail_describeeventaggregates.yml
+++ b/data_sources/aws_cloudtrail_describeeventaggregates.yml
@@ -1,92 +1,93 @@
name: AWS CloudTrail DescribeEventAggregates
id: 7efe4afe-62ae-4f96-81d1-76598ea37fc2
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when aggregate details about AWS events are queried, often for analysis.
+description: Logs an event when aggregate details about AWS events are queried, often
+ for analysis.
mitre_components:
-- Cloud Service Enumeration
-- Cloud Service Metadata
+ - Cloud Service Enumeration
+ - Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DescribeEventAggregates
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.aggregateField
-- requestParameters.filter.eventStatusCodes{}
-- requestParameters.filter.startTimes{}.from
-- responseElements
-- sessionCredentialFromConsole
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.aggregateField
+ - requestParameters.filter.eventStatusCodes{}
+ - requestParameters.filter.startTimes{}.from
+ - responseElements
+ - sessionCredentialFromConsole
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
"140429656527", "arn": "arn:aws:iam::140429656527:root", "accountId": "140429656527",
"accessKeyId": "ASIASBMSCQHHQQ6LB24V", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
diff --git a/data_sources/aws_cloudtrail_describeimagescanfindings.yml b/data_sources/aws_cloudtrail_describeimagescanfindings.yml
index d29dc3e798..fab3a5b39f 100644
--- a/data_sources/aws_cloudtrail_describeimagescanfindings.yml
+++ b/data_sources/aws_cloudtrail_describeimagescanfindings.yml
@@ -1,900 +1,985 @@
name: AWS CloudTrail DescribeImageScanFindings
id: 688ea789-9ba2-4970-90a2-17e541e273c9
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when findings from an image vulnerability scan are described using the DescribeImageScanFindings operation in AWS CloudTrail.
+description: Logs an event when findings from an image vulnerability scan are described
+ using the DescribeImageScanFindings operation in AWS CloudTrail.
mitre_components:
-- Image Metadata
-- Image Modification
-- Malware Metadata
+ - Image Metadata
+ - Image Modification
+ - Malware Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DescribeImageScanFindings
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.imageId.imageDigest
-- requestParameters.maxResults
-- requestParameters.repositoryName
-- responseElements.imageId.imageDigest
-- responseElements.imageScanFindings.findingSeverityCounts.HIGH
-- responseElements.imageScanFindings.findingSeverityCounts.INFORMATIONAL
-- responseElements.imageScanFindings.findingSeverityCounts.LOW
-- responseElements.imageScanFindings.findingSeverityCounts.MEDIUM
-- responseElements.imageScanFindings.findingSeverityCounts.UNDEFINED
-- responseElements.imageScanFindings.findings{}.attributes{}.key
-- responseElements.imageScanFindings.findings{}.attributes{}.value
-- responseElements.imageScanFindings.findings{}.description
-- responseElements.imageScanFindings.findings{}.name
-- responseElements.imageScanFindings.findings{}.severity
-- responseElements.imageScanFindings.findings{}.uri
-- responseElements.imageScanFindings.imageScanCompletedAt
-- responseElements.imageScanFindings.vulnerabilitySourceUpdatedAt
-- responseElements.imageScanStatus.description
-- responseElements.imageScanStatus.status
-- responseElements.registryId
-- responseElements.repositoryName
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.sessionContext.sessionIssuer.accountId
-- userIdentity.sessionContext.sessionIssuer.arn
-- userIdentity.sessionContext.sessionIssuer.principalId
-- userIdentity.sessionContext.sessionIssuer.type
-- userIdentity.sessionContext.sessionIssuer.userName
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
-example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
- "AAAAAAAAAAAAAAAAAAAAA:test@test.com", "arn": "arn:aws:sts::111111111111:assumed-role/role_name/test@test.com",
- "accountId": "111111111111", "accessKeyId": "AKIAIOSFODNN7EXAMPLE", "sessionContext":
- {"sessionIssuer": {"type": "Role", "principalId": "AKIAIOSFODNN7EXAMPLE", "arn":
- "arn:aws:iam::111111111111:role/aws-reserved/test/region/group", "accountId": "111111111111",
- "userName": "test"}, "webIdFederationData": {}, "attributes": {"creationDate": "2021-08-11T09:42:53Z",
- "mfaAuthenticated": "false"}}}, "eventTime": "2021-08-11T11:52:27Z", "eventSource":
- "ecr.amazonaws.com", "eventName": "DescribeImageScanFindings", "awsRegion": "eu-central-1",
- "sourceIPAddress": "154.16.165.133", "userAgent": "aws-internal/3 aws-sdk-java/1.11.1030
+ - _time
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.imageId.imageDigest
+ - requestParameters.maxResults
+ - requestParameters.repositoryName
+ - responseElements.imageId.imageDigest
+ - responseElements.imageScanFindings.findingSeverityCounts.HIGH
+ - responseElements.imageScanFindings.findingSeverityCounts.INFORMATIONAL
+ - responseElements.imageScanFindings.findingSeverityCounts.LOW
+ - responseElements.imageScanFindings.findingSeverityCounts.MEDIUM
+ - responseElements.imageScanFindings.findingSeverityCounts.UNDEFINED
+ - responseElements.imageScanFindings.findings{}.attributes{}.key
+ - responseElements.imageScanFindings.findings{}.attributes{}.value
+ - responseElements.imageScanFindings.findings{}.description
+ - responseElements.imageScanFindings.findings{}.name
+ - responseElements.imageScanFindings.findings{}.severity
+ - responseElements.imageScanFindings.findings{}.uri
+ - responseElements.imageScanFindings.imageScanCompletedAt
+ - responseElements.imageScanFindings.vulnerabilitySourceUpdatedAt
+ - responseElements.imageScanStatus.description
+ - responseElements.imageScanStatus.status
+ - responseElements.registryId
+ - responseElements.repositoryName
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.sessionContext.sessionIssuer.accountId
+ - userIdentity.sessionContext.sessionIssuer.arn
+ - userIdentity.sessionContext.sessionIssuer.principalId
+ - userIdentity.sessionContext.sessionIssuer.type
+ - userIdentity.sessionContext.sessionIssuer.userName
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
+example_log: "{\"eventVersion\": \"1.08\", \"userIdentity\": {\"type\": \"AssumedRole\"\
+ , \"principalId\": \"AAAAAAAAAAAAAAAAAAAAA:test@test.com\", \"arn\": \"arn:aws:sts::111111111111:assumed-role/role_name/test@test.com\"\
+ , \"accountId\": \"111111111111\", \"accessKeyId\": \"AKIAIOSFODNN7EXAMPLE\", \"\
+ sessionContext\": {\"sessionIssuer\": {\"type\": \"Role\", \"principalId\": \"AKIAIOSFODNN7EXAMPLE\"\
+ , \"arn\": \"arn:aws:iam::111111111111:role/aws-reserved/test/region/group\", \"\
+ accountId\": \"111111111111\", \"userName\": \"test\"}, \"webIdFederationData\"
+ : {}, \"attributes\": {\"creationDate\": \"2021-08-11T09:42:53Z\", \"mfaAuthenticated\"\
+ : \"false\"}}}, \"eventTime\": \"2021-08-11T11:52:27Z\", \"eventSource\": \"ecr.amazonaws.com\"\
+ , \"eventName\": \"DescribeImageScanFindings\", \"awsRegion\": \"eu-central-1\"
+ , \"sourceIPAddress\": \"154.16.165.133\", \"userAgent\": \"aws-internal/3 aws-sdk-java/1.11.1030
Linux/4.9.273-0.1.ac.226.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.302-b08
- java/1.8.0_302 vendor/Oracle_Corporation cfg/retry-mode/legacy", "requestParameters":
- {"repositoryName": "devsecops/cat_dog_client", "imageId": {"imageDigest": "sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6"},
- "maxResults": 1000}, "responseElements": {"registryId": "111111111111", "repositoryName":
- "devsecops/cat_dog_client", "imageId": {"imageDigest": "sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6"},
- "imageScanStatus": {"status": "COMPLETE", "description": "The scan was completed
- successfully."}, "imageScanFindings": {"imageScanCompletedAt": "Aug 11, 2021, 11:30:16
- AM", "vulnerabilitySourceUpdatedAt": "Aug 11, 2021, 1:17:52 AM", "findings": [{"name":
- "CVE-2019-25013", "description": "The iconv feature in the GNU C Library (aka glibc
- or libc6) through 2.32, when processing invalid multi-byte input sequences in the
- EUC-KR encoding, may have a buffer over-read.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-25013",
- "severity": "HIGH", "attributes": [{"key": "package_version", "value": "2.28-10"},
- {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:C"},
- {"key": "CVSS2_SCORE", "value": "7.1"}]}, {"name": "CVE-2021-33574", "description":
- "The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33
- has a use-after-free. It may use the notification thread attributes object (passed
- through its struct sigevent parameter) after it has been freed by the caller, leading
- to a denial of service (application crash) or possibly unspecified other impact.",
- "uri": "https://security-tracker.debian.org/tracker/CVE-2021-33574", "severity":
- "HIGH", "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
- "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"},
- {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2018-12886", "description":
- "stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c
- in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate
- instruction sequences when targeting ARM targets that spill the address of the stack
- protector guard, which allows an attacker to bypass the protection of -fstack-protector,
- -fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit
- against stack overflow by controlling what the stack canary is compared against.",
- "uri": "https://security-tracker.debian.org/tracker/CVE-2018-12886", "severity":
- "MEDIUM", "attributes": [{"key": "package_version", "value": "8.3.0-6"}, {"key":
- "package_name", "value": "gcc-8"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
- {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2020-1751", "description":
- "An out-of-bounds write vulnerability was found in glibc before 2.31 when handling
- signal trampolines on PowerPC. Specifically, the backtrace function did not properly
- check the array bounds when storing the frame address, resulting in a denial of
- service or potential code execution. The highest threat from this vulnerability
- is to system availability.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-1751",
- "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.28-10"},
- {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:P/I:P/A:C"},
- {"key": "CVSS2_SCORE", "value": "5.9"}]}, {"name": "CVE-2021-3326", "description":
- "The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier,
- when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an
- assertion in the code path and aborts the program, potentially resulting in a denial
- of service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-3326",
- "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.28-10"},
- {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2021-35942", "description":
- "The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or
- read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted,
- crafted pattern, potentially resulting in a denial of service or disclosure of information.
- This occurs because atoi was used but strtoul should have been used to ensure correct
- calculations.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-35942",
- "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.28-10"},
- {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "6.4"}]}, {"name": "CVE-2019-12904", "description":
- "In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload
- side-channel attack because physical addresses are available to other processes.
- (The C implementation is used on platforms where an assembly-language implementation
- is unavailable.)", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-12904",
- "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "1.8.4-5+deb10u1"},
- {"key": "package_name", "value": "libgcrypt20"}, {"key": "CVSS2_VECTOR", "value":
- "AV:N/AC:M/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name":
- "CVE-2017-6363", "description": "** DISPUTED ** In the GD Graphics Library (aka
- LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c.
- NOTE: the vendor says \"In my opinion this issue should not have a CVE, since the
- GD and GD2 formats are documented to be ''obsolete, and should only be used for
- development and testing purposes.''\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-6363",
- "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.2.5-5.2"},
- {"key": "package_name", "value": "libgd2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2019-12290", "description":
- "GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490
- Section 4.2 when converting A-labels to U-labels. This makes it possible in some
- circumstances for one domain to impersonate another. By creating a malicious domain
- that matches a target domain except for the inclusion of certain punycoded Unicode
- characters (that would be discarded when converted first to a Unicode label and
- then back to an ASCII label), arbitrary domains can be impersonated.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-12290",
- "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.0.5-1+deb10u1"},
- {"key": "package_name", "value": "libidn2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"},
- {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2019-13115", "description":
- "In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange
+ java/1.8.0_302 vendor/Oracle_Corporation cfg/retry-mode/legacy\", \"requestParameters\"\
+ : {\"repositoryName\": \"devsecops/cat_dog_client\", \"imageId\": {\"imageDigest\"\
+ : \"sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6\"},
+ \"maxResults\": 1000}, \"responseElements\": {\"registryId\": \"111111111111\",
+ \"repositoryName\": \"devsecops/cat_dog_client\", \"imageId\": {\"imageDigest\"
+ : \"sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6\"},
+ \"imageScanStatus\": {\"status\": \"COMPLETE\", \"description\": \"The scan was
+ completed successfully.\"}, \"imageScanFindings\": {\"imageScanCompletedAt\": \"\
+ Aug 11, 2021, 11:30:16 AM\", \"vulnerabilitySourceUpdatedAt\": \"Aug 11, 2021, 1:17:52
+ AM\", \"findings\": [{\"name\": \"CVE-2019-25013\", \"description\": \"The iconv
+ feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing
+ invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.\"\
+ , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-25013\", \"severity\"\
+ : \"HIGH\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.28-10\"\
+ }, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\
+ , \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:C\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
+ : \"7.1\"}]}, {\"name\": \"CVE-2021-33574\", \"description\": \"The mq_notify function
+ in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It
+ may use the notification thread attributes object (passed through its struct sigevent
+ parameter) after it has been freed by the caller, leading to a denial of service
+ (application crash) or possibly unspecified other impact.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-33574\"\
+ , \"severity\": \"HIGH\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"7.5\"}]}, {\"name\": \"CVE-2018-12886\", \"description\": \"stack_protect_prologue
+ in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection
+ (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences
+ when targeting ARM targets that spill the address of the stack protector guard,
+ which allows an attacker to bypass the protection of -fstack-protector, -fstack-protector-all,
+ -fstack-protector-strong, and -fstack-protector-explicit against stack overflow
+ by controlling what the stack canary is compared against.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-12886\"\
+ , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"8.3.0-6\"}, {\"key\": \"package_name\", \"value\": \"gcc-8\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-1751\", \"description\": \"An out-of-bounds
+ write vulnerability was found in glibc before 2.31 when handling signal trampolines
+ on PowerPC. Specifically, the backtrace function did not properly check the array
+ bounds when storing the frame address, resulting in a denial of service or potential
+ code execution. The highest threat from this vulnerability is to system availability.\"\
+ , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-1751\", \"severity\"\
+ : \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.28-10\"\
+ }, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\
+ , \"value\": \"AV:L/AC:M/Au:N/C:P/I:P/A:C\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
+ : \"5.9\"}]}, {\"name\": \"CVE-2021-3326\", \"description\": \"The iconv function
+ in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid
+ input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path
+ and aborts the program, potentially resulting in a denial of service.\", \"uri\"\
+ : \"https://security-tracker.debian.org/tracker/CVE-2021-3326\", \"severity\": \"\
+ MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.28-10\"\
+ }, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\
+ , \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
+ : \"5\"}]}, {\"name\": \"CVE-2021-35942\", \"description\": \"The wordexp function
+ in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory
+ in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern,
+ potentially resulting in a denial of service or disclosure of information. This
+ occurs because atoi was used but strtoul should have been used to ensure correct
+ calculations.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-35942\"\
+ , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"6.4\"}]}, {\"name\": \"CVE-2019-12904\", \"description\": \"In Libgcrypt
+ 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel
+ attack because physical addresses are available to other processes. (The C implementation
+ is used on platforms where an assembly-language implementation is unavailable.)\"\
+ , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-12904\", \"severity\"\
+ : \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"1.8.4-5+deb10u1\"\
+ }, {\"key\": \"package_name\", \"value\": \"libgcrypt20\"}, {\"key\": \"CVSS2_VECTOR\"\
+ , \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
+ : \"4.3\"}]}, {\"name\": \"CVE-2017-6363\", \"description\": \"** DISPUTED ** In
+ the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer
+ over-read in tiffWriter in gd_tiff.c. NOTE: the vendor says \\\"In my opinion this
+ issue should not have a CVE, since the GD and GD2 formats are documented to be 'obsolete,
+ and should only be used for development and testing purposes.'\\\"\", \"uri\": \"\
+ https://security-tracker.debian.org/tracker/CVE-2017-6363\", \"severity\": \"MEDIUM\"\
+ , \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.2.5-5.2\"}, {\"\
+ key\": \"package_name\", \"value\": \"libgd2\"}, {\"key\": \"CVSS2_VECTOR\", \"\
+ value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\":
+ \"5.8\"}]}, {\"name\": \"CVE-2019-12290\", \"description\": \"GNU libidn2 before
+ 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when
+ converting A-labels to U-labels. This makes it possible in some circumstances for
+ one domain to impersonate another. By creating a malicious domain that matches a
+ target domain except for the inclusion of certain punycoded Unicode characters (that
+ would be discarded when converted first to a Unicode label and then back to an ASCII
+ label), arbitrary domains can be impersonated.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-12290\"\
+ , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"2.0.5-1+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libidn2\"}, {\"\
+ key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"\
+ CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2019-13115\", \"description\"\
+ : \"In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange
in kex.c has an integer overflow that could lead to an out-of-bounds read in the
way packets are read from the server. A remote attacker who compromises a SSH server
may be able to disclose sensitive information or cause a denial of service condition
on the client system when a user connects to the server. This is related to an _libssh2_check_length
- mistake, and is different from the various issues fixed in 1.8.1, such as CVE-2019-3855.",
- "uri": "https://security-tracker.debian.org/tracker/CVE-2019-13115", "severity":
- "MEDIUM", "attributes": [{"key": "package_version", "value": "1.8.0-2.1"}, {"key":
- "package_name", "value": "libssh2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2016-9318", "description":
- "libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products,
- does not offer a flag directly indicating that the current document may be read
- but other files may not be opened, which makes it easier for remote attackers to
- conduct XML External Entity (XXE) attacks via a crafted document.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-9318",
- "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.9.4+dfsg1-7+deb10u2"},
- {"key": "package_name", "value": "libxml2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:N"},
- {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2017-16932", "description":
- "parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter
- entities.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-16932",
- "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.9.4+dfsg1-7+deb10u2"},
- {"key": "package_name", "value": "libxml2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2020-36309", "description":
- "ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe
- characters in an argument when using the API to mutate a URI, or a request or response
- header.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-36309", "severity":
- "MEDIUM", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"},
- {"key": "package_name", "value": "nginx"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"},
- {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2020-14155", "description":
- "libpcre in PCRE before 8.44 allows an integer overflow via a large number after
- a (?C substring.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-14155",
- "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2:8.39-12"},
- {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2019-3843", "description":
- "It was discovered that a systemd service that uses DynamicUser property can create
- a SUID/SGID binary that would be allowed to run as the transient service UID/GID
- even after the service is terminated. A local attacker may use this flaw to access
- resources that will be owned by a potentially different service in the future, when
- the UID/GID will be recycled.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-3843",
- "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"},
- {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:P/I:P/A:P"},
- {"key": "CVSS2_SCORE", "value": "4.6"}]}, {"name": "CVE-2019-3844", "description":
- "It was discovered that a systemd service that uses DynamicUser property can get
- new privileges through the execution of SUID binaries, which would allow to create
- binaries owned by the service transient group with the setgid bit set. A local attacker
- may use this flaw to access resources that will be owned by a potentially different
- service in the future, when the GID will be recycled.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-3844",
- "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"},
- {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:P/I:P/A:P"},
- {"key": "CVSS2_SCORE", "value": "4.6"}]}, {"name": "CVE-2016-2781", "description":
- "chroot in GNU coreutils, when used with --userspec, allows local users to escape
- to the parent session via a crafted TIOCSTI ioctl call, which pushes characters
- to the terminal''s input buffer.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-2781",
- "severity": "LOW", "attributes": [{"key": "package_version", "value": "8.30-3"},
- {"key": "package_name", "value": "coreutils"}, {"key": "CVSS2_VECTOR", "value":
- "AV:L/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name":
- "CVE-2021-22898", "description": "curl 7.7 through 7.76.1 suffers from an information
- disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in
- libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw
- in the option parser for sending NEW_ENV variables, libcurl could be made to pass
- on uninitialized data from a stack based buffer to the server, resulting in potentially
- revealing sensitive internal information to the server using a clear-text network
- protocol.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22898",
- "severity": "LOW", "attributes": [{"key": "package_version", "value": "7.64.0-4+deb10u2"},
- {"key": "package_name", "value": "curl"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:H/Au:N/C:P/I:N/A:N"},
- {"key": "CVSS2_SCORE", "value": "2.6"}]}, {"name": "CVE-2019-15847", "description":
- "The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize
- multiple calls of the __builtin_darn intrinsic into a single call, thus reducing
- the entropy of the random number generator. This occurred because a volatile operation
- was not specified. For example, within a single execution of a program, the output
- of every __builtin_darn() call may be the same.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-15847",
- "severity": "LOW", "attributes": [{"key": "package_version", "value": "8.3.0-6"},
- {"key": "package_name", "value": "gcc-8"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"},
- {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2020-1752", "description":
- "A use-after-free vulnerability introduced in glibc upstream version 2.14 was found
- in the way the tilde expansion was carried out. Directory paths containing an initial
- tilde followed by a valid username were affected by this issue. A local attacker
- could exploit this flaw by creating a specially crafted path that, when processed
- by the glob function, would potentially lead to arbitrary code execution. This was
- fixed in version 2.32.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-1752",
- "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"},
- {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:H/Au:N/C:P/I:P/A:P"},
- {"key": "CVSS2_SCORE", "value": "3.7"}]}, {"name": "CVE-2020-6096", "description":
- "An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation
- of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU
- glibc implementation) with a negative value for the ''num'' parameter results in
- a signed comparison vulnerability. If an attacker underflows the ''num'' parameter
- to memcpy(), this vulnerability could lead to undefined behavior such as writing
- to out-of-bounds memory and potentially remote code execution. Furthermore, this
- memcpy() implementation allows for program execution to continue in scenarios where
- a segmentation fault or crash should have occurred. The dangers occur in that subsequent
- execution and iterations of this code will be executed with this corrupted data.",
- "uri": "https://security-tracker.debian.org/tracker/CVE-2020-6096", "severity":
- "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
- "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
- {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2020-10029", "description":
- "The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer
- during range reduction if an input to an 80-bit long double function contains a
- non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to
- sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.",
- "uri": "https://security-tracker.debian.org/tracker/CVE-2020-10029", "severity":
- "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
- "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2020-27618", "description":
- "The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier,
- when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388,
- IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead
- to an infinite loop in applications, resulting in a denial of service, a different
- vulnerability from CVE-2016-10228.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-27618",
- "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"},
- {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2016-10228", "description":
- "The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when
- invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE)
- along with the -c option, enters an infinite loop when processing invalid multi-byte
- input sequences, leading to a denial of service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-10228",
- "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"},
- {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2019-19126", "description":
- "On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to
- ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution
- after a security transition, allowing local attackers to restrict the possible mapping
- addresses for loaded libraries and thus bypass ASLR for a setuid program.", "uri":
- "https://security-tracker.debian.org/tracker/CVE-2019-19126", "severity": "LOW",
- "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
- "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:P/I:N/A:N"},
- {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-27645", "description":
- "The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6)
- 2.29 through 2.33, when processing a request for netgroup lookup, may crash due
- to a double-free, potentially resulting in degraded service or Denial of Service
- on the local system. This is related to netgroupcache.c.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-27645",
- "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"},
- {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:N/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "1.9"}]}, {"name": "CVE-2019-14855", "description":
- "A flaw was found in the way certificate signatures could be forged using collisions
- found in the SHA-1 algorithm. An attacker could use this weakness to create forged
- certificate signatures. This issue affects GnuPG versions before 2.2.18.", "uri":
- "https://security-tracker.debian.org/tracker/CVE-2019-14855", "severity": "LOW",
- "attributes": [{"key": "package_version", "value": "2.2.12-1+deb10u1"}, {"key":
- "package_name", "value": "gnupg2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"},
- {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2019-13627", "description":
- "It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic
+ mistake, and is different from the various issues fixed in 1.8.1, such as CVE-2019-3855.\"\
+ , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-13115\", \"severity\"\
+ : \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"1.8.0-2.1\"\
+ }, {\"key\": \"package_name\", \"value\": \"libssh2\"}, {\"key\": \"CVSS2_VECTOR\"\
+ , \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
+ : \"5.8\"}]}, {\"name\": \"CVE-2016-9318\", \"description\": \"libxml2 2.9.4 and
+ earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer
+ a flag directly indicating that the current document may be read but other files
+ may not be opened, which makes it easier for remote attackers to conduct XML External
+ Entity (XXE) attacks via a crafted document.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2016-9318\"\
+ , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"2.9.4+dfsg1-7+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"libxml2\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:N\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-16932\", \"description\"\
+ : \"parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter
+ entities.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-16932\"\
+ , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"2.9.4+dfsg1-7+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"libxml2\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2020-36309\", \"description\"\
+ : \"ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows
+ unsafe characters in an argument when using the API to mutate a URI, or a request
+ or response header.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-36309\"\
+ , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"1.21.1-1~buster\"}, {\"key\": \"package_name\", \"value\": \"nginx\"}, {\"key\"\
+ : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"5\"}]}, {\"name\": \"CVE-2020-14155\", \"description\": \"libpcre
+ in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.\"\
+ , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-14155\", \"severity\"\
+ : \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2:8.39-12\"\
+ }, {\"key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"CVSS2_VECTOR\"\
+ , \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
+ : \"5\"}]}, {\"name\": \"CVE-2019-3843\", \"description\": \"It was discovered that
+ a systemd service that uses DynamicUser property can create a SUID/SGID binary that
+ would be allowed to run as the transient service UID/GID even after the service
+ is terminated. A local attacker may use this flaw to access resources that will
+ be owned by a potentially different service in the future, when the UID/GID will
+ be recycled.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-3843\"\
+ , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"}, {\"key\"\
+ : \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"4.6\"}]}, {\"name\": \"CVE-2019-3844\", \"description\": \"It was
+ discovered that a systemd service that uses DynamicUser property can get new privileges
+ through the execution of SUID binaries, which would allow to create binaries owned
+ by the service transient group with the setgid bit set. A local attacker may use
+ this flaw to access resources that will be owned by a potentially different service
+ in the future, when the GID will be recycled.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-3844\"\
+ , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"}, {\"key\"\
+ : \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"4.6\"}]}, {\"name\": \"CVE-2016-2781\", \"description\": \"chroot
+ in GNU coreutils, when used with --userspec, allows local users to escape to the
+ parent session via a crafted TIOCSTI ioctl call, which pushes characters to the
+ terminal's input buffer.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2016-2781\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"8.30-3\"}, {\"key\": \"package_name\", \"value\": \"coreutils\"}, {\"key\":
+ \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-22898\", \"description\": \"curl
+ 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command
+ line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content
+ pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV
+ variables, libcurl could be made to pass on uninitialized data from a stack based
+ buffer to the server, resulting in potentially revealing sensitive internal information
+ to the server using a clear-text network protocol.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-22898\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"7.64.0-4+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"curl\"}, {\"key\"\
+ : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:H/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"2.6\"}]}, {\"name\": \"CVE-2019-15847\", \"description\": \"The POWER9
+ backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple
+ calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy
+ of the random number generator. This occurred because a volatile operation was not
+ specified. For example, within a single execution of a program, the output of every
+ __builtin_darn() call may be the same.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-15847\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"8.3.0-6\"}, {\"key\": \"package_name\", \"value\": \"gcc-8\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"5\"}]}, {\"name\": \"CVE-2020-1752\", \"description\": \"A use-after-free
+ vulnerability introduced in glibc upstream version 2.14 was found in the way the
+ tilde expansion was carried out. Directory paths containing an initial tilde followed
+ by a valid username were affected by this issue. A local attacker could exploit
+ this flaw by creating a specially crafted path that, when processed by the glob
+ function, would potentially lead to arbitrary code execution. This was fixed in
+ version 2.32.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-1752\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:L/AC:H/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"3.7\"}]}, {\"name\": \"CVE-2020-6096\", \"description\": \"An exploitable
+ signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU
+ glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation)
+ with a negative value for the 'num' parameter results in a signed comparison vulnerability.
+ If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could
+ lead to undefined behavior such as writing to out-of-bounds memory and potentially
+ remote code execution. Furthermore, this memcpy() implementation allows for program
+ execution to continue in scenarios where a segmentation fault or crash should have
+ occurred. The dangers occur in that subsequent execution and iterations of this
+ code will be executed with this corrupted data.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-6096\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-10029\", \"description\": \"The GNU
+ C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during
+ range reduction if an input to an 80-bit long double function contains a non-canonical
+ bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets.
+ This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-10029\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2020-27618\", \"description\": \"The iconv
+ function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing
+ invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399
+ encodings, fails to advance the input state, which could lead to an infinite loop
+ in applications, resulting in a denial of service, a different vulnerability from
+ CVE-2016-10228.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-27618\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2016-10228\", \"description\": \"The iconv
+ program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked
+ with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with
+ the -c option, enters an infinite loop when processing invalid multi-byte input
+ sequences, leading to a denial of service.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2016-10228\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2019-19126\", \"description\": \"On the
+ x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the
+ LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security
+ transition, allowing local attackers to restrict the possible mapping addresses
+ for loaded libraries and thus bypass ASLR for a setuid program.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-19126\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-27645\", \"description\": \"The nameserver
+ caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33,
+ when processing a request for netgroup lookup, may crash due to a double-free, potentially
+ resulting in degraded service or Denial of Service on the local system. This is
+ related to netgroupcache.c.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-27645\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"1.9\"}]}, {\"name\": \"CVE-2019-14855\", \"description\": \"A flaw
+ was found in the way certificate signatures could be forged using collisions found
+ in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate
+ signatures. This issue affects GnuPG versions before 2.2.18.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-14855\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"2.2.12-1+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"gnupg2\"}, {\"\
+ key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"\
+ CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2019-13627\", \"description\"\
+ : \"It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic
library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions
- fixed: 1.8.5-2 and 1.6.3-2+deb8u7.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-13627",
- "severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.4-5+deb10u1"},
- {"key": "package_name", "value": "libgcrypt20"}, {"key": "CVSS2_VECTOR", "value":
- "AV:L/AC:H/Au:N/C:P/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "2.6"}]}, {"name":
- "CVE-2018-14553", "description": "gdImageClone in gd.c in libgd 2.1.0-rc2 through
- 2.2.5 has a NULL pointer dereference allowing attackers to crash an application
- via a specific function call sequence. Only affects PHP when linked with an external
- libgd (not bundled).", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-14553",
- "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.2.5-5.2"},
- {"key": "package_name", "value": "libgd2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2021-36086", "description":
- "The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission
- (called from cil_reset_classperms_set and cil_reset_classperms_list).", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36086",
- "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.8-1"},
- {"key": "package_name", "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-36085", "description":
- "The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms
- (called from __verify_map_perm_classperms and hashtab_map).", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36085",
- "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.8-1"},
- {"key": "package_name", "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-36087", "description":
- "The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any
- (called indirectly from cil_check_neverallow). This occurs because there is sometimes
- a lack of checks for invalid statements in an optional block.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36087",
- "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.8-1"},
- {"key": "package_name", "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-36084", "description":
- "The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms
- (called from __cil_verify_classpermission and __cil_pre_verify_helper).", "uri":
- "https://security-tracker.debian.org/tracker/CVE-2021-36084", "severity": "LOW",
- "attributes": [{"key": "package_version", "value": "2.8-1"}, {"key": "package_name",
- "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2019-17498", "description":
- "In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c
- has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary
- (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be
- able to disclose sensitive information or cause a denial of service condition on
- the client system when a user connects to the server.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-17498",
- "severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.0-2.1"},
- {"key": "package_name", "value": "libssh2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2019-17543", "description":
- "LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize),
+ fixed: 1.8.5-2 and 1.6.3-2+deb8u7.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-13627\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"1.8.4-5+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libgcrypt20\"},
+ {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:H/Au:N/C:P/I:P/A:N\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"2.6\"}]}, {\"name\": \"CVE-2018-14553\", \"description\"\
+ : \"gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference
+ allowing attackers to crash an application via a specific function call sequence.
+ Only affects PHP when linked with an external libgd (not bundled).\", \"uri\": \"\
+ https://security-tracker.debian.org/tracker/CVE-2018-14553\", \"severity\": \"LOW\"\
+ , \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.2.5-5.2\"}, {\"\
+ key\": \"package_name\", \"value\": \"libgd2\"}, {\"key\": \"CVSS2_VECTOR\", \"\
+ value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\":
+ \"5\"}]}, {\"name\": \"CVE-2021-36086\", \"description\": \"The CIL compiler in
+ SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set
+ and cil_reset_classperms_list).\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36086\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"2.8-1\"}, {\"key\": \"package_name\", \"value\": \"libsepol\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-36085\", \"description\": \"The CIL
+ compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called
+ from __verify_map_perm_classperms and hashtab_map).\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36085\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"2.8-1\"}, {\"key\": \"package_name\", \"value\": \"libsepol\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-36087\", \"description\": \"The CIL
+ compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any (called
+ indirectly from cil_check_neverallow). This occurs because there is sometimes a
+ lack of checks for invalid statements in an optional block.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36087\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"2.8-1\"}, {\"key\": \"package_name\", \"value\": \"libsepol\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-36084\", \"description\": \"The CIL
+ compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called
+ from __cil_verify_classpermission and __cil_pre_verify_helper).\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36084\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"2.8-1\"}, {\"key\": \"package_name\", \"value\": \"libsepol\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2019-17498\", \"description\": \"In libssh2
+ v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer
+ overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds)
+ offset for a subsequent memory read. A crafted SSH server may be able to disclose
+ sensitive information or cause a denial of service condition on the client system
+ when a user connects to the server.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-17498\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"1.8.0-2.1\"}, {\"key\": \"package_name\", \"value\": \"libssh2\"}, {\"key\"
+ : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"5.8\"}]}, {\"name\": \"CVE-2019-17543\", \"description\": \"LZ4 before
+ 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize),
affecting applications that call LZ4_compress_fast with a large input. (This issue
- can also lead to data corruption.) NOTE: the vendor states \"only a few specific
- / uncommon usages of the API are at risk.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-17543",
- "severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.3-1+deb10u1"},
- {"key": "package_name", "value": "lz4"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
- {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2013-0337", "description":
- "The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable
- permissions for the (1) access.log and (2) error.log files, which allows local users
- to obtain sensitive information by reading the files.", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-0337",
- "severity": "LOW", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"},
- {"key": "package_name", "value": "nginx"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"},
- {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2018-7169", "description":
- "An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and
- allows an unprivileged user to be placed in a user namespace where setgroups(2)
- is permitted. This allows an attacker to remove themselves from a supplementary
- group, which may allow access to certain filesystem paths if the administrator has
- used \"group blacklisting\" (e.g., chmod g-rwx) to restrict access to paths. This
- flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups
- knob) to prevent this sort of privilege escalation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-7169",
- "severity": "LOW", "attributes": [{"key": "package_version", "value": "1:4.5-1.1"},
- {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"},
- {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2021-37600", "description":
- "An integer overflow in util-linux through 2.37.1 can potentially cause a buffer
- overflow if an attacker were able to use system resources in a way that leads to
- a large number in the /proc/sysvipc/sem file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-37600",
- "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.33.1-0.1"},
- {"key": "package_name", "value": "util-linux"}, {"key": "CVSS2_VECTOR", "value":
- "AV:N/AC:L/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name":
- "CVE-2011-3374", "description": "It was found that apt-key in apt, all versions,
- do not correctly validate gpg keys with the master keyring, leading to a potential
- man-in-the-middle attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2011-3374",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "1.8.2.3"}, {"key": "package_name", "value": "apt"}, {"key": "CVSS2_VECTOR", "value":
- "AV:N/AC:M/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name":
- "CVE-2019-18276", "description": "An issue was discovered in disable_priv_mode in
- shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective
- UID not equal to its real UID, it will drop privileges by setting its effective
- UID to its real UID. However, it does so incorrectly. On Linux and other systems
- that support \"saved UID\" functionality, the saved UID is not dropped. An attacker
- with command execution in the shell can use \"enable -f\" for runtime loading of
- a new builtin, which can be a shared object that calls setuid() and therefore regains
- privileges. However, binaries running with an effective UID of 0 are unaffected.",
- "uri": "https://security-tracker.debian.org/tracker/CVE-2019-18276", "severity":
- "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "5.0-4"}, {"key":
- "package_name", "value": "bash"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:C/I:C/A:C"},
- {"key": "CVSS2_SCORE", "value": "7.2"}]}, {"name": "CVE-2017-18018", "description":
- "In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent
- replacement of a plain file with a symlink during use of the POSIX \"-R -L\" options,
- which allows local users to modify the ownership of arbitrary files by leveraging
- a race condition.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-18018",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "8.30-3"}, {"key": "package_name", "value": "coreutils"}, {"key": "CVSS2_VECTOR",
- "value": "AV:L/AC:M/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "1.9"}]},
- {"name": "CVE-2021-22923", "description": "When curl is instructed to get content
- using the metalink feature, and a user name and password are used to download the
- metalink XML file, those same credentials are then subsequently passed on to each
- of the servers from which curl will download or try to download the contents from.
- Often contrary to the user''s expectations and intentions and without telling the
- user it happened.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22923",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "7.64.0-4+deb10u2"}, {"key": "package_name", "value": "curl"}]}, {"name": "CVE-2021-22922",
- "description": "When curl is instructed to download content using the metalink feature,
- thecontents is verified against a hash provided in the metalink XML file.The metalink
- XML file points out to the client how to get the same contentfrom a set of different
- URLs, potentially hosted by different servers and theclient can then download the
- file from one or several of them. In a serial orparallel manner.If one of the servers
- hosting the contents has been breached and the contentsof the specific file on that
- server is replaced with a modified payload, curlshould detect this when the hash
- of the file mismatches after a completeddownload. It should remove the contents
- and instead try getting the contentsfrom another URL. This is not done, and instead
- such a hash mismatch is onlymentioned in text and the potentially malicious content
- is kept in the file ondisk.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22922",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "7.64.0-4+deb10u2"}, {"key": "package_name", "value": "curl"}]}, {"name": "CVE-2013-0340",
- "description": "expat 2.1.0 and earlier does not properly handle entities expansion
- unless an application developer uses the XML_SetEntityDeclHandler function, which
- allows remote attackers to cause a denial of service (resource consumption), send
- HTTP requests to intranet servers, or read arbitrary files via a crafted XML document,
- aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat
- already provides the ability to disable external entity expansion, the responsibility
- for resolving this issue lies with application developers; according to this argument,
- this entry should be REJECTed, and each affected application would need its own
- CVE.", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-0340", "severity":
- "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "2.2.6-2+deb10u1"},
- {"key": "package_name", "value": "expat"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
- {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2019-1010023", "description":
- "** DISPUTED ** GNU Libc current is affected by: Re-mapping current loaded library
+ can also lead to data corruption.) NOTE: the vendor states \\\"only a few specific
+ / uncommon usages of the API are at risk.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-17543\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"1.8.3-1+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"lz4\"}, {\"key\"\
+ : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2013-0337\", \"description\": \"The default
+ configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions
+ for the (1) access.log and (2) error.log files, which allows local users to obtain
+ sensitive information by reading the files.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2013-0337\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"1.21.1-1~buster\"}, {\"key\": \"package_name\", \"value\": \"nginx\"}, {\"key\"\
+ : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"7.5\"}]}, {\"name\": \"CVE-2018-7169\", \"description\": \"An issue
+ was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an
+ unprivileged user to be placed in a user namespace where setgroups(2) is permitted.
+ This allows an attacker to remove themselves from a supplementary group, which may
+ allow access to certain filesystem paths if the administrator has used \\\"group
+ blacklisting\\\" (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively
+ reverts a security feature in the kernel (in particular, the /proc/self/setgroups
+ knob) to prevent this sort of privilege escalation.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-7169\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"1:4.5-1.1\"}, {\"key\": \"package_name\", \"value\": \"shadow\"}, {\"key\":
+ \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"5\"}]}, {\"name\": \"CVE-2021-37600\", \"description\": \"An integer
+ overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if
+ an attacker were able to use system resources in a way that leads to a large number
+ in the /proc/sysvipc/sem file.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-37600\"\
+ , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
+ : \"2.33.1-0.1\"}, {\"key\": \"package_name\", \"value\": \"util-linux\"}, {\"key\"\
+ : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"7.5\"}]}, {\"name\": \"CVE-2011-3374\", \"description\": \"It was
+ found that apt-key in apt, all versions, do not correctly validate gpg keys with
+ the master keyring, leading to a potential man-in-the-middle attack.\", \"uri\"
+ : \"https://security-tracker.debian.org/tracker/CVE-2011-3374\", \"severity\": \"\
+ INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"1.8.2.3\"\
+ }, {\"key\": \"package_name\", \"value\": \"apt\"}, {\"key\": \"CVSS2_VECTOR\",
+ \"value\": \"AV:N/AC:M/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
+ : \"4.3\"}]}, {\"name\": \"CVE-2019-18276\", \"description\": \"An issue was discovered
+ in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if
+ Bash is run with its effective UID not equal to its real UID, it will drop privileges
+ by setting its effective UID to its real UID. However, it does so incorrectly. On
+ Linux and other systems that support \\\"saved UID\\\" functionality, the saved
+ UID is not dropped. An attacker with command execution in the shell can use \\\"\
+ enable -f\\\" for runtime loading of a new builtin, which can be a shared object
+ that calls setuid() and therefore regains privileges. However, binaries running
+ with an effective UID of 0 are unaffected.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-18276\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"5.0-4\"}, {\"key\": \"package_name\", \"value\": \"bash\"}, {\"key\"\
+ : \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:C/I:C/A:C\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"7.2\"}]}, {\"name\": \"CVE-2017-18018\", \"description\": \"In GNU
+ Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement
+ of a plain file with a symlink during use of the POSIX \\\"-R -L\\\" options, which
+ allows local users to modify the ownership of arbitrary files by leveraging a race
+ condition.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-18018\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"8.30-3\"}, {\"key\": \"package_name\", \"value\": \"coreutils\"},
+ {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:N/I:P/A:N\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"1.9\"}]}, {\"name\": \"CVE-2021-22923\", \"description\"\
+ : \"When curl is instructed to get content using the metalink feature, and a user
+ name and password are used to download the metalink XML file, those same credentials
+ are then subsequently passed on to each of the servers from which curl will download
+ or try to download the contents from. Often contrary to the user's expectations
+ and intentions and without telling the user it happened.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-22923\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"7.64.0-4+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"curl\"\
+ }]}, {\"name\": \"CVE-2021-22922\", \"description\": \"When curl is instructed to
+ download content using the metalink feature, thecontents is verified against a hash
+ provided in the metalink XML file.The metalink XML file points out to the client
+ how to get the same contentfrom a set of different URLs, potentially hosted by different
+ servers and theclient can then download the file from one or several of them. In
+ a serial orparallel manner.If one of the servers hosting the contents has been breached
+ and the contentsof the specific file on that server is replaced with a modified
+ payload, curlshould detect this when the hash of the file mismatches after a completeddownload.
+ It should remove the contents and instead try getting the contentsfrom another URL.
+ This is not done, and instead such a hash mismatch is onlymentioned in text and
+ the potentially malicious content is kept in the file ondisk.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-22922\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"7.64.0-4+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"curl\"\
+ }]}, {\"name\": \"CVE-2013-0340\", \"description\": \"expat 2.1.0 and earlier does
+ not properly handle entities expansion unless an application developer uses the
+ XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial
+ of service (resource consumption), send HTTP requests to intranet servers, or read
+ arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue.\
+ \ NOTE: it could be argued that because expat already provides the ability to disable
+ external entity expansion, the responsibility for resolving this issue lies with
+ application developers; according to this argument, this entry should be REJECTed,
+ and each affected application would need its own CVE.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2013-0340\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"2.2.6-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"expat\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2019-1010023\", \"description\"\
+ : \"** DISPUTED ** GNU Libc current is affected by: Re-mapping current loaded library
with malicious ELF file. The impact is: In worst case attacker may evaluate privileges.
The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim
- and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this
- is being treated as a non-security bug and no real threat.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-1010023",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
- "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name":
- "CVE-2010-4051", "description": "The regcomp implementation in the GNU C Library
- (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent
- attackers to cause a denial of service (application crash) via a regular expression
- containing adjacent bounded repetitions that bypass the intended RE_DUP_MAX limitation,
- as demonstrated by a {10,}{10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit
- for ProFTPD, related to a \"RE_DUP_MAX overflow.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-4051",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
- "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
- "CVE-2019-1010022", "description": "** DISPUTED ** GNU Libc current is affected
- by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection.
- The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability
- and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments
- indicate \"this is being treated as a non-security bug and no real threat.\"", "uri":
- "https://security-tracker.debian.org/tracker/CVE-2019-1010022", "severity": "INFORMATIONAL",
- "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
- "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"},
- {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2010-4052", "description":
- "Stack consumption vulnerability in the regcomp implementation in the GNU C Library
+ and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \\\
+ \"this is being treated as a non-security bug and no real threat.\\\"\", \"uri\"\
+ : \"https://security-tracker.debian.org/tracker/CVE-2019-1010023\", \"severity\"\
+ : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
+ \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\
+ , \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
+ : \"6.8\"}]}, {\"name\": \"CVE-2010-4051\", \"description\": \"The regcomp implementation
+ in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2,
+ allows context-dependent attackers to cause a denial of service (application crash)
+ via a regular expression containing adjacent bounded repetitions that bypass the
+ intended RE_DUP_MAX limitation, as demonstrated by a {10,}{10,}{10,}{10,}{10,} sequence
+ in the proftpd.gnu.c exploit for ProFTPD, related to a \\\"RE_DUP_MAX overflow.\\\
+ \"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2010-4051\", \"\
+ severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"\
+ value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\"\
+ : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"5\"}]}, {\"name\": \"CVE-2019-1010022\", \"description\": \"** DISPUTED
+ ** GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may
+ bypass stack guard protection. The component is: nptl. The attack vector is: Exploit
+ stack buffer overflow vulnerability and use this bypass vulnerability to bypass
+ stack guard. NOTE: Upstream comments indicate \\\"this is being treated as a non-security
+ bug and no real threat.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-1010022\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\
+ key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"\
+ CVSS2_SCORE\", \"value\": \"7.5\"}]}, {\"name\": \"CVE-2010-4052\", \"description\"\
+ : \"Stack consumption vulnerability in the regcomp implementation in the GNU C Library
(aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent
attackers to cause a denial of service (resource exhaustion) via a regular expression
containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,}
- sequence in the proftpd.gnu.c exploit for ProFTPD.", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-4052",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
- "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
- "CVE-2019-1010024", "description": "** DISPUTED ** GNU Libc current is affected
- by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread
- stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this
- is being treated as a non-security bug and no real threat.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-1010024",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
- "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
- "CVE-2010-4756", "description": "The glob implementation in the GNU C Library (aka
- glibc or libc6) allows remote authenticated users to cause a denial of service (CPU
- and memory consumption) via crafted glob expressions that do not match any pathnames,
- as demonstrated by glob expressions in STAT commands to an FTP daemon, a different
- vulnerability than CVE-2010-2632.", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-4756",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
- "AV:N/AC:L/Au:S/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4"}]}, {"name":
- "CVE-2019-1010025", "description": "** DISPUTED ** GNU Libc current is affected
- by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created
- thread. The component is: glibc. NOTE: the vendor''s position is \"ASLR bypass itself
- is not a vulnerability.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-1010025",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
- "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
- "CVE-2018-20796", "description": "In the GNU C Library (aka glibc or libc6) through
- 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion,
- as demonstrated by ''(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+'' in grep.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-20796",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
- "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
- "CVE-2019-9192", "description": "** DISPUTED ** In the GNU C Library (aka glibc
- or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled
- Recursion, as demonstrated by ''(|)(\\\\1\\\\1)*'' in grep, a different issue than
- CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability
- because the behavior occurs only with a crafted pattern.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-9192",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
- "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
- "CVE-2011-3389", "description": "The SSL protocol, as used in certain configurations
- in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome,
- Opera, and other products, encrypts data by using CBC mode with chained initialization
- vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers
- via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction
- with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection
- API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2011-3389",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "3.6.7-4+deb10u7"}, {"key": "package_name", "value": "gnutls28"}, {"key": "CVSS2_VECTOR",
- "value": "AV:N/AC:M/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
- {"name": "CVE-2021-30535", "description": "Double free in ICU in Google Chrome prior
- to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption
- via a crafted HTML page.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-30535",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "63.1-6+deb10u1"}, {"key": "package_name", "value": "icu"}, {"key": "CVSS2_VECTOR",
- "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]},
- {"name": "CVE-2017-9937", "description": "In LibTIFF 4.0.8, there is a memory malloc
- failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in
- a remote denial of service attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-9937",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "2.1-3.1"}, {"key": "package_name", "value": "jbigkit"}, {"key": "CVSS2_VECTOR",
- "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
- {"name": "CVE-2018-5709", "description": "An issue was discovered in MIT Kerberos
- 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c
- that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable
- to it, which is for 32-bit data. An attacker can use this vulnerability to affect
- other artifacts of the database as we know that a Kerberos database dump file contains
- trusted data.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-5709",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "1.17-3+deb10u1"}, {"key": "package_name", "value": "krb5"}, {"key": "CVSS2_VECTOR",
- "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
- {"name": "CVE-2021-36222", "description": "ec_verify in kdc/kdc_preauth_ec.c in
- the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and
- 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference
- and daemon crash. This occurs because a return value is not properly managed in
- a certain situation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36222",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "1.17-3+deb10u1"}, {"key": "package_name", "value": "krb5"}, {"key": "CVSS2_VECTOR",
- "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]},
- {"name": "CVE-2004-0971", "description": "The krb5-send-pr script in the kerberos5
- (krb5) package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating
- systems, allows local users to overwrite files via a symlink attack on temporary
- files.", "uri": "https://security-tracker.debian.org/tracker/CVE-2004-0971", "severity":
- "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "1.17-3+deb10u1"},
- {"key": "package_name", "value": "krb5"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:P/A:N"},
- {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2018-6829", "description":
- "cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly,
+ sequence in the proftpd.gnu.c exploit for ProFTPD.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2010-4052\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\
+ key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"\
+ CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2019-1010024\", \"description\"\
+ : \"** DISPUTED ** GNU Libc current is affected by: Mitigation bypass. The impact
+ is: Attacker may bypass ASLR using cache of thread stack and heap. The component
+ is: glibc. NOTE: Upstream comments indicate \\\"this is being treated as a non-security
+ bug and no real threat.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-1010024\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\
+ key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"\
+ CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2010-4756\", \"description\"\
+ : \"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote
+ authenticated users to cause a denial of service (CPU and memory consumption) via
+ crafted glob expressions that do not match any pathnames, as demonstrated by glob
+ expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.\"\
+ , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2010-4756\", \"severity\"\
+ : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
+ \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\
+ , \"value\": \"AV:N/AC:L/Au:S/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
+ : \"4\"}]}, {\"name\": \"CVE-2019-1010025\", \"description\": \"** DISPUTED ** GNU
+ Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess
+ the heap addresses of pthread_created thread. The component is: glibc. NOTE: the
+ vendor's position is \\\"ASLR bypass itself is not a vulnerability.\\\"\", \"uri\"\
+ : \"https://security-tracker.debian.org/tracker/CVE-2019-1010025\", \"severity\"\
+ : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
+ \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\
+ , \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
+ : \"5\"}]}, {\"name\": \"CVE-2018-20796\", \"description\": \"In the GNU C Library
+ (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c
+ has Uncontrolled Recursion, as demonstrated by '(\\\\227|)(\\\\\\\\1\\\\\\\\1|t1|\\\
+ \\\\\\\\\\2537)+' in grep.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-20796\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\
+ key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"\
+ CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2019-9192\", \"description\"\
+ : \"** DISPUTED ** In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1
+ in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\\\\\\
+ 1\\\\\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software
+ maintainer disputes that this is a vulnerability because the behavior occurs only
+ with a crafted pattern.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-9192\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\
+ key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"\
+ CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2011-3389\", \"description\"\
+ : \"The SSL protocol, as used in certain configurations in Microsoft Windows and
+ Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products,
+ encrypts data by using CBC mode with chained initialization vectors, which allows
+ man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary
+ attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses
+ (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight
+ WebClient API, aka a \\\"BEAST\\\" attack.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2011-3389\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"3.6.7-4+deb10u7\"}, {\"key\": \"package_name\", \"value\": \"gnutls28\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:N\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2021-30535\", \"description\"\
+ : \"Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker
+ to potentially exploit heap corruption via a crafted HTML page.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-30535\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"63.1-6+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"icu\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2017-9937\", \"description\"\
+ : \"In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted
+ TIFF document can lead to an abort resulting in a remote denial of service attack.\"\
+ , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-9937\", \"severity\"\
+ : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
+ \"2.1-3.1\"}, {\"key\": \"package_name\", \"value\": \"jbigkit\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2018-5709\", \"description\": \"An issue
+ was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \\\
+ \"dbentry->n_key_data\\\" in kadmin/dbutil/dump.c that can store 16-bit data but
+ unknowingly the developer has assigned a \\\"u4\\\" variable to it, which is for
+ 32-bit data. An attacker can use this vulnerability to affect other artifacts of
+ the database as we know that a Kerberos database dump file contains trusted data.\"\
+ , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-5709\", \"severity\"\
+ : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
+ \"1.17-3+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"krb5\"}, {\"key\"
+ : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"5\"}]}, {\"name\": \"CVE-2021-36222\", \"description\": \"ec_verify
+ in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka
+ krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a
+ NULL pointer dereference and daemon crash. This occurs because a return value is
+ not properly managed in a certain situation.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36222\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"1.17-3+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"krb5\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2004-0971\", \"description\"\
+ : \"The krb5-send-pr script in the kerberos5 (krb5) package in Trustix Secure Linux
+ 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite
+ files via a symlink attack on temporary files.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2004-0971\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"1.17-3+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"krb5\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"2.1\"}]}, {\"name\": \"CVE-2018-6829\", \"description\"\
+ : \"cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly,
improperly encodes plaintexts, which allows attackers to obtain sensitive information
by reading ciphertext data (i.e., it does not have semantic security in face of
a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not
- hold for Libgcrypt''s ElGamal implementation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-6829",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "1.8.4-5+deb10u1"}, {"key": "package_name", "value": "libgcrypt20"}, {"key": "CVSS2_VECTOR",
- "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
- {"name": "CVE-2018-11813", "description": "libjpeg 9c has a large loop because read_pixel
- in rdtarga.c mishandles EOF.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-11813",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "1:1.5.2-2+deb10u1"}, {"key": "package_name", "value": "libjpeg-turbo"}, {"key":
- "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
- "5"}]}, {"name": "CVE-2020-17541", "description": "Libjpeg-turbo all version have
- a stack-based buffer overflow in the \"transform\" component. A remote attacker
- can send a malformed jpeg file to the service and cause arbitrary code execution
- or denial of service of the target service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-17541",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "1:1.5.2-2+deb10u1"}, {"key": "package_name", "value": "libjpeg-turbo"}, {"key":
- "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value":
- "6.8"}]}, {"name": "CVE-2017-15232", "description": "libjpeg-turbo 1.5.2 has a NULL
- Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.", "uri":
- "https://security-tracker.debian.org/tracker/CVE-2017-15232", "severity": "INFORMATIONAL",
- "attributes": [{"key": "package_version", "value": "1:1.5.2-2+deb10u1"}, {"key":
- "package_name", "value": "libjpeg-turbo"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2018-14048", "description":
- "An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data
- in png.c, related to the recommended error handling for png_read_image.", "uri":
- "https://security-tracker.debian.org/tracker/CVE-2018-14048", "severity": "INFORMATIONAL",
- "attributes": [{"key": "package_version", "value": "1.6.36-6"}, {"key": "package_name",
- "value": "libpng1.6"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2019-6129", "description":
- "** DISPUTED ** png_create_info_struct in png.c in libpng 1.6.36 has a memory leak,
- as demonstrated by pngcp. NOTE: a third party has stated \"I don''t think it is
- libpng''s job to free this buffer.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-6129",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "1.6.36-6"}, {"key": "package_name", "value": "libpng1.6"}, {"key": "CVSS2_VECTOR",
- "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
- {"name": "CVE-2018-14550", "description": "An issue has been found in third-party
- PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow
- in the function get_token in pnm2png.c in pnm2png.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-14550",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "1.6.36-6"}, {"key": "package_name", "value": "libpng1.6"}, {"key": "CVSS2_VECTOR",
- "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]},
- {"name": "CVE-2019-9893", "description": "libseccomp before 2.4.0 did not correctly
- generate 64-bit syscall argument comparisons using the arithmetic operators (LT,
- GT, LE, GE), which might able to lead to bypassing seccomp filters and potential
- privilege escalations.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-9893",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "2.3.3-4"}, {"key": "package_name", "value": "libseccomp"}, {"key": "CVSS2_VECTOR",
- "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "7.5"}]},
- {"name": "CVE-2018-1000654", "description": "GNU Libtasn1-4.13 libtasn1-4.13 version
- libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100%
- when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree),
- after a long time, the program will be killed. This attack appears to be exploitable
- via parsing a crafted file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-1000654",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "4.13-3"}, {"key": "package_name", "value": "libtasn1-6"}, {"key": "CVSS2_VECTOR",
- "value": "AV:N/AC:M/Au:N/C:N/I:N/A:C"}, {"key": "CVSS2_SCORE", "value": "7.1"}]},
- {"name": "CVE-2016-9085", "description": "Multiple integer overflows in libwebp
- allows attackers to have unspecified impact via unknown vectors.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-9085",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "0.6.1-2+deb10u1"}, {"key": "package_name", "value": "libwebp"}, {"key": "CVSS2_VECTOR",
- "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "2.1"}]},
- {"name": "CVE-2015-9019", "description": "In libxslt 1.1.29 and earlier, the EXSLT
- math.random function was not initialized with a random seed during startup, which
- could cause usage of this function to produce predictable outputs.", "uri": "https://security-tracker.debian.org/tracker/CVE-2015-9019",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "1.1.32-2.2~deb10u1"}, {"key": "package_name", "value": "libxslt"}, {"key": "CVSS2_VECTOR",
- "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
- {"name": "CVE-2009-4487", "description": "nginx 0.7.64 writes data to a log file
- without sanitizing non-printable characters, which might allow remote attackers
- to modify a window''s title, or possibly execute arbitrary commands or overwrite
- files, via an HTTP request containing an escape sequence for a terminal emulator.",
- "uri": "https://security-tracker.debian.org/tracker/CVE-2009-4487", "severity":
- "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"},
- {"key": "package_name", "value": "nginx"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
- {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2020-15719", "description":
- "libldap in certain third-party OpenLDAP packages has a certificate-validation flaw
- when the third-party package is asserting RFC6125 support. It considers CN even
- when there is a non-matching subjectAltName (SAN). This is fixed in, for example,
- openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-15719",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "2.4.47+dfsg-3+deb10u6"}, {"key": "package_name", "value": "openldap"}, {"key":
- "CVSS2_VECTOR", "value": "AV:N/AC:H/Au:N/C:P/I:P/A:N"}, {"key": "CVSS2_SCORE", "value":
- "4"}]}, {"name": "CVE-2015-3276", "description": "The nss_parse_ciphers function
- in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword
- mode cipher strings, which might cause a weaker than intended cipher to be used
- and allow remote attackers to have unspecified impact via unknown vectors.", "uri":
- "https://security-tracker.debian.org/tracker/CVE-2015-3276", "severity": "INFORMATIONAL",
- "attributes": [{"key": "package_version", "value": "2.4.47+dfsg-3+deb10u6"}, {"key":
- "package_name", "value": "openldap"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"},
- {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2017-14159", "description":
- "slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges
- to a non-root account, which might allow local users to kill arbitrary processes
- by leveraging access to this non-root account for PID file modification before a
- root script executes a \"kill `cat /pathname`\" command, as demonstrated by openldap-initscript.",
- "uri": "https://security-tracker.debian.org/tracker/CVE-2017-14159", "severity":
- "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "2.4.47+dfsg-3+deb10u6"},
- {"key": "package_name", "value": "openldap"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:N/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "1.9"}]}, {"name": "CVE-2017-17740", "description":
- "contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops
- module and the memberof overlay are enabled, attempts to free a buffer that was
- allocated on the stack, which allows remote attackers to cause a denial of service
- (slapd crash) via a member MODDN operation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-17740",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "2.4.47+dfsg-3+deb10u6"}, {"key": "package_name", "value": "openldap"}, {"key":
- "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
- "5"}]}, {"name": "CVE-2010-0928", "description": "OpenSSL 0.9.8i on the Gaisler
- Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation
- (FWE) algorithm for certain signature calculations, and does not verify the signature
- before providing it to a caller, which makes it easier for physically proximate
- attackers to determine the private key via a modified supply voltage for the microprocessor,
- related to a \"fault-based attack.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-0928",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "1.1.1d-0+deb10u6"}, {"key": "package_name", "value": "openssl"}, {"key": "CVSS2_VECTOR",
- "value": "AV:L/AC:H/Au:N/C:C/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4"}]},
- {"name": "CVE-2007-6755", "description": "The NIST SP 800-90A default statement
- of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm
- contains point Q constants with a possible relationship to certain \"skeleton key\"
- values, which might allow context-dependent attackers to defeat cryptographic protection
- mechanisms by leveraging knowledge of those values. NOTE: this is a preliminary
- CVE for Dual_EC_DRBG; future research may provide additional details about point
- Q and associated attacks, and could potentially lead to a RECAST or REJECT of this
- CVE.", "uri": "https://security-tracker.debian.org/tracker/CVE-2007-6755", "severity":
- "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "1.1.1d-0+deb10u6"},
- {"key": "package_name", "value": "openssl"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:N"},
- {"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2017-7246", "description":
- "Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c
+ hold for Libgcrypt's ElGamal implementation.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-6829\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"1.8.4-5+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libgcrypt20\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2018-11813\", \"description\"\
+ : \"libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.\"\
+ , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-11813\", \"severity\"\
+ : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
+ \"1:1.5.2-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libjpeg-turbo\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2020-17541\", \"description\"\
+ : \"Libjpeg-turbo all version have a stack-based buffer overflow in the \\\"transform\\\
+ \" component. A remote attacker can send a malformed jpeg file to the service and
+ cause arbitrary code execution or denial of service of the target service.\", \"\
+ uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-17541\", \"severity\"\
+ : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
+ \"1:1.5.2-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libjpeg-turbo\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2017-15232\", \"description\"\
+ : \"libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c
+ via a crafted JPEG file.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-15232\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"1:1.5.2-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libjpeg-turbo\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2018-14048\", \"description\"\
+ : \"An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data
+ in png.c, related to the recommended error handling for png_read_image.\", \"uri\"\
+ : \"https://security-tracker.debian.org/tracker/CVE-2018-14048\", \"severity\":
+ \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"\
+ 1.6.36-6\"}, {\"key\": \"package_name\", \"value\": \"libpng1.6\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2019-6129\", \"description\": \"** DISPUTED
+ ** png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated
+ by pngcp. NOTE: a third party has stated \\\"I don't think it is libpng's job to
+ free this buffer.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-6129\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"1.6.36-6\"}, {\"key\": \"package_name\", \"value\": \"libpng1.6\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2018-14550\", \"description\"\
+ : \"An issue has been found in third-party PNM decoding associated with libpng 1.6.35.
+ It is a stack-based buffer overflow in the function get_token in pnm2png.c in pnm2png.\"\
+ , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-14550\", \"severity\"\
+ : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
+ \"1.6.36-6\"}, {\"key\": \"package_name\", \"value\": \"libpng1.6\"}, {\"key\":
+ \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2019-9893\", \"description\": \"libseccomp
+ before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using
+ the arithmetic operators (LT, GT, LE, GE), which might able to lead to bypassing
+ seccomp filters and potential privilege escalations.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-9893\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"2.3.3-4\"}, {\"key\": \"package_name\", \"value\": \"libseccomp\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"7.5\"}]}, {\"name\": \"CVE-2018-1000654\", \"description\"\
+ : \"GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains
+ a DoS, specifically CPU usage will reach 100% when running asn1Paser against the
+ POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program
+ will be killed. This attack appears to be exploitable via parsing a crafted file.\"\
+ , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-1000654\", \"\
+ severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"\
+ value\": \"4.13-3\"}, {\"key\": \"package_name\", \"value\": \"libtasn1-6\"}, {\"\
+ key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:C\"}, {\"key\": \"\
+ CVSS2_SCORE\", \"value\": \"7.1\"}]}, {\"name\": \"CVE-2016-9085\", \"description\"\
+ : \"Multiple integer overflows in libwebp allows attackers to have unspecified impact
+ via unknown vectors.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2016-9085\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"0.6.1-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libwebp\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"2.1\"}]}, {\"name\": \"CVE-2015-9019\", \"description\"\
+ : \"In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized
+ with a random seed during startup, which could cause usage of this function to produce
+ predictable outputs.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2015-9019\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"1.1.32-2.2~deb10u1\"}, {\"key\": \"package_name\", \"value\": \"\
+ libxslt\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"\
+ }, {\"key\": \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2009-4487\"
+ , \"description\": \"nginx 0.7.64 writes data to a log file without sanitizing non-printable
+ characters, which might allow remote attackers to modify a window's title, or possibly
+ execute arbitrary commands or overwrite files, via an HTTP request containing an
+ escape sequence for a terminal emulator.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2009-4487\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"1.21.1-1~buster\"}, {\"key\": \"package_name\", \"value\": \"nginx\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-15719\", \"description\"\
+ : \"libldap in certain third-party OpenLDAP packages has a certificate-validation
+ flaw when the third-party package is asserting RFC6125 support. It considers CN
+ even when there is a non-matching subjectAltName (SAN). This is fixed in, for example,
+ openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-15719\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"2.4.47+dfsg-3+deb10u6\"}, {\"key\": \"package_name\", \"value\":
+ \"openldap\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:H/Au:N/C:P/I:P/A:N\"\
+ }, {\"key\": \"CVSS2_SCORE\", \"value\": \"4\"}]}, {\"name\": \"CVE-2015-3276\"
+ , \"description\": \"The nss_parse_ciphers function in libraries/libldap/tls_m.c
+ in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings,
+ which might cause a weaker than intended cipher to be used and allow remote attackers
+ to have unspecified impact via unknown vectors.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2015-3276\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"2.4.47+dfsg-3+deb10u6\"}, {\"key\": \"package_name\", \"value\":
+ \"openldap\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"\
+ }, {\"key\": \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2017-14159\"\
+ , \"description\": \"slapd in OpenLDAP 2.4.45 and earlier creates a PID file after
+ dropping privileges to a non-root account, which might allow local users to kill
+ arbitrary processes by leveraging access to this non-root account for PID file modification
+ before a root script executes a \\\"kill `cat /pathname`\\\" command, as demonstrated
+ by openldap-initscript.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-14159\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"2.4.47+dfsg-3+deb10u6\"}, {\"key\": \"package_name\", \"value\":
+ \"openldap\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:N/I:N/A:P\"\
+ }, {\"key\": \"CVSS2_SCORE\", \"value\": \"1.9\"}]}, {\"name\": \"CVE-2017-17740\"\
+ , \"description\": \"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45,
+ when both the nops module and the memberof overlay are enabled, attempts to free
+ a buffer that was allocated on the stack, which allows remote attackers to cause
+ a denial of service (slapd crash) via a member MODDN operation.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-17740\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"2.4.47+dfsg-3+deb10u6\"}, {\"key\": \"package_name\", \"value\":
+ \"openldap\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"\
+ }, {\"key\": \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2010-0928\"
+ , \"description\": \"OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx
+ Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain
+ signature calculations, and does not verify the signature before providing it to
+ a caller, which makes it easier for physically proximate attackers to determine
+ the private key via a modified supply voltage for the microprocessor, related to
+ a \\\"fault-based attack.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2010-0928\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"1.1.1d-0+deb10u6\"}, {\"key\": \"package_name\", \"value\": \"openssl\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:H/Au:N/C:C/I:N/A:N\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"4\"}]}, {\"name\": \"CVE-2007-6755\", \"description\"\
+ : \"The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic
+ Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a
+ possible relationship to certain \\\"skeleton key\\\" values, which might allow
+ context-dependent attackers to defeat cryptographic protection mechanisms by leveraging
+ knowledge of those values. NOTE: this is a preliminary CVE for Dual_EC_DRBG; future
+ research may provide additional details about point Q and associated attacks, and
+ could potentially lead to a RECAST or REJECT of this CVE.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2007-6755\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"1.1.1d-0+deb10u6\"}, {\"key\": \"package_name\", \"value\": \"openssl\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:N\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"5.8\"}]}, {\"name\": \"CVE-2017-7246\", \"description\"\
+ : \"Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c
in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE
- of size 268) or possibly have unspecified other impact via a crafted file.", "uri":
- "https://security-tracker.debian.org/tracker/CVE-2017-7246", "severity": "INFORMATIONAL",
- "attributes": [{"key": "package_version", "value": "2:8.39-12"}, {"key": "package_name",
- "value": "pcre3"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
- {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2019-20838", "description":
- "libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is
- disabled, and \\X or \\R has more than one fixed quantifier, a related issue to
- CVE-2019-20454.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-20838",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR",
- "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
- {"name": "CVE-2017-7245", "description": "Stack-based buffer overflow in the pcre32_copy_substring
- function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause
- a denial of service (WRITE of size 4) or possibly have unspecified other impact
- via a crafted file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-7245",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR",
- "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]},
- {"name": "CVE-2017-16231", "description": "** DISPUTED ** In PCRE 8.41, after compiling,
- a pcretest load test PoC produces a crash overflow in the function match() in pcre_exec.c
- because of a self-recursive call. NOTE: third parties dispute the relevance of this
- report, noting that there are options that can be used to limit the amount of stack
- that is used.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-16231",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR",
- "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "2.1"}]},
- {"name": "CVE-2017-11164", "description": "In PCRE 8.41, the OP_KETRMAX feature
- in the match function in pcre_exec.c allows stack exhaustion (uncontrolled recursion)
- when processing a crafted regular expression.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-11164",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR",
- "value": "AV:N/AC:L/Au:N/C:N/I:N/A:C"}, {"key": "CVSS2_SCORE", "value": "7.8"}]},
- {"name": "CVE-2011-4116", "description": "_is_safe in the File::Temp module for
- Perl does not properly handle symlinks.", "uri": "https://security-tracker.debian.org/tracker/CVE-2011-4116",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "5.28.1-6+deb10u1"}, {"key": "package_name", "value": "perl"}, {"key": "CVSS2_VECTOR",
- "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
- {"name": "CVE-2019-19882", "description": "shadow 4.8, in certain circumstances
- affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain
- root access because setuid programs are misconfigured. Specifically, this affects
- shadow 4.8 when compiled using --with-libpam but without explicitly passing --disable-account-tools-setuid,
- and without a PAM configuration suitable for use with setuid account management
- tools. This combination leads to account management tools (groupadd, groupdel, groupmod,
- useradd, userdel, usermod) that can easily be used by unprivileged local users to
- escalate privileges to root in multiple ways. This issue became much more relevant
- in approximately December 2019 when an unrelated bug was fixed (i.e., the chmod
- calls to suidusbins were fixed in the upstream Makefile which is now included in
- the release version 4.8).", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-19882",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR",
- "value": "AV:L/AC:M/Au:N/C:C/I:C/A:C"}, {"key": "CVSS2_SCORE", "value": "6.9"}]},
- {"name": "CVE-2007-5686", "description": "initscripts in rPath Linux 1 sets insecure
- permissions for the /var/log/btmp file, which allows local users to obtain sensitive
- information regarding authentication attempts. NOTE: because sshd detects the insecure
- permissions and does not log certain events, this also prevents sshd from logging
- failed authentication attempts by remote attackers.", "uri": "https://security-tracker.debian.org/tracker/CVE-2007-5686",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR",
- "value": "AV:L/AC:L/Au:N/C:C/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.9"}]},
- {"name": "CVE-2013-4235", "description": "shadow: TOCTOU (time-of-check time-of-use)
- race condition when copying and removing directory trees", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-4235",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR",
- "value": "AV:L/AC:M/Au:N/C:N/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "3.3"}]},
- {"name": "CVE-2020-13529", "description": "An exploitable denial-of-service vulnerability
- exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server
- running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker
- can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server.",
- "uri": "https://security-tracker.debian.org/tracker/CVE-2020-13529", "severity":
- "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"},
- {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:A/AC:M/Au:N/C:N/I:N/A:P"},
- {"key": "CVSS2_SCORE", "value": "2.9"}]}, {"name": "CVE-2013-4392", "description":
- "systemd, when updating file permissions, allows local users to change the permissions
+ of size 268) or possibly have unspecified other impact via a crafted file.\", \"\
+ uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-7246\", \"severity\"\
+ : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
+ \"2:8.39-12\"}, {\"key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2019-20838\", \"description\": \"libpcre
+ in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled,
+ and \\\\X or \\\\R has more than one fixed quantifier, a related issue to CVE-2019-20454.\"\
+ , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-20838\", \"severity\"\
+ : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
+ \"2:8.39-12\"}, {\"key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-7245\", \"description\": \"Stack-based
+ buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1
+ in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size
+ 4) or possibly have unspecified other impact via a crafted file.\", \"uri\": \"\
+ https://security-tracker.debian.org/tracker/CVE-2017-7245\", \"severity\": \"INFORMATIONAL\"\
+ , \"attributes\": [{\"key\": \"package_version\", \"value\": \"2:8.39-12\"}, {\"\
+ key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"CVSS2_VECTOR\", \"value\"\
+ : \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\": \"6.8\"\
+ }]}, {\"name\": \"CVE-2017-16231\", \"description\": \"** DISPUTED ** In PCRE 8.41,
+ after compiling, a pcretest load test PoC produces a crash overflow in the function
+ match() in pcre_exec.c because of a self-recursive call. NOTE: third parties dispute
+ the relevance of this report, noting that there are options that can be used to
+ limit the amount of stack that is used.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-16231\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"2:8.39-12\"}, {\"key\": \"package_name\", \"value\": \"pcre3\"},
+ {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"2.1\"}]}, {\"name\": \"CVE-2017-11164\", \"description\"\
+ : \"In PCRE 8.41, the OP_KETRMAX feature in the match function in pcre_exec.c allows
+ stack exhaustion (uncontrolled recursion) when processing a crafted regular expression.\"\
+ , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-11164\", \"severity\"\
+ : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
+ \"2:8.39-12\"}, {\"key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:C\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"7.8\"}]}, {\"name\": \"CVE-2011-4116\", \"description\": \"_is_safe
+ in the File::Temp module for Perl does not properly handle symlinks.\", \"uri\"
+ : \"https://security-tracker.debian.org/tracker/CVE-2011-4116\", \"severity\": \"\
+ INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"5.28.1-6+deb10u1\"\
+ }, {\"key\": \"package_name\", \"value\": \"perl\"}, {\"key\": \"CVSS2_VECTOR\"
+ , \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
+ : \"5\"}]}, {\"name\": \"CVE-2019-19882\", \"description\": \"shadow 4.8, in certain
+ circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local
+ users to obtain root access because setuid programs are misconfigured. Specifically,
+ this affects shadow 4.8 when compiled using --with-libpam but without explicitly
+ passing --disable-account-tools-setuid, and without a PAM configuration suitable
+ for use with setuid account management tools. This combination leads to account
+ management tools (groupadd, groupdel, groupmod, useradd, userdel, usermod) that
+ can easily be used by unprivileged local users to escalate privileges to root in
+ multiple ways. This issue became much more relevant in approximately December 2019
+ when an unrelated bug was fixed (i.e., the chmod calls to suidusbins were fixed
+ in the upstream Makefile which is now included in the release version 4.8).\", \"\
+ uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-19882\", \"severity\"\
+ : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
+ \"1:4.5-1.1\"}, {\"key\": \"package_name\", \"value\": \"shadow\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:C/I:C/A:C\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"6.9\"}]}, {\"name\": \"CVE-2007-5686\", \"description\": \"initscripts
+ in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows
+ local users to obtain sensitive information regarding authentication attempts. \
+ \ NOTE: because sshd detects the insecure permissions and does not log certain events,
+ this also prevents sshd from logging failed authentication attempts by remote attackers.\"\
+ , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2007-5686\", \"severity\"\
+ : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
+ \"1:4.5-1.1\"}, {\"key\": \"package_name\", \"value\": \"shadow\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:C/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"4.9\"}]}, {\"name\": \"CVE-2013-4235\", \"description\": \"shadow:
+ TOCTOU (time-of-check time-of-use) race condition when copying and removing directory
+ trees\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2013-4235\"
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"1:4.5-1.1\"}, {\"key\": \"package_name\", \"value\": \"shadow\"},
+ {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:N/I:P/A:P\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"3.3\"}]}, {\"name\": \"CVE-2020-13529\", \"description\"\
+ : \"An exploitable denial-of-service vulnerability exists in Systemd 245. A specially
+ crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be
+ vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW
+ and DCHP ACK packets to reconfigure the server.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-13529\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:A/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"2.9\"}]}, {\"name\": \"CVE-2013-4392\", \"description\"\
+ : \"systemd, when updating file permissions, allows local users to change the permissions
and SELinux security contexts for arbitrary files via a symlink attack on unspecified
- files.", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-4392", "severity":
- "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"},
- {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:P/I:P/A:N"},
- {"key": "CVSS2_SCORE", "value": "3.3"}]}, {"name": "CVE-2020-13776", "description":
- "systemd through v245 mishandles numerical usernames such as ones composed of decimal
- digits or 0x followed by hex digits, as demonstrated by use of root privileges when
- privileges of the 0x0 user account were intended. NOTE: this issue exists because
- of an incomplete fix for CVE-2017-1000082.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-13776",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "241-7~deb10u8"}, {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR",
- "value": "AV:L/AC:H/Au:N/C:C/I:C/A:C"}, {"key": "CVSS2_SCORE", "value": "6.2"}]},
- {"name": "CVE-2019-20386", "description": "An issue was discovered in button_open
- in login/logind-button.c in systemd before 243. When executing the udevadm trigger
- command, a memory leak may occur.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-20386",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "241-7~deb10u8"}, {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR",
- "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "2.1"}]},
- {"name": "CVE-2019-9923", "description": "pax_decode_header in sparse.c in GNU Tar
- before 1.32 had a NULL pointer dereference when parsing certain archives that have
- malformed extended headers.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-9923",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR",
- "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]},
- {"name": "CVE-2005-2541", "description": "Tar 1.15.1 does not properly warn the
- user when extracting setuid or setgid files, which may allow local users or remote
- attackers to gain privileges.", "uri": "https://security-tracker.debian.org/tracker/CVE-2005-2541",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR",
- "value": "AV:N/AC:L/Au:N/C:C/I:C/A:C"}, {"key": "CVSS2_SCORE", "value": "10"}]},
- {"name": "CVE-2021-20193", "description": "A flaw was found in the src/list.c of
- tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input
- file to tar to cause uncontrolled consumption of memory. The highest threat from
- this vulnerability is to system availability.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-20193",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR",
- "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
- {"name": "CVE-2017-17973", "description": "** DISPUTED ** In LibTIFF 4.0.8, there
- is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE:
- there is a third-party report of inability to reproduce this issue.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-17973",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
- "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value":
- "6.8"}]}, {"name": "CVE-2020-35521", "description": "A flaw was found in libtiff.
- Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to
- an abort, resulting in denial of service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-35521",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
- "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
- "4.3"}]}, {"name": "CVE-2014-8130", "description": "The _TIFFmalloc function in
- tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers
- to cause a denial of service (divide-by-zero error and application crash) via a
- crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c,
- as demonstrated by tiffdither.", "uri": "https://security-tracker.debian.org/tracker/CVE-2014-8130",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
- "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
- "4.3"}]}, {"name": "CVE-2017-5563", "description": "LibTIFF version 4.0.7 is vulnerable
- to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution
- via a crafted bmp image to tools/bmp2tiff.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-5563",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
- "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value":
- "6.8"}]}, {"name": "CVE-2020-35522", "description": "In LibTIFF, there is a memory
- malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort,
- resulting in a remote denial of service attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-35522",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
- "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
- "4.3"}]}, {"name": "CVE-2017-9117", "description": "In LibTIFF 4.0.7, the program
- processes BMP images without verifying that biWidth and biHeight in the bitmap-information
- header match the actual input, leading to a heap-based buffer over-read in bmp2tiff.",
- "uri": "https://security-tracker.debian.org/tracker/CVE-2017-9117", "severity":
- "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "4.1.0+git191117-2~deb10u2"},
- {"key": "package_name", "value": "tiff"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"},
- {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2017-16232", "description":
- "** DISPUTED ** LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow
- attackers to cause a denial of service (memory consumption), as demonstrated by
- tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce
- the issue.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-16232",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
- "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
- "5"}]}, {"name": "CVE-2018-10126", "description": "LibTIFF 4.0.9 has a NULL pointer
- dereference in the jpeg_fdct_16x16 function in jfdctint.c.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-10126",
- "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
- "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
- "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
- "4.3"}]}, {"name": "CVE-2021-22924", "description": "libcurl keeps previously used
- connections in a connection pool for subsequenttransfers to reuse, if one of them
- matches the setup.Due to errors in the logic, the config matching function did not
- take ''issuercert'' into account and it compared the involved paths *case insensitively*,which
- could lead to libcurl reusing wrong connections.File paths are, or can be, case
- sensitive on many systems but not all, and caneven vary depending on used file systems.The
- comparison also didn''t include the ''issuer cert'' which a transfer can setto qualify
- how to verify the server certificate.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22924",
- "severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "7.64.0-4+deb10u2"},
- {"key": "package_name", "value": "curl"}]}, {"name": "CVE-2021-38115", "description":
- "read_header_tga in gd_tga.c in the GD Graphics Library (aka LibGD) through 2.3.2
- allows remote attackers to cause a denial of service (out-of-bounds read) via a
- crafted TGA file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-38115",
- "severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "2.2.5-5.2"},
- {"key": "package_name", "value": "libgd2"}]}, {"name": "CVE-2021-3618", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-3618",
- "severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"},
- {"key": "package_name", "value": "nginx"}]}], "findingSeverityCounts": {"HIGH":
- 2, "MEDIUM": 14, "INFORMATIONAL": 63, "LOW": 22, "UNDEFINED": 3}}}, "requestID":
- "23c19e2d-c48b-4265-b4eb-853e7b325780", "eventID": "6c94a9b2-36dc-43f8-a6dd-4ec839ded8af",
- "readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
- "111111111111", "eventCategory": "Management"}'
+ files.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2013-4392\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:P/I:P/A:N\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"3.3\"}]}, {\"name\": \"CVE-2020-13776\", \"description\"\
+ : \"systemd through v245 mishandles numerical usernames such as ones composed of
+ decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges
+ when privileges of the 0x0 user account were intended. NOTE: this issue exists because
+ of an incomplete fix for CVE-2017-1000082.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-13776\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"\
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:H/Au:N/C:C/I:C/A:C\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"6.2\"}]}, {\"name\": \"CVE-2019-20386\", \"description\"\
+ : \"An issue was discovered in button_open in login/logind-button.c in systemd before
+ 243. When executing the udevadm trigger command, a memory leak may occur.\", \"\
+ uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-20386\", \"severity\"\
+ : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
+ \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"}, {\"key\"\
+ : \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2019-9923\", \"description\": \"pax_decode_header
+ in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain
+ archives that have malformed extended headers.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-9923\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"1.30+dfsg-6\"}, {\"key\": \"package_name\", \"value\": \"tar\"},
+ {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2005-2541\", \"description\"\
+ : \"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid
+ files, which may allow local users or remote attackers to gain privileges.\", \"\
+ uri\": \"https://security-tracker.debian.org/tracker/CVE-2005-2541\", \"severity\"\
+ : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
+ \"1.30+dfsg-6\"}, {\"key\": \"package_name\", \"value\": \"tar\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:C/I:C/A:C\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"10\"}]}, {\"name\": \"CVE-2021-20193\", \"description\": \"A flaw
+ was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker
+ who can submit a crafted input file to tar to cause uncontrolled consumption of
+ memory. The highest threat from this vulnerability is to system availability.\"
+ , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-20193\", \"severity\"\
+ : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
+ \"1.30+dfsg-6\"}, {\"key\": \"package_name\", \"value\": \"tar\"}, {\"key\": \"\
+ CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
+ , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-17973\", \"description\": \"** DISPUTED
+ ** In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function
+ in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this
+ issue.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-17973\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\
+ : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"\
+ }, {\"key\": \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-35521\"\
+ , \"description\": \"A flaw was found in libtiff. Due to a memory allocation failure
+ in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of
+ service.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-35521\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\
+ : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"\
+ }, {\"key\": \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2014-8130\"\
+ , \"description\": \"The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does
+ not reject a zero size, which allows remote attackers to cause a denial of service
+ (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled
+ by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.\"\
+ , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2014-8130\", \"severity\"\
+ : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
+ \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\": \"tiff\"
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-5563\", \"description\"\
+ : \"LibTIFF version 4.0.7 is vulnerable to a heap-based buffer over-read in tif_lzw.c
+ resulting in DoS or code execution via a crafted bmp image to tools/bmp2tiff.\"
+ , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-5563\", \"severity\"\
+ : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
+ \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\": \"tiff\"
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-35522\", \"description\"\
+ : \"In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF
+ document can lead to an abort, resulting in a remote denial of service attack.\"\
+ , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-35522\", \"severity\"\
+ : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
+ \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\": \"tiff\"
+ }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\
+ : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-9117\", \"description\"\
+ : \"In LibTIFF 4.0.7, the program processes BMP images without verifying that biWidth
+ and biHeight in the bitmap-information header match the actual input, leading to
+ a heap-based buffer over-read in bmp2tiff.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-9117\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\
+ : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"\
+ }, {\"key\": \"CVSS2_SCORE\", \"value\": \"7.5\"}]}, {\"name\": \"CVE-2017-16232\"\
+ , \"description\": \"** DISPUTED ** LibTIFF 4.0.8 has multiple memory leak vulnerabilities,
+ which allow attackers to cause a denial of service (memory consumption), as demonstrated
+ by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce
+ the issue.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-16232\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\
+ : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"\
+ }, {\"key\": \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2018-10126\"\
+ , \"description\": \"LibTIFF 4.0.9 has a NULL pointer dereference in the jpeg_fdct_16x16
+ function in jfdctint.c.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-10126\"\
+ , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
+ , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\
+ : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"\
+ }, {\"key\": \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2021-22924\"\
+ , \"description\": \"libcurl keeps previously used connections in a connection pool
+ for subsequenttransfers to reuse, if one of them matches the setup.Due to errors
+ in the logic, the config matching function did not take 'issuercert' into account
+ and it compared the involved paths *case insensitively*,which could lead to libcurl
+ reusing wrong connections.File paths are, or can be, case sensitive on many systems
+ but not all, and caneven vary depending on used file systems.The comparison also
+ didn't include the 'issuer cert' which a transfer can setto qualify how to verify
+ the server certificate.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-22924\"\
+ , \"severity\": \"UNDEFINED\", \"attributes\": [{\"key\": \"package_version\", \"\
+ value\": \"7.64.0-4+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"curl\"
+ }]}, {\"name\": \"CVE-2021-38115\", \"description\": \"read_header_tga in gd_tga.c
+ in the GD Graphics Library (aka LibGD) through 2.3.2 allows remote attackers to
+ cause a denial of service (out-of-bounds read) via a crafted TGA file.\", \"uri\"\
+ : \"https://security-tracker.debian.org/tracker/CVE-2021-38115\", \"severity\":
+ \"UNDEFINED\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.2.5-5.2\"\
+ }, {\"key\": \"package_name\", \"value\": \"libgd2\"}]}, {\"name\": \"CVE-2021-3618\"\
+ , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-3618\", \"severity\"\
+ : \"UNDEFINED\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"1.21.1-1~buster\"\
+ }, {\"key\": \"package_name\", \"value\": \"nginx\"}]}], \"findingSeverityCounts\"\
+ : {\"HIGH\": 2, \"MEDIUM\": 14, \"INFORMATIONAL\": 63, \"LOW\": 22, \"UNDEFINED\"\
+ : 3}}}, \"requestID\": \"23c19e2d-c48b-4265-b4eb-853e7b325780\", \"eventID\": \"\
+ 6c94a9b2-36dc-43f8-a6dd-4ec839ded8af\", \"readOnly\": true, \"eventType\": \"AwsApiCall\"\
+ , \"managementEvent\": true, \"recipientAccountId\": \"111111111111\", \"eventCategory\"\
+ : \"Management\"}"
diff --git a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml
index d4abfd2473..56fa1914b9 100644
--- a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml
+++ b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml
@@ -1,95 +1,96 @@
name: AWS CloudTrail GetAccountPasswordPolicy
id: 439bdc53-6e4b-4cd7-b326-86c7317fd396
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when a request is made to get the account password policy in AWS CloudTrail.
+description: Logs an event when a request is made to get the account password policy
+ in AWS CloudTrail.
mitre_components:
-- User Account Authentication
-- User Account Metadata
+ - User Account Authentication
+ - User Account Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: GetAccountPasswordPolicy
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- desc
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters
-- responseElements
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- status
-- timeendpos
-- timestartpos
-- tlsDetails.cipherSuite
-- tlsDetails.clientProvidedHostHeader
-- tlsDetails.tlsVersion
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - desc
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters
+ - responseElements
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - status
+ - timeendpos
+ - timestartpos
+ - tlsDetails.cipherSuite
+ - tlsDetails.clientProvidedHostHeader
+ - tlsDetails.tlsVersion
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDASBMSCQHHTH5NDF4GD", "arn": "arn:aws:iam::111111111111:user/strt_fonder", "accountId":
"111111111111", "accessKeyId": "AKIASBMSCQHH5A5NJDM5", "userName": "strt_fonder"},
diff --git a/data_sources/aws_cloudtrail_getobject.yml b/data_sources/aws_cloudtrail_getobject.yml
index 3a3c9a6e10..d303eb012c 100644
--- a/data_sources/aws_cloudtrail_getobject.yml
+++ b/data_sources/aws_cloudtrail_getobject.yml
@@ -1,104 +1,105 @@
name: AWS CloudTrail GetObject
id: 5063cb10-84c0-44af-ade4-ab9ecad11dfe
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when a request is made to access an object stored in an AWS S3 bucket.
+description: Logs an event when a request is made to access an object stored in an
+ AWS S3 bucket.
mitre_components:
-- Cloud Storage Access
-- Cloud Storage Metadata
-- Cloud Storage Enumeration
+ - Cloud Storage Access
+ - Cloud Storage Metadata
+ - Cloud Storage Enumeration
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: GetObject
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- additionalEventData.AuthenticationMethod
-- additionalEventData.CipherSuite
-- additionalEventData.SignatureVersion
-- additionalEventData.bytesTransferredIn
-- additionalEventData.bytesTransferredOut
-- additionalEventData.x-amz-id-2
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.Host
-- requestParameters.bucketName
-- requestParameters.key
-- requestParameters.x-amz-request-payer
-- resources{}.ARN
-- resources{}.accountId
-- resources{}.type
-- responseElements
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- timeendpos
-- timestartpos
-- tlsDetails.cipherSuite
-- tlsDetails.clientProvidedHostHeader
-- tlsDetails.tlsVersion
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - additionalEventData.AuthenticationMethod
+ - additionalEventData.CipherSuite
+ - additionalEventData.SignatureVersion
+ - additionalEventData.bytesTransferredIn
+ - additionalEventData.bytesTransferredOut
+ - additionalEventData.x-amz-id-2
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.Host
+ - requestParameters.bucketName
+ - requestParameters.key
+ - requestParameters.x-amz-request-payer
+ - resources{}.ARN
+ - resources{}.accountId
+ - resources{}.type
+ - responseElements
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - timeendpos
+ - timestartpos
+ - tlsDetails.cipherSuite
+ - tlsDetails.clientProvidedHostHeader
+ - tlsDetails.tlsVersion
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/console", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName": "console"}, "eventTime":
diff --git a/data_sources/aws_cloudtrail_getpassworddata.yml b/data_sources/aws_cloudtrail_getpassworddata.yml
index 7b86ddd0fe..6644109837 100644
--- a/data_sources/aws_cloudtrail_getpassworddata.yml
+++ b/data_sources/aws_cloudtrail_getpassworddata.yml
@@ -1,105 +1,106 @@
name: AWS CloudTrail GetPasswordData
id: 6ff2ce99-85b1-4c17-888a-56dbc3570671
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when a request is made to retrieve the administrator password of an EC2 instance.
+description: Logs an event when a request is made to retrieve the administrator password
+ of an EC2 instance.
mitre_components:
-- Instance Metadata
-- User Account Authentication
+ - Instance Metadata
+ - User Account Authentication
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: GetPasswordData
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- errorMessage
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- reason
-- recipientAccountId
-- region
-- requestID
-- requestParameters.instanceId
-- responseElements
-- result
-- result_id
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- tlsDetails.cipherSuite
-- tlsDetails.clientProvidedHostHeader
-- tlsDetails.tlsVersion
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.sessionContext.sessionIssuer.accountId
-- userIdentity.sessionContext.sessionIssuer.arn
-- userIdentity.sessionContext.sessionIssuer.principalId
-- userIdentity.sessionContext.sessionIssuer.type
-- userIdentity.sessionContext.sessionIssuer.userName
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - errorMessage
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - reason
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.instanceId
+ - responseElements
+ - result
+ - result_id
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - tlsDetails.cipherSuite
+ - tlsDetails.clientProvidedHostHeader
+ - tlsDetails.tlsVersion
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.sessionContext.sessionIssuer.accountId
+ - userIdentity.sessionContext.sessionIssuer.arn
+ - userIdentity.sessionContext.sessionIssuer.principalId
+ - userIdentity.sessionContext.sessionIssuer.type
+ - userIdentity.sessionContext.sessionIssuer.userName
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLP5AASA6I5:aws-go-sdk-1660169051746043000", "arn": "arn:aws:sts::111111111111:assumed-role/sample-role-used-by-stratus-for-ec2-password-data/aws-go-sdk-1660169051746043000",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLLY5RQXEF", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_jobcreated.yml b/data_sources/aws_cloudtrail_jobcreated.yml
index fb86a52163..2278f224a5 100644
--- a/data_sources/aws_cloudtrail_jobcreated.yml
+++ b/data_sources/aws_cloudtrail_jobcreated.yml
@@ -1,81 +1,81 @@
name: AWS CloudTrail JobCreated
id: 6473289b-d097-4c86-a837-3cc5ae408155
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when a new job is created in AWS CloudTrail.
mitre_components:
-- Scheduled Job Creation
-- Cloud Service Metadata
+ - Scheduled Job Creation
+ - Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: JobCreated
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- desc
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestParameters
-- responseElements
-- serviceEventDetails.jobArn
-- serviceEventDetails.jobEventId
-- serviceEventDetails.jobId
-- serviceEventDetails.status
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- timeendpos
-- timestartpos
-- userAgent
-- userIdentity.accountId
-- userIdentity.invokedBy
-- user_agent
-- user_group_id
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - desc
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestParameters
+ - responseElements
+ - serviceEventDetails.jobArn
+ - serviceEventDetails.jobEventId
+ - serviceEventDetails.jobId
+ - serviceEventDetails.status
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - timeendpos
+ - timestartpos
+ - userAgent
+ - userIdentity.accountId
+ - userIdentity.invokedBy
+ - user_agent
+ - user_group_id
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"accountId": "111111111111",
"invokedBy": "s3.amazonaws.com"}, "eventTime": "2023-04-24T23:51:17Z", "eventSource":
"s3.amazonaws.com", "eventName": "JobCreated", "awsRegion": "us-west-2", "sourceIPAddress":
diff --git a/data_sources/aws_cloudtrail_modifydbinstance.yml b/data_sources/aws_cloudtrail_modifydbinstance.yml
index df5c25ffe5..99cb79f0b2 100644
--- a/data_sources/aws_cloudtrail_modifydbinstance.yml
+++ b/data_sources/aws_cloudtrail_modifydbinstance.yml
@@ -1,154 +1,155 @@
name: AWS CloudTrail ModifyDBInstance
id: bfa2912d-1a33-4b05-be46-543874d68241
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when a modification is made to an AWS database instance, such as parameters or configurations.
+description: Logs an event when a modification is made to an AWS database instance,
+ such as parameters or configurations.
mitre_components:
-- Instance Modification
-- Cloud Service Modification
-- Instance Metadata
+ - Instance Modification
+ - Cloud Service Modification
+ - Instance Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: ModifyDBInstance
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.allowMajorVersionUpgrade
-- requestParameters.applyImmediately
-- requestParameters.dBInstanceIdentifier
-- requestParameters.deletionProtection
-- requestParameters.masterUserPassword
-- responseElements.allocatedStorage
-- responseElements.autoMinorVersionUpgrade
-- responseElements.availabilityZone
-- responseElements.backupRetentionPeriod
-- responseElements.backupTarget
-- responseElements.cACertificateIdentifier
-- responseElements.copyTagsToSnapshot
-- responseElements.customerOwnedIpEnabled
-- responseElements.dBInstanceArn
-- responseElements.dBInstanceClass
-- responseElements.dBInstanceIdentifier
-- responseElements.dBInstanceStatus
-- responseElements.dBParameterGroups{}.dBParameterGroupName
-- responseElements.dBParameterGroups{}.parameterApplyStatus
-- responseElements.dBSubnetGroup.dBSubnetGroupDescription
-- responseElements.dBSubnetGroup.dBSubnetGroupName
-- responseElements.dBSubnetGroup.subnetGroupStatus
-- responseElements.dBSubnetGroup.subnets{}.subnetAvailabilityZone.name
-- responseElements.dBSubnetGroup.subnets{}.subnetIdentifier
-- responseElements.dBSubnetGroup.subnets{}.subnetStatus
-- responseElements.dBSubnetGroup.vpcId
-- responseElements.dbInstancePort
-- responseElements.dbiResourceId
-- responseElements.deletionProtection
-- responseElements.endpoint.address
-- responseElements.endpoint.hostedZoneId
-- responseElements.endpoint.port
-- responseElements.engine
-- responseElements.engineVersion
-- responseElements.enhancedMonitoringResourceArn
-- responseElements.httpEndpointEnabled
-- responseElements.iAMDatabaseAuthenticationEnabled
-- responseElements.instanceCreateTime
-- responseElements.kmsKeyId
-- responseElements.latestRestorableTime
-- responseElements.licenseModel
-- responseElements.masterUsername
-- responseElements.monitoringInterval
-- responseElements.monitoringRoleArn
-- responseElements.multiAZ
-- responseElements.networkType
-- responseElements.optionGroupMemberships{}.optionGroupName
-- responseElements.optionGroupMemberships{}.status
-- responseElements.pendingModifiedValues.masterUserPassword
-- responseElements.performanceInsightsEnabled
-- responseElements.performanceInsightsKMSKeyId
-- responseElements.performanceInsightsRetentionPeriod
-- responseElements.preferredBackupWindow
-- responseElements.preferredMaintenanceWindow
-- responseElements.publiclyAccessible
-- responseElements.storageEncrypted
-- responseElements.storageThroughput
-- responseElements.storageType
-- responseElements.vpcSecurityGroups{}.status
-- responseElements.vpcSecurityGroups{}.vpcSecurityGroupId
-- sessionCredentialFromConsole
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.sessionContext.sessionIssuer.accountId
-- userIdentity.sessionContext.sessionIssuer.arn
-- userIdentity.sessionContext.sessionIssuer.principalId
-- userIdentity.sessionContext.sessionIssuer.type
-- userIdentity.sessionContext.sessionIssuer.userName
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.allowMajorVersionUpgrade
+ - requestParameters.applyImmediately
+ - requestParameters.dBInstanceIdentifier
+ - requestParameters.deletionProtection
+ - requestParameters.masterUserPassword
+ - responseElements.allocatedStorage
+ - responseElements.autoMinorVersionUpgrade
+ - responseElements.availabilityZone
+ - responseElements.backupRetentionPeriod
+ - responseElements.backupTarget
+ - responseElements.cACertificateIdentifier
+ - responseElements.copyTagsToSnapshot
+ - responseElements.customerOwnedIpEnabled
+ - responseElements.dBInstanceArn
+ - responseElements.dBInstanceClass
+ - responseElements.dBInstanceIdentifier
+ - responseElements.dBInstanceStatus
+ - responseElements.dBParameterGroups{}.dBParameterGroupName
+ - responseElements.dBParameterGroups{}.parameterApplyStatus
+ - responseElements.dBSubnetGroup.dBSubnetGroupDescription
+ - responseElements.dBSubnetGroup.dBSubnetGroupName
+ - responseElements.dBSubnetGroup.subnetGroupStatus
+ - responseElements.dBSubnetGroup.subnets{}.subnetAvailabilityZone.name
+ - responseElements.dBSubnetGroup.subnets{}.subnetIdentifier
+ - responseElements.dBSubnetGroup.subnets{}.subnetStatus
+ - responseElements.dBSubnetGroup.vpcId
+ - responseElements.dbInstancePort
+ - responseElements.dbiResourceId
+ - responseElements.deletionProtection
+ - responseElements.endpoint.address
+ - responseElements.endpoint.hostedZoneId
+ - responseElements.endpoint.port
+ - responseElements.engine
+ - responseElements.engineVersion
+ - responseElements.enhancedMonitoringResourceArn
+ - responseElements.httpEndpointEnabled
+ - responseElements.iAMDatabaseAuthenticationEnabled
+ - responseElements.instanceCreateTime
+ - responseElements.kmsKeyId
+ - responseElements.latestRestorableTime
+ - responseElements.licenseModel
+ - responseElements.masterUsername
+ - responseElements.monitoringInterval
+ - responseElements.monitoringRoleArn
+ - responseElements.multiAZ
+ - responseElements.networkType
+ - responseElements.optionGroupMemberships{}.optionGroupName
+ - responseElements.optionGroupMemberships{}.status
+ - responseElements.pendingModifiedValues.masterUserPassword
+ - responseElements.performanceInsightsEnabled
+ - responseElements.performanceInsightsKMSKeyId
+ - responseElements.performanceInsightsRetentionPeriod
+ - responseElements.preferredBackupWindow
+ - responseElements.preferredMaintenanceWindow
+ - responseElements.publiclyAccessible
+ - responseElements.storageEncrypted
+ - responseElements.storageThroughput
+ - responseElements.storageType
+ - responseElements.vpcSecurityGroups{}.status
+ - responseElements.vpcSecurityGroups{}.vpcSecurityGroupId
+ - sessionCredentialFromConsole
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.sessionContext.sessionIssuer.accountId
+ - userIdentity.sessionContext.sessionIssuer.arn
+ - userIdentity.sessionContext.sessionIssuer.principalId
+ - userIdentity.sessionContext.sessionIssuer.type
+ - userIdentity.sessionContext.sessionIssuer.userName
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLDF6WP4HD6:gowthamarajr@splunk.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/gowthamarajr@splunk.com",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLAKJDBQGB", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_modifyimageattribute.yml b/data_sources/aws_cloudtrail_modifyimageattribute.yml
index 3d415b44b9..67fd0edb8a 100644
--- a/data_sources/aws_cloudtrail_modifyimageattribute.yml
+++ b/data_sources/aws_cloudtrail_modifyimageattribute.yml
@@ -1,99 +1,100 @@
name: AWS CloudTrail ModifyImageAttribute
id: 667c2115-8082-419e-b541-8150066bda4d
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when the attributes of an Amazon Machine Image (AMI) are modified.
+description: Logs an event when the attributes of an Amazon Machine Image (AMI) are
+ modified.
mitre_components:
-- Image Modification
-- Image Metadata
+ - Image Modification
+ - Image Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: ModifyImageAttribute
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.attributeType
-- requestParameters.imageId
-- requestParameters.launchPermission.add.items{}.userId
-- responseElements._return
-- responseElements.requestId
-- sessionCredentialFromConsole
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.sessionContext.sessionIssuer.accountId
-- userIdentity.sessionContext.sessionIssuer.arn
-- userIdentity.sessionContext.sessionIssuer.principalId
-- userIdentity.sessionContext.sessionIssuer.type
-- userIdentity.sessionContext.sessionIssuer.userName
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.attributeType
+ - requestParameters.imageId
+ - requestParameters.launchPermission.add.items{}.userId
+ - responseElements._return
+ - responseElements.requestId
+ - sessionCredentialFromConsole
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.sessionContext.sessionIssuer.accountId
+ - userIdentity.sessionContext.sessionIssuer.arn
+ - userIdentity.sessionContext.sessionIssuer.principalId
+ - userIdentity.sessionContext.sessionIssuer.type
+ - userIdentity.sessionContext.sessionIssuer.userName
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLDF6WP4HD6:bonobo@bo.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/bonobo@bo.com",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLBHIEEEPN", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml
index 211ccdf1dc..d44c5fa436 100644
--- a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml
+++ b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml
@@ -1,94 +1,95 @@
name: AWS CloudTrail ModifySnapshotAttribute
id: 7e5aa947-3a0d-4ee5-b800-0c10b555da05
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when modifications are made to the attributes of a snapshot in AWS CloudTrail.
+description: Logs an event when modifications are made to the attributes of a snapshot
+ in AWS CloudTrail.
mitre_components:
-- Snapshot Modification
+ - Snapshot Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: ModifySnapshotAttribute
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.attributeType
-- requestParameters.createVolumePermission.add.items{}.userId
-- requestParameters.snapshotId
-- responseElements._return
-- responseElements.requestId
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- timeendpos
-- timestartpos
-- tlsDetails.cipherSuite
-- tlsDetails.clientProvidedHostHeader
-- tlsDetails.tlsVersion
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.attributeType
+ - requestParameters.createVolumePermission.add.items{}.userId
+ - requestParameters.snapshotId
+ - responseElements._return
+ - responseElements.requestId
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - timeendpos
+ - timestartpos
+ - tlsDetails.cipherSuite
+ - tlsDetails.clientProvidedHostHeader
+ - tlsDetails.tlsVersion
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/bhavin_console",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName":
diff --git a/data_sources/aws_cloudtrail_putbucketacl.yml b/data_sources/aws_cloudtrail_putbucketacl.yml
index 24be91aea5..715cb571cb 100644
--- a/data_sources/aws_cloudtrail_putbucketacl.yml
+++ b/data_sources/aws_cloudtrail_putbucketacl.yml
@@ -1,108 +1,109 @@
name: AWS CloudTrail PutBucketAcl
id: 28fffbfd-d98d-4a42-990b-b04ab47422eb
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when an ACL is set or modified for an S3 bucket in AWS CloudTrail.
+description: Logs an event when an ACL is set or modified for an S3 bucket in AWS
+ CloudTrail.
mitre_components:
-- Cloud Storage Modification
-- Cloud Storage Metadata
+ - Cloud Storage Modification
+ - Cloud Storage Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: PutBucketAcl
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- additionalEventData.AuthenticationMethod
-- additionalEventData.CipherSuite
-- additionalEventData.SignatureVersion
-- additionalEventData.bytesTransferredIn
-- additionalEventData.bytesTransferredOut
-- additionalEventData.x-amz-id-2
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object
-- object_category
-- object_id
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.Host
-- requestParameters.accessControlList.x-amz-grant-write-acp
-- requestParameters.acl
-- requestParameters.bucketName
-- resources{}.ARN
-- resources{}.accountId
-- resources{}.type
-- responseElements
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- src_user
-- start_time
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - additionalEventData.AuthenticationMethod
+ - additionalEventData.CipherSuite
+ - additionalEventData.SignatureVersion
+ - additionalEventData.bytesTransferredIn
+ - additionalEventData.bytesTransferredOut
+ - additionalEventData.x-amz-id-2
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object
+ - object_category
+ - object_id
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.Host
+ - requestParameters.accessControlList.x-amz-grant-write-acp
+ - requestParameters.acl
+ - requestParameters.bucketName
+ - resources{}.ARN
+ - resources{}.accountId
+ - resources{}.type
+ - responseElements
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - src_user
+ - start_time
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLNALZHZ6KX", "arn": "arn:aws:iam::111111111111:user/patrick_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLJ2OYSF6E", "userName": "patrick_cli"},
diff --git a/data_sources/aws_cloudtrail_putbucketlifecycle.yml b/data_sources/aws_cloudtrail_putbucketlifecycle.yml
index a01d2b76d2..e5108f5812 100644
--- a/data_sources/aws_cloudtrail_putbucketlifecycle.yml
+++ b/data_sources/aws_cloudtrail_putbucketlifecycle.yml
@@ -1,109 +1,110 @@
name: AWS CloudTrail PutBucketLifecycle
id: 1c73e954-87b6-4bd7-ac6a-5db7c4082b22
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when a lifecycle configuration is added to an S3 bucket in AWS CloudTrail.
+description: Logs an event when a lifecycle configuration is added to an S3 bucket
+ in AWS CloudTrail.
mitre_components:
-- Cloud Storage Modification
-- Cloud Storage Metadata
+ - Cloud Storage Modification
+ - Cloud Storage Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: PutBucketLifecycle
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- additionalEventData.AuthenticationMethod
-- additionalEventData.CipherSuite
-- additionalEventData.SignatureVersion
-- additionalEventData.bytesTransferredIn
-- additionalEventData.bytesTransferredOut
-- additionalEventData.x-amz-id-2
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object
-- object_category
-- object_id
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.Host
-- requestParameters.LifecycleConfiguration.Rule.Expiration.Days
-- requestParameters.LifecycleConfiguration.Rule.Filter.Prefix
-- requestParameters.LifecycleConfiguration.Rule.ID
-- requestParameters.LifecycleConfiguration.Rule.Status
-- requestParameters.LifecycleConfiguration.xmlns
-- requestParameters.bucketName
-- requestParameters.lifecycle
-- resources{}.ARN
-- resources{}.accountId
-- resources{}.type
-- responseElements
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- timeendpos
-- timestartpos
-- tlsDetails.cipherSuite
-- tlsDetails.clientProvidedHostHeader
-- tlsDetails.tlsVersion
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - additionalEventData.AuthenticationMethod
+ - additionalEventData.CipherSuite
+ - additionalEventData.SignatureVersion
+ - additionalEventData.bytesTransferredIn
+ - additionalEventData.bytesTransferredOut
+ - additionalEventData.x-amz-id-2
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object
+ - object_category
+ - object_id
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.Host
+ - requestParameters.LifecycleConfiguration.Rule.Expiration.Days
+ - requestParameters.LifecycleConfiguration.Rule.Filter.Prefix
+ - requestParameters.LifecycleConfiguration.Rule.ID
+ - requestParameters.LifecycleConfiguration.Rule.Status
+ - requestParameters.LifecycleConfiguration.xmlns
+ - requestParameters.bucketName
+ - requestParameters.lifecycle
+ - resources{}.ARN
+ - resources{}.accountId
+ - resources{}.type
+ - responseElements
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - timeendpos
+ - timestartpos
+ - tlsDetails.cipherSuite
+ - tlsDetails.clientProvidedHostHeader
+ - tlsDetails.tlsVersion
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"},
diff --git a/data_sources/aws_cloudtrail_putbucketreplication.yml b/data_sources/aws_cloudtrail_putbucketreplication.yml
index b16eec7546..779545c3e7 100644
--- a/data_sources/aws_cloudtrail_putbucketreplication.yml
+++ b/data_sources/aws_cloudtrail_putbucketreplication.yml
@@ -1,121 +1,122 @@
name: AWS CloudTrail PutBucketReplication
id: 0e1362eb-e592-419f-8fa5-556d3a122417
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when replication configurations are added or modified for an S3 bucket.
+description: Logs an event when replication configurations are added or modified for
+ an S3 bucket.
mitre_components:
-- Cloud Storage Modification
+ - Cloud Storage Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: PutBucketReplication
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- additionalEventData.AuthenticationMethod
-- additionalEventData.CipherSuite
-- additionalEventData.SignatureVersion
-- additionalEventData.bytesTransferredIn
-- additionalEventData.bytesTransferredOut
-- additionalEventData.x-amz-id-2
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object
-- object_category
-- object_id
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.Host
-- requestParameters.ReplicationConfiguration.Role
-- requestParameters.ReplicationConfiguration.Rule.DeleteMarkerReplication.Status
-- requestParameters.ReplicationConfiguration.Rule.Destination.Bucket
-- requestParameters.ReplicationConfiguration.Rule.Filter
-- requestParameters.ReplicationConfiguration.Rule.ID
-- requestParameters.ReplicationConfiguration.Rule.Priority
-- requestParameters.ReplicationConfiguration.Rule.Status
-- requestParameters.ReplicationConfiguration.xmlns
-- requestParameters.bucketName
-- requestParameters.replication
-- resources{}.ARN
-- resources{}.accountId
-- resources{}.type
-- responseElements
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- tlsDetails.cipherSuite
-- tlsDetails.clientProvidedHostHeader
-- tlsDetails.tlsVersion
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.sessionContext.sessionIssuer.accountId
-- userIdentity.sessionContext.sessionIssuer.arn
-- userIdentity.sessionContext.sessionIssuer.principalId
-- userIdentity.sessionContext.sessionIssuer.type
-- userIdentity.sessionContext.sessionIssuer.userName
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
-- vpcEndpointId
+ - _time
+ - additionalEventData.AuthenticationMethod
+ - additionalEventData.CipherSuite
+ - additionalEventData.SignatureVersion
+ - additionalEventData.bytesTransferredIn
+ - additionalEventData.bytesTransferredOut
+ - additionalEventData.x-amz-id-2
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object
+ - object_category
+ - object_id
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.Host
+ - requestParameters.ReplicationConfiguration.Role
+ - requestParameters.ReplicationConfiguration.Rule.DeleteMarkerReplication.Status
+ - requestParameters.ReplicationConfiguration.Rule.Destination.Bucket
+ - requestParameters.ReplicationConfiguration.Rule.Filter
+ - requestParameters.ReplicationConfiguration.Rule.ID
+ - requestParameters.ReplicationConfiguration.Rule.Priority
+ - requestParameters.ReplicationConfiguration.Rule.Status
+ - requestParameters.ReplicationConfiguration.xmlns
+ - requestParameters.bucketName
+ - requestParameters.replication
+ - resources{}.ARN
+ - resources{}.accountId
+ - resources{}.type
+ - responseElements
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - tlsDetails.cipherSuite
+ - tlsDetails.clientProvidedHostHeader
+ - tlsDetails.tlsVersion
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.sessionContext.sessionIssuer.accountId
+ - userIdentity.sessionContext.sessionIssuer.arn
+ - userIdentity.sessionContext.sessionIssuer.principalId
+ - userIdentity.sessionContext.sessionIssuer.type
+ - userIdentity.sessionContext.sessionIssuer.userName
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
+ - vpcEndpointId
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLDF6WP4H11:bpatel@splunk.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/bpatel@splunk.com",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLJOVYQHW2", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_putbucketversioning.yml b/data_sources/aws_cloudtrail_putbucketversioning.yml
index 1fcc3c6668..1d727cc4d1 100644
--- a/data_sources/aws_cloudtrail_putbucketversioning.yml
+++ b/data_sources/aws_cloudtrail_putbucketversioning.yml
@@ -1,112 +1,113 @@
name: AWS CloudTrail PutBucketVersioning
id: 17b2fc7d-c8ce-487c-8815-f9a65a09e980
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when the bucket versioning state is modified in an AWS S3 bucket.
+description: Logs an event when the bucket versioning state is modified in an AWS
+ S3 bucket.
mitre_components:
-- Cloud Storage Modification
+ - Cloud Storage Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: PutBucketVersioning
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- additionalEventData.AuthenticationMethod
-- additionalEventData.CipherSuite
-- additionalEventData.SignatureVersion
-- additionalEventData.bytesTransferredIn
-- additionalEventData.bytesTransferredOut
-- additionalEventData.x-amz-id-2
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object
-- object_category
-- object_id
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.Host
-- requestParameters.VersioningConfiguration.Status
-- requestParameters.VersioningConfiguration.xmlns
-- requestParameters.bucketName
-- requestParameters.versioning
-- resources{}.ARN
-- resources{}.accountId
-- resources{}.type
-- responseElements
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- timeendpos
-- timestartpos
-- tlsDetails.cipherSuite
-- tlsDetails.clientProvidedHostHeader
-- tlsDetails.tlsVersion
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.sessionContext.sessionIssuer.accountId
-- userIdentity.sessionContext.sessionIssuer.arn
-- userIdentity.sessionContext.sessionIssuer.principalId
-- userIdentity.sessionContext.sessionIssuer.type
-- userIdentity.sessionContext.sessionIssuer.userName
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
-- vpcEndpointId
+ - _time
+ - additionalEventData.AuthenticationMethod
+ - additionalEventData.CipherSuite
+ - additionalEventData.SignatureVersion
+ - additionalEventData.bytesTransferredIn
+ - additionalEventData.bytesTransferredOut
+ - additionalEventData.x-amz-id-2
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object
+ - object_category
+ - object_id
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.Host
+ - requestParameters.VersioningConfiguration.Status
+ - requestParameters.VersioningConfiguration.xmlns
+ - requestParameters.bucketName
+ - requestParameters.versioning
+ - resources{}.ARN
+ - resources{}.accountId
+ - resources{}.type
+ - responseElements
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - timeendpos
+ - timestartpos
+ - tlsDetails.cipherSuite
+ - tlsDetails.clientProvidedHostHeader
+ - tlsDetails.tlsVersion
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.sessionContext.sessionIssuer.accountId
+ - userIdentity.sessionContext.sessionIssuer.arn
+ - userIdentity.sessionContext.sessionIssuer.principalId
+ - userIdentity.sessionContext.sessionIssuer.type
+ - userIdentity.sessionContext.sessionIssuer.userName
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
+ - vpcEndpointId
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLDF6WP4HD6:daftpunk@splunk.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/daftpunk@splunk.com",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLAQ5VXXXX", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_putimage.yml b/data_sources/aws_cloudtrail_putimage.yml
index 263b630172..713ed667e1 100644
--- a/data_sources/aws_cloudtrail_putimage.yml
+++ b/data_sources/aws_cloudtrail_putimage.yml
@@ -1,102 +1,103 @@
name: AWS CloudTrail PutImage
id: bb13f10d-0d8c-4fde-9136-b7cfd930e87c
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when a container image is uploaded to a repository in AWS CloudTrail.
+description: Logs an event when a container image is uploaded to a repository in AWS
+ CloudTrail.
mitre_components:
-- Image Creation
-- Image Metadata
+ - Image Creation
+ - Image Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: PutImage
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.imageManifest
-- requestParameters.imageManifestMediaType
-- requestParameters.imageTag
-- requestParameters.registryId
-- requestParameters.repositoryName
-- resources{}.ARN
-- resources{}.accountId
-- responseElements.image.imageId.imageDigest
-- responseElements.image.imageId.imageTag
-- responseElements.image.imageManifest
-- responseElements.image.imageManifestMediaType
-- responseElements.image.registryId
-- responseElements.image.repositoryName
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.invokedBy
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.imageManifest
+ - requestParameters.imageManifestMediaType
+ - requestParameters.imageTag
+ - requestParameters.registryId
+ - requestParameters.repositoryName
+ - resources{}.ARN
+ - resources{}.accountId
+ - responseElements.image.imageId.imageDigest
+ - responseElements.image.imageId.imageTag
+ - responseElements.image.imageManifest
+ - responseElements.image.imageManifestMediaType
+ - responseElements.image.registryId
+ - responseElements.image.repositoryName
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.invokedBy
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AAAAAAAAAAAAAAAAAAAAA", "arn": "arn:aws:iam::111111111111:user/test", "accountId":
"111111111111", "accessKeyId": "AAAAAAAAAAAAAAAAAAAAA", "userName": "test", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_putkeypolicy.yml b/data_sources/aws_cloudtrail_putkeypolicy.yml
index edac5877b5..d291365312 100644
--- a/data_sources/aws_cloudtrail_putkeypolicy.yml
+++ b/data_sources/aws_cloudtrail_putkeypolicy.yml
@@ -1,101 +1,102 @@
name: AWS CloudTrail PutKeyPolicy
id: 9c54c86b-43b9-4bb8-915d-6838beb7f07c
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs changes made to AWS Key Management Service (KMS) key policies, including updates and permission assignments.
+description: Logs changes made to AWS Key Management Service (KMS) key policies, including
+ updates and permission assignments.
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.bypassPolicyLockoutSafetyCheck
-- requestParameters.keyId
-- requestParameters.policy
-- requestParameters.policyName
-- resources{}.ARN
-- resources{}.accountId
-- resources{}.type
-- responseElements
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.sessionContext.sessionIssuer.accountId
-- userIdentity.sessionContext.sessionIssuer.arn
-- userIdentity.sessionContext.sessionIssuer.principalId
-- userIdentity.sessionContext.sessionIssuer.type
-- userIdentity.sessionContext.sessionIssuer.userName
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.bypassPolicyLockoutSafetyCheck
+ - requestParameters.keyId
+ - requestParameters.policy
+ - requestParameters.policyName
+ - resources{}.ARN
+ - resources{}.accountId
+ - resources{}.type
+ - responseElements
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.sessionContext.sessionIssuer.accountId
+ - userIdentity.sessionContext.sessionIssuer.arn
+ - userIdentity.sessionContext.sessionIssuer.principalId
+ - userIdentity.sessionContext.sessionIssuer.type
+ - userIdentity.sessionContext.sessionIssuer.userName
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
mitre_components:
-- Cloud Service Modification
+ - Cloud Service Modification
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLK74OPBDR", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml
index af51b981b1..4e7c3f9359 100644
--- a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml
+++ b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml
@@ -1,110 +1,110 @@
name: AWS CloudTrail ReplaceNetworkAclEntry
id: db0c240e-3754-40e4-86ef-cde018ee9f65
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when a network ACL entry is replaced within the AWS CloudTrail.
mitre_components:
-- Firewall Rule Modification
-- Cloud Service Modification
+ - Firewall Rule Modification
+ - Cloud Service Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: ReplaceNetworkAclEntry
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- direction
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- protocol
-- protocol_code
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.aclProtocol
-- requestParameters.cidrBlock
-- requestParameters.egress
-- requestParameters.networkAclId
-- requestParameters.ruleAction
-- requestParameters.ruleNumber
-- responseElements._return
-- responseElements.requestId
-- rule_action
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- src_ip_range
-- start_time
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.sessionContext.sessionIssuer.accountId
-- userIdentity.sessionContext.sessionIssuer.arn
-- userIdentity.sessionContext.sessionIssuer.principalId
-- userIdentity.sessionContext.sessionIssuer.type
-- userIdentity.sessionContext.sessionIssuer.userName
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - direction
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - protocol
+ - protocol_code
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.aclProtocol
+ - requestParameters.cidrBlock
+ - requestParameters.egress
+ - requestParameters.networkAclId
+ - requestParameters.ruleAction
+ - requestParameters.ruleNumber
+ - responseElements._return
+ - responseElements.requestId
+ - rule_action
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - src_ip_range
+ - start_time
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.sessionContext.sessionIssuer.accountId
+ - userIdentity.sessionContext.sessionIssuer.arn
+ - userIdentity.sessionContext.sessionIssuer.principalId
+ - userIdentity.sessionContext.sessionIssuer.type
+ - userIdentity.sessionContext.sessionIssuer.userName
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml
index df1e0b4657..d5c2a78694 100644
--- a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml
+++ b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml
@@ -1,95 +1,96 @@
name: AWS CloudTrail SetDefaultPolicyVersion
id: 06e0b5a0-8d36-485e-befc-4ae79d77ef6c
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when the default version of a resource policy in AWS is set or changed.
+description: Logs an event when the default version of a resource policy in AWS is
+ set or changed.
mitre_components:
-- Cloud Service Modification
-- Cloud Service Metadata
+ - Cloud Service Modification
+ - Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: SetDefaultPolicyVersion
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.policyArn
-- requestParameters.versionId
-- responseElements
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.policyArn
+ - requestParameters.versionId
+ - responseElements
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLESDK2NOSX", "arn": "arn:aws:iam::111111111111:user/AtomicRedTeam",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLKMZDMPVA", "userName":
diff --git a/data_sources/aws_cloudtrail_stoplogging.yml b/data_sources/aws_cloudtrail_stoplogging.yml
index 69859da19d..934920e8fb 100644
--- a/data_sources/aws_cloudtrail_stoplogging.yml
+++ b/data_sources/aws_cloudtrail_stoplogging.yml
@@ -1,90 +1,91 @@
name: AWS CloudTrail StopLogging
id: c5de7c54-4809-4659-bf9f-3bacf8bdfd35
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when a cloud service in AWS, such as CloudTrail, is deactivated or stopped.
+description: Logs an event when a cloud service in AWS, such as CloudTrail, is deactivated
+ or stopped.
mitre_components:
-- Cloud Service Disable
+ - Cloud Service Disable
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: StopLogging
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.name
-- responseElements
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- timeendpos
-- timestartpos
-- tlsDetails.cipherSuite
-- tlsDetails.clientProvidedHostHeader
-- tlsDetails.tlsVersion
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.name
+ - responseElements
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - timeendpos
+ - timestartpos
+ - tlsDetails.cipherSuite
+ - tlsDetails.clientProvidedHostHeader
+ - tlsDetails.tlsVersion
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"},
diff --git a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml
index 3959397892..6fd33c83e7 100644
--- a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml
+++ b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml
@@ -1,102 +1,102 @@
name: AWS CloudTrail UpdateAccountPasswordPolicy
id: 35a8cc97-3600-40e1-a5d1-1c2ad5060be0
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when an AWS account's password policy is updated.
mitre_components:
-- User Account Modification
-- Cloud Service Modification
+ - User Account Modification
+ - Cloud Service Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: UpdateAccountPasswordPolicy
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.allowUsersToChangePassword
-- requestParameters.hardExpiry
-- requestParameters.minimumPasswordLength
-- requestParameters.requireLowercaseCharacters
-- requestParameters.requireNumbers
-- requestParameters.requireSymbols
-- requestParameters.requireUppercaseCharacters
-- responseElements
-- sessionCredentialFromConsole
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.allowUsersToChangePassword
+ - requestParameters.hardExpiry
+ - requestParameters.minimumPasswordLength
+ - requestParameters.requireLowercaseCharacters
+ - requestParameters.requireNumbers
+ - requestParameters.requireSymbols
+ - requestParameters.requireUppercaseCharacters
+ - responseElements
+ - sessionCredentialFromConsole
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
"111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111",
"accessKeyId": "ASIASBMSCQHHZZ4THONS", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
diff --git a/data_sources/aws_cloudtrail_updateloginprofile.yml b/data_sources/aws_cloudtrail_updateloginprofile.yml
index e8d28c061a..911021b6d6 100644
--- a/data_sources/aws_cloudtrail_updateloginprofile.yml
+++ b/data_sources/aws_cloudtrail_updateloginprofile.yml
@@ -1,94 +1,94 @@
name: AWS CloudTrail UpdateLoginProfile
id: 1db79158-e5d3-4d35-9d3c-586e44e09f1c
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when an IAM user's login profile is updated.
mitre_components:
-- User Account Modification
-- User Account Authentication
+ - User Account Modification
+ - User Account Authentication
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: UpdateLoginProfile
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.userName
-- responseElements
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - action
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.userName
+ - responseElements
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
diff --git a/data_sources/aws_cloudtrail_updatesamlprovider.yml b/data_sources/aws_cloudtrail_updatesamlprovider.yml
index 9477d6a455..3c7f55c5ea 100644
--- a/data_sources/aws_cloudtrail_updatesamlprovider.yml
+++ b/data_sources/aws_cloudtrail_updatesamlprovider.yml
@@ -1,192 +1,211 @@
name: AWS CloudTrail UpdateSAMLProvider
id: e5eb628d-711e-499c-87d9-8fa5dee419ec
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when a SAML provider is updated in AWS.
mitre_components:
-- Cloud Service Modification
-- User Account Modification
-- Cloud Service Metadata
+ - Cloud Service Modification
+ - User Account Modification
+ - Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: UpdateSAMLProvider
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- action
-- app
-- awsRegion
-- aws_account_id
-- change_type
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- eventtype
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.sAMLMetadataDocument
-- requestParameters.sAMLProviderArn
-- responseElements.sAMLProviderArn
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.sessionContext.attributes.creationDate
-- userIdentity.sessionContext.attributes.mfaAuthenticated
-- userIdentity.sessionContext.sessionIssuer.accountId
-- userIdentity.sessionContext.sessionIssuer.arn
-- userIdentity.sessionContext.sessionIssuer.principalId
-- userIdentity.sessionContext.sessionIssuer.type
-- userIdentity.sessionContext.sessionIssuer.userName
-- userIdentity.type
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
-example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
- "AROAYTOGP2RLKFUVAQAIJ:rodsoto@rodsoto.onmicrosoft.com", "arn": "arn:aws:sts::111111111111:assumed-role/rodonmicrotestrole/rodsoto@rodsoto.onmicrosoft.com",
- "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLMZGPIW6C", "sessionContext":
- {"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLKFUVAQAIJ", "arn":
- "arn:aws:iam::111111111111:role/rodonmicrotestrole", "accountId": "111111111111",
- "userName": "rodonmicrotestrole"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated":
- "false", "creationDate": "2021-01-20T03:10:32Z"}}}, "eventTime": "2021-01-20T03:12:39Z",
- "eventSource": "iam.amazonaws.com", "eventName": "UpdateSAMLProvider", "awsRegion":
- "us-east-1", "sourceIPAddress": "66.176.252.11", "userAgent": "aws-internal/3 aws-sdk-java/1.11.930
- Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.275-b01
- java/1.8.0_275 vendor/Oracle_Corporation", "requestParameters": {"sAMLMetadataDocument":
- "ncp+pf0e75KdoRTy1PQeu74OKXjcVNM+bnT7Ns6cwQI=J9PRCq201gGMzMtt4Ye+gsM7xOgrNvDg/usqIMvsyUy2r/MeTBz5FKCK+Okjwm49vyTWUoUioYGiwm/TD2Knv59g1zy+/OjZcmBJgDrCmksFJdkwG/fDlOZQNGuj2qh1CEKL5n6Ipy2z1dQ9XUmhhndtXNnjdZ0fJ9QWufWoxveSCLHcU7eUB9obwq96pbAp+6as0XreMNC/xPv5gDdHfKaIppsXtEwcZY7m1c25jDWqPUTQrtbVC0uryffg1Yu0JLTr646GMTzxulBSpQGRfNf5UT0bUiLtKngi++UHrngKdv3ovWwpVmY82JhG7rMDhkuWZu3LdEFvY3svNxGtsQ==MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KNNameThe
+ - _time
+ - action
+ - app
+ - awsRegion
+ - aws_account_id
+ - change_type
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - eventtype
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.sAMLMetadataDocument
+ - requestParameters.sAMLProviderArn
+ - responseElements.sAMLProviderArn
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.sessionContext.attributes.creationDate
+ - userIdentity.sessionContext.attributes.mfaAuthenticated
+ - userIdentity.sessionContext.sessionIssuer.accountId
+ - userIdentity.sessionContext.sessionIssuer.arn
+ - userIdentity.sessionContext.sessionIssuer.principalId
+ - userIdentity.sessionContext.sessionIssuer.type
+ - userIdentity.sessionContext.sessionIssuer.userName
+ - userIdentity.type
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
+example_log: "{\"eventVersion\": \"1.08\", \"userIdentity\": {\"type\": \"AssumedRole\"\
+ , \"principalId\": \"AROAYTOGP2RLKFUVAQAIJ:rodsoto@rodsoto.onmicrosoft.com\", \"\
+ arn\": \"arn:aws:sts::111111111111:assumed-role/rodonmicrotestrole/rodsoto@rodsoto.onmicrosoft.com\"\
+ , \"accountId\": \"111111111111\", \"accessKeyId\": \"ASIAYTOGP2RLMZGPIW6C\", \"\
+ sessionContext\": {\"sessionIssuer\": {\"type\": \"Role\", \"principalId\": \"AROAYTOGP2RLKFUVAQAIJ\"\
+ , \"arn\": \"arn:aws:iam::111111111111:role/rodonmicrotestrole\", \"accountId\"
+ : \"111111111111\", \"userName\": \"rodonmicrotestrole\"}, \"webIdFederationData\"\
+ : {}, \"attributes\": {\"mfaAuthenticated\": \"false\", \"creationDate\": \"2021-01-20T03:10:32Z\"\
+ }}}, \"eventTime\": \"2021-01-20T03:12:39Z\", \"eventSource\": \"iam.amazonaws.com\"\
+ , \"eventName\": \"UpdateSAMLProvider\", \"awsRegion\": \"us-east-1\", \"sourceIPAddress\"\
+ : \"66.176.252.11\", \"userAgent\": \"aws-internal/3 aws-sdk-java/1.11.930 Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64
+ OpenJDK_64-Bit_Server_VM/25.275-b01 java/1.8.0_275 vendor/Oracle_Corporation\",
+ \"requestParameters\": {\"sAMLMetadataDocument\": \"ncp+pf0e75KdoRTy1PQeu74OKXjcVNM+bnT7Ns6cwQI=J9PRCq201gGMzMtt4Ye+gsM7xOgrNvDg/usqIMvsyUy2r/MeTBz5FKCK+Okjwm49vyTWUoUioYGiwm/TD2Knv59g1zy+/OjZcmBJgDrCmksFJdkwG/fDlOZQNGuj2qh1CEKL5n6Ipy2z1dQ9XUmhhndtXNnjdZ0fJ9QWufWoxveSCLHcU7eUB9obwq96pbAp+6as0XreMNC/xPv5gDdHfKaIppsXtEwcZY7m1c25jDWqPUTQrtbVC0uryffg1Yu0JLTr646GMTzxulBSpQGRfNf5UT0bUiLtKngi++UHrngKdv3ovWwpVmY82JhG7rMDhkuWZu3LdEFvY3svNxGtsQ==MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KNNameThe
mutable display name of the user.SubjectAn
+ Uri=\\\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier\\\"\
+ \ xmlns:auth=\\\"http://docs.oasis-open.org/wsfed/authorization/200706\\\">SubjectAn
immutable, globally unique, non-reusable identifier of the user that is unique to
the application for which a token is issued.Given
+ Uri=\\\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname\\\" xmlns:auth=\\\
+ \"http://docs.oasis-open.org/wsfed/authorization/200706\\\">Given
NameFirst name of the user.SurnameLast
- name of the user.Display
+ Uri=\\\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname\\\" xmlns:auth=\\\
+ \"http://docs.oasis-open.org/wsfed/authorization/200706\\\">SurnameLast
+ name of the user.Display
NameDisplay name of the user.Nick
+ Uri=\\\"http://schemas.microsoft.com/identity/claims/nickname\\\" xmlns:auth=\\\"\
+ http://docs.oasis-open.org/wsfed/authorization/200706\\\">Nick
NameNick name of the user.Authentication
+ Uri=\\\"http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant\\\
+ \" xmlns:auth=\\\"http://docs.oasis-open.org/wsfed/authorization/200706\\\">Authentication
InstantThe time (UTC) when the user is authenticated
to Windows Azure Active Directory.Authentication
+ Uri=\\\"http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod\\\
+ \" xmlns:auth=\\\"http://docs.oasis-open.org/wsfed/authorization/200706\\\">Authentication
MethodThe method that Windows Azure Active
Directory uses to authenticate users.ObjectIdentifierPrimary
+ Uri=\\\"http://schemas.microsoft.com/identity/claims/objectidentifier\\\" xmlns:auth=\\\
+ \"http://docs.oasis-open.org/wsfed/authorization/200706\\\">ObjectIdentifierPrimary
identifier for the user in the directory. Immutable, globally unique, non-reusable.TenantIdIdentifier
- for the user''s tenant.IdentityProviderIdentity
- provider for the user.EmailEmail
- address of the user.GroupsGroups
- of the user.External
+ Uri=\\\"http://schemas.microsoft.com/identity/claims/tenantid\\\" xmlns:auth=\\\"\
+ http://docs.oasis-open.org/wsfed/authorization/200706\\\">TenantIdIdentifier
+ for the user's tenant.IdentityProviderIdentity
+ provider for the user.EmailEmail
+ address of the user.GroupsGroups
+ of the user.External
Access TokenAccess token issued by external
- identity provider.External
+ identity provider.External
Access Token ExpirationUTC expiration time
of access token issued by external identity provider.External
+ Uri=\\\"http://schemas.microsoft.com/identity/claims/openid2_id\\\" xmlns:auth=\\\
+ \"http://docs.oasis-open.org/wsfed/authorization/200706\\\">External
OpenID 2.0 IdentifierOpenID 2.0 identifier
issued by external identity provider.GroupsOverageClaimIssued
- when number of user''s group claims exceeds return limit.Role
+ Uri=\\\"http://schemas.microsoft.com/claims/groups.link\\\" xmlns:auth=\\\"http://docs.oasis-open.org/wsfed/authorization/200706\\\
+ \">GroupsOverageClaimIssued
+ when number of user's group claims exceeds return limit.Role
ClaimRoles that the user or Service Principal
- is attached toRoleTemplate
+ is attached toRoleTemplate
Id ClaimRole template id of the Built-in Directory
Roles that the user is a member ofhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedMIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KNhttps://sts.windows.net/0e8108b1-18e9-41a4-961b-dfcddf92ef08/https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedMIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KN", "sAMLProviderArn": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"},
- "responseElements": {"sAMLProviderArn": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"},
- "requestID": "83d621ad-5b33-4ff0-acf4-0043cb432844", "eventID": "51b6d859-0cc4-4591-ba76-3494f3f43832",
- "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
- "Management", "recipientAccountId": "111111111111"}'
+ xmlns:wsa=\\\"http://www.w3.org/2005/08/addressing\\\">https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedMIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KNhttps://sts.windows.net/0e8108b1-18e9-41a4-961b-dfcddf92ef08/https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedMIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KN\", \"sAMLProviderArn\": \"arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft\"\
+ }, \"responseElements\": {\"sAMLProviderArn\": \"arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft\"\
+ }, \"requestID\": \"83d621ad-5b33-4ff0-acf4-0043cb432844\", \"eventID\": \"51b6d859-0cc4-4591-ba76-3494f3f43832\"\
+ , \"readOnly\": false, \"eventType\": \"AwsApiCall\", \"managementEvent\": true,
+ \"eventCategory\": \"Management\", \"recipientAccountId\": \"111111111111\"}"
diff --git a/data_sources/aws_cloudtrail_updatetrail.yml b/data_sources/aws_cloudtrail_updatetrail.yml
index edc2d3ff2a..6020310ebe 100644
--- a/data_sources/aws_cloudtrail_updatetrail.yml
+++ b/data_sources/aws_cloudtrail_updatetrail.yml
@@ -1,99 +1,100 @@
name: AWS CloudTrail UpdateTrail
id: d5b7a1eb-711a-4c96-aa93-235fe3c8a939
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when an AWS CloudTrail trail is updated, typically involving changes to settings or configuration.
+description: Logs an event when an AWS CloudTrail trail is updated, typically involving
+ changes to settings or configuration.
mitre_components:
-- Cloud Service Modification
-- Cloud Service Metadata
+ - Cloud Service Modification
+ - Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: UpdateTrail
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- app
-- awsRegion
-- aws_account_id
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- errorCode
-- eventCategory
-- eventID
-- eventName
-- eventSource
-- eventTime
-- eventType
-- eventVersion
-- host
-- index
-- linecount
-- managementEvent
-- msg
-- object_category
-- product
-- punct
-- readOnly
-- recipientAccountId
-- region
-- requestID
-- requestParameters.includeGlobalServiceEvents
-- requestParameters.isMultiRegionTrail
-- requestParameters.name
-- responseElements.includeGlobalServiceEvents
-- responseElements.isMultiRegionTrail
-- responseElements.isOrganizationTrail
-- responseElements.logFileValidationEnabled
-- responseElements.name
-- responseElements.s3BucketName
-- responseElements.trailARN
-- signature
-- source
-- sourceIPAddress
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- start_time
-- timeendpos
-- timestartpos
-- tlsDetails.cipherSuite
-- tlsDetails.clientProvidedHostHeader
-- tlsDetails.tlsVersion
-- user
-- userAgent
-- userIdentity.accessKeyId
-- userIdentity.accountId
-- userIdentity.arn
-- userIdentity.principalId
-- userIdentity.type
-- userIdentity.userName
-- userName
-- user_access_key
-- user_agent
-- user_arn
-- user_group_id
-- user_id
-- user_name
-- user_type
-- vendor
-- vendor_account
-- vendor_product
-- vendor_region
+ - _time
+ - app
+ - awsRegion
+ - aws_account_id
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - errorCode
+ - eventCategory
+ - eventID
+ - eventName
+ - eventSource
+ - eventTime
+ - eventType
+ - eventVersion
+ - host
+ - index
+ - linecount
+ - managementEvent
+ - msg
+ - object_category
+ - product
+ - punct
+ - readOnly
+ - recipientAccountId
+ - region
+ - requestID
+ - requestParameters.includeGlobalServiceEvents
+ - requestParameters.isMultiRegionTrail
+ - requestParameters.name
+ - responseElements.includeGlobalServiceEvents
+ - responseElements.isMultiRegionTrail
+ - responseElements.isOrganizationTrail
+ - responseElements.logFileValidationEnabled
+ - responseElements.name
+ - responseElements.s3BucketName
+ - responseElements.trailARN
+ - signature
+ - source
+ - sourceIPAddress
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - start_time
+ - timeendpos
+ - timestartpos
+ - tlsDetails.cipherSuite
+ - tlsDetails.clientProvidedHostHeader
+ - tlsDetails.tlsVersion
+ - user
+ - userAgent
+ - userIdentity.accessKeyId
+ - userIdentity.accountId
+ - userIdentity.arn
+ - userIdentity.principalId
+ - userIdentity.type
+ - userIdentity.userName
+ - userName
+ - user_access_key
+ - user_agent
+ - user_arn
+ - user_group_id
+ - user_id
+ - user_name
+ - user_type
+ - vendor
+ - vendor_account
+ - vendor_product
+ - vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
diff --git a/data_sources/aws_cloudwatchlogs_vpcflow.yml b/data_sources/aws_cloudwatchlogs_vpcflow.yml
index bec254d4fa..6cd8b1cec1 100644
--- a/data_sources/aws_cloudwatchlogs_vpcflow.yml
+++ b/data_sources/aws_cloudwatchlogs_vpcflow.yml
@@ -1,71 +1,73 @@
name: AWS CloudWatchLogs VPCflow
id: 38a34fc4-e128-4478-a8f4-7835d51d5135
-version: 1
+version: 2
author: Bhavin Patel, Splunk
-date: '2024-07-18'
-description: Logs an event when network traffic flow information such as source and destination IPs, ports, protocol, and action (allow/deny) is captured for VPC in AWS.
+date: '2025-01-23'
+description: Logs an event when network traffic flow information such as source and
+ destination IPs, ports, protocol, and action (allow/deny) is captured for VPC in
+ AWS.
mitre_components:
-- Network Traffic Flow
-- Network Connection Creation
+ - Network Traffic Flow
+ - Network Connection Creation
source: aws_cloudwatchlogs_vpcflow
sourcetype: aws:cloudwatchlogs:vpcflow
supported_TA:
-- name: Splunk Add-on for AWS
- version: 7.9.0
- url: https://splunkbase.splunk.com/app/1876
+ - name: Splunk Add-on for AWS
+ version: 7.9.0
+ url: https://splunkbase.splunk.com/app/1876
fields:
-- _raw
-- _time
-- account_id
-- action
-- app
-- aws_account_id
-- bytes
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_ip
-- dest_port
-- duration
-- dvc
-- end_time
-- eventtype
-- host
-- index
-- interface_id
-- linecount
-- log_status
-- packets
-- protocol
-- protocol_code
-- protocol_full_name
-- protocol_version
-- punct
-- region
-- source
-- sourcetype
-- splunk_server
-- splunk_server_group
-- src
-- src_ip
-- src_port
-- start_time
-- tag
-- tag::action
-- tag::eventtype
-- timeendpos
-- timestartpos
-- transport
-- user_id
-- vendor_account
-- vendor_product
-- version
-- vpcflow_action
+ - _raw
+ - _time
+ - account_id
+ - action
+ - app
+ - aws_account_id
+ - bytes
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_ip
+ - dest_port
+ - duration
+ - dvc
+ - end_time
+ - eventtype
+ - host
+ - index
+ - interface_id
+ - linecount
+ - log_status
+ - packets
+ - protocol
+ - protocol_code
+ - protocol_full_name
+ - protocol_version
+ - punct
+ - region
+ - source
+ - sourcetype
+ - splunk_server
+ - splunk_server_group
+ - src
+ - src_ip
+ - src_port
+ - start_time
+ - tag
+ - tag::action
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - transport
+ - user_id
+ - vendor_account
+ - vendor_product
+ - version
+ - vpcflow_action
example_log: 2 123397614277 eni-0b0f9f261f45e6489 10.0.1.30 10.0.1.1 47254 22 17 2
98 1697608042 1697608070 ACCEPT OK
diff --git a/data_sources/aws_security_hub.yml b/data_sources/aws_security_hub.yml
index 5d72ddeb75..0173357cdf 100644
--- a/data_sources/aws_security_hub.yml
+++ b/data_sources/aws_security_hub.yml
@@ -1,124 +1,125 @@
name: AWS Security Hub
id: b02bfbf3-294f-478e-99a1-e24b8c692d7e
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when AWS Security Hub identifies potential security risks or deviations from configured best practices across AWS accounts.
+description: Logs an event when AWS Security Hub identifies potential security risks
+ or deviations from configured best practices across AWS accounts.
mitre_components:
-- Cloud Service Metadata
-- Cloud Service Enumeration
-- Cloud Service Modification
-- Cloud Service Disable
+ - Cloud Service Metadata
+ - Cloud Service Enumeration
+ - Cloud Service Modification
+ - Cloud Service Disable
source: aws_securityhub_finding
sourcetype: aws:securityhub:finding
supported_TA:
-- name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+ - name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
-- _time
-- AwsAccountId
-- CreatedAt
-- Description
-- FirstObservedAt
-- GeneratorId
-- Id
-- LastObservedAt
-- ProductArn
-- ProductFields.aws/guardduty/service/action/actionType
-- ProductFields.aws/guardduty/service/action/awsApiCallAction/affectedResources/AWS::S3::Bucket
-- ProductFields.aws/guardduty/service/action/awsApiCallAction/api
-- ProductFields.aws/guardduty/service/action/awsApiCallAction/callerType
-- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/city/cityName
-- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/country/countryName
-- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lat
-- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lon
-- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/ipAddressV4
-- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asn
-- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asnOrg
-- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/isp
-- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/org
-- ProductFields.aws/guardduty/service/action/awsApiCallAction/serviceName
-- ProductFields.aws/guardduty/service/additionalInfo/sample
-- ProductFields.aws/guardduty/service/additionalInfo/unusual/hoursOfDay.0_
-- ProductFields.aws/guardduty/service/additionalInfo/unusual/userNames.0_
-- ProductFields.aws/guardduty/service/archived
-- ProductFields.aws/guardduty/service/count
-- ProductFields.aws/guardduty/service/detectorId
-- ProductFields.aws/guardduty/service/eventFirstSeen
-- ProductFields.aws/guardduty/service/eventLastSeen
-- ProductFields.aws/guardduty/service/resourceRole
-- ProductFields.aws/guardduty/service/serviceName
-- ProductFields.aws/securityhub/CompanyName
-- ProductFields.aws/securityhub/FindingId
-- ProductFields.aws/securityhub/ProductName
-- RecordState
-- Resources{}.Details.AwsEc2Instance.IamInstanceProfileArn
-- Resources{}.Details.AwsEc2Instance.ImageId
-- Resources{}.Details.AwsEc2Instance.IpV4Addresses{}
-- Resources{}.Details.AwsEc2Instance.LaunchedAt
-- Resources{}.Details.AwsEc2Instance.SubnetId
-- Resources{}.Details.AwsEc2Instance.Type
-- Resources{}.Details.AwsEc2Instance.VpcId
-- Resources{}.Details.AwsIamAccessKey.PrincipalId
-- Resources{}.Details.AwsIamAccessKey.PrincipalName
-- Resources{}.Details.AwsIamAccessKey.PrincipalType
-- Resources{}.Details.AwsS3Bucket.CreatedAt
-- Resources{}.Details.AwsS3Bucket.OwnerId
-- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.KMSMasterKeyID
-- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.SSEAlgorithm
-- Resources{}.Id
-- Resources{}.Partition
-- Resources{}.Region
-- Resources{}.Tags.GeneratedFindingInstaceTag1
-- Resources{}.Tags.GeneratedFindingInstaceTag2
-- Resources{}.Tags.GeneratedFindingInstaceTag3
-- Resources{}.Tags.GeneratedFindingInstaceTag4
-- Resources{}.Tags.GeneratedFindingInstaceTag5
-- Resources{}.Tags.GeneratedFindingInstaceTag6
-- Resources{}.Tags.GeneratedFindingInstaceTag7
-- Resources{}.Tags.GeneratedFindingInstaceTag8
-- Resources{}.Tags.GeneratedFindingInstaceTag9
-- Resources{}.Tags.foo
-- Resources{}.Type
-- SchemaVersion
-- Severity.Label
-- Severity.Normalized
-- Severity.Product
-- SourceUrl
-- Title
-- Types{}
-- UpdatedAt
-- Workflow.Status
-- WorkflowState
-- accesskey_extract
-- app
-- body
-- description
-- dest
-- dest_type
-- eventtype
-- host
-- id
-- index
-- instance_extract
-- linecount
-- punct
-- s3bucket_extract
-- severity
-- severity_id
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- subject
-- tag
-- tag::eventtype
-- timestamp
-- type
-- vendor_account
-- vendor_region
+ - _time
+ - AwsAccountId
+ - CreatedAt
+ - Description
+ - FirstObservedAt
+ - GeneratorId
+ - Id
+ - LastObservedAt
+ - ProductArn
+ - ProductFields.aws/guardduty/service/action/actionType
+ - ProductFields.aws/guardduty/service/action/awsApiCallAction/affectedResources/AWS::S3::Bucket
+ - ProductFields.aws/guardduty/service/action/awsApiCallAction/api
+ - ProductFields.aws/guardduty/service/action/awsApiCallAction/callerType
+ - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/city/cityName
+ - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/country/countryName
+ - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lat
+ - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lon
+ - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/ipAddressV4
+ - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asn
+ - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asnOrg
+ - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/isp
+ - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/org
+ - ProductFields.aws/guardduty/service/action/awsApiCallAction/serviceName
+ - ProductFields.aws/guardduty/service/additionalInfo/sample
+ - ProductFields.aws/guardduty/service/additionalInfo/unusual/hoursOfDay.0_
+ - ProductFields.aws/guardduty/service/additionalInfo/unusual/userNames.0_
+ - ProductFields.aws/guardduty/service/archived
+ - ProductFields.aws/guardduty/service/count
+ - ProductFields.aws/guardduty/service/detectorId
+ - ProductFields.aws/guardduty/service/eventFirstSeen
+ - ProductFields.aws/guardduty/service/eventLastSeen
+ - ProductFields.aws/guardduty/service/resourceRole
+ - ProductFields.aws/guardduty/service/serviceName
+ - ProductFields.aws/securityhub/CompanyName
+ - ProductFields.aws/securityhub/FindingId
+ - ProductFields.aws/securityhub/ProductName
+ - RecordState
+ - Resources{}.Details.AwsEc2Instance.IamInstanceProfileArn
+ - Resources{}.Details.AwsEc2Instance.ImageId
+ - Resources{}.Details.AwsEc2Instance.IpV4Addresses{}
+ - Resources{}.Details.AwsEc2Instance.LaunchedAt
+ - Resources{}.Details.AwsEc2Instance.SubnetId
+ - Resources{}.Details.AwsEc2Instance.Type
+ - Resources{}.Details.AwsEc2Instance.VpcId
+ - Resources{}.Details.AwsIamAccessKey.PrincipalId
+ - Resources{}.Details.AwsIamAccessKey.PrincipalName
+ - Resources{}.Details.AwsIamAccessKey.PrincipalType
+ - Resources{}.Details.AwsS3Bucket.CreatedAt
+ - Resources{}.Details.AwsS3Bucket.OwnerId
+ - Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.KMSMasterKeyID
+ - Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.SSEAlgorithm
+ - Resources{}.Id
+ - Resources{}.Partition
+ - Resources{}.Region
+ - Resources{}.Tags.GeneratedFindingInstaceTag1
+ - Resources{}.Tags.GeneratedFindingInstaceTag2
+ - Resources{}.Tags.GeneratedFindingInstaceTag3
+ - Resources{}.Tags.GeneratedFindingInstaceTag4
+ - Resources{}.Tags.GeneratedFindingInstaceTag5
+ - Resources{}.Tags.GeneratedFindingInstaceTag6
+ - Resources{}.Tags.GeneratedFindingInstaceTag7
+ - Resources{}.Tags.GeneratedFindingInstaceTag8
+ - Resources{}.Tags.GeneratedFindingInstaceTag9
+ - Resources{}.Tags.foo
+ - Resources{}.Type
+ - SchemaVersion
+ - Severity.Label
+ - Severity.Normalized
+ - Severity.Product
+ - SourceUrl
+ - Title
+ - Types{}
+ - UpdatedAt
+ - Workflow.Status
+ - WorkflowState
+ - accesskey_extract
+ - app
+ - body
+ - description
+ - dest
+ - dest_type
+ - eventtype
+ - host
+ - id
+ - index
+ - instance_extract
+ - linecount
+ - punct
+ - s3bucket_extract
+ - severity
+ - severity_id
+ - signature
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - subject
+ - tag
+ - tag::eventtype
+ - timestamp
+ - type
+ - vendor_account
+ - vendor_region
example_log: '{"ProductArn":"arn:aws:securityhub:us-east-1::product/aws/guardduty","Types":["Software
and Configuration Checks/Exfiltration:S3.ObjectRead.Unusual"],"SourceUrl":"https://us-east-1.console.aws.amazon.com/guardduty/home?region=us-east-1#/findings?macros=current&fId=6aba6b696aea10606e8b336f68d98819","Description":"Principal
GeneratedFindingUserName read objects from S3 bucket GeneratedFindingS3Bucket in
diff --git a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml
index 2afbd8e4ba..b0f85d0cb5 100644
--- a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml
+++ b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml
@@ -1,97 +1,99 @@
name: Azure Active Directory Add app role assignment to service principal
id: 8b2e84cd-6db0-47e9-badc-75c17df1995f
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the addition of an application role assignment to a service principal in Azure Active Directory, including details about the role, service principal, and the user or process performing the action.
+description: Logs the addition of an application role assignment to a service principal
+ in Azure Active Directory, including details about the role, service principal,
+ and the user or process performing the action.
mitre_components:
-- User Account Modification
-- Group Modification
-- Cloud Service Modification
-- Cloud Service Metadata
+ - User Account Modification
+ - Group Modification
+ - Cloud Service Modification
+ - Cloud Service Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Add app role assignment to service principal
supported_TA:
-- name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+ - name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
-- _time
-- Level
-- additional_details
-- additional_details_name
-- additional_details_value
-- category
-- command
-- correlationId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_type
-- durationMs
-- dvc
-- eventtype
-- host
-- id
-- identity
-- index
-- linecount
-- object_attrs
-- object_id
-- operationName
-- operationVersion
-- path_from_resourceId
-- properties.activityDateTime
-- properties.activityDisplayName
-- properties.additionalDetails{}.key
-- properties.additionalDetails{}.value
-- properties.category
-- properties.correlationId
-- properties.id
-- properties.initiatedBy.app.appId
-- properties.initiatedBy.app.displayName
-- properties.initiatedBy.app.servicePrincipalId
-- properties.initiatedBy.app.servicePrincipalName
-- properties.loggedByService
-- properties.operationType
-- properties.result
-- properties.resultReason
-- properties.targetResources{}.displayName
-- properties.targetResources{}.id
-- properties.targetResources{}.modifiedProperties{}.displayName
-- properties.targetResources{}.modifiedProperties{}.newValue
-- properties.targetResources{}.modifiedProperties{}.oldValue
-- properties.targetResources{}.type
-- properties.userAgent
-- punct
-- resourceId
-- result
-- resultSignature
-- result_id
-- signature
-- source
-- sourcetype
-- splunk_server
-- src_user_type
-- status
-- tag
-- tag::eventtype
-- tenantId
-- time
-- timeendpos
-- timestartpos
-- user_agent
-- user_type
-- vendor_account
-- vendor_product
+ - _time
+ - Level
+ - additional_details
+ - additional_details_name
+ - additional_details_value
+ - category
+ - command
+ - correlationId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_type
+ - durationMs
+ - dvc
+ - eventtype
+ - host
+ - id
+ - identity
+ - index
+ - linecount
+ - object_attrs
+ - object_id
+ - operationName
+ - operationVersion
+ - path_from_resourceId
+ - properties.activityDateTime
+ - properties.activityDisplayName
+ - properties.additionalDetails{}.key
+ - properties.additionalDetails{}.value
+ - properties.category
+ - properties.correlationId
+ - properties.id
+ - properties.initiatedBy.app.appId
+ - properties.initiatedBy.app.displayName
+ - properties.initiatedBy.app.servicePrincipalId
+ - properties.initiatedBy.app.servicePrincipalName
+ - properties.loggedByService
+ - properties.operationType
+ - properties.result
+ - properties.resultReason
+ - properties.targetResources{}.displayName
+ - properties.targetResources{}.id
+ - properties.targetResources{}.modifiedProperties{}.displayName
+ - properties.targetResources{}.modifiedProperties{}.newValue
+ - properties.targetResources{}.modifiedProperties{}.oldValue
+ - properties.targetResources{}.type
+ - properties.userAgent
+ - punct
+ - resourceId
+ - result
+ - resultSignature
+ - result_id
+ - signature
+ - source
+ - sourcetype
+ - splunk_server
+ - src_user_type
+ - status
+ - tag
+ - tag::eventtype
+ - tenantId
+ - time
+ - timeendpos
+ - timestartpos
+ - user_agent
+ - user_type
+ - vendor_account
+ - vendor_product
example_log: '{"time": "2024-02-08T21:49:53.7643129Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam",
"operationName": "Add app role assignment to service principal", "operationVersion":
"1.0", "category": "AuditLogs", "tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
diff --git a/data_sources/azure_active_directory_add_member_to_role.yml b/data_sources/azure_active_directory_add_member_to_role.yml
index c2dfa64ecb..8a977d8625 100644
--- a/data_sources/azure_active_directory_add_member_to_role.yml
+++ b/data_sources/azure_active_directory_add_member_to_role.yml
@@ -1,73 +1,75 @@
name: Azure Active Directory Add member to role
id: 1660d196-127f-4678-81b2-472d51711b07
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the addition of a member to a directory role in Azure Active Directory, including details about the role, the member added, and the user or process performing the action.
+description: Logs the addition of a member to a directory role in Azure Active Directory,
+ including details about the role, the member added, and the user or process performing
+ the action.
mitre_components:
-- Group Modification
-- Group Metadata
-- User Account Metadata
-- Cloud Service Modification
+ - Group Modification
+ - Group Metadata
+ - User Account Metadata
+ - Cloud Service Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Add member to role
supported_TA:
-- name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+ - name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
-- _time
-- Level
-- callerIpAddress
-- category
-- correlationId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- durationMs
-- host
-- index
-- linecount
-- operationName
-- operationVersion
-- properties.activityDateTime
-- properties.activityDisplayName
-- properties.category
-- properties.correlationId
-- properties.id
-- properties.initiatedBy.user.displayName
-- properties.initiatedBy.user.id
-- properties.initiatedBy.user.ipAddress
-- properties.initiatedBy.user.userPrincipalName
-- properties.loggedByService
-- properties.operationType
-- properties.result
-- properties.resultReason
-- properties.targetResources{}.displayName
-- properties.targetResources{}.id
-- properties.targetResources{}.modifiedProperties{}.displayName
-- properties.targetResources{}.modifiedProperties{}.newValue
-- properties.targetResources{}.modifiedProperties{}.oldValue
-- properties.targetResources{}.type
-- properties.targetResources{}.userPrincipalName
-- properties.userAgent
-- punct
-- resourceId
-- resultSignature
-- source
-- sourcetype
-- splunk_server
-- tenantId
-- time
-- timeendpos
-- timestartpos
+ - _time
+ - Level
+ - callerIpAddress
+ - category
+ - correlationId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - durationMs
+ - host
+ - index
+ - linecount
+ - operationName
+ - operationVersion
+ - properties.activityDateTime
+ - properties.activityDisplayName
+ - properties.category
+ - properties.correlationId
+ - properties.id
+ - properties.initiatedBy.user.displayName
+ - properties.initiatedBy.user.id
+ - properties.initiatedBy.user.ipAddress
+ - properties.initiatedBy.user.userPrincipalName
+ - properties.loggedByService
+ - properties.operationType
+ - properties.result
+ - properties.resultReason
+ - properties.targetResources{}.displayName
+ - properties.targetResources{}.id
+ - properties.targetResources{}.modifiedProperties{}.displayName
+ - properties.targetResources{}.modifiedProperties{}.newValue
+ - properties.targetResources{}.modifiedProperties{}.oldValue
+ - properties.targetResources{}.type
+ - properties.targetResources{}.userPrincipalName
+ - properties.userAgent
+ - punct
+ - resourceId
+ - resultSignature
+ - source
+ - sourcetype
+ - splunk_server
+ - tenantId
+ - time
+ - timeendpos
+ - timestartpos
example_log: '{"time": "2023-04-28T16:39:51.9312625Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Add member to role", "operationVersion": "1.0", "category": "AuditLogs",
"tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs":
diff --git a/data_sources/azure_active_directory_add_owner_to_application.yml b/data_sources/azure_active_directory_add_owner_to_application.yml
index f174ee00b6..70948b2b1f 100644
--- a/data_sources/azure_active_directory_add_owner_to_application.yml
+++ b/data_sources/azure_active_directory_add_owner_to_application.yml
@@ -1,78 +1,80 @@
name: Azure Active Directory Add owner to application
id: e895ed56-7be4-4b3a-b782-ecd0f594ec4c
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the addition of an owner to an application in Azure Active Directory, including details about the application, the owner added, and the user or process performing the action.
+description: Logs the addition of an owner to an application in Azure Active Directory,
+ including details about the application, the owner added, and the user or process
+ performing the action.
mitre_components:
-- User Account Modification
-- Group Modification
-- Cloud Service Modification
-- Cloud Service Metadata
+ - User Account Modification
+ - Group Modification
+ - Cloud Service Modification
+ - Cloud Service Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Add owner to application
supported_TA:
-- name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+ - name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
-- _time
-- Level
-- callerIpAddress
-- category
-- correlationId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- durationMs
-- eventtype
-- host
-- index
-- linecount
-- operationName
-- operationVersion
-- properties.activityDateTime
-- properties.activityDisplayName
-- properties.additionalDetails{}.key
-- properties.additionalDetails{}.value
-- properties.category
-- properties.correlationId
-- properties.id
-- properties.initiatedBy.user.displayName
-- properties.initiatedBy.user.id
-- properties.initiatedBy.user.ipAddress
-- properties.initiatedBy.user.userPrincipalName
-- properties.loggedByService
-- properties.operationType
-- properties.result
-- properties.resultReason
-- properties.targetResources{}.displayName
-- properties.targetResources{}.id
-- properties.targetResources{}.modifiedProperties{}.displayName
-- properties.targetResources{}.modifiedProperties{}.newValue
-- properties.targetResources{}.modifiedProperties{}.oldValue
-- properties.targetResources{}.type
-- properties.targetResources{}.userPrincipalName
-- properties.userAgent
-- punct
-- resourceId
-- resultSignature
-- source
-- sourcetype
-- splunk_server
-- tag
-- tag::eventtype
-- tenantId
-- time
-- timeendpos
-- timestartpos
+ - _time
+ - Level
+ - callerIpAddress
+ - category
+ - correlationId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - durationMs
+ - eventtype
+ - host
+ - index
+ - linecount
+ - operationName
+ - operationVersion
+ - properties.activityDateTime
+ - properties.activityDisplayName
+ - properties.additionalDetails{}.key
+ - properties.additionalDetails{}.value
+ - properties.category
+ - properties.correlationId
+ - properties.id
+ - properties.initiatedBy.user.displayName
+ - properties.initiatedBy.user.id
+ - properties.initiatedBy.user.ipAddress
+ - properties.initiatedBy.user.userPrincipalName
+ - properties.loggedByService
+ - properties.operationType
+ - properties.result
+ - properties.resultReason
+ - properties.targetResources{}.displayName
+ - properties.targetResources{}.id
+ - properties.targetResources{}.modifiedProperties{}.displayName
+ - properties.targetResources{}.modifiedProperties{}.newValue
+ - properties.targetResources{}.modifiedProperties{}.oldValue
+ - properties.targetResources{}.type
+ - properties.targetResources{}.userPrincipalName
+ - properties.userAgent
+ - punct
+ - resourceId
+ - resultSignature
+ - source
+ - sourcetype
+ - splunk_server
+ - tag
+ - tag::eventtype
+ - tenantId
+ - time
+ - timeendpos
+ - timestartpos
example_log: '{"time": "2023-06-20T15:54:13.2420879Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Add owner to application", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
diff --git a/data_sources/azure_active_directory_add_service_principal.yml b/data_sources/azure_active_directory_add_service_principal.yml
index d100855262..46f3c3d7d9 100644
--- a/data_sources/azure_active_directory_add_service_principal.yml
+++ b/data_sources/azure_active_directory_add_service_principal.yml
@@ -1,73 +1,75 @@
name: Azure Active Directory Add service principal
id: fd89d337-e4c0-4162-ad13-bca36f096fe6
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the creation of a new service principal in Azure Active Directory, including details about the service principal, associated application, and the user or process performing the action.
+description: Logs the creation of a new service principal in Azure Active Directory,
+ including details about the service principal, associated application, and the user
+ or process performing the action.
mitre_components:
-- Cloud Service Creation
-- Cloud Service Metadata
-- User Account Metadata
-- Active Directory Object Creation
+ - Cloud Service Creation
+ - Cloud Service Metadata
+ - User Account Metadata
+ - Active Directory Object Creation
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Add service principal
supported_TA:
-- name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+ - name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
-- _time
-- Level
-- category
-- correlationId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- durationMs
-- host
-- index
-- linecount
-- operationName
-- operationVersion
-- properties.activityDateTime
-- properties.activityDisplayName
-- properties.additionalDetails{}.key
-- properties.additionalDetails{}.value
-- properties.category
-- properties.correlationId
-- properties.id
-- properties.initiatedBy.user.displayName
-- properties.initiatedBy.user.id
-- properties.initiatedBy.user.ipAddress
-- properties.initiatedBy.user.userPrincipalName
-- properties.loggedByService
-- properties.operationType
-- properties.result
-- properties.resultReason
-- properties.targetResources{}.displayName
-- properties.targetResources{}.id
-- properties.targetResources{}.modifiedProperties{}.displayName
-- properties.targetResources{}.modifiedProperties{}.newValue
-- properties.targetResources{}.modifiedProperties{}.oldValue
-- properties.targetResources{}.type
-- properties.userAgent
-- punct
-- resourceId
-- resultSignature
-- source
-- sourcetype
-- splunk_server
-- tenantId
-- time
-- timeendpos
-- timestartpos
+ - _time
+ - Level
+ - category
+ - correlationId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - durationMs
+ - host
+ - index
+ - linecount
+ - operationName
+ - operationVersion
+ - properties.activityDateTime
+ - properties.activityDisplayName
+ - properties.additionalDetails{}.key
+ - properties.additionalDetails{}.value
+ - properties.category
+ - properties.correlationId
+ - properties.id
+ - properties.initiatedBy.user.displayName
+ - properties.initiatedBy.user.id
+ - properties.initiatedBy.user.ipAddress
+ - properties.initiatedBy.user.userPrincipalName
+ - properties.loggedByService
+ - properties.operationType
+ - properties.result
+ - properties.resultReason
+ - properties.targetResources{}.displayName
+ - properties.targetResources{}.id
+ - properties.targetResources{}.modifiedProperties{}.displayName
+ - properties.targetResources{}.modifiedProperties{}.newValue
+ - properties.targetResources{}.modifiedProperties{}.oldValue
+ - properties.targetResources{}.type
+ - properties.userAgent
+ - punct
+ - resourceId
+ - resultSignature
+ - source
+ - sourcetype
+ - splunk_server
+ - tenantId
+ - time
+ - timeendpos
+ - timestartpos
example_log: '{"time": "2024-02-07T22:31:14.4970418Z", "resourceId": "/tenants/a417c578-c7ee-480d-a225-d48057e74df5/providers/Microsoft.aadiam",
"operationName": "Add service principal", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "a417c578-c7ee-480d-a225-d48057e74df5", "resultSignature":
diff --git a/data_sources/azure_active_directory_add_unverified_domain.yml b/data_sources/azure_active_directory_add_unverified_domain.yml
index 1b06002e40..444d3e1a6f 100644
--- a/data_sources/azure_active_directory_add_unverified_domain.yml
+++ b/data_sources/azure_active_directory_add_unverified_domain.yml
@@ -1,73 +1,74 @@
name: Azure Active Directory Add unverified domain
id: d4c01fb1-3b88-46d3-bd12-9b9e256450f7
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the addition of an unverified domain to Azure Active Directory, including details about the domain name and the user or process performing the action.
+description: Logs the addition of an unverified domain to Azure Active Directory,
+ including details about the domain name and the user or process performing the action.
mitre_components:
-- Domain Registration
-- Cloud Service Modification
-- Cloud Service Metadata
-- Configuration Modification
+ - Domain Registration
+ - Cloud Service Modification
+ - Cloud Service Metadata
+ - Configuration Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Add unverified domain
supported_TA:
-- name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+ - name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
-- _time
-- Level
-- callerIpAddress
-- category
-- correlationId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- durationMs
-- host
-- index
-- linecount
-- operationName
-- operationVersion
-- properties.activityDateTime
-- properties.activityDisplayName
-- properties.additionalDetails{}.key
-- properties.additionalDetails{}.value
-- properties.category
-- properties.correlationId
-- properties.id
-- properties.initiatedBy.user.displayName
-- properties.initiatedBy.user.id
-- properties.initiatedBy.user.ipAddress
-- properties.initiatedBy.user.userPrincipalName
-- properties.loggedByService
-- properties.operationType
-- properties.result
-- properties.resultReason
-- properties.targetResources{}.displayName
-- properties.targetResources{}.id
-- properties.targetResources{}.modifiedProperties{}.displayName
-- properties.targetResources{}.modifiedProperties{}.newValue
-- properties.targetResources{}.modifiedProperties{}.oldValue
-- properties.userAgent
-- punct
-- resourceId
-- resultSignature
-- source
-- sourcetype
-- splunk_server
-- tenantId
-- time
-- timeendpos
-- timestartpos
+ - _time
+ - Level
+ - callerIpAddress
+ - category
+ - correlationId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - durationMs
+ - host
+ - index
+ - linecount
+ - operationName
+ - operationVersion
+ - properties.activityDateTime
+ - properties.activityDisplayName
+ - properties.additionalDetails{}.key
+ - properties.additionalDetails{}.value
+ - properties.category
+ - properties.correlationId
+ - properties.id
+ - properties.initiatedBy.user.displayName
+ - properties.initiatedBy.user.id
+ - properties.initiatedBy.user.ipAddress
+ - properties.initiatedBy.user.userPrincipalName
+ - properties.loggedByService
+ - properties.operationType
+ - properties.result
+ - properties.resultReason
+ - properties.targetResources{}.displayName
+ - properties.targetResources{}.id
+ - properties.targetResources{}.modifiedProperties{}.displayName
+ - properties.targetResources{}.modifiedProperties{}.newValue
+ - properties.targetResources{}.modifiedProperties{}.oldValue
+ - properties.userAgent
+ - punct
+ - resourceId
+ - resultSignature
+ - source
+ - sourcetype
+ - splunk_server
+ - tenantId
+ - time
+ - timeendpos
+ - timestartpos
example_log: '{"time": "2023-07-26T13:45:54.1582053Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Add unverified domain", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
diff --git a/data_sources/azure_active_directory_consent_to_application.yml b/data_sources/azure_active_directory_consent_to_application.yml
index cc0ee34156..4222ab6a7c 100644
--- a/data_sources/azure_active_directory_consent_to_application.yml
+++ b/data_sources/azure_active_directory_consent_to_application.yml
@@ -1,78 +1,80 @@
name: Azure Active Directory Consent to application
id: 4c5d6c49-53e3-4980-a4de-c63e26291ed0
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs user or admin consent to an application's permissions in Azure Active Directory, including details about the application, granted permissions, and the consenting user or process.
+description: Logs user or admin consent to an application's permissions in Azure Active
+ Directory, including details about the application, granted permissions, and the
+ consenting user or process.
mitre_components:
-- User Account Modification
-- Cloud Service Modification
-- Cloud Service Metadata
-- Configuration Modification
+ - User Account Modification
+ - Cloud Service Modification
+ - Cloud Service Metadata
+ - Configuration Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Consent to application
supported_TA:
-- name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+ - name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
-- _time
-- Level
-- callerIpAddress
-- category
-- correlationId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- durationMs
-- eventtype
-- host
-- index
-- linecount
-- operationName
-- operationVersion
-- properties.activityDateTime
-- properties.activityDisplayName
-- properties.additionalDetails{}.key
-- properties.additionalDetails{}.value
-- properties.category
-- properties.correlationId
-- properties.id
-- properties.initiatedBy.user.displayName
-- properties.initiatedBy.user.id
-- properties.initiatedBy.user.ipAddress
-- properties.initiatedBy.user.userPrincipalName
-- properties.loggedByService
-- properties.operationType
-- properties.result
-- properties.resultReason
-- properties.targetResources{}.displayName
-- properties.targetResources{}.id
-- properties.targetResources{}.modifiedProperties{}.displayName
-- properties.targetResources{}.modifiedProperties{}.newValue
-- properties.targetResources{}.modifiedProperties{}.oldValue
-- properties.targetResources{}.type
-- properties.userAgent
-- punct
-- resourceId
-- resultDescription
-- resultSignature
-- source
-- sourcetype
-- splunk_server
-- tag
-- tag::eventtype
-- tenantId
-- time
-- timeendpos
-- timestartpos
+ - _time
+ - Level
+ - callerIpAddress
+ - category
+ - correlationId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - durationMs
+ - eventtype
+ - host
+ - index
+ - linecount
+ - operationName
+ - operationVersion
+ - properties.activityDateTime
+ - properties.activityDisplayName
+ - properties.additionalDetails{}.key
+ - properties.additionalDetails{}.value
+ - properties.category
+ - properties.correlationId
+ - properties.id
+ - properties.initiatedBy.user.displayName
+ - properties.initiatedBy.user.id
+ - properties.initiatedBy.user.ipAddress
+ - properties.initiatedBy.user.userPrincipalName
+ - properties.loggedByService
+ - properties.operationType
+ - properties.result
+ - properties.resultReason
+ - properties.targetResources{}.displayName
+ - properties.targetResources{}.id
+ - properties.targetResources{}.modifiedProperties{}.displayName
+ - properties.targetResources{}.modifiedProperties{}.newValue
+ - properties.targetResources{}.modifiedProperties{}.oldValue
+ - properties.targetResources{}.type
+ - properties.userAgent
+ - punct
+ - resourceId
+ - resultDescription
+ - resultSignature
+ - source
+ - sourcetype
+ - splunk_server
+ - tag
+ - tag::eventtype
+ - tenantId
+ - time
+ - timeendpos
+ - timestartpos
example_log: '{"time": "2023-10-27T16:14:14.9747033Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam",
"operationName": "Consent to application", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "resultSignature":
diff --git a/data_sources/azure_active_directory_disable_strong_authentication.yml b/data_sources/azure_active_directory_disable_strong_authentication.yml
index c32bf6b639..6c329d8872 100644
--- a/data_sources/azure_active_directory_disable_strong_authentication.yml
+++ b/data_sources/azure_active_directory_disable_strong_authentication.yml
@@ -1,71 +1,72 @@
name: Azure Active Directory Disable Strong Authentication
id: 8f31966d-c496-496d-8837-f7fd11f31255
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when strong authentication methods are disabled in Azure Active Directory.
+description: Logs an event when strong authentication methods are disabled in Azure
+ Active Directory.
mitre_components:
-- User Account Authentication
-- User Account Modification
-- Cloud Service Modification
+ - User Account Authentication
+ - User Account Modification
+ - Cloud Service Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Disable Strong Authentication
supported_TA:
-- name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+ - name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
-- _time
-- Level
-- category
-- correlationId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- durationMs
-- host
-- index
-- linecount
-- operationName
-- operationVersion
-- properties.activityDateTime
-- properties.activityDisplayName
-- properties.category
-- properties.correlationId
-- properties.id
-- properties.initiatedBy.user.displayName
-- properties.initiatedBy.user.id
-- properties.initiatedBy.user.ipAddress
-- properties.initiatedBy.user.userPrincipalName
-- properties.loggedByService
-- properties.operationType
-- properties.result
-- properties.resultReason
-- properties.targetResources{}.displayName
-- properties.targetResources{}.id
-- properties.targetResources{}.modifiedProperties{}.displayName
-- properties.targetResources{}.modifiedProperties{}.newValue
-- properties.targetResources{}.modifiedProperties{}.oldValue
-- properties.targetResources{}.type
-- properties.targetResources{}.userPrincipalName
-- properties.userAgent
-- punct
-- resourceId
-- resultSignature
-- source
-- sourcetype
-- splunk_server
-- tenantId
-- time
-- timeendpos
-- timestartpos
+ - _time
+ - Level
+ - category
+ - correlationId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - durationMs
+ - host
+ - index
+ - linecount
+ - operationName
+ - operationVersion
+ - properties.activityDateTime
+ - properties.activityDisplayName
+ - properties.category
+ - properties.correlationId
+ - properties.id
+ - properties.initiatedBy.user.displayName
+ - properties.initiatedBy.user.id
+ - properties.initiatedBy.user.ipAddress
+ - properties.initiatedBy.user.userPrincipalName
+ - properties.loggedByService
+ - properties.operationType
+ - properties.result
+ - properties.resultReason
+ - properties.targetResources{}.displayName
+ - properties.targetResources{}.id
+ - properties.targetResources{}.modifiedProperties{}.displayName
+ - properties.targetResources{}.modifiedProperties{}.newValue
+ - properties.targetResources{}.modifiedProperties{}.oldValue
+ - properties.targetResources{}.type
+ - properties.targetResources{}.userPrincipalName
+ - properties.userAgent
+ - punct
+ - resourceId
+ - resultSignature
+ - source
+ - sourcetype
+ - splunk_server
+ - tenantId
+ - time
+ - timeendpos
+ - timestartpos
example_log: '{"time": "2023-07-11T00:01:35.0251899Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Disable Strong Authentication", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
diff --git a/data_sources/azure_active_directory_enable_account.yml b/data_sources/azure_active_directory_enable_account.yml
index d335c79ffc..2e3380277d 100644
--- a/data_sources/azure_active_directory_enable_account.yml
+++ b/data_sources/azure_active_directory_enable_account.yml
@@ -1,72 +1,72 @@
name: Azure Active Directory Enable account
id: cb49f3cd-04ad-415c-a5ed-9b27b2829fa7
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when an Azure Active Directory account is enabled.
mitre_components:
-- User Account Modification
-- User Account Authentication
-- User Account Metadata
+ - User Account Modification
+ - User Account Authentication
+ - User Account Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Enable account
supported_TA:
-- name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+ - name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
-- _time
-- Level
-- callerIpAddress
-- category
-- correlationId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- durationMs
-- host
-- index
-- linecount
-- operationName
-- operationVersion
-- properties.activityDateTime
-- properties.activityDisplayName
-- properties.category
-- properties.correlationId
-- properties.id
-- properties.initiatedBy.user.displayName
-- properties.initiatedBy.user.id
-- properties.initiatedBy.user.ipAddress
-- properties.initiatedBy.user.userPrincipalName
-- properties.loggedByService
-- properties.operationType
-- properties.result
-- properties.resultReason
-- properties.targetResources{}.displayName
-- properties.targetResources{}.id
-- properties.targetResources{}.modifiedProperties{}.displayName
-- properties.targetResources{}.modifiedProperties{}.newValue
-- properties.targetResources{}.modifiedProperties{}.oldValue
-- properties.targetResources{}.type
-- properties.targetResources{}.userPrincipalName
-- properties.userAgent
-- punct
-- resourceId
-- resultSignature
-- source
-- sourcetype
-- splunk_server
-- tenantId
-- time
-- timeendpos
-- timestartpos
+ - _time
+ - Level
+ - callerIpAddress
+ - category
+ - correlationId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - durationMs
+ - host
+ - index
+ - linecount
+ - operationName
+ - operationVersion
+ - properties.activityDateTime
+ - properties.activityDisplayName
+ - properties.category
+ - properties.correlationId
+ - properties.id
+ - properties.initiatedBy.user.displayName
+ - properties.initiatedBy.user.id
+ - properties.initiatedBy.user.ipAddress
+ - properties.initiatedBy.user.userPrincipalName
+ - properties.loggedByService
+ - properties.operationType
+ - properties.result
+ - properties.resultReason
+ - properties.targetResources{}.displayName
+ - properties.targetResources{}.id
+ - properties.targetResources{}.modifiedProperties{}.displayName
+ - properties.targetResources{}.modifiedProperties{}.newValue
+ - properties.targetResources{}.modifiedProperties{}.oldValue
+ - properties.targetResources{}.type
+ - properties.targetResources{}.userPrincipalName
+ - properties.userAgent
+ - punct
+ - resourceId
+ - resultSignature
+ - source
+ - sourcetype
+ - splunk_server
+ - tenantId
+ - time
+ - timeendpos
+ - timestartpos
example_log: '{"time": "2023-07-24T14:28:15.2223487Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Enable account", "operationVersion": "1.0", "category": "AuditLogs",
"tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs":
diff --git a/data_sources/azure_active_directory_invite_external_user.yml b/data_sources/azure_active_directory_invite_external_user.yml
index d7cb59bbba..08726897f3 100644
--- a/data_sources/azure_active_directory_invite_external_user.yml
+++ b/data_sources/azure_active_directory_invite_external_user.yml
@@ -1,71 +1,72 @@
name: Azure Active Directory Invite external user
id: d3818bd5-f283-4518-8b67-df19240c3e40
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when an external user is invited to join an Azure Active Directory tenant.
+description: Logs an event when an external user is invited to join an Azure Active
+ Directory tenant.
mitre_components:
-- Active Directory Object Creation
-- User Account Creation
-- User Account Authentication
+ - Active Directory Object Creation
+ - User Account Creation
+ - User Account Authentication
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Invite external user
supported_TA:
-- name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+ - name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
-- _time
-- Level
-- callerIpAddress
-- category
-- correlationId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- durationMs
-- host
-- index
-- linecount
-- operationName
-- operationVersion
-- properties.activityDateTime
-- properties.activityDisplayName
-- properties.additionalDetails{}.key
-- properties.additionalDetails{}.value
-- properties.category
-- properties.correlationId
-- properties.id
-- properties.initiatedBy.user.displayName
-- properties.initiatedBy.user.id
-- properties.initiatedBy.user.ipAddress
-- properties.initiatedBy.user.userPrincipalName
-- properties.loggedByService
-- properties.operationType
-- properties.result
-- properties.resultReason
-- properties.targetResources{}.displayName
-- properties.targetResources{}.id
-- properties.targetResources{}.type
-- properties.targetResources{}.userPrincipalName
-- properties.userAgent
-- punct
-- resourceId
-- resultSignature
-- source
-- sourcetype
-- splunk_server
-- tenantId
-- time
-- timeendpos
-- timestartpos
+ - _time
+ - Level
+ - callerIpAddress
+ - category
+ - correlationId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - durationMs
+ - host
+ - index
+ - linecount
+ - operationName
+ - operationVersion
+ - properties.activityDateTime
+ - properties.activityDisplayName
+ - properties.additionalDetails{}.key
+ - properties.additionalDetails{}.value
+ - properties.category
+ - properties.correlationId
+ - properties.id
+ - properties.initiatedBy.user.displayName
+ - properties.initiatedBy.user.id
+ - properties.initiatedBy.user.ipAddress
+ - properties.initiatedBy.user.userPrincipalName
+ - properties.loggedByService
+ - properties.operationType
+ - properties.result
+ - properties.resultReason
+ - properties.targetResources{}.displayName
+ - properties.targetResources{}.id
+ - properties.targetResources{}.type
+ - properties.targetResources{}.userPrincipalName
+ - properties.userAgent
+ - punct
+ - resourceId
+ - resultSignature
+ - source
+ - sourcetype
+ - splunk_server
+ - tenantId
+ - time
+ - timeendpos
+ - timestartpos
example_log: '{"time": "2023-07-13T00:29:59.5100003Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Invite external user", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
diff --git a/data_sources/azure_active_directory_reset_password_(by_admin).yml b/data_sources/azure_active_directory_reset_password_(by_admin).yml
index 9c4db01f1f..54208cb250 100644
--- a/data_sources/azure_active_directory_reset_password_(by_admin).yml
+++ b/data_sources/azure_active_directory_reset_password_(by_admin).yml
@@ -1,72 +1,73 @@
name: Azure Active Directory Reset password (by admin)
id: dcd0e4dc-68f8-4b77-a66f-89c57b3afa6b
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when an admin resets a user's password in Azure Active Directory.
+description: Logs an event when an admin resets a user's password in Azure Active
+ Directory.
mitre_components:
-- User Account Authentication
-- User Account Modification
-- Active Directory Object Modification
+ - User Account Authentication
+ - User Account Modification
+ - Active Directory Object Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Reset password (by admin)
supported_TA:
-- name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+ - name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
-- _time
-- Level
-- callerIpAddress
-- category
-- correlationId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- durationMs
-- host
-- index
-- linecount
-- operationName
-- operationVersion
-- properties.activityDateTime
-- properties.activityDisplayName
-- properties.additionalDetails{}.key
-- properties.additionalDetails{}.value
-- properties.category
-- properties.correlationId
-- properties.id
-- properties.initiatedBy.user.displayName
-- properties.initiatedBy.user.id
-- properties.initiatedBy.user.ipAddress
-- properties.initiatedBy.user.userPrincipalName
-- properties.loggedByService
-- properties.operationType
-- properties.result
-- properties.resultReason
-- properties.targetResources{}.displayName
-- properties.targetResources{}.id
-- properties.targetResources{}.type
-- properties.targetResources{}.userPrincipalName
-- properties.userAgent
-- punct
-- resourceId
-- resultDescription
-- resultSignature
-- source
-- sourcetype
-- splunk_server
-- tenantId
-- time
-- timeendpos
-- timestartpos
+ - _time
+ - Level
+ - callerIpAddress
+ - category
+ - correlationId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - durationMs
+ - host
+ - index
+ - linecount
+ - operationName
+ - operationVersion
+ - properties.activityDateTime
+ - properties.activityDisplayName
+ - properties.additionalDetails{}.key
+ - properties.additionalDetails{}.value
+ - properties.category
+ - properties.correlationId
+ - properties.id
+ - properties.initiatedBy.user.displayName
+ - properties.initiatedBy.user.id
+ - properties.initiatedBy.user.ipAddress
+ - properties.initiatedBy.user.userPrincipalName
+ - properties.loggedByService
+ - properties.operationType
+ - properties.result
+ - properties.resultReason
+ - properties.targetResources{}.displayName
+ - properties.targetResources{}.id
+ - properties.targetResources{}.type
+ - properties.targetResources{}.userPrincipalName
+ - properties.userAgent
+ - punct
+ - resourceId
+ - resultDescription
+ - resultSignature
+ - source
+ - sourcetype
+ - splunk_server
+ - tenantId
+ - time
+ - timeendpos
+ - timestartpos
example_log: '{"time": "2023-07-24T14:28:55.0648789Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Reset password (by admin)", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
diff --git a/data_sources/azure_active_directory_set_domain_authentication.yml b/data_sources/azure_active_directory_set_domain_authentication.yml
index c20d10043c..c29183d14e 100644
--- a/data_sources/azure_active_directory_set_domain_authentication.yml
+++ b/data_sources/azure_active_directory_set_domain_authentication.yml
@@ -1,72 +1,73 @@
name: Azure Active Directory Set domain authentication
id: e7bcdab9-908c-40ab-ba38-5db54fa87750
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when the authentication method for a domain in Azure Active Directory is set or modified.
+description: Logs an event when the authentication method for a domain in Azure Active
+ Directory is set or modified.
mitre_components:
-- Active Directory Object Modification
-- User Account Authentication
-- Cloud Service Modification
+ - Active Directory Object Modification
+ - User Account Authentication
+ - Cloud Service Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Set domain authentication
supported_TA:
-- name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+ - name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
-- _time
-- Level
-- callerIpAddress
-- category
-- correlationId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- durationMs
-- host
-- index
-- linecount
-- operationName
-- operationVersion
-- properties.activityDateTime
-- properties.activityDisplayName
-- properties.additionalDetails{}.key
-- properties.additionalDetails{}.value
-- properties.category
-- properties.correlationId
-- properties.id
-- properties.initiatedBy.user.displayName
-- properties.initiatedBy.user.id
-- properties.initiatedBy.user.ipAddress
-- properties.initiatedBy.user.userPrincipalName
-- properties.loggedByService
-- properties.operationType
-- properties.result
-- properties.resultReason
-- properties.targetResources{}.displayName
-- properties.targetResources{}.id
-- properties.targetResources{}.modifiedProperties{}.displayName
-- properties.targetResources{}.modifiedProperties{}.newValue
-- properties.targetResources{}.modifiedProperties{}.oldValue
-- properties.userAgent
-- punct
-- resourceId
-- resultSignature
-- source
-- sourcetype
-- splunk_server
-- tenantId
-- time
-- timeendpos
-- timestartpos
+ - _time
+ - Level
+ - callerIpAddress
+ - category
+ - correlationId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - durationMs
+ - host
+ - index
+ - linecount
+ - operationName
+ - operationVersion
+ - properties.activityDateTime
+ - properties.activityDisplayName
+ - properties.additionalDetails{}.key
+ - properties.additionalDetails{}.value
+ - properties.category
+ - properties.correlationId
+ - properties.id
+ - properties.initiatedBy.user.displayName
+ - properties.initiatedBy.user.id
+ - properties.initiatedBy.user.ipAddress
+ - properties.initiatedBy.user.userPrincipalName
+ - properties.loggedByService
+ - properties.operationType
+ - properties.result
+ - properties.resultReason
+ - properties.targetResources{}.displayName
+ - properties.targetResources{}.id
+ - properties.targetResources{}.modifiedProperties{}.displayName
+ - properties.targetResources{}.modifiedProperties{}.newValue
+ - properties.targetResources{}.modifiedProperties{}.oldValue
+ - properties.userAgent
+ - punct
+ - resourceId
+ - resultSignature
+ - source
+ - sourcetype
+ - splunk_server
+ - tenantId
+ - time
+ - timeendpos
+ - timestartpos
example_log: '{"time": "2023-07-26T13:44:59.0372448Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Set domain authentication", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
diff --git a/data_sources/azure_active_directory_sign_in_activity.yml b/data_sources/azure_active_directory_sign_in_activity.yml
index 3fca810c95..d5ed7fa94d 100644
--- a/data_sources/azure_active_directory_sign_in_activity.yml
+++ b/data_sources/azure_active_directory_sign_in_activity.yml
@@ -1,122 +1,123 @@
name: Azure Active Directory Sign-in activity
id: f9ed0a3a-9e20-4198-a035-d0a29593fbe0
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when a user attempts to sign into Azure Active Directory, capturing authentication details and outcomes.
+description: Logs an event when a user attempts to sign into Azure Active Directory,
+ capturing authentication details and outcomes.
mitre_components:
-- User Account Authentication
-- Logon Session Creation
-- User Account Metadata
+ - User Account Authentication
+ - Logon Session Creation
+ - User Account Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Sign-in activity
supported_TA:
-- name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+ - name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
-- _time
-- Level
-- callerIpAddress
-- category
-- correlationId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- durationMs
-- host
-- identity
-- index
-- linecount
-- location
-- operationName
-- operationVersion
-- properties.alternateSignInName
-- properties.appDisplayName
-- properties.appId
-- properties.appServicePrincipalId
-- properties.authenticationDetails{}.RequestSequence
-- properties.authenticationDetails{}.StatusSequence
-- properties.authenticationDetails{}.authenticationMethod
-- properties.authenticationDetails{}.authenticationMethodDetail
-- properties.authenticationDetails{}.authenticationStepDateTime
-- properties.authenticationDetails{}.authenticationStepRequirement
-- properties.authenticationDetails{}.authenticationStepResultDetail
-- properties.authenticationDetails{}.succeeded
-- properties.authenticationProcessingDetails{}.key
-- properties.authenticationProcessingDetails{}.value
-- properties.authenticationProtocol
-- properties.authenticationRequirement
-- properties.authenticationRequirementPolicies{}.detail
-- properties.authenticationRequirementPolicies{}.requirementProvider
-- properties.autonomousSystemNumber
-- properties.clientAppUsed
-- properties.clientCredentialType
-- properties.conditionalAccessStatus
-- properties.correlationId
-- properties.createdDateTime
-- properties.crossTenantAccessType
-- properties.deviceDetail.deviceId
-- properties.deviceDetail.operatingSystem
-- properties.flaggedForReview
-- properties.homeTenantId
-- properties.id
-- properties.incomingTokenType
-- properties.ipAddress
-- properties.isInteractive
-- properties.isTenantRestricted
-- properties.location.city
-- properties.location.countryOrRegion
-- properties.location.geoCoordinates.latitude
-- properties.location.geoCoordinates.longitude
-- properties.location.state
-- properties.originalRequestId
-- properties.originalTransferMethod
-- properties.processingTimeInMilliseconds
-- properties.resourceDisplayName
-- properties.resourceId
-- properties.resourceServicePrincipalId
-- properties.resourceTenantId
-- properties.riskDetail
-- properties.riskLevelAggregated
-- properties.riskLevelDuringSignIn
-- properties.riskState
-- properties.rngcStatus
-- properties.servicePrincipalId
-- properties.signInIdentifier
-- properties.signInTokenProtectionStatus
-- properties.ssoExtensionVersion
-- properties.status.additionalDetails
-- properties.status.errorCode
-- properties.status.failureReason
-- properties.tenantId
-- properties.tokenIssuerName
-- properties.tokenIssuerType
-- properties.uniqueTokenIdentifier
-- properties.userAgent
-- properties.userDisplayName
-- properties.userId
-- properties.userPrincipalName
-- properties.userType
-- punct
-- resourceId
-- resultDescription
-- resultSignature
-- resultType
-- source
-- sourcetype
-- splunk_server
-- tenantId
-- time
-- timeendpos
-- timestartpos
+ - _time
+ - Level
+ - callerIpAddress
+ - category
+ - correlationId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - durationMs
+ - host
+ - identity
+ - index
+ - linecount
+ - location
+ - operationName
+ - operationVersion
+ - properties.alternateSignInName
+ - properties.appDisplayName
+ - properties.appId
+ - properties.appServicePrincipalId
+ - properties.authenticationDetails{}.RequestSequence
+ - properties.authenticationDetails{}.StatusSequence
+ - properties.authenticationDetails{}.authenticationMethod
+ - properties.authenticationDetails{}.authenticationMethodDetail
+ - properties.authenticationDetails{}.authenticationStepDateTime
+ - properties.authenticationDetails{}.authenticationStepRequirement
+ - properties.authenticationDetails{}.authenticationStepResultDetail
+ - properties.authenticationDetails{}.succeeded
+ - properties.authenticationProcessingDetails{}.key
+ - properties.authenticationProcessingDetails{}.value
+ - properties.authenticationProtocol
+ - properties.authenticationRequirement
+ - properties.authenticationRequirementPolicies{}.detail
+ - properties.authenticationRequirementPolicies{}.requirementProvider
+ - properties.autonomousSystemNumber
+ - properties.clientAppUsed
+ - properties.clientCredentialType
+ - properties.conditionalAccessStatus
+ - properties.correlationId
+ - properties.createdDateTime
+ - properties.crossTenantAccessType
+ - properties.deviceDetail.deviceId
+ - properties.deviceDetail.operatingSystem
+ - properties.flaggedForReview
+ - properties.homeTenantId
+ - properties.id
+ - properties.incomingTokenType
+ - properties.ipAddress
+ - properties.isInteractive
+ - properties.isTenantRestricted
+ - properties.location.city
+ - properties.location.countryOrRegion
+ - properties.location.geoCoordinates.latitude
+ - properties.location.geoCoordinates.longitude
+ - properties.location.state
+ - properties.originalRequestId
+ - properties.originalTransferMethod
+ - properties.processingTimeInMilliseconds
+ - properties.resourceDisplayName
+ - properties.resourceId
+ - properties.resourceServicePrincipalId
+ - properties.resourceTenantId
+ - properties.riskDetail
+ - properties.riskLevelAggregated
+ - properties.riskLevelDuringSignIn
+ - properties.riskState
+ - properties.rngcStatus
+ - properties.servicePrincipalId
+ - properties.signInIdentifier
+ - properties.signInTokenProtectionStatus
+ - properties.ssoExtensionVersion
+ - properties.status.additionalDetails
+ - properties.status.errorCode
+ - properties.status.failureReason
+ - properties.tenantId
+ - properties.tokenIssuerName
+ - properties.tokenIssuerType
+ - properties.uniqueTokenIdentifier
+ - properties.userAgent
+ - properties.userDisplayName
+ - properties.userId
+ - properties.userPrincipalName
+ - properties.userType
+ - punct
+ - resourceId
+ - resultDescription
+ - resultSignature
+ - resultType
+ - source
+ - sourcetype
+ - splunk_server
+ - tenantId
+ - time
+ - timeendpos
+ - timestartpos
example_log: '{"time": "2023-10-24T20:13:31.4449614Z", "resourceId": "/tenants/887c9144-28b8-431b-885b-764fdeefcf62/providers/Microsoft.aadiam",
"operationName": "Sign-in activity", "operationVersion": "1.0", "category": "SignInLogs",
"tenantId": "887c9144-28b8-431b-885b-764fdeefcf62", "resultType": "50076", "resultSignature":
diff --git a/data_sources/azure_active_directory_update_application.yml b/data_sources/azure_active_directory_update_application.yml
index cc9da95340..fe57e659f8 100644
--- a/data_sources/azure_active_directory_update_application.yml
+++ b/data_sources/azure_active_directory_update_application.yml
@@ -1,72 +1,73 @@
name: Azure Active Directory Update application
id: 2c08188a-ba25-496e-87c7-803cf28b6c90
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when an application in Azure Active Directory is updated, such as changes to its settings or permissions.
+description: Logs an event when an application in Azure Active Directory is updated,
+ such as changes to its settings or permissions.
mitre_components:
-- Service Modification
-- User Account Modification
-- Cloud Service Modification
+ - Service Modification
+ - User Account Modification
+ - Cloud Service Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Update application
supported_TA:
-- name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+ - name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
-- _time
-- Level
-- category
-- correlationId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- durationMs
-- host
-- index
-- linecount
-- operationName
-- operationVersion
-- properties.activityDateTime
-- properties.activityDisplayName
-- properties.additionalDetails{}.key
-- properties.additionalDetails{}.value
-- properties.category
-- properties.correlationId
-- properties.id
-- properties.initiatedBy.user.displayName
-- properties.initiatedBy.user.id
-- properties.initiatedBy.user.ipAddress
-- properties.initiatedBy.user.userPrincipalName
-- properties.loggedByService
-- properties.operationType
-- properties.result
-- properties.resultReason
-- properties.targetResources{}.displayName
-- properties.targetResources{}.id
-- properties.targetResources{}.modifiedProperties{}.displayName
-- properties.targetResources{}.modifiedProperties{}.newValue
-- properties.targetResources{}.modifiedProperties{}.oldValue
-- properties.targetResources{}.type
-- properties.userAgent
-- punct
-- resourceId
-- resultSignature
-- source
-- sourcetype
-- splunk_server
-- tenantId
-- time
-- timeendpos
-- timestartpos
+ - _time
+ - Level
+ - category
+ - correlationId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - durationMs
+ - host
+ - index
+ - linecount
+ - operationName
+ - operationVersion
+ - properties.activityDateTime
+ - properties.activityDisplayName
+ - properties.additionalDetails{}.key
+ - properties.additionalDetails{}.value
+ - properties.category
+ - properties.correlationId
+ - properties.id
+ - properties.initiatedBy.user.displayName
+ - properties.initiatedBy.user.id
+ - properties.initiatedBy.user.ipAddress
+ - properties.initiatedBy.user.userPrincipalName
+ - properties.loggedByService
+ - properties.operationType
+ - properties.result
+ - properties.resultReason
+ - properties.targetResources{}.displayName
+ - properties.targetResources{}.id
+ - properties.targetResources{}.modifiedProperties{}.displayName
+ - properties.targetResources{}.modifiedProperties{}.newValue
+ - properties.targetResources{}.modifiedProperties{}.oldValue
+ - properties.targetResources{}.type
+ - properties.userAgent
+ - punct
+ - resourceId
+ - resultSignature
+ - source
+ - sourcetype
+ - splunk_server
+ - tenantId
+ - time
+ - timeendpos
+ - timestartpos
example_log: '{"time": "2024-01-29T21:31:03.0102031Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam",
"operationName": "Update application", "operationVersion": "1.0", "category": "AuditLogs",
"tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "resultSignature": "None", "durationMs":
diff --git a/data_sources/azure_active_directory_update_authorization_policy.yml b/data_sources/azure_active_directory_update_authorization_policy.yml
index 37b2c7c4be..34e141f92e 100644
--- a/data_sources/azure_active_directory_update_authorization_policy.yml
+++ b/data_sources/azure_active_directory_update_authorization_policy.yml
@@ -1,73 +1,74 @@
name: Azure Active Directory Update authorization policy
id: c5b7ffcd-73d8-4fe5-afd8-b1218d715c0c
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when an authorization policy is updated in Azure Active Directory.
+description: Logs an event when an authorization policy is updated in Azure Active
+ Directory.
mitre_components:
-- User Account Modification
-- Group Modification
-- Active Directory Object Modification
+ - User Account Modification
+ - Group Modification
+ - Active Directory Object Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Update authorization policy
supported_TA:
-- name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+ - name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
-- _time
-- Level
-- callerIpAddress
-- category
-- correlationId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- durationMs
-- host
-- index
-- linecount
-- operationName
-- operationVersion
-- properties.activityDateTime
-- properties.activityDisplayName
-- properties.additionalDetails{}.key
-- properties.additionalDetails{}.value
-- properties.category
-- properties.correlationId
-- properties.id
-- properties.initiatedBy.user.displayName
-- properties.initiatedBy.user.id
-- properties.initiatedBy.user.ipAddress
-- properties.initiatedBy.user.userPrincipalName
-- properties.loggedByService
-- properties.operationType
-- properties.result
-- properties.resultReason
-- properties.targetResources{}.displayName
-- properties.targetResources{}.id
-- properties.targetResources{}.modifiedProperties{}.displayName
-- properties.targetResources{}.modifiedProperties{}.newValue
-- properties.targetResources{}.modifiedProperties{}.oldValue
-- properties.targetResources{}.type
-- properties.userAgent
-- punct
-- resourceId
-- resultSignature
-- source
-- sourcetype
-- splunk_server
-- tenantId
-- time
-- timeendpos
-- timestartpos
+ - _time
+ - Level
+ - callerIpAddress
+ - category
+ - correlationId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - durationMs
+ - host
+ - index
+ - linecount
+ - operationName
+ - operationVersion
+ - properties.activityDateTime
+ - properties.activityDisplayName
+ - properties.additionalDetails{}.key
+ - properties.additionalDetails{}.value
+ - properties.category
+ - properties.correlationId
+ - properties.id
+ - properties.initiatedBy.user.displayName
+ - properties.initiatedBy.user.id
+ - properties.initiatedBy.user.ipAddress
+ - properties.initiatedBy.user.userPrincipalName
+ - properties.loggedByService
+ - properties.operationType
+ - properties.result
+ - properties.resultReason
+ - properties.targetResources{}.displayName
+ - properties.targetResources{}.id
+ - properties.targetResources{}.modifiedProperties{}.displayName
+ - properties.targetResources{}.modifiedProperties{}.newValue
+ - properties.targetResources{}.modifiedProperties{}.oldValue
+ - properties.targetResources{}.type
+ - properties.userAgent
+ - punct
+ - resourceId
+ - resultSignature
+ - source
+ - sourcetype
+ - splunk_server
+ - tenantId
+ - time
+ - timeendpos
+ - timestartpos
example_log: '{"time": "2023-10-26T19:22:20.2814027Z", "resourceId": "/tenants/5f210575-a69b-41a7-b623-3f6d79ccd432/providers/Microsoft.aadiam",
"operationName": "Update authorization policy", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "5f210575-a69b-41a7-b623-3f6d79ccd432", "resultSignature":
diff --git a/data_sources/azure_active_directory_update_user.yml b/data_sources/azure_active_directory_update_user.yml
index a37a792233..3bc111e209 100644
--- a/data_sources/azure_active_directory_update_user.yml
+++ b/data_sources/azure_active_directory_update_user.yml
@@ -1,73 +1,73 @@
name: Azure Active Directory Update user
id: 5495c90a-047c-4b8e-b2fe-1db6282d3872
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when a user account is updated in Azure Active Directory.
mitre_components:
-- User Account Modification
-- User Account Metadata
+ - User Account Modification
+ - User Account Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Update user
supported_TA:
-- name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+ - name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
-- _time
-- Level
-- callerIpAddress
-- category
-- correlationId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- durationMs
-- host
-- index
-- linecount
-- operationName
-- operationVersion
-- properties.activityDateTime
-- properties.activityDisplayName
-- properties.additionalDetails{}.key
-- properties.additionalDetails{}.value
-- properties.category
-- properties.correlationId
-- properties.id
-- properties.initiatedBy.user.displayName
-- properties.initiatedBy.user.id
-- properties.initiatedBy.user.ipAddress
-- properties.initiatedBy.user.userPrincipalName
-- properties.loggedByService
-- properties.operationType
-- properties.result
-- properties.resultReason
-- properties.targetResources{}.displayName
-- properties.targetResources{}.id
-- properties.targetResources{}.modifiedProperties{}.displayName
-- properties.targetResources{}.modifiedProperties{}.newValue
-- properties.targetResources{}.modifiedProperties{}.oldValue
-- properties.targetResources{}.type
-- properties.targetResources{}.userPrincipalName
-- properties.userAgent
-- punct
-- resourceId
-- resultSignature
-- source
-- sourcetype
-- splunk_server
-- tenantId
-- time
-- timeendpos
-- timestartpos
+ - _time
+ - Level
+ - callerIpAddress
+ - category
+ - correlationId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - durationMs
+ - host
+ - index
+ - linecount
+ - operationName
+ - operationVersion
+ - properties.activityDateTime
+ - properties.activityDisplayName
+ - properties.additionalDetails{}.key
+ - properties.additionalDetails{}.value
+ - properties.category
+ - properties.correlationId
+ - properties.id
+ - properties.initiatedBy.user.displayName
+ - properties.initiatedBy.user.id
+ - properties.initiatedBy.user.ipAddress
+ - properties.initiatedBy.user.userPrincipalName
+ - properties.loggedByService
+ - properties.operationType
+ - properties.result
+ - properties.resultReason
+ - properties.targetResources{}.displayName
+ - properties.targetResources{}.id
+ - properties.targetResources{}.modifiedProperties{}.displayName
+ - properties.targetResources{}.modifiedProperties{}.newValue
+ - properties.targetResources{}.modifiedProperties{}.oldValue
+ - properties.targetResources{}.type
+ - properties.targetResources{}.userPrincipalName
+ - properties.userAgent
+ - punct
+ - resourceId
+ - resultSignature
+ - source
+ - sourcetype
+ - splunk_server
+ - tenantId
+ - time
+ - timeendpos
+ - timestartpos
example_log: '{"time": "2023-07-24T14:28:15.2233481Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Update user", "operationVersion": "1.0", "category": "AuditLogs",
"tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs":
diff --git a/data_sources/azure_active_directory_user_registered_security_info.yml b/data_sources/azure_active_directory_user_registered_security_info.yml
index ae651e960d..db1c5af928 100644
--- a/data_sources/azure_active_directory_user_registered_security_info.yml
+++ b/data_sources/azure_active_directory_user_registered_security_info.yml
@@ -1,69 +1,70 @@
name: Azure Active Directory User registered security info
id: b63240de-8a01-4ba8-8987-89d18d4b375d
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when a user registers or updates their security information in Azure Active Directory.
+description: Logs an event when a user registers or updates their security information
+ in Azure Active Directory.
mitre_components:
-- User Account Modification
-- User Account Metadata
+ - User Account Modification
+ - User Account Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: User registered security info
supported_TA:
-- name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+ - name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
-- _time
-- Level
-- callerIpAddress
-- category
-- correlationId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- durationMs
-- host
-- index
-- linecount
-- operationName
-- operationVersion
-- properties.activityDateTime
-- properties.activityDisplayName
-- properties.category
-- properties.correlationId
-- properties.id
-- properties.initiatedBy.user.displayName
-- properties.initiatedBy.user.id
-- properties.initiatedBy.user.ipAddress
-- properties.initiatedBy.user.userPrincipalName
-- properties.loggedByService
-- properties.operationType
-- properties.result
-- properties.resultReason
-- properties.targetResources{}.displayName
-- properties.targetResources{}.id
-- properties.targetResources{}.type
-- properties.targetResources{}.userPrincipalName
-- properties.userAgent
-- punct
-- resourceId
-- resultDescription
-- resultSignature
-- source
-- sourcetype
-- splunk_server
-- tenantId
-- time
-- timeendpos
-- timestartpos
+ - _time
+ - Level
+ - callerIpAddress
+ - category
+ - correlationId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - durationMs
+ - host
+ - index
+ - linecount
+ - operationName
+ - operationVersion
+ - properties.activityDateTime
+ - properties.activityDisplayName
+ - properties.category
+ - properties.correlationId
+ - properties.id
+ - properties.initiatedBy.user.displayName
+ - properties.initiatedBy.user.id
+ - properties.initiatedBy.user.ipAddress
+ - properties.initiatedBy.user.userPrincipalName
+ - properties.loggedByService
+ - properties.operationType
+ - properties.result
+ - properties.resultReason
+ - properties.targetResources{}.displayName
+ - properties.targetResources{}.id
+ - properties.targetResources{}.type
+ - properties.targetResources{}.userPrincipalName
+ - properties.userAgent
+ - punct
+ - resourceId
+ - resultDescription
+ - resultSignature
+ - source
+ - sourcetype
+ - splunk_server
+ - tenantId
+ - time
+ - timeendpos
+ - timestartpos
example_log: '{"time": "2023-01-30T21:11:30.8690619Z", "resourceId": "/tenants/91da745f-8abb-4a7d-ba94-5667c6f9e01a/providers/Microsoft.aadiam",
"operationName": "User registered security info", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "91da745f-8abb-4a7d-ba94-5667c6f9e01a", "resultSignature":
diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml
index 290688b816..d16b39fe67 100644
--- a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml
+++ b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml
@@ -1,110 +1,110 @@
name: Azure Audit Create or Update an Azure Automation account
id: 2ab182e7-feda-4249-9418-32710b55a885
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when an Azure Automation account is created or updated.
mitre_components:
-- Cloud Service Creation
-- Cloud Service Modification
-- Cloud Service Metadata
+ - Cloud Service Creation
+ - Cloud Service Modification
+ - Cloud Service Metadata
source: mscs:azure:audit
sourcetype: mscs:azure:audit
separator: operationName.localizedValue
separator_value: Create or Update an Azure Automation account
supported_TA:
-- name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+ - name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
-- _time
-- authorization.action
-- authorization.scope
-- caller
-- channels
-- claims.aio
-- claims.altsecid
-- claims.appid
-- claims.appidacr
-- claims.aud
-- claims.exp
-- claims.groups
-- claims.http://schemas.microsoft.com/claims/authnclassreference
-- claims.http://schemas.microsoft.com/claims/authnmethodsreferences
-- claims.http://schemas.microsoft.com/identity/claims/identityprovider
-- claims.http://schemas.microsoft.com/identity/claims/objectidentifier
-- claims.http://schemas.microsoft.com/identity/claims/scope
-- claims.http://schemas.microsoft.com/identity/claims/tenantid
-- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
-- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
-- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
-- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
-- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
-- claims.iat
-- claims.ipaddr
-- claims.iss
-- claims.name
-- claims.nbf
-- claims.puid
-- claims.rh
-- claims.uti
-- claims.ver
-- claims.wids
-- claims.xms_tcdt
-- correlationId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- eventDataId
-- eventName.localizedValue
-- eventName.value
-- eventSource.localizedValue
-- eventSource.value
-- eventTimestamp
-- host
-- id
-- index
-- level
-- linecount
-- object
-- object_id
-- object_path
-- operationId
-- operationName.localizedValue
-- operationName.value
-- product
-- properties.entity
-- properties.eventCategory
-- properties.hierarchy
-- properties.message
-- punct
-- resourceGroupName
-- resourceProviderName.localizedValue
-- resourceProviderName.value
-- resourceUri
-- source
-- sourcetype
-- splunk_server
-- status
-- status.localizedValue
-- status.value
-- subStatus.value
-- submissionTimestamp
-- subscriptionId
-- timeendpos
-- timestartpos
-- user
-- user_name
-- vendor
-- vendor_product
-- vendor_res_code
+ - _time
+ - authorization.action
+ - authorization.scope
+ - caller
+ - channels
+ - claims.aio
+ - claims.altsecid
+ - claims.appid
+ - claims.appidacr
+ - claims.aud
+ - claims.exp
+ - claims.groups
+ - claims.http://schemas.microsoft.com/claims/authnclassreference
+ - claims.http://schemas.microsoft.com/claims/authnmethodsreferences
+ - claims.http://schemas.microsoft.com/identity/claims/identityprovider
+ - claims.http://schemas.microsoft.com/identity/claims/objectidentifier
+ - claims.http://schemas.microsoft.com/identity/claims/scope
+ - claims.http://schemas.microsoft.com/identity/claims/tenantid
+ - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
+ - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
+ - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
+ - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
+ - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
+ - claims.iat
+ - claims.ipaddr
+ - claims.iss
+ - claims.name
+ - claims.nbf
+ - claims.puid
+ - claims.rh
+ - claims.uti
+ - claims.ver
+ - claims.wids
+ - claims.xms_tcdt
+ - correlationId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - eventDataId
+ - eventName.localizedValue
+ - eventName.value
+ - eventSource.localizedValue
+ - eventSource.value
+ - eventTimestamp
+ - host
+ - id
+ - index
+ - level
+ - linecount
+ - object
+ - object_id
+ - object_path
+ - operationId
+ - operationName.localizedValue
+ - operationName.value
+ - product
+ - properties.entity
+ - properties.eventCategory
+ - properties.hierarchy
+ - properties.message
+ - punct
+ - resourceGroupName
+ - resourceProviderName.localizedValue
+ - resourceProviderName.value
+ - resourceUri
+ - source
+ - sourcetype
+ - splunk_server
+ - status
+ - status.localizedValue
+ - status.value
+ - subStatus.value
+ - submissionTimestamp
+ - subscriptionId
+ - timeendpos
+ - timestartpos
+ - user
+ - user_name
+ - vendor
+ - vendor_product
+ - vendor_res_code
example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/write",
"scope": "/subscriptions/67165197-75ea-4ca3-96a5-3e23868eacd0/resourcegroups/ResourceGroup1/providers/Microsoft.Automation/automationAccounts/TestAutomationAccount"},
"caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/",
diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml
index e7ee46661a..8522e7ab79 100644
--- a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml
+++ b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml
@@ -1,109 +1,110 @@
name: Azure Audit Create or Update an Azure Automation Runbook
id: 2bd83221-7a8b-436f-9b2b-efa1d44d009e
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when a new Azure Automation Runbook is created or an existing one is updated.
+description: Logs an event when a new Azure Automation Runbook is created or an existing
+ one is updated.
mitre_components:
-- Scheduled Job Modification
-- Scheduled Job Creation
+ - Scheduled Job Modification
+ - Scheduled Job Creation
source: mscs:azure:audit
sourcetype: mscs:azure:audit
separator: operationName.localizedValue
separator_value: Create or Update an Azure Automation Runbook
supported_TA:
-- name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+ - name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
-- _time
-- authorization.action
-- authorization.scope
-- caller
-- channels
-- claims.aio
-- claims.altsecid
-- claims.appid
-- claims.appidacr
-- claims.aud
-- claims.exp
-- claims.groups
-- claims.http://schemas.microsoft.com/claims/authnclassreference
-- claims.http://schemas.microsoft.com/claims/authnmethodsreferences
-- claims.http://schemas.microsoft.com/identity/claims/identityprovider
-- claims.http://schemas.microsoft.com/identity/claims/objectidentifier
-- claims.http://schemas.microsoft.com/identity/claims/scope
-- claims.http://schemas.microsoft.com/identity/claims/tenantid
-- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
-- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
-- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
-- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
-- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
-- claims.iat
-- claims.ipaddr
-- claims.iss
-- claims.name
-- claims.nbf
-- claims.puid
-- claims.rh
-- claims.uti
-- claims.ver
-- claims.wids
-- claims.xms_tcdt
-- correlationId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- eventDataId
-- eventName.localizedValue
-- eventName.value
-- eventSource.localizedValue
-- eventSource.value
-- eventTimestamp
-- host
-- id
-- index
-- level
-- linecount
-- object
-- object_id
-- object_path
-- operationId
-- operationName.localizedValue
-- operationName.value
-- product
-- properties.entity
-- properties.eventCategory
-- properties.hierarchy
-- properties.message
-- punct
-- resourceGroupName
-- resourceProviderName.localizedValue
-- resourceProviderName.value
-- resourceUri
-- source
-- sourcetype
-- splunk_server
-- status
-- status.localizedValue
-- status.value
-- subStatus.value
-- submissionTimestamp
-- subscriptionId
-- timeendpos
-- timestartpos
-- user
-- user_name
-- vendor
-- vendor_product
-- vendor_res_code
+ - _time
+ - authorization.action
+ - authorization.scope
+ - caller
+ - channels
+ - claims.aio
+ - claims.altsecid
+ - claims.appid
+ - claims.appidacr
+ - claims.aud
+ - claims.exp
+ - claims.groups
+ - claims.http://schemas.microsoft.com/claims/authnclassreference
+ - claims.http://schemas.microsoft.com/claims/authnmethodsreferences
+ - claims.http://schemas.microsoft.com/identity/claims/identityprovider
+ - claims.http://schemas.microsoft.com/identity/claims/objectidentifier
+ - claims.http://schemas.microsoft.com/identity/claims/scope
+ - claims.http://schemas.microsoft.com/identity/claims/tenantid
+ - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
+ - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
+ - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
+ - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
+ - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
+ - claims.iat
+ - claims.ipaddr
+ - claims.iss
+ - claims.name
+ - claims.nbf
+ - claims.puid
+ - claims.rh
+ - claims.uti
+ - claims.ver
+ - claims.wids
+ - claims.xms_tcdt
+ - correlationId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - eventDataId
+ - eventName.localizedValue
+ - eventName.value
+ - eventSource.localizedValue
+ - eventSource.value
+ - eventTimestamp
+ - host
+ - id
+ - index
+ - level
+ - linecount
+ - object
+ - object_id
+ - object_path
+ - operationId
+ - operationName.localizedValue
+ - operationName.value
+ - product
+ - properties.entity
+ - properties.eventCategory
+ - properties.hierarchy
+ - properties.message
+ - punct
+ - resourceGroupName
+ - resourceProviderName.localizedValue
+ - resourceProviderName.value
+ - resourceUri
+ - source
+ - sourcetype
+ - splunk_server
+ - status
+ - status.localizedValue
+ - status.value
+ - subStatus.value
+ - submissionTimestamp
+ - subscriptionId
+ - timeendpos
+ - timestartpos
+ - user
+ - user_name
+ - vendor
+ - vendor_product
+ - vendor_res_code
example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/runbooks/write",
"scope": "/subscriptions/1aee0e3d-b75b-440a-a927-76f0552a14e6/resourceGroups/resourceGroup1/providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/runbooks/SuspiciousRunbook"},
"caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/",
diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml
index 584e44aaff..eb21ed90a8 100644
--- a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml
+++ b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml
@@ -1,119 +1,119 @@
name: Azure Audit Create or Update an Azure Automation webhook
id: 575faeb2-09d0-4849-b1f6-eae241f26ff2
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when a webhook is created or updated in Azure Automation.
mitre_components:
-- Scheduled Job Modification
-- Cloud Service Modification
-- Scheduled Job Metadata
+ - Scheduled Job Modification
+ - Cloud Service Modification
+ - Scheduled Job Metadata
source: mscs:azure:audit
sourcetype: mscs:azure:audit
separator: operationName.localizedValue
separator_value: Create or Update an Azure Automation webhook
supported_TA:
-- name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+ - name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
-- _time
-- authorization.action
-- authorization.scope
-- caller
-- channels
-- claims.aio
-- claims.altsecid
-- claims.appid
-- claims.appidacr
-- claims.aud
-- claims.exp
-- claims.groups
-- claims.http://schemas.microsoft.com/claims/authnclassreference
-- claims.http://schemas.microsoft.com/claims/authnmethodsreferences
-- claims.http://schemas.microsoft.com/identity/claims/identityprovider
-- claims.http://schemas.microsoft.com/identity/claims/objectidentifier
-- claims.http://schemas.microsoft.com/identity/claims/scope
-- claims.http://schemas.microsoft.com/identity/claims/tenantid
-- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
-- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
-- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
-- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
-- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
-- claims.iat
-- claims.ipaddr
-- claims.iss
-- claims.name
-- claims.nbf
-- claims.puid
-- claims.rh
-- claims.uti
-- claims.ver
-- claims.wids
-- claims.xms_tcdt
-- correlationId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- eventDataId
-- eventName.localizedValue
-- eventName.value
-- eventSource.localizedValue
-- eventSource.value
-- eventTimestamp
-- host
-- httpRequest.clientIpAddress
-- httpRequest.clientRequestId
-- httpRequest.method
-- id
-- index
-- level
-- linecount
-- object
-- object_id
-- object_path
-- operationId
-- operationName.localizedValue
-- operationName.value
-- product
-- properties.entity
-- properties.eventCategory
-- properties.hierarchy
-- properties.message
-- properties.serviceRequestId
-- properties.statusCode
-- punct
-- resourceGroupName
-- resourceProviderName.localizedValue
-- resourceProviderName.value
-- resourceUri
-- result
-- result_id
-- source
-- sourcetype
-- splunk_server
-- src
-- status
-- status.localizedValue
-- status.value
-- subStatus.localizedValue
-- subStatus.value
-- submissionTimestamp
-- subscriptionId
-- timeendpos
-- timestartpos
-- user
-- user_name
-- vendor
-- vendor_product
-- vendor_res_code
+ - _time
+ - authorization.action
+ - authorization.scope
+ - caller
+ - channels
+ - claims.aio
+ - claims.altsecid
+ - claims.appid
+ - claims.appidacr
+ - claims.aud
+ - claims.exp
+ - claims.groups
+ - claims.http://schemas.microsoft.com/claims/authnclassreference
+ - claims.http://schemas.microsoft.com/claims/authnmethodsreferences
+ - claims.http://schemas.microsoft.com/identity/claims/identityprovider
+ - claims.http://schemas.microsoft.com/identity/claims/objectidentifier
+ - claims.http://schemas.microsoft.com/identity/claims/scope
+ - claims.http://schemas.microsoft.com/identity/claims/tenantid
+ - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
+ - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
+ - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
+ - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
+ - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
+ - claims.iat
+ - claims.ipaddr
+ - claims.iss
+ - claims.name
+ - claims.nbf
+ - claims.puid
+ - claims.rh
+ - claims.uti
+ - claims.ver
+ - claims.wids
+ - claims.xms_tcdt
+ - correlationId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - eventDataId
+ - eventName.localizedValue
+ - eventName.value
+ - eventSource.localizedValue
+ - eventSource.value
+ - eventTimestamp
+ - host
+ - httpRequest.clientIpAddress
+ - httpRequest.clientRequestId
+ - httpRequest.method
+ - id
+ - index
+ - level
+ - linecount
+ - object
+ - object_id
+ - object_path
+ - operationId
+ - operationName.localizedValue
+ - operationName.value
+ - product
+ - properties.entity
+ - properties.eventCategory
+ - properties.hierarchy
+ - properties.message
+ - properties.serviceRequestId
+ - properties.statusCode
+ - punct
+ - resourceGroupName
+ - resourceProviderName.localizedValue
+ - resourceProviderName.value
+ - resourceUri
+ - result
+ - result_id
+ - source
+ - sourcetype
+ - splunk_server
+ - src
+ - status
+ - status.localizedValue
+ - status.value
+ - subStatus.localizedValue
+ - subStatus.value
+ - submissionTimestamp
+ - subscriptionId
+ - timeendpos
+ - timestartpos
+ - user
+ - user_name
+ - vendor
+ - vendor_product
+ - vendor_res_code
example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/webhooks/write",
"scope": "/subscriptions/e0c00901-96b2-4151-80f7-746e24c03e98/resourceGroups/resourceGroup1providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/webhooks/MaliciousWebHook"},
"caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/",
diff --git a/data_sources/bro_conn.yml b/data_sources/bro_conn.yml
index d4ed14b382..992da75275 100644
--- a/data_sources/bro_conn.yml
+++ b/data_sources/bro_conn.yml
@@ -1,14 +1,15 @@
name: Bro conn
id: c5a7e93b-2172-45a7-a7e9-3b217255a7f5
-version: 1
-date: '2025-20-01'
+version: 2
+date: '2025-01-23'
author: Jacob Delgado, SnapAttack
-description: Logs network connection metadata captured by Zeek (formerly Bro), including details such as source and destination IPs, ports, connection state, and protocol.
+description: Logs network connection metadata captured by Zeek (formerly Bro), including
+ details such as source and destination IPs, ports, connection state, and protocol.
mitre_components:
-- Network Connection Creation
-- Network Traffic Flow
-- Response Metadata
-- Application Log Content
+ - Network Connection Creation
+ - Network Traffic Flow
+ - Response Metadata
+ - Application Log Content
source: bro:conn:json
sourcetype: bro:conn:json
supported_TA: []
diff --git a/data_sources/bro_dns.yml b/data_sources/bro_dns.yml
index 2b7cf87568..7d878c681b 100644
--- a/data_sources/bro_dns.yml
+++ b/data_sources/bro_dns.yml
@@ -1,15 +1,16 @@
name: Bro dns
id: a4576cbf-06cc-4ed0-976c-bf06ccaed011
-version: 1
-date: '2025-20-01'
+version: 2
+date: '2025-01-23'
author: Jacob Delgado, SnapAttack
-description: Logs DNS queries and responses captured by Zeek (formerly Bro), including details such as queried domains, resolved IPs, query types, and response codes.
+description: Logs DNS queries and responses captured by Zeek (formerly Bro), including
+ details such as queried domains, resolved IPs, query types, and response codes.
mitre_components:
-- Active DNS
-- Passive DNS
-- Network Traffic Content
-- Network Traffic Flow
-- Response Metadata
+ - Active DNS
+ - Passive DNS
+ - Network Traffic Content
+ - Network Traffic Flow
+ - Response Metadata
source: bro:dns:json
sourcetype: bro:dns:json
supported_TA: []
diff --git a/data_sources/bro_files.yml b/data_sources/bro_files.yml
index b8b0f83dc8..4cb84af9fa 100644
--- a/data_sources/bro_files.yml
+++ b/data_sources/bro_files.yml
@@ -1,15 +1,17 @@
name: Bro files
id: f72d34d0-3495-4826-ad34-d03495782633
-version: 1
-date: '2025-20-01'
+version: 2
+date: '2025-01-23'
author: Jacob Delgado, SnapAttack
-description: Logs metadata about files transferred over the network captured by Zeek (formerly Bro), including details such as file names, hashes, MIME types, and transfer protocols.
+description: Logs metadata about files transferred over the network captured by Zeek
+ (formerly Bro), including details such as file names, hashes, MIME types, and transfer
+ protocols.
mitre_components:
-- File Metadata
-- Network Traffic Content
-- Network Traffic Flow
-- Response Metadata
-- Application Log Content
+ - File Metadata
+ - Network Traffic Content
+ - Network Traffic Flow
+ - Response Metadata
+ - Application Log Content
source: bro:files:json
sourcetype: bro:files:json
supported_TA: []
diff --git a/data_sources/bro_http.yml b/data_sources/bro_http.yml
index f0e879954e..59232b529e 100644
--- a/data_sources/bro_http.yml
+++ b/data_sources/bro_http.yml
@@ -1,15 +1,16 @@
name: Bro http
id: c5d9612b-0ffd-44d3-8247-3cf3486ec5e2
-version: 2
-date: '2024-07-18'
+version: 3
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs HTTP traffic analyzed by Zeek (formerly Bro), including details such as request methods, URLs, user agents, response codes, and headers.
+description: Logs HTTP traffic analyzed by Zeek (formerly Bro), including details
+ such as request methods, URLs, user agents, response codes, and headers.
mitre_components:
-- Network Traffic Content
-- Network Traffic Flow
-- Response Content
-- Response Metadata
-- Application Log Content
+ - Network Traffic Content
+ - Network Traffic Flow
+ - Response Content
+ - Response Metadata
+ - Application Log Content
source: bro:http:json
sourcetype: bro:http:json
supported_TA: []
diff --git a/data_sources/bro_loaded_scripts.yml b/data_sources/bro_loaded_scripts.yml
index e6f2764604..be17c3a7e1 100644
--- a/data_sources/bro_loaded_scripts.yml
+++ b/data_sources/bro_loaded_scripts.yml
@@ -1,14 +1,15 @@
name: Bro loaded_scripts
id: 81e08a21-a735-42b1-a08a-21a73582b1bf
-version: 1
-date: '2025-20-01'
+version: 2
+date: '2025-01-23'
author: Jacob Delgado, SnapAttack
-description: Logs details about the scripts loaded by Zeek (formerly Bro) during initialization, including script names and paths.
+description: Logs details about the scripts loaded by Zeek (formerly Bro) during initialization,
+ including script names and paths.
mitre_components:
-- Application Log Content
-- Configuration Modification
-- Script Execution
-- OS API Execution
+ - Application Log Content
+ - Configuration Modification
+ - Script Execution
+ - OS API Execution
source: bro:loaded_scripts:json
sourcetype: bro:loaded_scripts:json
supported_TA: []
diff --git a/data_sources/bro_ntp.yml b/data_sources/bro_ntp.yml
index 15ea709585..b849d5d5db 100644
--- a/data_sources/bro_ntp.yml
+++ b/data_sources/bro_ntp.yml
@@ -1,14 +1,15 @@
name: Bro ntp
id: 3f64a544-47a4-4958-a4a5-4447a47958df
-version: 1
-date: '2025-20-01'
+version: 2
+date: '2025-01-23'
author: Jacob Delgado, SnapAttack
-description: Logs Network Time Protocol (NTP) activity captured by Zeek (formerly Bro), including details such as NTP requests, responses, and server metadata.
+description: Logs Network Time Protocol (NTP) activity captured by Zeek (formerly
+ Bro), including details such as NTP requests, responses, and server metadata.
mitre_components:
-- Network Traffic Flow
-- Network Traffic Content
-- Response Metadata
-- Application Log Content
+ - Network Traffic Flow
+ - Network Traffic Content
+ - Response Metadata
+ - Application Log Content
source: bro:ntp:json
sourcetype: bro:ntp:json
supported_TA: []
diff --git a/data_sources/bro_ocsp.yml b/data_sources/bro_ocsp.yml
index c0da63d49e..00e8942e83 100644
--- a/data_sources/bro_ocsp.yml
+++ b/data_sources/bro_ocsp.yml
@@ -1,15 +1,16 @@
name: Bro ocsp
id: d20909ab-70be-409a-8909-ab70be609af1
-version: 1
-date: '2025-20-01'
+version: 2
+date: '2025-01-23'
author: Jacob Delgado, SnapAttack
-description: Logs Online Certificate Status Protocol (OCSP) activity captured by Zeek (formerly Bro), including details such as certificate validation requests and responses.
+description: Logs Online Certificate Status Protocol (OCSP) activity captured by Zeek
+ (formerly Bro), including details such as certificate validation requests and responses.
mitre_components:
-- Certificate Registration
-- Network Traffic Flow
-- Network Traffic Content
-- Response Metadata
-- Application Log Content
+ - Certificate Registration
+ - Network Traffic Flow
+ - Network Traffic Content
+ - Response Metadata
+ - Application Log Content
source: bro:ocsp:json
sourcetype: bro:ocsp:json
-supported_TA: []
\ No newline at end of file
+supported_TA: []
diff --git a/data_sources/bro_ssl.yml b/data_sources/bro_ssl.yml
index 2616ce8186..a2c17d7261 100644
--- a/data_sources/bro_ssl.yml
+++ b/data_sources/bro_ssl.yml
@@ -1,15 +1,16 @@
name: Bro ssl
id: 22c637eb-f62e-41f0-8637-ebf62e11f0a8
-version: 1
-date: '2025-20-01'
+version: 2
+date: '2025-01-23'
author: Jacob Delgado, SnapAttack
-description: Logs SSL/TLS handshake and session details captured by Zeek (formerly Bro), including certificates, cipher suites, and session information.
+description: Logs SSL/TLS handshake and session details captured by Zeek (formerly
+ Bro), including certificates, cipher suites, and session information.
mitre_components:
-- Certificate Registration
-- Network Traffic Flow
-- Network Traffic Content
-- Response Metadata
-- Application Log Content
+ - Certificate Registration
+ - Network Traffic Flow
+ - Network Traffic Content
+ - Response Metadata
+ - Application Log Content
source: bro:ssl:json
sourcetype: bro:ssl:json
-supported_TA: []
\ No newline at end of file
+supported_TA: []
diff --git a/data_sources/bro_weird.yml b/data_sources/bro_weird.yml
index 346236e53d..1fc72ac2de 100644
--- a/data_sources/bro_weird.yml
+++ b/data_sources/bro_weird.yml
@@ -1,15 +1,16 @@
name: Bro weird
id: e03762c5-c4b8-44e3-b762-c5c4b8e4e3b6
-version: 1
-date: '2025-20-01'
+version: 2
+date: '2025-01-23'
author: Jacob Delgado, SnapAttack
-description: Logs anomalous or unexpected network behaviors identified by Zeek (formerly Bro), including protocol violations and unusual traffic patterns.
+description: Logs anomalous or unexpected network behaviors identified by Zeek (formerly
+ Bro), including protocol violations and unusual traffic patterns.
mitre_components:
-- Network Traffic Flow
-- Network Traffic Content
-- Response Metadata
-- Application Log Content
-- Host Status
+ - Network Traffic Flow
+ - Network Traffic Content
+ - Response Metadata
+ - Application Log Content
+ - Host Status
source: bro:weird:json
sourcetype: bro:weird:json
supported_TA: []
diff --git a/data_sources/bro_x509.yml b/data_sources/bro_x509.yml
index 8c41ee6ac1..3d9d08adf7 100644
--- a/data_sources/bro_x509.yml
+++ b/data_sources/bro_x509.yml
@@ -1,15 +1,16 @@
name: Bro x509
id: e8792367-64b0-47e9-b923-6764b0f7e936
-version: 1
-date: '2025-20-01'
+version: 2
+date: '2025-01-23'
author: Jacob Delgado, SnapAttack
-description: Logs details about X.509 certificates observed in network traffic captured by Zeek (formerly Bro), including certificate fields, validity periods, and issuers.
+description: Logs details about X.509 certificates observed in network traffic captured
+ by Zeek (formerly Bro), including certificate fields, validity periods, and issuers.
mitre_components:
-- Certificate Registration
-- Network Traffic Content
-- Response Metadata
-- Application Log Content
-- Host Status
+ - Certificate Registration
+ - Network Traffic Content
+ - Response Metadata
+ - Application Log Content
+ - Host Status
source: bro:x509:json
sourcetype: bro:x509:json
-supported_TA: []
\ No newline at end of file
+supported_TA: []
diff --git a/data_sources/circleci.yml b/data_sources/circleci.yml
index 6cf9ff1092..b07ad95c84 100644
--- a/data_sources/circleci.yml
+++ b/data_sources/circleci.yml
@@ -1,74 +1,75 @@
name: CircleCI
id: 34ad06fc-a296-4ab5-8315-2f07714948e3
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs activities related to CI/CD pipelines executed in CircleCI, including job execution, workflow progress, and configuration changes.
+description: Logs activities related to CI/CD pipelines executed in CircleCI, including
+ job execution, workflow progress, and configuration changes.
mitre_components:
-- Scheduled Job Execution
-- Scheduled Job Metadata
-- Application Log Content
-- Configuration Modification
-- Host Status
+ - Scheduled Job Execution
+ - Scheduled Job Metadata
+ - Application Log Content
+ - Configuration Modification
+ - Host Status
source: circleci
sourcetype: circleci
supported_TA:
-- name: App for CircleCI
- url: https://splunkbase.splunk.com/app/5162
- version: 0.1.1
+ - name: App for CircleCI
+ url: https://splunkbase.splunk.com/app/5162
+ version: 0.1.1
fields:
-- _time
-- author_name
-- avatar_url
-- branch
-- build_num
-- build_time_millis
-- build_url
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- eventtype
-- fail_reason
-- host
-- index
-- job_name
-- job_time
-- linecount
-- owners{}
-- project_slug
-- punct
-- queued_time
-- reponame
-- source
-- sourcetype
-- splunk_server
-- start_time
-- status
-- stop_time
-- tag
-- tag::eventtype
-- timedout
-- timeendpos
-- timestartpos
-- username
-- vcs.commit_time
-- vcs.committer_name
-- vcs.revision
-- vcs.subject
-- vcs.tag
-- vcs.type
-- vcs.url
-- workflows.job_id
-- workflows.job_name
-- workflows.upstream_job_ids{}
-- workflows.workflow_id
-- workflows.workflow_name
-- workflows.workspace_id
+ - _time
+ - author_name
+ - avatar_url
+ - branch
+ - build_num
+ - build_time_millis
+ - build_url
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - eventtype
+ - fail_reason
+ - host
+ - index
+ - job_name
+ - job_time
+ - linecount
+ - owners{}
+ - project_slug
+ - punct
+ - queued_time
+ - reponame
+ - source
+ - sourcetype
+ - splunk_server
+ - start_time
+ - status
+ - stop_time
+ - tag
+ - tag::eventtype
+ - timedout
+ - timeendpos
+ - timestartpos
+ - username
+ - vcs.commit_time
+ - vcs.committer_name
+ - vcs.revision
+ - vcs.subject
+ - vcs.tag
+ - vcs.type
+ - vcs.url
+ - workflows.job_id
+ - workflows.job_name
+ - workflows.upstream_job_ids{}
+ - workflows.workflow_id
+ - workflows.workflow_name
+ - workflows.workspace_id
example_log: '{"job_time": "2021-09-02T08:13:34.273Z", "stop_time": "2021-09-02T08:13:34.273Z",
"start_time": "2021-09-02T08:10:15.829Z", "queued_time": "2021-09-02T08:10:12.764Z",
"job_name": "Unknown", "reponame": "devsecops_poc", "build_num": 94, "build_url":
diff --git a/data_sources/crowdstrike_processrollup2.yml b/data_sources/crowdstrike_processrollup2.yml
index e9074afdd5..d160cf8620 100644
--- a/data_sources/crowdstrike_processrollup2.yml
+++ b/data_sources/crowdstrike_processrollup2.yml
@@ -1,113 +1,115 @@
name: CrowdStrike ProcessRollup2
id: cbb06880-9dd9-4542-ac60-bd6e5d3c3e4e
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs process-related activities captured by CrowdStrike, including process creation, termination, and metadata such as hashes, parent processes, and command-line arguments.
+description: Logs process-related activities captured by CrowdStrike, including process
+ creation, termination, and metadata such as hashes, parent processes, and command-line
+ arguments.
mitre_components:
-- Process Creation
-- Process Termination
-- Process Metadata
-- Command Execution
-- OS API Execution
+ - Process Creation
+ - Process Termination
+ - Process Metadata
+ - Command Execution
+ - OS API Execution
source: crowdstrike
sourcetype: crowdstrike:events:sensor
separator: event_simpleName
separator_value: ProcessRollup2
supported_TA:
-- name: Splunk Add-on for CrowdStrike FDR
- url: https://splunkbase.splunk.com/app/5579
- version: 2.0.3
+ - name: Splunk Add-on for CrowdStrike FDR
+ url: https://splunkbase.splunk.com/app/5579
+ version: 2.0.3
fields:
-- AuthenticationId
-- AuthenticationId_meaning
-- AuthenticodeHashData
-- CommandLine
-- ConfigBuild
-- ConfigStateHash
-- EffectiveTransmissionClass
-- Entitlements
-- EventOrigin
-- ImageFileName
-- ImageSubsystem
-- ImageSubsystem_meaning
-- IntegrityLevel
-- IntegrityLevel_meaning
-- MD5HashData
-- ParentAuthenticationId
-- ParentBaseFileName
-- ParentProcessId
-- ProcessCreateFlags
-- ProcessEndTime
-- ProcessParameterFlags
-- ProcessParameterFlags_meaning
-- ProcessStartTime
-- ProcessSxsFlags
-- ProcessSxsFlags_meaning
-- RawProcessId
-- SHA1HashData
-- SHA256HashData
-- SessionId
-- SignInfoFlags
-- SignInfoFlags_meaning
-- SourceProcessId
-- SourceThreadId
-- Tags
-- TargetProcessId
-- TokenType
-- TokenType_meaning
-- UserSid
-- WindowFlags
-- WindowFlags_meaning
-- action
-- aid
-- aid_city
-- aid_computer_name
-- aid_continent
-- aid_country
-- aid_machine_domain
-- aid_os_version
-- aid_ou
-- aid_site_name
-- aid_system_product_name
-- aip
-- cid
-- dest
-- event_ingest_time
-- event_platform
-- event_simpleName
-- eventtype
-- host_res_aid
-- id
-- os
-- parent_process_exec
-- parent_process_id
-- parent_process_name
-- process
-- process_exec
-- process_hash
-- process_id
-- process_integrity_level
-- process_name
-- process_path
-- resolve_dest
-- resolve_process_integrity_level
-- tag
-- timestamp
-- user
-- user_id
-- vendor_product
+ - AuthenticationId
+ - AuthenticationId_meaning
+ - AuthenticodeHashData
+ - CommandLine
+ - ConfigBuild
+ - ConfigStateHash
+ - EffectiveTransmissionClass
+ - Entitlements
+ - EventOrigin
+ - ImageFileName
+ - ImageSubsystem
+ - ImageSubsystem_meaning
+ - IntegrityLevel
+ - IntegrityLevel_meaning
+ - MD5HashData
+ - ParentAuthenticationId
+ - ParentBaseFileName
+ - ParentProcessId
+ - ProcessCreateFlags
+ - ProcessEndTime
+ - ProcessParameterFlags
+ - ProcessParameterFlags_meaning
+ - ProcessStartTime
+ - ProcessSxsFlags
+ - ProcessSxsFlags_meaning
+ - RawProcessId
+ - SHA1HashData
+ - SHA256HashData
+ - SessionId
+ - SignInfoFlags
+ - SignInfoFlags_meaning
+ - SourceProcessId
+ - SourceThreadId
+ - Tags
+ - TargetProcessId
+ - TokenType
+ - TokenType_meaning
+ - UserSid
+ - WindowFlags
+ - WindowFlags_meaning
+ - action
+ - aid
+ - aid_city
+ - aid_computer_name
+ - aid_continent
+ - aid_country
+ - aid_machine_domain
+ - aid_os_version
+ - aid_ou
+ - aid_site_name
+ - aid_system_product_name
+ - aip
+ - cid
+ - dest
+ - event_ingest_time
+ - event_platform
+ - event_simpleName
+ - eventtype
+ - host_res_aid
+ - id
+ - os
+ - parent_process_exec
+ - parent_process_id
+ - parent_process_name
+ - process
+ - process_exec
+ - process_hash
+ - process_id
+ - process_integrity_level
+ - process_name
+ - process_path
+ - resolve_dest
+ - resolve_process_integrity_level
+ - tag
+ - timestamp
+ - user
+ - user_id
+ - vendor_product
field_mappings:
-- data_model: cim
- data_set: Endpoint.Processes
- mapping:
- CommandLine: Processes.process
- ImageFileName: Processes.process_path
- ParentBaseFileName: Processes.parent_process_name
- ParentProcessId: Processes.parent_process_id
- RawProcessId: Processes.process_id
- SHA256HashData: Processes.process_hash
- UserSid: Processes.user
+ - data_model: cim
+ data_set: Endpoint.Processes
+ mapping:
+ CommandLine: Processes.process
+ ImageFileName: Processes.process_path
+ ParentBaseFileName: Processes.parent_process_name
+ ParentProcessId: Processes.parent_process_id
+ RawProcessId: Processes.process_id
+ SHA256HashData: Processes.process_hash
+ UserSid: Processes.user
example_log: '{"LinkName":"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start
Menu\\Programs\\Windows PowerShell\\Windows PowerShell.lnk","ProcessCreateFlags":"67634196","IntegrityLevel":"12288","ParentProcessId":"5459598860","SourceProcessId":"5459598860","aip":"3.126.231.40","SHA1HashData":"0000000000000000000000000000000000000000","UserSid":"S-1-5-21-586445407-708991241-1829972403-500","event_platform":"Win","TokenType":"1","ProcessEndTime":"","AuthenticodeHashData":"3b98faafc17b47beb9027c437fceeafdf0624a1c","ParentBaseFileName":"explorer.exe","EventOrigin":"1","ImageSubsystem":"3","id":"e2210781-0e8f-47d2-bf6a-56d2c59f38ee","EffectiveTransmissionClass":"3","SessionId":"2","ShowWindowFlags":"1","Tags":"27,
40, 151, 874, 924, 12094627905582, 12094627906234, 211106232533012, 212205744161605,
diff --git a/data_sources/crushftp.yml b/data_sources/crushftp.yml
index 04a5b0827c..67968d73ef 100644
--- a/data_sources/crushftp.yml
+++ b/data_sources/crushftp.yml
@@ -1,21 +1,22 @@
name: CrushFTP
id: 8a42ace5-e4c8-4653-80cf-1b8e7e6024ef
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs activities related to file transfers and user interactions in CrushFTP, including file uploads, downloads, user authentication, and session details.
+description: Logs activities related to file transfers and user interactions in CrushFTP,
+ including file uploads, downloads, user authentication, and session details.
mitre_components:
-- File Access
-- File Metadata
-- User Account Authentication
-- Logon Session Metadata
-- Network Traffic Content
+ - File Access
+ - File Metadata
+ - User Account Authentication
+ - Logon Session Metadata
+ - Network Traffic Content
source: crushftp
sourcetype: crushftp:sessionlogs
supported_TA: []
fields:
-- _time
-- _raw
+ - _time
+ - _raw
example_log: 'SESSION|05/14/2024 17:36:21.859|[HTTPS:169_52326_sMa:anonymous:10.0.1.30]
READ: *POST /WebInterface/function/?c2f=CmF1&command=zip&path=%3CINCLUDE%3Eusers/MainUsers/groups.XML%3C/INCLUDE%3E&names=/a
HTTP/1.1*'
diff --git a/data_sources/g_suite_drive.yml b/data_sources/g_suite_drive.yml
index a07ee5cd8c..0d56a7944d 100644
--- a/data_sources/g_suite_drive.yml
+++ b/data_sources/g_suite_drive.yml
@@ -1,53 +1,54 @@
name: G Suite Drive
id: 5f79120f-a235-4468-bd0d-55203758ac22
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs activities related to Google Drive in G Suite, including file creation, modification, sharing, and access details.
+description: Logs activities related to Google Drive in G Suite, including file creation,
+ modification, sharing, and access details.
mitre_components:
-- File Access
-- File Creation
-- File Modification
-- Cloud Storage Access
-- Cloud Storage Metadata
+ - File Access
+ - File Creation
+ - File Modification
+ - Cloud Storage Access
+ - Cloud Storage Metadata
source: http:gsuite
sourcetype: gsuite:drive:json
supported_TA:
-- name: Splunk Add-on for Google Workspace
- url: https://splunkbase.splunk.com/app/5556
- version: 3.0.2
+ - name: Splunk Add-on for Google Workspace
+ url: https://splunkbase.splunk.com/app/5556
+ version: 3.0.2
fields:
-- _time
-- email
-- host
-- index
-- ip_address
-- linecount
-- name
-- parameters.actor_is_collaborator_account
-- parameters.billable
-- parameters.doc_id
-- parameters.doc_title
-- parameters.doc_type
-- parameters.is_encrypted
-- parameters.new_value{}
-- parameters.old_value{}
-- parameters.old_visibility
-- parameters.originating_app_id
-- parameters.owner
-- parameters.owner_is_shared_drive
-- parameters.owner_is_team_drive
-- parameters.primary_event
-- parameters.target_user
-- parameters.visibility
-- parameters.visibility_change
-- punct
-- source
-- sourcetype
-- splunk_server
-- timestamp
-- type
-- unique_id
+ - _time
+ - email
+ - host
+ - index
+ - ip_address
+ - linecount
+ - name
+ - parameters.actor_is_collaborator_account
+ - parameters.billable
+ - parameters.doc_id
+ - parameters.doc_title
+ - parameters.doc_type
+ - parameters.is_encrypted
+ - parameters.new_value{}
+ - parameters.old_value{}
+ - parameters.old_visibility
+ - parameters.originating_app_id
+ - parameters.owner
+ - parameters.owner_is_shared_drive
+ - parameters.owner_is_team_drive
+ - parameters.primary_event
+ - parameters.target_user
+ - parameters.visibility
+ - parameters.visibility_change
+ - punct
+ - source
+ - sourcetype
+ - splunk_server
+ - timestamp
+ - type
+ - unique_id
example_log: '{"type": "acl_change", "name": "change_user_access", "parameters": {"primary_event":
true, "billable": true, "visibility_change": "none", "target_user": "alberto@internal_test_email.com",
"old_value": ["none"], "new_value": ["can_edit"], "old_visibility": "private", "doc_id":
diff --git a/data_sources/g_suite_gmail.yml b/data_sources/g_suite_gmail.yml
index 0a6ddc9596..c89e7087fb 100644
--- a/data_sources/g_suite_gmail.yml
+++ b/data_sources/g_suite_gmail.yml
@@ -1,91 +1,92 @@
name: G Suite Gmail
id: 706c3978-41de-406b-b6e0-75bd01e12a5d
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs Gmail activities in G Suite, including email sending, receiving, and access details, as well as potential security-related events.
+description: Logs Gmail activities in G Suite, including email sending, receiving,
+ and access details, as well as potential security-related events.
mitre_components:
-- Application Log Content
-- User Account Metadata
-- Email Metadata
-- Cloud Service Metadata
+ - Application Log Content
+ - User Account Metadata
+ - Email Metadata
+ - Cloud Service Metadata
source: http:gsuite
sourcetype: gsuite:gmail:bigquery
supported_TA:
-- name: Splunk Add-on for Google Workspace
- url: https://splunkbase.splunk.com/app/5556
- version: 3.0.2
+ - name: Splunk Add-on for Google Workspace
+ url: https://splunkbase.splunk.com/app/5556
+ version: 3.0.2
fields:
-- _time
-- action_type
-- attachment{}.file_extension_type
-- attachment{}.malware_family
-- attachment{}.sha256
-- connection_info.authenticated_domain{}.name
-- connection_info.authenticated_domain{}.type
-- connection_info.client_host_zone
-- connection_info.client_ip
-- connection_info.dkim_pass
-- connection_info.dmarc_pass
-- connection_info.dmarc_published_domain
-- connection_info.ip_geo_city
-- connection_info.ip_geo_country
-- connection_info.is_internal
-- connection_info.is_intra_domain
-- connection_info.smtp_in_connect_ip
-- connection_info.smtp_out_connect_ip
-- connection_info.smtp_out_remote_host
-- connection_info.smtp_reply_code
-- connection_info.smtp_response_reason
-- connection_info.smtp_tls_cipher
-- connection_info.smtp_tls_state
-- connection_info.smtp_tls_version
-- connection_info.smtp_user_agent_ip
-- connection_info.spf_pass
-- connection_info.tls_required_but_unavailable
-- description
-- destination{}.address
-- destination{}.rcpt_response
-- destination{}.selector
-- destination{}.service
-- destination{}.smime_decryption_success
-- destination{}.smime_extraction_success
-- destination{}.smime_parsing_success
-- destination{}.smime_signature_verification_success
-- eventtype
-- flattened_destinations
-- flattened_triggered_rule_info
-- host
-- index
-- is_policy_check_for_sender
-- is_spam
-- linecount
-- message_set{}.type
-- num_message_attachments
-- payload_size
-- punct
-- rfc2822_message_id
-- smime_content_type
-- smime_encrypt_message
-- smime_extraction_success
-- smime_packaging_success
-- smime_sign_message
-- smtp_relay_error
-- source
-- source.address
-- source.from_header_address
-- source.from_header_displayname
-- source.selector
-- source.service
-- sourcetype
-- spam_info
-- splunk_server
-- structured_policy_log_info
-- subject
-- tag
-- tag::eventtype
-- timestamp
-- upload_error_category
+ - _time
+ - action_type
+ - attachment{}.file_extension_type
+ - attachment{}.malware_family
+ - attachment{}.sha256
+ - connection_info.authenticated_domain{}.name
+ - connection_info.authenticated_domain{}.type
+ - connection_info.client_host_zone
+ - connection_info.client_ip
+ - connection_info.dkim_pass
+ - connection_info.dmarc_pass
+ - connection_info.dmarc_published_domain
+ - connection_info.ip_geo_city
+ - connection_info.ip_geo_country
+ - connection_info.is_internal
+ - connection_info.is_intra_domain
+ - connection_info.smtp_in_connect_ip
+ - connection_info.smtp_out_connect_ip
+ - connection_info.smtp_out_remote_host
+ - connection_info.smtp_reply_code
+ - connection_info.smtp_response_reason
+ - connection_info.smtp_tls_cipher
+ - connection_info.smtp_tls_state
+ - connection_info.smtp_tls_version
+ - connection_info.smtp_user_agent_ip
+ - connection_info.spf_pass
+ - connection_info.tls_required_but_unavailable
+ - description
+ - destination{}.address
+ - destination{}.rcpt_response
+ - destination{}.selector
+ - destination{}.service
+ - destination{}.smime_decryption_success
+ - destination{}.smime_extraction_success
+ - destination{}.smime_parsing_success
+ - destination{}.smime_signature_verification_success
+ - eventtype
+ - flattened_destinations
+ - flattened_triggered_rule_info
+ - host
+ - index
+ - is_policy_check_for_sender
+ - is_spam
+ - linecount
+ - message_set{}.type
+ - num_message_attachments
+ - payload_size
+ - punct
+ - rfc2822_message_id
+ - smime_content_type
+ - smime_encrypt_message
+ - smime_extraction_success
+ - smime_packaging_success
+ - smime_sign_message
+ - smtp_relay_error
+ - source
+ - source.address
+ - source.from_header_address
+ - source.from_header_displayname
+ - source.selector
+ - source.service
+ - sourcetype
+ - spam_info
+ - splunk_server
+ - structured_policy_log_info
+ - subject
+ - tag
+ - tag::eventtype
+ - timestamp
+ - upload_error_category
example_log: '{"action_type": 10, "rfc2822_message_id": "",
"subject": "New Order DHL0000001 - Dummy email for Detection Development", "payload_size":
6733, "source": {"address": "john@external_test_email.com", "service": "gmail-for-work",
diff --git a/data_sources/github.yml b/data_sources/github.yml
index e9125f7f07..32ebea53e7 100644
--- a/data_sources/github.yml
+++ b/data_sources/github.yml
@@ -1,211 +1,212 @@
name: GitHub
id: 88aa4632-3c3e-43f6-a00a-998d71f558e3
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs activities on GitHub repositories, including push events, pull requests, issue creation, and user authentication events.
+description: Logs activities on GitHub repositories, including push events, pull requests,
+ issue creation, and user authentication events.
mitre_components:
-- User Account Authentication
-- Configuration Modification
-- Application Log Content
-- User Account Metadata
-- Scheduled Job Metadata
+ - User Account Authentication
+ - Configuration Modification
+ - Application Log Content
+ - User Account Metadata
+ - Scheduled Job Metadata
source: github
sourcetype: aws:firehose:json
supported_TA:
-- name: Splunk Add-on for Github
- url: https://splunkbase.splunk.com/app/6254
- version: 3.1.0
+ - name: Splunk Add-on for Github
+ url: https://splunkbase.splunk.com/app/6254
+ version: 3.1.0
fields:
-- _time
-- action
-- host
-- index
-- linecount
-- meta
-- punct
-- source
-- sourcetype
-- splunk_server
-- timestamp
-- workflow_run.actor.avatar_url
-- workflow_run.actor.events_url
-- workflow_run.actor.followers_url
-- workflow_run.actor.following_url
-- workflow_run.actor.gists_url
-- workflow_run.actor.gravatar_id
-- workflow_run.actor.html_url
-- workflow_run.actor.id
-- workflow_run.actor.login
-- workflow_run.actor.node_id
-- workflow_run.actor.organizations_url
-- workflow_run.actor.received_events_url
-- workflow_run.actor.repos_url
-- workflow_run.actor.site_admin
-- workflow_run.actor.starred_url
-- workflow_run.actor.subscriptions_url
-- workflow_run.actor.type
-- workflow_run.actor.url
-- workflow_run.artifacts_url
-- workflow_run.cancel_url
-- workflow_run.check_suite_id
-- workflow_run.check_suite_node_id
-- workflow_run.check_suite_url
-- workflow_run.conclusion
-- workflow_run.created_at
-- workflow_run.event
-- workflow_run.head_branch
-- workflow_run.head_commit.author.email
-- workflow_run.head_commit.author.name
-- workflow_run.head_commit.committer.email
-- workflow_run.head_commit.committer.name
-- workflow_run.head_commit.id
-- workflow_run.head_commit.message
-- workflow_run.head_commit.timestamp
-- workflow_run.head_commit.tree_id
-- workflow_run.head_repository.collaborators_url
-- workflow_run.head_repository.description
-- workflow_run.head_repository.fork
-- workflow_run.head_repository.forks_url
-- workflow_run.head_repository.full_name
-- workflow_run.head_repository.hooks_url
-- workflow_run.head_repository.html_url
-- workflow_run.head_repository.id
-- workflow_run.head_repository.keys_url
-- workflow_run.head_repository.name
-- workflow_run.head_repository.node_id
-- workflow_run.head_repository.owner.avatar_url
-- workflow_run.head_repository.owner.events_url
-- workflow_run.head_repository.owner.followers_url
-- workflow_run.head_repository.owner.following_url
-- workflow_run.head_repository.owner.gists_url
-- workflow_run.head_repository.owner.gravatar_id
-- workflow_run.head_repository.owner.html_url
-- workflow_run.head_repository.owner.id
-- workflow_run.head_repository.owner.login
-- workflow_run.head_repository.owner.node_id
-- workflow_run.head_repository.owner.organizations_url
-- workflow_run.head_repository.owner.received_events_url
-- workflow_run.head_repository.owner.repos_url
-- workflow_run.head_repository.owner.site_admin
-- workflow_run.head_repository.owner.starred_url
-- workflow_run.head_repository.owner.subscriptions_url
-- workflow_run.head_repository.owner.type
-- workflow_run.head_repository.owner.url
-- workflow_run.head_repository.private
-- workflow_run.head_repository.teams_url
-- workflow_run.head_repository.url
-- workflow_run.head_sha
-- workflow_run.html_url
-- workflow_run.id
-- workflow_run.jobs_url
-- workflow_run.logs_url
-- workflow_run.name
-- workflow_run.node_id
-- workflow_run.previous_attempt_url
-- workflow_run.pull_requests{}.base.ref
-- workflow_run.pull_requests{}.base.repo.id
-- workflow_run.pull_requests{}.base.repo.name
-- workflow_run.pull_requests{}.base.repo.url
-- workflow_run.pull_requests{}.base.sha
-- workflow_run.pull_requests{}.head.ref
-- workflow_run.pull_requests{}.head.repo.id
-- workflow_run.pull_requests{}.head.repo.name
-- workflow_run.pull_requests{}.head.repo.url
-- workflow_run.pull_requests{}.head.sha
-- workflow_run.pull_requests{}.id
-- workflow_run.pull_requests{}.number
-- workflow_run.pull_requests{}.url
-- workflow_run.repository.archive_url
-- workflow_run.repository.assignees_url
-- workflow_run.repository.blobs_url
-- workflow_run.repository.branches_url
-- workflow_run.repository.collaborators_url
-- workflow_run.repository.comments_url
-- workflow_run.repository.commits_url
-- workflow_run.repository.compare_url
-- workflow_run.repository.contents_url
-- workflow_run.repository.contributors_url
-- workflow_run.repository.deployments_url
-- workflow_run.repository.description
-- workflow_run.repository.downloads_url
-- workflow_run.repository.events_url
-- workflow_run.repository.fork
-- workflow_run.repository.forks_url
-- workflow_run.repository.full_name
-- workflow_run.repository.git_commits_url
-- workflow_run.repository.git_refs_url
-- workflow_run.repository.git_tags_url
-- workflow_run.repository.hooks_url
-- workflow_run.repository.html_url
-- workflow_run.repository.id
-- workflow_run.repository.issue_comment_url
-- workflow_run.repository.issue_events_url
-- workflow_run.repository.issues_url
-- workflow_run.repository.keys_url
-- workflow_run.repository.labels_url
-- workflow_run.repository.languages_url
-- workflow_run.repository.merges_url
-- workflow_run.repository.milestones_url
-- workflow_run.repository.name
-- workflow_run.repository.node_id
-- workflow_run.repository.notifications_url
-- workflow_run.repository.owner.avatar_url
-- workflow_run.repository.owner.events_url
-- workflow_run.repository.owner.followers_url
-- workflow_run.repository.owner.following_url
-- workflow_run.repository.owner.gists_url
-- workflow_run.repository.owner.gravatar_id
-- workflow_run.repository.owner.html_url
-- workflow_run.repository.owner.id
-- workflow_run.repository.owner.login
-- workflow_run.repository.owner.node_id
-- workflow_run.repository.owner.organizations_url
-- workflow_run.repository.owner.received_events_url
-- workflow_run.repository.owner.repos_url
-- workflow_run.repository.owner.site_admin
-- workflow_run.repository.owner.starred_url
-- workflow_run.repository.owner.subscriptions_url
-- workflow_run.repository.owner.type
-- workflow_run.repository.owner.url
-- workflow_run.repository.private
-- workflow_run.repository.pulls_url
-- workflow_run.repository.releases_url
-- workflow_run.repository.stargazers_url
-- workflow_run.repository.statuses_url
-- workflow_run.repository.subscribers_url
-- workflow_run.repository.subscription_url
-- workflow_run.repository.tags_url
-- workflow_run.repository.teams_url
-- workflow_run.repository.trees_url
-- workflow_run.repository.url
-- workflow_run.rerun_url
-- workflow_run.run_attempt
-- workflow_run.run_number
-- workflow_run.run_started_at
-- workflow_run.status
-- workflow_run.triggering_actor.avatar_url
-- workflow_run.triggering_actor.events_url
-- workflow_run.triggering_actor.followers_url
-- workflow_run.triggering_actor.following_url
-- workflow_run.triggering_actor.gists_url
-- workflow_run.triggering_actor.gravatar_id
-- workflow_run.triggering_actor.html_url
-- workflow_run.triggering_actor.id
-- workflow_run.triggering_actor.login
-- workflow_run.triggering_actor.node_id
-- workflow_run.triggering_actor.organizations_url
-- workflow_run.triggering_actor.received_events_url
-- workflow_run.triggering_actor.repos_url
-- workflow_run.triggering_actor.site_admin
-- workflow_run.triggering_actor.starred_url
-- workflow_run.triggering_actor.subscriptions_url
-- workflow_run.triggering_actor.type
-- workflow_run.triggering_actor.url
-- workflow_run.updated_at
-- workflow_run.url
-- workflow_run.workflow_id
-- workflow_run.workflow_url
+ - _time
+ - action
+ - host
+ - index
+ - linecount
+ - meta
+ - punct
+ - source
+ - sourcetype
+ - splunk_server
+ - timestamp
+ - workflow_run.actor.avatar_url
+ - workflow_run.actor.events_url
+ - workflow_run.actor.followers_url
+ - workflow_run.actor.following_url
+ - workflow_run.actor.gists_url
+ - workflow_run.actor.gravatar_id
+ - workflow_run.actor.html_url
+ - workflow_run.actor.id
+ - workflow_run.actor.login
+ - workflow_run.actor.node_id
+ - workflow_run.actor.organizations_url
+ - workflow_run.actor.received_events_url
+ - workflow_run.actor.repos_url
+ - workflow_run.actor.site_admin
+ - workflow_run.actor.starred_url
+ - workflow_run.actor.subscriptions_url
+ - workflow_run.actor.type
+ - workflow_run.actor.url
+ - workflow_run.artifacts_url
+ - workflow_run.cancel_url
+ - workflow_run.check_suite_id
+ - workflow_run.check_suite_node_id
+ - workflow_run.check_suite_url
+ - workflow_run.conclusion
+ - workflow_run.created_at
+ - workflow_run.event
+ - workflow_run.head_branch
+ - workflow_run.head_commit.author.email
+ - workflow_run.head_commit.author.name
+ - workflow_run.head_commit.committer.email
+ - workflow_run.head_commit.committer.name
+ - workflow_run.head_commit.id
+ - workflow_run.head_commit.message
+ - workflow_run.head_commit.timestamp
+ - workflow_run.head_commit.tree_id
+ - workflow_run.head_repository.collaborators_url
+ - workflow_run.head_repository.description
+ - workflow_run.head_repository.fork
+ - workflow_run.head_repository.forks_url
+ - workflow_run.head_repository.full_name
+ - workflow_run.head_repository.hooks_url
+ - workflow_run.head_repository.html_url
+ - workflow_run.head_repository.id
+ - workflow_run.head_repository.keys_url
+ - workflow_run.head_repository.name
+ - workflow_run.head_repository.node_id
+ - workflow_run.head_repository.owner.avatar_url
+ - workflow_run.head_repository.owner.events_url
+ - workflow_run.head_repository.owner.followers_url
+ - workflow_run.head_repository.owner.following_url
+ - workflow_run.head_repository.owner.gists_url
+ - workflow_run.head_repository.owner.gravatar_id
+ - workflow_run.head_repository.owner.html_url
+ - workflow_run.head_repository.owner.id
+ - workflow_run.head_repository.owner.login
+ - workflow_run.head_repository.owner.node_id
+ - workflow_run.head_repository.owner.organizations_url
+ - workflow_run.head_repository.owner.received_events_url
+ - workflow_run.head_repository.owner.repos_url
+ - workflow_run.head_repository.owner.site_admin
+ - workflow_run.head_repository.owner.starred_url
+ - workflow_run.head_repository.owner.subscriptions_url
+ - workflow_run.head_repository.owner.type
+ - workflow_run.head_repository.owner.url
+ - workflow_run.head_repository.private
+ - workflow_run.head_repository.teams_url
+ - workflow_run.head_repository.url
+ - workflow_run.head_sha
+ - workflow_run.html_url
+ - workflow_run.id
+ - workflow_run.jobs_url
+ - workflow_run.logs_url
+ - workflow_run.name
+ - workflow_run.node_id
+ - workflow_run.previous_attempt_url
+ - workflow_run.pull_requests{}.base.ref
+ - workflow_run.pull_requests{}.base.repo.id
+ - workflow_run.pull_requests{}.base.repo.name
+ - workflow_run.pull_requests{}.base.repo.url
+ - workflow_run.pull_requests{}.base.sha
+ - workflow_run.pull_requests{}.head.ref
+ - workflow_run.pull_requests{}.head.repo.id
+ - workflow_run.pull_requests{}.head.repo.name
+ - workflow_run.pull_requests{}.head.repo.url
+ - workflow_run.pull_requests{}.head.sha
+ - workflow_run.pull_requests{}.id
+ - workflow_run.pull_requests{}.number
+ - workflow_run.pull_requests{}.url
+ - workflow_run.repository.archive_url
+ - workflow_run.repository.assignees_url
+ - workflow_run.repository.blobs_url
+ - workflow_run.repository.branches_url
+ - workflow_run.repository.collaborators_url
+ - workflow_run.repository.comments_url
+ - workflow_run.repository.commits_url
+ - workflow_run.repository.compare_url
+ - workflow_run.repository.contents_url
+ - workflow_run.repository.contributors_url
+ - workflow_run.repository.deployments_url
+ - workflow_run.repository.description
+ - workflow_run.repository.downloads_url
+ - workflow_run.repository.events_url
+ - workflow_run.repository.fork
+ - workflow_run.repository.forks_url
+ - workflow_run.repository.full_name
+ - workflow_run.repository.git_commits_url
+ - workflow_run.repository.git_refs_url
+ - workflow_run.repository.git_tags_url
+ - workflow_run.repository.hooks_url
+ - workflow_run.repository.html_url
+ - workflow_run.repository.id
+ - workflow_run.repository.issue_comment_url
+ - workflow_run.repository.issue_events_url
+ - workflow_run.repository.issues_url
+ - workflow_run.repository.keys_url
+ - workflow_run.repository.labels_url
+ - workflow_run.repository.languages_url
+ - workflow_run.repository.merges_url
+ - workflow_run.repository.milestones_url
+ - workflow_run.repository.name
+ - workflow_run.repository.node_id
+ - workflow_run.repository.notifications_url
+ - workflow_run.repository.owner.avatar_url
+ - workflow_run.repository.owner.events_url
+ - workflow_run.repository.owner.followers_url
+ - workflow_run.repository.owner.following_url
+ - workflow_run.repository.owner.gists_url
+ - workflow_run.repository.owner.gravatar_id
+ - workflow_run.repository.owner.html_url
+ - workflow_run.repository.owner.id
+ - workflow_run.repository.owner.login
+ - workflow_run.repository.owner.node_id
+ - workflow_run.repository.owner.organizations_url
+ - workflow_run.repository.owner.received_events_url
+ - workflow_run.repository.owner.repos_url
+ - workflow_run.repository.owner.site_admin
+ - workflow_run.repository.owner.starred_url
+ - workflow_run.repository.owner.subscriptions_url
+ - workflow_run.repository.owner.type
+ - workflow_run.repository.owner.url
+ - workflow_run.repository.private
+ - workflow_run.repository.pulls_url
+ - workflow_run.repository.releases_url
+ - workflow_run.repository.stargazers_url
+ - workflow_run.repository.statuses_url
+ - workflow_run.repository.subscribers_url
+ - workflow_run.repository.subscription_url
+ - workflow_run.repository.tags_url
+ - workflow_run.repository.teams_url
+ - workflow_run.repository.trees_url
+ - workflow_run.repository.url
+ - workflow_run.rerun_url
+ - workflow_run.run_attempt
+ - workflow_run.run_number
+ - workflow_run.run_started_at
+ - workflow_run.status
+ - workflow_run.triggering_actor.avatar_url
+ - workflow_run.triggering_actor.events_url
+ - workflow_run.triggering_actor.followers_url
+ - workflow_run.triggering_actor.following_url
+ - workflow_run.triggering_actor.gists_url
+ - workflow_run.triggering_actor.gravatar_id
+ - workflow_run.triggering_actor.html_url
+ - workflow_run.triggering_actor.id
+ - workflow_run.triggering_actor.login
+ - workflow_run.triggering_actor.node_id
+ - workflow_run.triggering_actor.organizations_url
+ - workflow_run.triggering_actor.received_events_url
+ - workflow_run.triggering_actor.repos_url
+ - workflow_run.triggering_actor.site_admin
+ - workflow_run.triggering_actor.starred_url
+ - workflow_run.triggering_actor.subscriptions_url
+ - workflow_run.triggering_actor.type
+ - workflow_run.triggering_actor.url
+ - workflow_run.updated_at
+ - workflow_run.url
+ - workflow_run.workflow_id
+ - workflow_run.workflow_url
example_log: '{"action":"requested","workflow_run":{"id":2088708615,"name":"auto-update","node_id":"WFR_kwLOCa00Ec58fyoH","head_branch":"mac_os_detections","head_sha":"4049334910ea3d52a917ca35aed66d11c80ed966","run_number":9504,"event":"push","status":"queued","conclusion":null,"workflow_id":4692335,"check_suite_id":5918781611,"check_suite_node_id":"CS_kwDOCa00Ec8AAAABYMlwqw","url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615","html_url":"https://github.com/splunk/security_content/actions/runs/2088708615","pull_requests":[{"url":"https://api.github.com/repos/splunk/security_content/pulls/2131","id":893091277,"number":2131,"head":{"ref":"mac_os_detections","sha":"4049334910ea3d52a917ca35aed66d11c80ed966","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}},"base":{"ref":"develop","sha":"a7d3d1dc57f9bf36fe22e470bcf518fcc2c89283","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}}}],"created_at":"2022-04-04T08:43:15Z","updated_at":"2022-04-04T08:43:15Z","actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"run_attempt":1,"run_started_at":"2022-04-04T08:43:15Z","triggering_actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"jobs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/jobs","logs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/logs","check_suite_url":"https://api.github.com/repos/splunk/security_content/check-suites/5918781611","artifacts_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/artifacts","cancel_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/cancel","rerun_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/rerun","previous_attempt_url":null,"workflow_url":"https://api.github.com/repos/splunk/security_content/actions/workflows/4692335","head_commit":{"id":"4049334910ea3d52a917ca35aed66d11c80ed966","tree_id":"df4ddc1359be3b19f093b7a27dbf5708187743a0","message":"small
change","timestamp":"2022-04-04T08:43:01Z","author":{"name":"jsmith","email":"jsmith@evilcorp.com"},"committer":{"name":"jsmith","email":"jsmith@evilcorp.com"}},"repository":{"id":162346001,"node_id":"MDEwOlJlcG9zaXRvcnkxNjIzNDYwMDE=","name":"security_content","full_name":"splunk/security_content","private":false,"owner":{"login":"splunk","id":651467,"node_id":"MDEyOk9yZ2FuaXphdGlvbjY1MTQ2Nw==","avatar_url":"https://avatars.githubusercontent.com/u/651467?v=4","gravatar_id":"","url":"https://api.github.com/users/splunk","html_url":"https://github.com/splunk","followers_url":"https://api.github.com/users/splunk/followers","following_url":"https://api.github.com/users/splunk/following{/other_user}","gists_url":"https://api.github.com/users/splunk/gists{/gist_id}","starred_url":"https://api.github.com/users/splunk/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/splunk/subscriptions","organizations_url":"https://api.github.com/users/splunk/orgs","repos_url":"https://api.github.com/users/splunk/repos","events_url":"https://api.github.com/users/splunk/events{/privacy}","received_events_url":"https://api.github.com/users/splunk/received_events","type":"Organization","site_admin":false},"html_url":"https://github.com/splunk/security_content","description":"Splunk
Security Content","fork":false,"url":"https://api.github.com/repos/splunk/security_content","forks_url":"https://api.github.com/repos/splunk/security_content/forks","keys_url":"https://api.github.com/repos/splunk/security_content/keys{/key_id}","collaborators_url":"https://api.github.com/repos/splunk/security_content/collaborators{/collaborator}","teams_url":"https://api.github.com/repos/splunk/security_content/teams","hooks_url":"https://api.github.com/repos/splunk/security_content/hooks","issue_events_url":"https://api.github.com/repos/splunk/security_content/issues/events{/number}","events_url":"https://api.github.com/repos/splunk/security_content/events","assignees_url":"https://api.github.com/repos/splunk/security_content/assignees{/user}","branches_url":"https://api.github.com/repos/splunk/security_content/branches{/branch}","tags_url":"https://api.github.com/repos/splunk/security_content/tags","blobs_url":"https://api.github.com/repos/splunk/security_content/git/blobs{/sha}","git_tags_url":"https://api.github.com/repos/splunk/security_content/git/tags{/sha}","git_refs_url":"https://api.github.com/repos/splunk/security_content/git/refs{/sha}","trees_url":"https://api.github.com/repos/splunk/security_content/git/trees{/sha}","statuses_url":"https://api.github.com/repos/splunk/security_content/statuses/{sha}","languages_url":"https://api.github.com/repos/splunk/security_content/languages","stargazers_url":"https://api.github.com/repos/splunk/security_content/stargazers","contributors_url":"https://api.github.com/repos/splunk/security_content/contributors","subscribers_url":"https://api.github.com/repos/splunk/security_content/subscribers","subscription_url":"https://api.github.com/repos/splunk/security_content/subscription","commits_url":"https://api.github.com/repos/splunk/security_content/commits{/sha}","git_commits_url":"https://api.github.com/repos/splunk/security_content/git/commits{/sha}","comments_url":"https://api.github.com/repos/splunk/security_content/comments{/number}","issue_comment_url":"https://api.github.com/repos/splunk/security_content/issues/comments{/number}","contents_url":"https://api.github.com/repos/splunk/security_content/contents/{+path}","compare_url":"https://api.github.com/repos/splunk/security_content/compare/{base}...{head}","merges_url":"https://api.github.com/repos/splunk/security_content/merges","archive_url":"https://api.github.com/repos/splunk/security_content/{archive_format}{/ref}","downloads_url":"https://api.github.com/repos/splunk/security_content/downloads","issues_url":"https://api.github.com/repos/splunk/security_content/issues{/number}","pulls_url":"https://api.github.com/repos/splunk/security_content/pulls{/number}","milestones_url":"https://api.github.com/repos/splunk/security_content/milestones{/number}","notifications_url":"https://api.github.com/repos/splunk/security_content/notifications{?since,all,participating}","labels_url":"https://api.github.com/repos/splunk/security_content/labels{/name}","releases_url":"https://api.github.com/repos/splunk/security_content/releases{/id}","deployments_url":"https://api.github.com/repos/splunk/security_content/deployments"},"head_repository":{"id":162346001,"node_id":"MDEwOlJlcG9zaXRvcnkxNjIzNDYwMDE=","name":"security_content","full_name":"splunk/security_content","private":false,"owner":{"login":"splunk","id":651467,"node_id":"MDEyOk9yZ2FuaXphdGlvbjY1MTQ2Nw==","avatar_url":"https://avatars.githubusercontent.com/u/651467?v=4","gravatar_id":"","url":"https://api.github.com/users/splunk","html_url":"https://github.com/splunk","followers_url":"https://api.github.com/users/splunk/followers","following_url":"https://api.github.com/users/splunk/following{/other_user}","gists_url":"https://api.github.com/users/splunk/gists{/gist_id}","starred_url":"https://api.github.com/users/splunk/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/splunk/subscriptions","organizations_url":"https://api.github.com/users/splunk/orgs","repos_url":"https://api.github.com/users/splunk/repos","events_url":"https://api.github.com/users/splunk/events{/privacy}","received_events_url":"https://api.github.com/users/splunk/received_events","type":"Organization","site_admin":false},"html_url":"https://github.com/splunk/security_content","description":"Splunk
diff --git a/data_sources/google_workspace_login_failure.yml b/data_sources/google_workspace_login_failure.yml
index 4f49e2a565..f853aa35f3 100644
--- a/data_sources/google_workspace_login_failure.yml
+++ b/data_sources/google_workspace_login_failure.yml
@@ -1,58 +1,59 @@
name: Google Workspace login_failure
id: cabec7cf-4008-4899-b47e-39c34a9a1255
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs failed login attempts to Google Workspace accounts, including details about the user, IP address, and reason for failure.
+description: Logs failed login attempts to Google Workspace accounts, including details
+ about the user, IP address, and reason for failure.
mitre_components:
-- User Account Authentication
-- Logon Session Metadata
-- User Account Metadata
-- Application Log Content
+ - User Account Authentication
+ - Logon Session Metadata
+ - User Account Metadata
+ - Application Log Content
source: gws:reports:admin
sourcetype: gws:reports:admin
separator: event.name
separator_value: login_failure
supported_TA:
-- name: Splunk Add-on for Google Workspace
- url: https://splunkbase.splunk.com/app/5556
- version: 3.0.2
+ - name: Splunk Add-on for Google Workspace
+ url: https://splunkbase.splunk.com/app/5556
+ version: 3.0.2
fields:
-- _time
-- actor.email
-- actor.profileId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- etag
-- event.name
-- event.parameters{}.multiValue{}
-- event.parameters{}.name
-- event.parameters{}.value
-- event.type
-- eventtype
-- host
-- id.applicationName
-- id.customerId
-- id.time
-- id.uniqueQualifier
-- index
-- ipAddress
-- kind
-- linecount
-- punct
-- source
-- sourcetype
-- splunk_server
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
+ - _time
+ - actor.email
+ - actor.profileId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - etag
+ - event.name
+ - event.parameters{}.multiValue{}
+ - event.parameters{}.name
+ - event.parameters{}.value
+ - event.type
+ - eventtype
+ - host
+ - id.applicationName
+ - id.customerId
+ - id.time
+ - id.uniqueQualifier
+ - index
+ - ipAddress
+ - kind
+ - linecount
+ - punct
+ - source
+ - sourcetype
+ - splunk_server
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
example_log: '{"kind": "admin#reports#activity", "id": {"time": "2022-10-12T01:05:35.119Z",
"uniqueQualifier": "720229394436", "applicationName": "login", "customerId": "C046r85ir"},
"etag": "\"JCPRxFaiNR1s5TJ6ecIH8OpGdY4efiOYXbIB65itOzY/_lixtTooT11WXorGf6w6ElN0m0g\"",
diff --git a/data_sources/google_workspace_login_success.yml b/data_sources/google_workspace_login_success.yml
index 723b1b2724..4f0d7d8265 100644
--- a/data_sources/google_workspace_login_success.yml
+++ b/data_sources/google_workspace_login_success.yml
@@ -1,56 +1,57 @@
name: Google Workspace login_success
id: bffe8013-9cdf-4fe6-9c1b-6784391a4951
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs successful login attempts to Google Workspace accounts, including details about the user, IP address, and session metadata.
+description: Logs successful login attempts to Google Workspace accounts, including
+ details about the user, IP address, and session metadata.
mitre_components:
-- User Account Authentication
-- Logon Session Creation
-- User Account Metadata
-- Logon Session Metadata
+ - User Account Authentication
+ - Logon Session Creation
+ - User Account Metadata
+ - Logon Session Metadata
source: gws:reports:admin
sourcetype: gws:reports:admin
separator: event.name
separator_value: login_success
supported_TA:
-- name: Splunk Add-on for Google Workspace
- url: https://splunkbase.splunk.com/app/5556
- version: 3.0.2
+ - name: Splunk Add-on for Google Workspace
+ url: https://splunkbase.splunk.com/app/5556
+ version: 3.0.2
fields:
-- _time
-- actor.email
-- actor.profileId
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- etag
-- event.name
-- event.parameters{}.boolValue
-- event.parameters{}.multiValue{}
-- event.parameters{}.name
-- event.parameters{}.value
-- event.type
-- host
-- id.applicationName
-- id.customerId
-- id.time
-- id.uniqueQualifier
-- index
-- ipAddress
-- kind
-- linecount
-- punct
-- source
-- sourcetype
-- splunk_server
-- timeendpos
-- timestartpos
+ - _time
+ - actor.email
+ - actor.profileId
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - etag
+ - event.name
+ - event.parameters{}.boolValue
+ - event.parameters{}.multiValue{}
+ - event.parameters{}.name
+ - event.parameters{}.value
+ - event.type
+ - host
+ - id.applicationName
+ - id.customerId
+ - id.time
+ - id.uniqueQualifier
+ - index
+ - ipAddress
+ - kind
+ - linecount
+ - punct
+ - source
+ - sourcetype
+ - splunk_server
+ - timeendpos
+ - timestartpos
example_log: '{"kind": "admin#reports#activity", "id": {"time": "2022-10-13T20:57:35.833Z",
"uniqueQualifier": "437744618349", "applicationName": "login", "customerId": "C046r85ir"},
"etag": "\"JCPRxFaiNR1s5TJ6ecIH8OpGdY4efiOYXbIB65itOzY/OgAbD-Tz8hSD1vUJWw7NLiJ5SF4\"",
diff --git a/data_sources/ivanti_vtm_audit.yml b/data_sources/ivanti_vtm_audit.yml
index a10ae34f02..389bf9b8d9 100644
--- a/data_sources/ivanti_vtm_audit.yml
+++ b/data_sources/ivanti_vtm_audit.yml
@@ -1,25 +1,27 @@
name: Ivanti VTM Audit
id: b04be6e5-2002-4a49-8722-52285635b8f5
-version: 1
-date: '2024-08-19'
+version: 2
+date: '2025-01-23'
author: Michael Haag, Splunk
-description: Logs administrative and operational activities in Ivanti Virtual Traffic Manager (VTM), including configuration changes, user actions, and system events.
+description: Logs administrative and operational activities in Ivanti Virtual Traffic
+ Manager (VTM), including configuration changes, user actions, and system events.
mitre_components:
-- Configuration Modification
-- Application Log Content
-- User Account Metadata
-- Host Status
-- Service Modification
+ - Configuration Modification
+ - Application Log Content
+ - User Account Metadata
+ - Host Status
+ - Service Modification
source: ivanti_vtm
sourcetype: ivanti_vtm_audit
supported_TA: []
fields:
-- _time
-- IP
-- MODUSER
-- OPERATION
-- MODGROUP
-- AUTH
-- USER
-- GROUP
-example_log: '[19/Aug/2024:19:41:22 +0000] USER=!!ABSENT!! GROUP=!!ABSENT!! AUTH=!!ABSENT!! IP=!!ABSENT!! OPERATION=adduser MODUSER=newadmin MODGROUP=admin'
+ - _time
+ - IP
+ - MODUSER
+ - OPERATION
+ - MODGROUP
+ - AUTH
+ - USER
+ - GROUP
+example_log: '[19/Aug/2024:19:41:22 +0000] USER=!!ABSENT!! GROUP=!!ABSENT!! AUTH=!!ABSENT!!
+ IP=!!ABSENT!! OPERATION=adduser MODUSER=newadmin MODGROUP=admin'
diff --git a/data_sources/kubernetes_audit.yml b/data_sources/kubernetes_audit.yml
index 9035f6c381..89588cee18 100644
--- a/data_sources/kubernetes_audit.yml
+++ b/data_sources/kubernetes_audit.yml
@@ -1,66 +1,67 @@
name: Kubernetes Audit
id: 6c25181a-0c07-4aaf-90e6-77ab1f0e6699
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs activities within a Kubernetes cluster, including API server requests, resource access, configuration changes, and user authentication events.
+description: Logs activities within a Kubernetes cluster, including API server requests,
+ resource access, configuration changes, and user authentication events.
mitre_components:
-- Pod Metadata
-- Pod Modification
-- Cluster Metadata
-- User Account Authentication
-- Configuration Modification
-- Application Log Content
+ - Pod Metadata
+ - Pod Modification
+ - Cluster Metadata
+ - User Account Authentication
+ - Configuration Modification
+ - Application Log Content
source: kubernetes
sourcetype: _json
supported_TA: []
fields:
-- _time
-- annotations.authorization.k8s.io/decision
-- annotations.authorization.k8s.io/reason
-- apiVersion
-- auditID
-- eventtype
-- host
-- index
-- kind
-- level
-- linecount
-- objectRef.apiGroup
-- objectRef.apiVersion
-- objectRef.namespace
-- objectRef.resource
-- punct
-- requestReceivedTimestamp
-- requestURI
-- responseObject.apiVersion
-- responseObject.code
-- responseObject.details.group
-- responseObject.details.kind
-- responseObject.kind
-- responseObject.message
-- responseObject.reason
-- responseObject.status
-- responseStatus.code
-- responseStatus.details.group
-- responseStatus.details.kind
-- responseStatus.message
-- responseStatus.reason
-- responseStatus.status
-- source
-- sourceIPs{}
-- sourcetype
-- splunk_server
-- stage
-- stageTimestamp
-- tag
-- tag::eventtype
-- timestamp
-- user.groups{}
-- user.uid
-- user.username
-- userAgent
-- verb
+ - _time
+ - annotations.authorization.k8s.io/decision
+ - annotations.authorization.k8s.io/reason
+ - apiVersion
+ - auditID
+ - eventtype
+ - host
+ - index
+ - kind
+ - level
+ - linecount
+ - objectRef.apiGroup
+ - objectRef.apiVersion
+ - objectRef.namespace
+ - objectRef.resource
+ - punct
+ - requestReceivedTimestamp
+ - requestURI
+ - responseObject.apiVersion
+ - responseObject.code
+ - responseObject.details.group
+ - responseObject.details.kind
+ - responseObject.kind
+ - responseObject.message
+ - responseObject.reason
+ - responseObject.status
+ - responseStatus.code
+ - responseStatus.details.group
+ - responseStatus.details.kind
+ - responseStatus.message
+ - responseStatus.reason
+ - responseStatus.status
+ - source
+ - sourceIPs{}
+ - sourcetype
+ - splunk_server
+ - stage
+ - stageTimestamp
+ - tag
+ - tag::eventtype
+ - timestamp
+ - user.groups{}
+ - user.uid
+ - user.username
+ - userAgent
+ - verb
example_log: '{"kind":"Event","apiVersion":"audit.k8s.io/v1","level":"RequestResponse","auditID":"582c31ab-4906-49bb-9ff9-872f980ccb84","stage":"ResponseComplete","requestURI":"/apis/batch/v1/namespaces/test2/jobs?fieldManager=kubectl-create\u0026fieldValidation=Strict","verb":"create","user":{"username":"k8s-test-user","uid":"aws-iam-authenticator:591511147606:AROAYTOGP2RLFHNBOTP5J","groups":["system:authenticated"]},"sourceIPs":["176.95.188.101"],"userAgent":"kubectl/v1.27.2
(darwin/arm64) kubernetes/7f6f68f","objectRef":{"resource":"jobs","namespace":"test2","apiGroup":"batch","apiVersion":"v1"},"responseStatus":{"metadata":{},"status":"Failure","message":"jobs.batch
is forbidden: User \"k8s-test-user\" cannot create resource \"jobs\" in API group
diff --git a/data_sources/kubernetes_falco.yml b/data_sources/kubernetes_falco.yml
index 6b21e39781..cff1b27f1c 100644
--- a/data_sources/kubernetes_falco.yml
+++ b/data_sources/kubernetes_falco.yml
@@ -1,54 +1,55 @@
name: Kubernetes Falco
id: 23c0eeed-840a-4711-a41b-6819c1ffbba5
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs suspicious or anomalous activities within a Kubernetes environment detected by Falco, including system calls, file access, and network activity.
+description: Logs suspicious or anomalous activities within a Kubernetes environment
+ detected by Falco, including system calls, file access, and network activity.
mitre_components:
-- File Access
-- Network Traffic Content
-- Process Creation
-- Process Modification
-- Application Log Content
-- Host Status
+ - File Access
+ - Network Traffic Content
+ - Process Creation
+ - Process Modification
+ - Application Log Content
+ - Host Status
source: kubernetes
sourcetype: kube:container:falco
supported_TA: []
fields:
-- _time
-- command
-- container_id
-- container_image
-- container_image_tag
-- container_name
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- evt_type
-- exe_flags
-- host
-- index
-- k8s_ns
-- k8s_pod_name
-- linecount
-- parent
-- proc_exepath
-- process
-- punct
-- source
-- sourcetype
-- splunk_server
-- terminal
-- timeendpos
-- timestartpos
-- user
-- user_loginuid
-- user_uid
+ - _time
+ - command
+ - container_id
+ - container_image
+ - container_image_tag
+ - container_name
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - evt_type
+ - exe_flags
+ - host
+ - index
+ - k8s_ns
+ - k8s_pod_name
+ - linecount
+ - parent
+ - proc_exepath
+ - process
+ - punct
+ - source
+ - sourcetype
+ - splunk_server
+ - terminal
+ - timeendpos
+ - timestartpos
+ - user
+ - user_loginuid
+ - user_uid
example_log: '12:18:18.691725165: Notice A shell was spawned in a container with an
attached terminal (evt_type=execve user=root user_uid=0 user_loginuid=-1 process=bash
proc_exepath=/usr/lib/splunk-otel-collector/agent-bundle/bin/bash parent=runc command=bash
diff --git a/data_sources/linux_auditd_add_user.yml b/data_sources/linux_auditd_add_user.yml
index 1b6bb6ba17..da361ede71 100644
--- a/data_sources/linux_auditd_add_user.yml
+++ b/data_sources/linux_auditd_add_user.yml
@@ -1,40 +1,44 @@
name: Linux Auditd Add User
id: 30f79353-e1d2-4585-8735-1e0359559f3f
-version: 1
-date: '2024-08-08'
+version: 2
+date: '2025-01-23'
author: Teoderick Contreras, Splunk
-description: Logs activities related to the addition of a new user account on a Linux system, including details about the username, UID, and the process initiating the action.
+description: Logs activities related to the addition of a new user account on a Linux
+ system, including details about the username, UID, and the process initiating the
+ action.
mitre_components:
-- User Account Creation
-- User Account Metadata
-- OS API Execution
-- Application Log Content
+ - User Account Creation
+ - User Account Metadata
+ - OS API Execution
+ - Application Log Content
source: /var/log/audit/audit.log
sourcetype: linux:audit
separator: type
separator_value: ADD_USER
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
-- name: Splunk Add-on for Unix and Linux
- url: https://splunkbase.splunk.com/app/833
- version: 9.2.0
+ - name: Splunk Add-on for Unix and Linux
+ url: https://splunkbase.splunk.com/app/833
+ version: 9.2.0
fields:
-- msg
-- type
-- pid
-- uid
-- auid
-- ses
-- subj
-- msg
-- op
-- id
-- exe
-- hostname
-- addr
-- terminal
-- res
-- UID
-- AUID
-- ID
-example_log: 'type=ADD_USER msg=audit(1722950859.266:6994): pid=1788 uid=0 auid=1000 ses=1 subj=unconfined msg=''op=adding user id=1002 exe="/usr/sbin/useradd" hostname=ar-linux1 addr=? terminal=pts/1 res=success''UID="root" AUID="ubuntu" ID="unknown(1002)"'
+ - msg
+ - type
+ - pid
+ - uid
+ - auid
+ - ses
+ - subj
+ - msg
+ - op
+ - id
+ - exe
+ - hostname
+ - addr
+ - terminal
+ - res
+ - UID
+ - AUID
+ - ID
+example_log: "type=ADD_USER msg=audit(1722950859.266:6994): pid=1788 uid=0 auid=1000
+ ses=1 subj=unconfined msg='op=adding user id=1002 exe=\"/usr/sbin/useradd\" hostname=ar-linux1
+ addr=? terminal=pts/1 res=success'UID=\"root\" AUID=\"ubuntu\" ID=\"unknown(1002)\""
diff --git a/data_sources/linux_auditd_execve.yml b/data_sources/linux_auditd_execve.yml
index f70b98a8f9..72433806de 100644
--- a/data_sources/linux_auditd_execve.yml
+++ b/data_sources/linux_auditd_execve.yml
@@ -1,27 +1,29 @@
name: Linux Auditd Execve
id: 9ef6364d-cc67-480e-8448-3306829a6a24
-version: 1
-date: '2024-08-08'
+version: 2
+date: '2025-01-23'
author: Teoderick Contreras, Splunk
-description: Logs the execution of processes on a Linux system, including details about the executed command, arguments, and the initiating process.
+description: Logs the execution of processes on a Linux system, including details
+ about the executed command, arguments, and the initiating process.
mitre_components:
-- Command Execution
-- Process Creation
-- Process Metadata
-- OS API Execution
-- Application Log Content
+ - Command Execution
+ - Process Creation
+ - Process Metadata
+ - OS API Execution
+ - Application Log Content
source: /var/log/audit/audit.log
sourcetype: linux:audit
separator: type
separator_value: EXECVE
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
-- name: Splunk Add-on for Unix and Linux
- url: https://splunkbase.splunk.com/app/833
- version: 9.2.0
+ - name: Splunk Add-on for Unix and Linux
+ url: https://splunkbase.splunk.com/app/833
+ version: 9.2.0
fields:
-- msg
-- type
-- msg
-- argc
-example_log: 'type=EXECVE msg=audit(1723044684.257:15795): argc=3 a0="sudo" a1="LD_PRELOAD=./myfopen.so" a2="./prog"'
+ - msg
+ - type
+ - msg
+ - argc
+example_log: 'type=EXECVE msg=audit(1723044684.257:15795): argc=3 a0="sudo" a1="LD_PRELOAD=./myfopen.so"
+ a2="./prog"'
diff --git a/data_sources/linux_auditd_path.yml b/data_sources/linux_auditd_path.yml
index 3dd0c9d22a..d612530b4e 100644
--- a/data_sources/linux_auditd_path.yml
+++ b/data_sources/linux_auditd_path.yml
@@ -1,41 +1,44 @@
name: Linux Auditd Path
id: 3d86125c-0496-4a5a-aae3-0d355a4f3d7d
-version: 1
-date: '2024-08-08'
+version: 2
+date: '2025-01-23'
author: Teoderick Contreras, Splunk
-description: Logs file system access events on a Linux system, including details about file paths, permissions, and associated processes.
+description: Logs file system access events on a Linux system, including details about
+ file paths, permissions, and associated processes.
mitre_components:
-- File Access
-- File Metadata
-- Process Metadata
-- OS API Execution
-- Application Log Content
+ - File Access
+ - File Metadata
+ - Process Metadata
+ - OS API Execution
+ - Application Log Content
source: /var/log/audit/audit.log
sourcetype: linux:audit
separator: type
separator_value: PATH
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
-- name: Splunk Add-on for Unix and Linux
- url: https://splunkbase.splunk.com/app/833
- version: 9.2.0
+ - name: Splunk Add-on for Unix and Linux
+ url: https://splunkbase.splunk.com/app/833
+ version: 9.2.0
fields:
-- msg
-- type
-- item
-- name
-- inode
-- dev
-- mode
-- ouid
-- ogid
-- rdev
-- nametype
-- cap_fp
-- cap_fi
-- cap_fe
-- cap_fver
-- cap_frootid
-- OUID
-- OGID
-example_log: 'type=PATH msg=audit(1723043687.149:14898): item=1 name="/etc/ssh/ssh_config~" inode=1292 dev=103:01 mode=0100644 ouid=0 ogid=0 rdev=00:00 nametype=DELETE cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0 OUID="root" OGID="root"'
+ - msg
+ - type
+ - item
+ - name
+ - inode
+ - dev
+ - mode
+ - ouid
+ - ogid
+ - rdev
+ - nametype
+ - cap_fp
+ - cap_fi
+ - cap_fe
+ - cap_fver
+ - cap_frootid
+ - OUID
+ - OGID
+example_log: 'type=PATH msg=audit(1723043687.149:14898): item=1 name="/etc/ssh/ssh_config~"
+ inode=1292 dev=103:01 mode=0100644 ouid=0 ogid=0 rdev=00:00 nametype=DELETE cap_fp=0
+ cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0 OUID="root" OGID="root"'
diff --git a/data_sources/linux_auditd_proctitle.yml b/data_sources/linux_auditd_proctitle.yml
index e0038b6a94..fbd067aed5 100644
--- a/data_sources/linux_auditd_proctitle.yml
+++ b/data_sources/linux_auditd_proctitle.yml
@@ -1,25 +1,26 @@
name: Linux Auditd Proctitle
id: 5a25984a-2789-400a-858b-d75c923e06b1
-version: 1
-date: '2024-08-08'
+version: 2
+date: '2025-01-23'
author: Teoderick Contreras, Splunk
-description: Logs the full command-line arguments of a process execution on a Linux system, providing visibility into the executed command and its parameters.
+description: Logs the full command-line arguments of a process execution on a Linux
+ system, providing visibility into the executed command and its parameters.
mitre_components:
-- Command Execution
-- Process Metadata
-- OS API Execution
-- Application Log Content
+ - Command Execution
+ - Process Metadata
+ - OS API Execution
+ - Application Log Content
separator: type
separator_value: PROCTITLE
source: /var/log/audit/audit.log
sourcetype: linux:audit
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
-- name: Splunk Add-on for Unix and Linux
- url: https://splunkbase.splunk.com/app/833
- version: 9.2.0
+ - name: Splunk Add-on for Unix and Linux
+ url: https://splunkbase.splunk.com/app/833
+ version: 9.2.0
fields:
-- proctitle
-- msg
-- type
+ - proctitle
+ - msg
+ - type
example_log: 'type=PROCTITLE msg=audit(1722944427.844:4146): proctitle=63686D6F640037373700312E7368'
diff --git a/data_sources/linux_auditd_service_stop.yml b/data_sources/linux_auditd_service_stop.yml
index 3c4f41bcbf..8b1c94b0f2 100644
--- a/data_sources/linux_auditd_service_stop.yml
+++ b/data_sources/linux_auditd_service_stop.yml
@@ -1,38 +1,42 @@
name: Linux Auditd Service Stop
id: 0643483c-bc62-455c-8d6e-1630e5f0e00d
-version: 1
-date: '2024-08-08'
+version: 2
+date: '2025-01-23'
author: Teoderick Contreras, Splunk
-description: Logs events related to the stoppage of a service on a Linux system, including details about the service name, the process initiating the stop, and associated timestamps.
+description: Logs events related to the stoppage of a service on a Linux system, including
+ details about the service name, the process initiating the stop, and associated
+ timestamps.
mitre_components:
-- Service Modification
-- Service Metadata
-- OS API Execution
-- Application Log Content
+ - Service Modification
+ - Service Metadata
+ - OS API Execution
+ - Application Log Content
separator: type
separator_value: SERVICE_STOP
source: /var/log/audit/audit.log
sourcetype: linux:audit
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
-- name: Splunk Add-on for Unix and Linux
- url: https://splunkbase.splunk.com/app/833
- version: 9.2.0
+ - name: Splunk Add-on for Unix and Linux
+ url: https://splunkbase.splunk.com/app/833
+ version: 9.2.0
fields:
-- msg
-- type
-- pid
-- uid
-- auid
-- ses
-- subj
-- msg
-- comm
-- exe
-- hostname
-- addr
-- terminal
-- res
-- UID
-- AUID
-example_log: 'type=SERVICE_STOP msg=audit(1722957155.494:4802): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=unconfined msg=''unit=atd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success''UID="root" AUID="unset"'
+ - msg
+ - type
+ - pid
+ - uid
+ - auid
+ - ses
+ - subj
+ - msg
+ - comm
+ - exe
+ - hostname
+ - addr
+ - terminal
+ - res
+ - UID
+ - AUID
+example_log: "type=SERVICE_STOP msg=audit(1722957155.494:4802): pid=1 uid=0 auid=4294967295
+ ses=4294967295 subj=unconfined msg='unit=atd comm=\"systemd\" exe=\"/usr/lib/systemd/systemd\"\
+ \ hostname=? addr=? terminal=? res=success'UID=\"root\" AUID=\"unset\""
diff --git a/data_sources/linux_auditd_syscall.yml b/data_sources/linux_auditd_syscall.yml
index 46f043e357..c753a66b54 100644
--- a/data_sources/linux_auditd_syscall.yml
+++ b/data_sources/linux_auditd_syscall.yml
@@ -1,61 +1,67 @@
name: Linux Auditd Syscall
id: 4dff7047-0d43-4096-bb3f-b756c889bbad
-version: 1
-date: '2024-08-08'
+version: 2
+date: '2025-01-23'
author: Teoderick Contreras, Splunk
-description: Logs system calls made by processes on a Linux system, including details about the syscall number, arguments, return values, and associated process metadata.
+description: Logs system calls made by processes on a Linux system, including details
+ about the syscall number, arguments, return values, and associated process metadata.
mitre_components:
-- OS API Execution
-- Process Metadata
-- Application Log Content
-- Host Status
+ - OS API Execution
+ - Process Metadata
+ - Application Log Content
+ - Host Status
source: /var/log/audit/audit.log
sourcetype: linux:audit
separator: type
separator_value: syscall
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
-- name: Splunk Add-on for Unix and Linux
- url: https://splunkbase.splunk.com/app/833
- version: 9.2.0
+ - name: Splunk Add-on for Unix and Linux
+ url: https://splunkbase.splunk.com/app/833
+ version: 9.2.0
fields:
-- msg
-- type
-- msg
-- arch
-- syscall
-- success
-- exit
-- a1
-- a2
-- a3
-- items
-- ppid
-- pid
-- auid
-- uid
-- gid
-- euid
-- suid
-- fsuid
-- egid
-- sgid
-- fsgid
-- tty
-- ses
-- comm
-- exe
-- subj
-- key
-- ARCH
-- SYSCALL
-- AUID
-- UID
-- GID
-- EUID
-- SUID
-- FSUID
-- EGID
-- SGID
-- FSGID
-example_log: 'type=SYSCALL msg=audit(1723035666.627:3663): arch=c000003e syscall=59 success=yes exit=0 a0=556a6d697a58 a1=556a6d68ad00 a2=556a6d69c980 a3=0 items=2 ppid=1300 pid=1301 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=1 comm="lsmod" exe="/usr/bin/kmod" subj=unconfined key="rootcmd" ARCH=x86_64 SYSCALL=execve AUID="ubuntu" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"'
+ - msg
+ - type
+ - msg
+ - arch
+ - syscall
+ - success
+ - exit
+ - a1
+ - a2
+ - a3
+ - items
+ - ppid
+ - pid
+ - auid
+ - uid
+ - gid
+ - euid
+ - suid
+ - fsuid
+ - egid
+ - sgid
+ - fsgid
+ - tty
+ - ses
+ - comm
+ - exe
+ - subj
+ - key
+ - ARCH
+ - SYSCALL
+ - AUID
+ - UID
+ - GID
+ - EUID
+ - SUID
+ - FSUID
+ - EGID
+ - SGID
+ - FSGID
+example_log: 'type=SYSCALL msg=audit(1723035666.627:3663): arch=c000003e syscall=59
+ success=yes exit=0 a0=556a6d697a58 a1=556a6d68ad00 a2=556a6d69c980 a3=0 items=2
+ ppid=1300 pid=1301 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0
+ tty=pts1 ses=1 comm="lsmod" exe="/usr/bin/kmod" subj=unconfined key="rootcmd" ARCH=x86_64
+ SYSCALL=execve AUID="ubuntu" UID="root" GID="root" EUID="root" SUID="root" FSUID="root"
+ EGID="root" SGID="root" FSGID="root"'
diff --git a/data_sources/linux_secure.yml b/data_sources/linux_secure.yml
index 1f1c1917e3..e6f8b78160 100644
--- a/data_sources/linux_secure.yml
+++ b/data_sources/linux_secure.yml
@@ -1,53 +1,54 @@
name: Linux Secure
id: 9a47d88b-1b17-49ce-a0ef-b440ddbd98bb
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs authentication and authorization events on a Linux system, including login attempts, SSH connections, and privilege escalation activities.
+description: Logs authentication and authorization events on a Linux system, including
+ login attempts, SSH connections, and privilege escalation activities.
mitre_components:
-- User Account Authentication
-- Logon Session Creation
-- Logon Session Metadata
-- User Account Metadata
-- Application Log Content
+ - User Account Authentication
+ - Logon Session Creation
+ - Logon Session Metadata
+ - User Account Metadata
+ - Application Log Content
source: /var/log/secure
sourcetype: linux_secure
supported_TA: []
fields:
-- _time
-- action
-- app
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- eventtype
-- host
-- index
-- linecount
-- pid
-- process
-- punct
-- source
-- sourcetype
-- splunk_server
-- src
-- src_port
-- sshd_protocol
-- tag
-- tag::action
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- user_name
-- vendor_action
-- vendor_product
+ - _time
+ - action
+ - app
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - eventtype
+ - host
+ - index
+ - linecount
+ - pid
+ - process
+ - punct
+ - source
+ - sourcetype
+ - splunk_server
+ - src
+ - src_port
+ - sshd_protocol
+ - tag
+ - tag::action
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - user_name
+ - vendor_action
+ - vendor_product
example_log: 'May 27 09:28:36 ip-172-31-24-46 sshd[5617]: Accepted password for mikael
from 84.202.159.161 port 63487 ssh2'
diff --git a/data_sources/ms365_defender_incident_alerts.yml b/data_sources/ms365_defender_incident_alerts.yml
index d8114c0151..80e582df46 100644
--- a/data_sources/ms365_defender_incident_alerts.yml
+++ b/data_sources/ms365_defender_incident_alerts.yml
@@ -1,189 +1,241 @@
name: MS365 Defender Incident Alerts
id: 12345678-90ab-cdef-1234-567890abcdef
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Bhavin Patel, Splunk
-description: Logs security incidents and correlated alerts in Microsoft 365 Defender, including details about affected assets, threat types, and remediation steps.
+description: Logs security incidents and correlated alerts in Microsoft 365 Defender,
+ including details about affected assets, threat types, and remediation steps.
mitre_components:
-- Host Status
-- User Account Metadata
-- Application Log Content
-- Malware Metadata
-- Active Directory Object Access
+ - Host Status
+ - User Account Metadata
+ - Application Log Content
+ - Malware Metadata
+ - Active Directory Object Access
source: ms365_defender_incident_alerts
sourcetype: ms365:defender:incident:alerts
supported_TA:
-- name: Splunk Add-on for Microsoft Security
- url: https://splunkbase.splunk.com/app/6207
- version: 2.4.1
+ - name: Splunk Add-on for Microsoft Security
+ url: https://splunkbase.splunk.com/app/6207
+ version: 2.4.1
fields:
-- actorName
-- alertId
-- app
-- assignedTo
-- body
-- category
-- classification
-- creationTime
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- description
-- dest
-- detectionSource
-- detectorId
-- determination
-- devices{}.aadDeviceId
-- devices{}.defenderAvStatus
-- devices{}.deviceDnsName
-- devices{}.firstSeen
-- devices{}.healthStatus
-- devices{}.loggedOnUsers{}.accountName
-- devices{}.loggedOnUsers{}.domainName
-- devices{}.mdatpDeviceId
-- devices{}.onboardingStatus
-- devices{}.osBuild
-- devices{}.osPlatform
-- devices{}.osProcessor
-- devices{}.rbacGroupName
-- devices{}.riskScore
-- devices{}.version
-- devices{}.vmMetadata
-- devices{}.vmMetadata.cloudProvider
-- devices{}.vmMetadata.resourceId
-- devices{}.vmMetadata.subscriptionId
-- devices{}.vmMetadata.vmId
-- entities{}.aadUserId
-- entities{}.accountName
-- entities{}.applicationId
-- entities{}.applicationName
-- entities{}.detectionStatus
-- entities{}.deviceId
-- entities{}.domainName
-- entities{}.entityType
-- entities{}.evidenceCreationTime
-- entities{}.fileName
-- entities{}.filePath
-- entities{}.ipAddress
-- entities{}.parentProcessCreationTime
-- entities{}.parentProcessFileName
-- entities{}.parentProcessFilePath
-- entities{}.parentProcessId
-- entities{}.processCommandLine
-- entities{}.processCreationTime
-- entities{}.processId
-- entities{}.remediationStatus
-- entities{}.remediationStatusDetails
-- entities{}.sha1
-- entities{}.sha256
-- entities{}.userPrincipalName
-- entities{}.userSid
-- entities{}.verdict
-- eventtype
-- firstActivity
-- host
-- id
-- incidentId
-- index
-- investigationId
-- investigationState
-- lastActivity
-- lastUpdatedTime
-- linecount
-- mitreTechniques{}
-- mitre_technique_id
-- providerAlertId
-- resolvedTime
-- serviceSource
-- severity
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- splunk_server_group
-- src
-- status
-- subject
-- tag
-- tag::app
-- tag::eventtype
-- threatFamilyName
-- timeendpos
-- timestartpos
-- title
-- type
-- user
-- user_name
-- _bkt
-- _cd
-- _eventtype_color
-- _indextime
-- _raw
-- _serial
-- _si
-- _sourcetype
-- _subsecond
-- _time
-example_log: "{\n \"alertId\": \"da638001130101730338_582949328\",\n \"providerAlertId\"\
- : \"da638001130101730338_582949328\",\n \"incidentId\": 486,\n \"serviceSource\"\
- : \"MicrosoftDefenderForEndpoint\",\n \"creationTime\": \"2022-09-30T05:36:50.1732198Z\"\
- ,\n \"lastUpdatedTime\": \"2022-11-19T01:35:42.7033333Z\",\n \"resolvedTime\"\
- : \"2022-10-01T01:36:00.5066667Z\",\n \"firstActivity\": \"2022-09-30T05:06:43.8196597Z\"\
- ,\n \"lastActivity\": \"2022-09-30T05:06:43.8196597Z\",\n \"title\": \"Suspicious\
- \ URL clicked\",\n \"description\": \"A user opened a potentially malicious URL.\
- \ This alert was triggered based on a Microsoft Defender for Office 365 alert.\"\
- ,\n \"category\": \"InitialAccess\",\n \"status\": \"Resolved\",\n \"severity\"\
- : \"High\",\n \"investigationId\": null,\n \"investigationState\": \"UnsupportedAlertType\"\
- ,\n \"classification\": \"TruePositive\",\n \"determination\": \"SecurityTesting\"\
- ,\n \"detectionSource\": \"MTP\",\n \"detectorId\": \"359b36eb-337c-4f1c-b280-8c5e08f9c4a0\"\
- ,\n \"assignedTo\": \"msftadmin@metal.m365dpoc.com\",\n \"actorName\": null,\n\
- \ \"threatFamilyName\": null,\n \"mitreTechniques\": [\n \"T1566.002\"\n ],\n\
- \ \"devices\": [\n {\n \"mdatpDeviceId\": \"c7e147cb0eb3534a4dcea5acb8e61c933713b145\"\
- ,\n \"aadDeviceId\": null,\n \"deviceDnsName\": \"metal-win10v.metal.m365dpoc.com\"\
- ,\n \"osPlatform\": \"Windows10\",\n \"version\": \"1809\",\n \"\
- osProcessor\": \"x64\",\n \"osBuild\": 17763,\n \"healthStatus\": \"Active\"\
- ,\n \"riskScore\": \"High\",\n \"rbacGroupName\": \"Full Auto Clients\"\
- ,\n \"firstSeen\": \"2022-08-08T08:51:02.455Z\",\n \"tags\": [\n \
- \ \"Full auto\"\n ],\n \"defenderAvStatus\": \"Updated\",\n \"\
- onboardingStatus\": \"Onboarded\",\n \"vmMetadata\": {\n \"vmId\": \"\
- 17881b39-b03f-4a2c-9b56-078be1330bd0\",\n \"cloudProvider\": \"Unknown\"\
- ,\n \"resourceId\": \"/subscriptions/29e73d07-8740-4164-a257-592a19a7b77c/resourceGroups/MSDXV2/providers/Microsoft.Compute/virtualMachines/MSDXV2-Win10V\"\
- ,\n \"subscriptionId\": \"29e73d07-8740-4164-a257-592a19a7b77c\"\n },\n\
- \ \"loggedOnUsers\": [\n {\n \"accountName\": \"hetfield\"\
- ,\n \"domainName\": \"MSDXV2\"\n }\n ]\n }\n ],\n \"entities\"\
- : [\n {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\":\
- \ \"2022-09-30T05:36:50.2133333Z\",\n \"verdict\": \"Suspicious\",\n \"\
- remediationStatus\": \"None\",\n \"sha1\": \"6cbce4a295c163791b60fc23d285e6d84f28ee4c\"\
- ,\n \"sha256\": \"de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c\"\
- ,\n \"fileName\": \"powershell.exe\",\n \"filePath\": \"\",\n \"\
- processId\": 7068,\n \"processCommandLine\": \"powershell.exe -command \\\"\
- \ $Process = New-Object\
- \ System.Diagnostics.Process; \
- \ $Process.StartInfo.FileName = 'https://nam12.safelinks.protection.outlook.com/?url=http%3A%2F%2Fgcajebahdi.corporatelogon.xyz%2Fab%2Fjnkmbkkdnlgedc&data=05%7C01%7Chetfield%40metal.m365dpoc.com%7Cca409616a82145bd6a5f08daa2a10255%7C1a49212958c8401191cd245285f5345c%7C0%7C0%7C638001109710345383%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=FyEjRS5qOd2SkJELlueibuxLFMYNjL7fz8EbuOAvFwg%3D&reserved=0';\
- \ $Process.StartInfo.UseShellExecute\
- \ = $true; $Process.Start()\
- \ | Out-Null; \\\" \
- \ \",\n \"processCreationTime\"\
- : \"2022-09-30T05:06:43.3390523Z\",\n \"parentProcessId\": 7116,\n \"\
- parentProcessCreationTime\": \"2022-09-30T05:06:43.3100364Z\",\n \"accountName\"\
- : \"hetfield\",\n \"userSid\": \"S-1-5-21-2300221942-1987151257-321556088-1104\"\
- \n },\n {\n \"entityType\": \"File\",\n \"evidenceCreationTime\"\
- : \"2022-09-30T05:36:50.2133333Z\",\n \"verdict\": \"Suspicious\",\n \"\
- remediationStatus\": \"None\",\n \"sha1\": \"6cbce4a295c163791b60fc23d285e6d84f28ee4c\"\
- ,\n \"sha256\": \"de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c\"\
- ,\n \"fileName\": \"powershell.exe\",\n \"filePath\": \"\"\n },\n \
- \ {\n \"entityType\": \"User\",\n \"evidenceCreationTime\": \"2022-09-30T05:36:50.2133333Z\"\
- ,\n \"verdict\": \"Suspicious\",\n \"remediationStatus\": \"None\",\n\
- \ \"accountName\": \"hetfield\",\n \"domainName\": \"metal.m365dpoc\"\
- ,\n \"userSid\": \"S-1-5-21-2300221942-1987151257-321556088-1104\",\n \
- \ \"aadUserId\": \"e848b07a-87af-4448-9979-09f0b809c8d4\",\n \"userPrincipalName\"\
- : \"daftpunk\"\n },\n {\n \"entityType\": \"Url\",\n \"evidenceCreationTime\"\
- : \"2022-09-30T05:36:50.2133333Z\",\n \"verdict\": \"Suspicious\",\n \"\
- remediationStatus\": \"None\",\n \"url\": \"http://gcajebahdi.corporatelogon.xyz/ab/jnkmbkkdnlgedc\"\
- \n }\n ]\n}"
+ - actorName
+ - alertId
+ - app
+ - assignedTo
+ - body
+ - category
+ - classification
+ - creationTime
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - description
+ - dest
+ - detectionSource
+ - detectorId
+ - determination
+ - devices{}.aadDeviceId
+ - devices{}.defenderAvStatus
+ - devices{}.deviceDnsName
+ - devices{}.firstSeen
+ - devices{}.healthStatus
+ - devices{}.loggedOnUsers{}.accountName
+ - devices{}.loggedOnUsers{}.domainName
+ - devices{}.mdatpDeviceId
+ - devices{}.onboardingStatus
+ - devices{}.osBuild
+ - devices{}.osPlatform
+ - devices{}.osProcessor
+ - devices{}.rbacGroupName
+ - devices{}.riskScore
+ - devices{}.version
+ - devices{}.vmMetadata
+ - devices{}.vmMetadata.cloudProvider
+ - devices{}.vmMetadata.resourceId
+ - devices{}.vmMetadata.subscriptionId
+ - devices{}.vmMetadata.vmId
+ - entities{}.aadUserId
+ - entities{}.accountName
+ - entities{}.applicationId
+ - entities{}.applicationName
+ - entities{}.detectionStatus
+ - entities{}.deviceId
+ - entities{}.domainName
+ - entities{}.entityType
+ - entities{}.evidenceCreationTime
+ - entities{}.fileName
+ - entities{}.filePath
+ - entities{}.ipAddress
+ - entities{}.parentProcessCreationTime
+ - entities{}.parentProcessFileName
+ - entities{}.parentProcessFilePath
+ - entities{}.parentProcessId
+ - entities{}.processCommandLine
+ - entities{}.processCreationTime
+ - entities{}.processId
+ - entities{}.remediationStatus
+ - entities{}.remediationStatusDetails
+ - entities{}.sha1
+ - entities{}.sha256
+ - entities{}.userPrincipalName
+ - entities{}.userSid
+ - entities{}.verdict
+ - eventtype
+ - firstActivity
+ - host
+ - id
+ - incidentId
+ - index
+ - investigationId
+ - investigationState
+ - lastActivity
+ - lastUpdatedTime
+ - linecount
+ - mitreTechniques{}
+ - mitre_technique_id
+ - providerAlertId
+ - resolvedTime
+ - serviceSource
+ - severity
+ - signature
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - splunk_server_group
+ - src
+ - status
+ - subject
+ - tag
+ - tag::app
+ - tag::eventtype
+ - threatFamilyName
+ - timeendpos
+ - timestartpos
+ - title
+ - type
+ - user
+ - user_name
+ - _bkt
+ - _cd
+ - _eventtype_color
+ - _indextime
+ - _raw
+ - _serial
+ - _si
+ - _sourcetype
+ - _subsecond
+ - _time
+example_log: |-
+ {
+ "alertId": "da638001130101730338_582949328",
+ "providerAlertId": "da638001130101730338_582949328",
+ "incidentId": 486,
+ "serviceSource": "MicrosoftDefenderForEndpoint",
+ "creationTime": "2022-09-30T05:36:50.1732198Z",
+ "lastUpdatedTime": "2022-11-19T01:35:42.7033333Z",
+ "resolvedTime": "2022-10-01T01:36:00.5066667Z",
+ "firstActivity": "2022-09-30T05:06:43.8196597Z",
+ "lastActivity": "2022-09-30T05:06:43.8196597Z",
+ "title": "Suspicious URL clicked",
+ "description": "A user opened a potentially malicious URL. This alert was triggered based on a Microsoft Defender for Office 365 alert.",
+ "category": "InitialAccess",
+ "status": "Resolved",
+ "severity": "High",
+ "investigationId": null,
+ "investigationState": "UnsupportedAlertType",
+ "classification": "TruePositive",
+ "determination": "SecurityTesting",
+ "detectionSource": "MTP",
+ "detectorId": "359b36eb-337c-4f1c-b280-8c5e08f9c4a0",
+ "assignedTo": "msftadmin@metal.m365dpoc.com",
+ "actorName": null,
+ "threatFamilyName": null,
+ "mitreTechniques": [
+ "T1566.002"
+ ],
+ "devices": [
+ {
+ "mdatpDeviceId": "c7e147cb0eb3534a4dcea5acb8e61c933713b145",
+ "aadDeviceId": null,
+ "deviceDnsName": "metal-win10v.metal.m365dpoc.com",
+ "osPlatform": "Windows10",
+ "version": "1809",
+ "osProcessor": "x64",
+ "osBuild": 17763,
+ "healthStatus": "Active",
+ "riskScore": "High",
+ "rbacGroupName": "Full Auto Clients",
+ "firstSeen": "2022-08-08T08:51:02.455Z",
+ "tags": [
+ "Full auto"
+ ],
+ "defenderAvStatus": "Updated",
+ "onboardingStatus": "Onboarded",
+ "vmMetadata": {
+ "vmId": "17881b39-b03f-4a2c-9b56-078be1330bd0",
+ "cloudProvider": "Unknown",
+ "resourceId": "/subscriptions/29e73d07-8740-4164-a257-592a19a7b77c/resourceGroups/MSDXV2/providers/Microsoft.Compute/virtualMachines/MSDXV2-Win10V",
+ "subscriptionId": "29e73d07-8740-4164-a257-592a19a7b77c"
+ },
+ "loggedOnUsers": [
+ {
+ "accountName": "hetfield",
+ "domainName": "MSDXV2"
+ }
+ ]
+ }
+ ],
+ "entities": [
+ {
+ "entityType": "Process",
+ "evidenceCreationTime": "2022-09-30T05:36:50.2133333Z",
+ "verdict": "Suspicious",
+ "remediationStatus": "None",
+ "sha1": "6cbce4a295c163791b60fc23d285e6d84f28ee4c",
+ "sha256": "de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c",
+ "fileName": "powershell.exe",
+ "filePath": "",
+ "processId": 7068,
+ "processCommandLine": "powershell.exe -command \" $Process = New-Object System.Diagnostics.Process; $Process.StartInfo.FileName = 'https://nam12.safelinks.protection.outlook.com/?url=http%3A%2F%2Fgcajebahdi.corporatelogon.xyz%2Fab%2Fjnkmbkkdnlgedc&data=05%7C01%7Chetfield%40metal.m365dpoc.com%7Cca409616a82145bd6a5f08daa2a10255%7C1a49212958c8401191cd245285f5345c%7C0%7C0%7C638001109710345383%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=FyEjRS5qOd2SkJELlueibuxLFMYNjL7fz8EbuOAvFwg%3D&reserved=0'; $Process.StartInfo.UseShellExecute = $true; $Process.Start() | Out-Null; \" ",
+ "processCreationTime": "2022-09-30T05:06:43.3390523Z",
+ "parentProcessId": 7116,
+ "parentProcessCreationTime": "2022-09-30T05:06:43.3100364Z",
+ "accountName": "hetfield",
+ "userSid": "S-1-5-21-2300221942-1987151257-321556088-1104"
+ },
+ {
+ "entityType": "File",
+ "evidenceCreationTime": "2022-09-30T05:36:50.2133333Z",
+ "verdict": "Suspicious",
+ "remediationStatus": "None",
+ "sha1": "6cbce4a295c163791b60fc23d285e6d84f28ee4c",
+ "sha256": "de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c",
+ "fileName": "powershell.exe",
+ "filePath": ""
+ },
+ {
+ "entityType": "User",
+ "evidenceCreationTime": "2022-09-30T05:36:50.2133333Z",
+ "verdict": "Suspicious",
+ "remediationStatus": "None",
+ "accountName": "hetfield",
+ "domainName": "metal.m365dpoc",
+ "userSid": "S-1-5-21-2300221942-1987151257-321556088-1104",
+ "aadUserId": "e848b07a-87af-4448-9979-09f0b809c8d4",
+ "userPrincipalName": "daftpunk"
+ },
+ {
+ "entityType": "Url",
+ "evidenceCreationTime": "2022-09-30T05:36:50.2133333Z",
+ "verdict": "Suspicious",
+ "remediationStatus": "None",
+ "url": "http://gcajebahdi.corporatelogon.xyz/ab/jnkmbkkdnlgedc"
+ }
+ ]
+ }
diff --git a/data_sources/ms_defender_atp_alerts.yml b/data_sources/ms_defender_atp_alerts.yml
index 09026a67d5..f1f68b0b7e 100644
--- a/data_sources/ms_defender_atp_alerts.yml
+++ b/data_sources/ms_defender_atp_alerts.yml
@@ -1,278 +1,429 @@
name: MS Defender ATP Alerts
id: 38f034ed-1598-46c8-95e8-14edf01fdf5d
-version: 1
-date: '2024-10-30'
+version: 2
+date: '2025-01-23'
author: Bryan Pluta, Bhavin Patel, Splunk
-description: Logs security alerts generated by Microsoft Defender for Endpoint, including information about detected threats, impacted devices, and recommended actions.
+description: Logs security alerts generated by Microsoft Defender for Endpoint, including
+ information about detected threats, impacted devices, and recommended actions.
mitre_components:
-- Host Status
-- Malware Metadata
-- Process Metadata
-- User Account Metadata
-- Application Log Content
+ - Host Status
+ - Malware Metadata
+ - Process Metadata
+ - User Account Metadata
+ - Application Log Content
source: ms_defender_atp_alerts
sourcetype: ms:defender:atp:alerts
supported_TA:
-- name: Splunk Add-on for Microsoft Security
- url: https://splunkbase.splunk.com/app/6207
- version: 2.4.1
+ - name: Splunk Add-on for Microsoft Security
+ url: https://splunkbase.splunk.com/app/6207
+ version: 2.4.1
fields:
-- column
-- accountName
-- action
-- activity
-- activityType
-- actor
-- actorName
-- alertId
-- app
-- assignedTo
-- body
-- category
-- classification
-- creationTime
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- description
-- dest
-- detectionSource
-- detectorId
-- determination
-- devices{}.aadDeviceId
-- devices{}.defenderAvStatus
-- devices{}.deviceDnsName
-- devices{}.firstSeen
-- devices{}.healthStatus
-- devices{}.loggedOnUsers{}.accountName
-- devices{}.loggedOnUsers{}.domainName
-- devices{}.mdatpDeviceId
-- devices{}.onboardingStatus
-- devices{}.osBuild
-- devices{}.osPlatform
-- devices{}.osProcessor
-- devices{}.rbacGroupName
-- devices{}.riskScore
-- devices{}.version
-- devices{}.vmMetadata
-- devices{}.vmMetadata.cloudProvider
-- devices{}.vmMetadata.resourceId
-- devices{}.vmMetadata.subscriptionId
-- devices{}.vmMetadata.vmId
-- entities{}.aadUserId
-- entities{}.accountName
-- entities{}.applicationId
-- entities{}.applicationName
-- entities{}.detectionStatus
-- entities{}.deviceId
-- entities{}.domainName
-- entities{}.entityType
-- entities{}.evidenceCreationTime
-- entities{}.fileName
-- entities{}.filePath
-- entities{}.ipAddress
-- entities{}.parentProcessCreationTime
-- entities{}.parentProcessFileName
-- entities{}.parentProcessFilePath
-- entities{}.parentProcessId
-- entities{}.processCommandLine
-- entities{}.processCreationTime
-- entities{}.processId
-- entities{}.remediationStatus
-- entities{}.remediationStatusDetails
-- entities{}.sha1
-- entities{}.sha256
-- entities{}.userPrincipalName
-- entities{}.userSid
-- entities{}.verdict
-- eventtype
-- firstActivity
-- host
-- id
-- incidentId
-- index
-- investigationId
-- investigationState
-- lastActivity
-- lastUpdatedTime
-- linecount
-- mitreTechniques{}
-- mitre_technique_id
-- providerAlertId
-- resolvedTime
-- serviceSource
-- severity
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- splunk_server_group
-- src
-- status
-- subject
-- tag
-- tag::app
-- tag::eventtype
-- threatFamilyName
-- timeendpos
-- timestartpos
-- title
-- type
-- user
-- user_name
-- _time
-example_log: "{\n\"id\": \"da47dc5671-e560-4229-984b-457564996b31_1\",\n\"incidentId\"\
- : 989,\n\"investigationId\": null,\n\"assignedTo\": null,\n\"severity\": \"High\"\
- ,\n\"status\": \"New\",\n\"classification\": null,\n\"determination\": null,\n\"\
- investigationState\": \"UnsupportedAlertType\",\n\"detectionSource\": \"WindowsDefenderAtp\"\
- ,\n\"detectorId\": \"9c3a70ec-e18a-4f92-865a-530f73130b7c\",\n\"category\": \"LateralMovement\"\
- ,\n\"threatFamilyName\": null,\n\"title\": \"Ongoing hands-on-keyboard attack via\
- \ Impacket toolkit\",\n\"description\": \"Suspicious execution of a command via\
- \ Impacket was observed on this device. This tool connects to other hosts to explore\
- \ network shares and execute commands. Attackers might be attempting to move laterally\
- \ across the network using this tool. This usage of Impacket has often been observed\
- \ in hands-on-keyboard attacks, where ransomware and other payloads are installed\
- \ on target devices.\",\n\"alertCreationTime\": \"2023-01-24T05:33:37.3245808Z\"\
- ,\n\"firstEventTime\": \"2023-01-24T05:31:07.5276179Z\",\n\"lastEventTime\": \"\
- 2023-01-24T13:02:50.7831636Z\",\n\"lastUpdateTime\": \"2023-01-24T13:07:13.3233333Z\"\
- ,\n\"resolvedTime\": null,\n\"machineId\": \"302293d9f276eae65553e5042156bce93cbc7148\"\
- ,\n\"computerDnsName\": \"diytestmachine\",\n\"rbacGroupName\": \"UnassignedGroup\"\
- ,\n\"aadTenantId\": \"1a492129-58c8-4011-91cd-245285f5345c\",\n\"threatName\": null,\n\
- \"mitreTechniques\": [\n \"T1021.002\",\n \"T1047\",\n \"T1059.003\"\n],\n\"\
- relatedUser\": {\n \"userName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\"\
- \n},\n\"loggedOnUsers\": [\n {\n \"accountName\": \"administrator1\",\n \"\
- domainName\": \"DIYTESTMACHINE\"\n }\n],\n\"comments\": [],\n\"evidence\": [\n\
- \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:45:51.6833333Z\"\
- ,\n \"sha1\": \"3ea7cc066317ac45f963c2227c4c7c50aa16eb7c\",\n \"sha256\":\
- \ \"2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3\",\n \"\
- fileName\": \"WmiPrvSE.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\\\\\
- wbem\",\n \"processId\": 4476,\n \"processCommandLine\": \"wmiprvse.exe -secured\
- \ -Embedding\",\n \"processCreationTime\": \"2023-01-24T05:43:32.4631151Z\",\n\
- \ \"parentProcessId\": 896,\n \"parentProcessCreationTime\": \"2023-01-24T04:44:17.1940386Z\"\
- ,\n \"parentProcessFileName\": \"svchost.exe\",\n \"parentProcessFilePath\"\
- : \"C:\\\\Windows\\\\System32\",\n \"ipAddress\": null,\n \"url\": null,\n\
- \ \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\
- : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\
- accountName\": \"NETWORK SERVICE\",\n \"domainName\": \"NT AUTHORITY\",\n \
- \ \"userSid\": \"S-1-5-20\",\n \"aadUserId\": null,\n \"userPrincipalName\"\
- : null,\n \"detectionStatus\": \"Detected\"\n },\n {\n \"entityType\": \"\
- User\",\n \"evidenceCreationTime\": \"2023-01-24T05:33:37.4166667Z\",\n \"\
- sha1\": null,\n \"sha256\": null,\n \"fileName\": null,\n \"filePath\"\
- : null,\n \"processId\": null,\n \"processCommandLine\": null,\n \"processCreationTime\"\
- : null,\n \"parentProcessId\": null,\n \"parentProcessCreationTime\": null,\n\
- \ \"parentProcessFileName\": null,\n \"parentProcessFilePath\": null,\n \
- \ \"ipAddress\": null,\n \"url\": null,\n \"registryKey\": null,\n \"\
- registryHive\": null,\n \"registryValueType\": null,\n \"registryValue\":\
- \ null,\n \"registryValueName\": null,\n \"accountName\": \"User1\",\n \
- \ \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\": \"S-1-5-21-4215714199-1288013905-3478400915-1002\"\
- ,\n \"aadUserId\": null,\n \"userPrincipalName\": null,\n \"detectionStatus\"\
- : null\n },\n {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\"\
- : \"2023-01-24T05:33:37.4166667Z\",\n \"sha1\": \"3ea7cc066317ac45f963c2227c4c7c50aa16eb7c\"\
- ,\n \"sha256\": \"2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3\"\
- ,\n \"fileName\": \"WmiPrvSE.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\\\
- \\wbem\",\n \"processId\": 7824,\n \"processCommandLine\": \"wmiprvse.exe\
- \ -secured -Embedding\",\n \"processCreationTime\": \"2023-01-24T05:30:50.8649791Z\"\
- ,\n \"parentProcessId\": 896,\n \"parentProcessCreationTime\": \"2023-01-24T04:44:17.1940386Z\"\
- ,\n \"parentProcessFileName\": \"svchost.exe\",\n \"parentProcessFilePath\"\
- : \"C:\\\\Windows\\\\System32\",\n \"ipAddress\": null,\n \"url\": null,\n\
- \ \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\
- : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\
- accountName\": \"NETWORK SERVICE\",\n \"domainName\": \"NT AUTHORITY\",\n \
- \ \"userSid\": \"S-1-5-20\",\n \"aadUserId\": null,\n \"userPrincipalName\"\
- : null,\n \"detectionStatus\": \"Detected\"\n },\n {\n \"entityType\": \"\
- Process\",\n \"evidenceCreationTime\": \"2023-01-24T13:07:13.2233333Z\",\n \
- \ \"sha1\": \"f1efb0fddc156e4c61c5f78a54700e4e7984d55d\",\n \"sha256\": \"b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450\"\
- ,\n \"fileName\": \"cmd.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\"\
- ,\n \"processId\": 5500,\n \"processCommandLine\": \"cmd.exe /Q /c powershell\
- \ -NoProfile -ExecutionPolicy Bypass -File \\\"C:\\\\Users\\\\administrator1\\\\\
- Desktop\\\\SharedFolder\\\\payload.ps1\\\" 1> \\\\\\\\127.0.0.1\\\\SharedFolder\\\
- \\__1674565222.7012053 2>&1\",\n \"processCreationTime\": \"2023-01-24T13:02:50.4661885Z\"\
- ,\n \"parentProcessId\": 756,\n \"parentProcessCreationTime\": \"2023-01-24T13:00:35.0107475Z\"\
- ,\n \"parentProcessFileName\": \"WmiPrvSE.exe\",\n \"parentProcessFilePath\"\
- : \"C:\\\\Windows\\\\System32\\\\wbem\",\n \"ipAddress\": null,\n \"url\"\
- : null,\n \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\
- : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\
- accountName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\"\
- : \"S-1-5-21-4215714199-1288013905-3478400915-1002\",\n \"aadUserId\": null,\n\
- \ \"userPrincipalName\": null,\n \"detectionStatus\": \"Detected\"\n },\n\
- \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:33:37.4166667Z\"\
- ,\n \"sha1\": \"f1efb0fddc156e4c61c5f78a54700e4e7984d55d\",\n \"sha256\":\
- \ \"b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450\",\n \"\
- fileName\": \"cmd.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\",\n \
- \ \"processId\": 8964,\n \"processCommandLine\": \"cmd.exe /Q /c powershell -NoProfile\
- \ -ExecutionPolicy Bypass -File \\\"C:\\\\Users\\\\administrator1\\\\Desktop\\\\\
- SharedFolder\\\\payload.ps1\\\" 1> \\\\\\\\127.0.0.1\\\\SharedFolder\\\\__1674538248.357367\
- \ 2>&1\",\n \"processCreationTime\": \"2023-01-24T05:31:04.0743902Z\",\n \"\
- parentProcessId\": 7824,\n \"parentProcessCreationTime\": \"2023-01-24T05:30:50.8649791Z\"\
- ,\n \"parentProcessFileName\": \"WmiPrvSE.exe\",\n \"parentProcessFilePath\"\
- : \"C:\\\\Windows\\\\System32\\\\wbem\",\n \"ipAddress\": null,\n \"url\"\
- : null,\n \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\
- : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\
- accountName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\"\
- : \"S-1-5-21-4215714199-1288013905-3478400915-1002\",\n \"aadUserId\": null,\n\
- \ \"userPrincipalName\": null,\n \"detectionStatus\": \"Detected\"\n },\n\
- \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:39:47.1733333Z\"\
- ,\n \"sha1\": \"f1efb0fddc156e4c61c5f78a54700e4e7984d55d\",\n \"sha256\":\
- \ \"b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450\",\n \"\
- fileName\": \"cmd.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\",\n \
- \ \"processId\": 884,\n \"processCommandLine\": \"cmd.exe /Q /c powershell -NoProfile\
- \ -ExecutionPolicy Bypass -File \\\"C:\\\\Users\\\\administrator1\\\\Desktop\\\\\
- SharedFolder\\\\payload.ps1\\\" 1> \\\\\\\\127.0.0.1\\\\SharedFolder\\\\__1674538583.8648584\
- \ 2>&1\",\n \"processCreationTime\": \"2023-01-24T05:36:38.826505Z\",\n \"\
- parentProcessId\": 7736,\n \"parentProcessCreationTime\": \"2023-01-24T05:36:26.0524655Z\"\
- ,\n \"parentProcessFileName\": \"WmiPrvSE.exe\",\n \"parentProcessFilePath\"\
- : \"C:\\\\Windows\\\\System32\\\\wbem\",\n \"ipAddress\": null,\n \"url\"\
- : null,\n \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\
- : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\
- accountName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\"\
- : \"S-1-5-21-4215714199-1288013905-3478400915-1002\",\n \"aadUserId\": null,\n\
- \ \"userPrincipalName\": null,\n \"detectionStatus\": \"Detected\"\n },\n\
- \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T13:07:13.2233333Z\"\
- ,\n \"sha1\": \"3ea7cc066317ac45f963c2227c4c7c50aa16eb7c\",\n \"sha256\":\
- \ \"2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3\",\n \"\
- fileName\": \"WmiPrvSE.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\\\\\
- wbem\",\n \"processId\": 756,\n \"processCommandLine\": \"wmiprvse.exe -secured\
- \ -Embedding\",\n \"processCreationTime\": \"2023-01-24T13:00:35.0107475Z\",\n\
- \ \"parentProcessId\": 908,\n \"parentProcessCreationTime\": \"2023-01-24T08:20:44.6877667Z\"\
- ,\n \"parentProcessFileName\": \"svchost.exe\",\n \"parentProcessFilePath\"\
- : \"C:\\\\Windows\\\\System32\",\n \"ipAddress\": null,\n \"url\": null,\n\
- \ \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\
- : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\
- accountName\": \"NETWORK SERVICE\",\n \"domainName\": \"NT AUTHORITY\",\n \
- \ \"userSid\": \"S-1-5-20\",\n \"aadUserId\": null,\n \"userPrincipalName\"\
- : null,\n \"detectionStatus\": \"Detected\"\n },\n {\n \"entityType\": \"\
- Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:45:51.6833333Z\",\n \
- \ \"sha1\": \"f1efb0fddc156e4c61c5f78a54700e4e7984d55d\",\n \"sha256\": \"b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450\"\
- ,\n \"fileName\": \"cmd.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\"\
- ,\n \"processId\": 1140,\n \"processCommandLine\": \"cmd.exe /Q /c powershell\
- \ -NoProfile -ExecutionPolicy Bypass -File \\\"C:\\\\Users\\\\administrator1\\\\\
- Desktop\\\\SharedFolder\\\\payload.ps1\\\" 1> \\\\\\\\127.0.0.1\\\\SharedFolder\\\
- \\__1674538878.1586335 2>&1\",\n \"processCreationTime\": \"2023-01-24T05:43:49.9375398Z\"\
- ,\n \"parentProcessId\": 4476,\n \"parentProcessCreationTime\": \"2023-01-24T05:43:32.4631151Z\"\
- ,\n \"parentProcessFileName\": \"WmiPrvSE.exe\",\n \"parentProcessFilePath\"\
- : \"C:\\\\Windows\\\\System32\\\\wbem\",\n \"ipAddress\": null,\n \"url\"\
- : null,\n \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\
- : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\
- accountName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\"\
- : \"S-1-5-21-4215714199-1288013905-3478400915-1002\",\n \"aadUserId\": null,\n\
- \ \"userPrincipalName\": null,\n \"detectionStatus\": \"Detected\"\n },\n\
- \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:39:47.1733333Z\"\
- ,\n \"sha1\": \"3ea7cc066317ac45f963c2227c4c7c50aa16eb7c\",\n \"sha256\":\
- \ \"2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3\",\n \"\
- fileName\": \"WmiPrvSE.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\\\\\
- wbem\",\n \"processId\": 7736,\n \"processCommandLine\": \"wmiprvse.exe -secured\
- \ -Embedding\",\n \"processCreationTime\": \"2023-01-24T05:36:26.0524655Z\",\n\
- \ \"parentProcessId\": 896,\n \"parentProcessCreationTime\": \"2023-01-24T04:44:17.1940386Z\"\
- ,\n \"parentProcessFileName\": \"svchost.exe\",\n \"parentProcessFilePath\"\
- : \"C:\\\\Windows\\\\System32\",\n \"ipAddress\": null,\n \"url\": null,\n\
- \ \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\
- : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\
- accountName\": \"NETWORK SERVICE\",\n \"domainName\": \"NT AUTHORITY\",\n \
- \ \"userSid\": \"S-1-5-20\",\n \"aadUserId\": null,\n \"userPrincipalName\"\
- : null,\n \"detectionStatus\": \"Detected\"\n }\n],\n\"domains\": []\n}"
+ - column
+ - accountName
+ - action
+ - activity
+ - activityType
+ - actor
+ - actorName
+ - alertId
+ - app
+ - assignedTo
+ - body
+ - category
+ - classification
+ - creationTime
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - description
+ - dest
+ - detectionSource
+ - detectorId
+ - determination
+ - devices{}.aadDeviceId
+ - devices{}.defenderAvStatus
+ - devices{}.deviceDnsName
+ - devices{}.firstSeen
+ - devices{}.healthStatus
+ - devices{}.loggedOnUsers{}.accountName
+ - devices{}.loggedOnUsers{}.domainName
+ - devices{}.mdatpDeviceId
+ - devices{}.onboardingStatus
+ - devices{}.osBuild
+ - devices{}.osPlatform
+ - devices{}.osProcessor
+ - devices{}.rbacGroupName
+ - devices{}.riskScore
+ - devices{}.version
+ - devices{}.vmMetadata
+ - devices{}.vmMetadata.cloudProvider
+ - devices{}.vmMetadata.resourceId
+ - devices{}.vmMetadata.subscriptionId
+ - devices{}.vmMetadata.vmId
+ - entities{}.aadUserId
+ - entities{}.accountName
+ - entities{}.applicationId
+ - entities{}.applicationName
+ - entities{}.detectionStatus
+ - entities{}.deviceId
+ - entities{}.domainName
+ - entities{}.entityType
+ - entities{}.evidenceCreationTime
+ - entities{}.fileName
+ - entities{}.filePath
+ - entities{}.ipAddress
+ - entities{}.parentProcessCreationTime
+ - entities{}.parentProcessFileName
+ - entities{}.parentProcessFilePath
+ - entities{}.parentProcessId
+ - entities{}.processCommandLine
+ - entities{}.processCreationTime
+ - entities{}.processId
+ - entities{}.remediationStatus
+ - entities{}.remediationStatusDetails
+ - entities{}.sha1
+ - entities{}.sha256
+ - entities{}.userPrincipalName
+ - entities{}.userSid
+ - entities{}.verdict
+ - eventtype
+ - firstActivity
+ - host
+ - id
+ - incidentId
+ - index
+ - investigationId
+ - investigationState
+ - lastActivity
+ - lastUpdatedTime
+ - linecount
+ - mitreTechniques{}
+ - mitre_technique_id
+ - providerAlertId
+ - resolvedTime
+ - serviceSource
+ - severity
+ - signature
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - splunk_server_group
+ - src
+ - status
+ - subject
+ - tag
+ - tag::app
+ - tag::eventtype
+ - threatFamilyName
+ - timeendpos
+ - timestartpos
+ - title
+ - type
+ - user
+ - user_name
+ - _time
+example_log: |-
+ {
+ "id": "da47dc5671-e560-4229-984b-457564996b31_1",
+ "incidentId": 989,
+ "investigationId": null,
+ "assignedTo": null,
+ "severity": "High",
+ "status": "New",
+ "classification": null,
+ "determination": null,
+ "investigationState": "UnsupportedAlertType",
+ "detectionSource": "WindowsDefenderAtp",
+ "detectorId": "9c3a70ec-e18a-4f92-865a-530f73130b7c",
+ "category": "LateralMovement",
+ "threatFamilyName": null,
+ "title": "Ongoing hands-on-keyboard attack via Impacket toolkit",
+ "description": "Suspicious execution of a command via Impacket was observed on this device. This tool connects to other hosts to explore network shares and execute commands. Attackers might be attempting to move laterally across the network using this tool. This usage of Impacket has often been observed in hands-on-keyboard attacks, where ransomware and other payloads are installed on target devices.",
+ "alertCreationTime": "2023-01-24T05:33:37.3245808Z",
+ "firstEventTime": "2023-01-24T05:31:07.5276179Z",
+ "lastEventTime": "2023-01-24T13:02:50.7831636Z",
+ "lastUpdateTime": "2023-01-24T13:07:13.3233333Z",
+ "resolvedTime": null,
+ "machineId": "302293d9f276eae65553e5042156bce93cbc7148",
+ "computerDnsName": "diytestmachine",
+ "rbacGroupName": "UnassignedGroup",
+ "aadTenantId": "1a492129-58c8-4011-91cd-245285f5345c",
+ "threatName": null,
+ "mitreTechniques": [
+ "T1021.002",
+ "T1047",
+ "T1059.003"
+ ],
+ "relatedUser": {
+ "userName": "User1",
+ "domainName": "DIYTESTMACHINE"
+ },
+ "loggedOnUsers": [
+ {
+ "accountName": "administrator1",
+ "domainName": "DIYTESTMACHINE"
+ }
+ ],
+ "comments": [],
+ "evidence": [
+ {
+ "entityType": "Process",
+ "evidenceCreationTime": "2023-01-24T05:45:51.6833333Z",
+ "sha1": "3ea7cc066317ac45f963c2227c4c7c50aa16eb7c",
+ "sha256": "2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3",
+ "fileName": "WmiPrvSE.exe",
+ "filePath": "C:\\Windows\\System32\\wbem",
+ "processId": 4476,
+ "processCommandLine": "wmiprvse.exe -secured -Embedding",
+ "processCreationTime": "2023-01-24T05:43:32.4631151Z",
+ "parentProcessId": 896,
+ "parentProcessCreationTime": "2023-01-24T04:44:17.1940386Z",
+ "parentProcessFileName": "svchost.exe",
+ "parentProcessFilePath": "C:\\Windows\\System32",
+ "ipAddress": null,
+ "url": null,
+ "registryKey": null,
+ "registryHive": null,
+ "registryValueType": null,
+ "registryValue": null,
+ "registryValueName": null,
+ "accountName": "NETWORK SERVICE",
+ "domainName": "NT AUTHORITY",
+ "userSid": "S-1-5-20",
+ "aadUserId": null,
+ "userPrincipalName": null,
+ "detectionStatus": "Detected"
+ },
+ {
+ "entityType": "User",
+ "evidenceCreationTime": "2023-01-24T05:33:37.4166667Z",
+ "sha1": null,
+ "sha256": null,
+ "fileName": null,
+ "filePath": null,
+ "processId": null,
+ "processCommandLine": null,
+ "processCreationTime": null,
+ "parentProcessId": null,
+ "parentProcessCreationTime": null,
+ "parentProcessFileName": null,
+ "parentProcessFilePath": null,
+ "ipAddress": null,
+ "url": null,
+ "registryKey": null,
+ "registryHive": null,
+ "registryValueType": null,
+ "registryValue": null,
+ "registryValueName": null,
+ "accountName": "User1",
+ "domainName": "DIYTESTMACHINE",
+ "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002",
+ "aadUserId": null,
+ "userPrincipalName": null,
+ "detectionStatus": null
+ },
+ {
+ "entityType": "Process",
+ "evidenceCreationTime": "2023-01-24T05:33:37.4166667Z",
+ "sha1": "3ea7cc066317ac45f963c2227c4c7c50aa16eb7c",
+ "sha256": "2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3",
+ "fileName": "WmiPrvSE.exe",
+ "filePath": "C:\\Windows\\System32\\wbem",
+ "processId": 7824,
+ "processCommandLine": "wmiprvse.exe -secured -Embedding",
+ "processCreationTime": "2023-01-24T05:30:50.8649791Z",
+ "parentProcessId": 896,
+ "parentProcessCreationTime": "2023-01-24T04:44:17.1940386Z",
+ "parentProcessFileName": "svchost.exe",
+ "parentProcessFilePath": "C:\\Windows\\System32",
+ "ipAddress": null,
+ "url": null,
+ "registryKey": null,
+ "registryHive": null,
+ "registryValueType": null,
+ "registryValue": null,
+ "registryValueName": null,
+ "accountName": "NETWORK SERVICE",
+ "domainName": "NT AUTHORITY",
+ "userSid": "S-1-5-20",
+ "aadUserId": null,
+ "userPrincipalName": null,
+ "detectionStatus": "Detected"
+ },
+ {
+ "entityType": "Process",
+ "evidenceCreationTime": "2023-01-24T13:07:13.2233333Z",
+ "sha1": "f1efb0fddc156e4c61c5f78a54700e4e7984d55d",
+ "sha256": "b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450",
+ "fileName": "cmd.exe",
+ "filePath": "C:\\Windows\\System32",
+ "processId": 5500,
+ "processCommandLine": "cmd.exe /Q /c powershell -NoProfile -ExecutionPolicy Bypass -File \"C:\\Users\\administrator1\\Desktop\\SharedFolder\\payload.ps1\" 1> \\\\127.0.0.1\\SharedFolder\\__1674565222.7012053 2>&1",
+ "processCreationTime": "2023-01-24T13:02:50.4661885Z",
+ "parentProcessId": 756,
+ "parentProcessCreationTime": "2023-01-24T13:00:35.0107475Z",
+ "parentProcessFileName": "WmiPrvSE.exe",
+ "parentProcessFilePath": "C:\\Windows\\System32\\wbem",
+ "ipAddress": null,
+ "url": null,
+ "registryKey": null,
+ "registryHive": null,
+ "registryValueType": null,
+ "registryValue": null,
+ "registryValueName": null,
+ "accountName": "User1",
+ "domainName": "DIYTESTMACHINE",
+ "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002",
+ "aadUserId": null,
+ "userPrincipalName": null,
+ "detectionStatus": "Detected"
+ },
+ {
+ "entityType": "Process",
+ "evidenceCreationTime": "2023-01-24T05:33:37.4166667Z",
+ "sha1": "f1efb0fddc156e4c61c5f78a54700e4e7984d55d",
+ "sha256": "b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450",
+ "fileName": "cmd.exe",
+ "filePath": "C:\\Windows\\System32",
+ "processId": 8964,
+ "processCommandLine": "cmd.exe /Q /c powershell -NoProfile -ExecutionPolicy Bypass -File \"C:\\Users\\administrator1\\Desktop\\SharedFolder\\payload.ps1\" 1> \\\\127.0.0.1\\SharedFolder\\__1674538248.357367 2>&1",
+ "processCreationTime": "2023-01-24T05:31:04.0743902Z",
+ "parentProcessId": 7824,
+ "parentProcessCreationTime": "2023-01-24T05:30:50.8649791Z",
+ "parentProcessFileName": "WmiPrvSE.exe",
+ "parentProcessFilePath": "C:\\Windows\\System32\\wbem",
+ "ipAddress": null,
+ "url": null,
+ "registryKey": null,
+ "registryHive": null,
+ "registryValueType": null,
+ "registryValue": null,
+ "registryValueName": null,
+ "accountName": "User1",
+ "domainName": "DIYTESTMACHINE",
+ "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002",
+ "aadUserId": null,
+ "userPrincipalName": null,
+ "detectionStatus": "Detected"
+ },
+ {
+ "entityType": "Process",
+ "evidenceCreationTime": "2023-01-24T05:39:47.1733333Z",
+ "sha1": "f1efb0fddc156e4c61c5f78a54700e4e7984d55d",
+ "sha256": "b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450",
+ "fileName": "cmd.exe",
+ "filePath": "C:\\Windows\\System32",
+ "processId": 884,
+ "processCommandLine": "cmd.exe /Q /c powershell -NoProfile -ExecutionPolicy Bypass -File \"C:\\Users\\administrator1\\Desktop\\SharedFolder\\payload.ps1\" 1> \\\\127.0.0.1\\SharedFolder\\__1674538583.8648584 2>&1",
+ "processCreationTime": "2023-01-24T05:36:38.826505Z",
+ "parentProcessId": 7736,
+ "parentProcessCreationTime": "2023-01-24T05:36:26.0524655Z",
+ "parentProcessFileName": "WmiPrvSE.exe",
+ "parentProcessFilePath": "C:\\Windows\\System32\\wbem",
+ "ipAddress": null,
+ "url": null,
+ "registryKey": null,
+ "registryHive": null,
+ "registryValueType": null,
+ "registryValue": null,
+ "registryValueName": null,
+ "accountName": "User1",
+ "domainName": "DIYTESTMACHINE",
+ "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002",
+ "aadUserId": null,
+ "userPrincipalName": null,
+ "detectionStatus": "Detected"
+ },
+ {
+ "entityType": "Process",
+ "evidenceCreationTime": "2023-01-24T13:07:13.2233333Z",
+ "sha1": "3ea7cc066317ac45f963c2227c4c7c50aa16eb7c",
+ "sha256": "2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3",
+ "fileName": "WmiPrvSE.exe",
+ "filePath": "C:\\Windows\\System32\\wbem",
+ "processId": 756,
+ "processCommandLine": "wmiprvse.exe -secured -Embedding",
+ "processCreationTime": "2023-01-24T13:00:35.0107475Z",
+ "parentProcessId": 908,
+ "parentProcessCreationTime": "2023-01-24T08:20:44.6877667Z",
+ "parentProcessFileName": "svchost.exe",
+ "parentProcessFilePath": "C:\\Windows\\System32",
+ "ipAddress": null,
+ "url": null,
+ "registryKey": null,
+ "registryHive": null,
+ "registryValueType": null,
+ "registryValue": null,
+ "registryValueName": null,
+ "accountName": "NETWORK SERVICE",
+ "domainName": "NT AUTHORITY",
+ "userSid": "S-1-5-20",
+ "aadUserId": null,
+ "userPrincipalName": null,
+ "detectionStatus": "Detected"
+ },
+ {
+ "entityType": "Process",
+ "evidenceCreationTime": "2023-01-24T05:45:51.6833333Z",
+ "sha1": "f1efb0fddc156e4c61c5f78a54700e4e7984d55d",
+ "sha256": "b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450",
+ "fileName": "cmd.exe",
+ "filePath": "C:\\Windows\\System32",
+ "processId": 1140,
+ "processCommandLine": "cmd.exe /Q /c powershell -NoProfile -ExecutionPolicy Bypass -File \"C:\\Users\\administrator1\\Desktop\\SharedFolder\\payload.ps1\" 1> \\\\127.0.0.1\\SharedFolder\\__1674538878.1586335 2>&1",
+ "processCreationTime": "2023-01-24T05:43:49.9375398Z",
+ "parentProcessId": 4476,
+ "parentProcessCreationTime": "2023-01-24T05:43:32.4631151Z",
+ "parentProcessFileName": "WmiPrvSE.exe",
+ "parentProcessFilePath": "C:\\Windows\\System32\\wbem",
+ "ipAddress": null,
+ "url": null,
+ "registryKey": null,
+ "registryHive": null,
+ "registryValueType": null,
+ "registryValue": null,
+ "registryValueName": null,
+ "accountName": "User1",
+ "domainName": "DIYTESTMACHINE",
+ "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002",
+ "aadUserId": null,
+ "userPrincipalName": null,
+ "detectionStatus": "Detected"
+ },
+ {
+ "entityType": "Process",
+ "evidenceCreationTime": "2023-01-24T05:39:47.1733333Z",
+ "sha1": "3ea7cc066317ac45f963c2227c4c7c50aa16eb7c",
+ "sha256": "2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3",
+ "fileName": "WmiPrvSE.exe",
+ "filePath": "C:\\Windows\\System32\\wbem",
+ "processId": 7736,
+ "processCommandLine": "wmiprvse.exe -secured -Embedding",
+ "processCreationTime": "2023-01-24T05:36:26.0524655Z",
+ "parentProcessId": 896,
+ "parentProcessCreationTime": "2023-01-24T04:44:17.1940386Z",
+ "parentProcessFileName": "svchost.exe",
+ "parentProcessFilePath": "C:\\Windows\\System32",
+ "ipAddress": null,
+ "url": null,
+ "registryKey": null,
+ "registryHive": null,
+ "registryValueType": null,
+ "registryValue": null,
+ "registryValueName": null,
+ "accountName": "NETWORK SERVICE",
+ "domainName": "NT AUTHORITY",
+ "userSid": "S-1-5-20",
+ "aadUserId": null,
+ "userPrincipalName": null,
+ "detectionStatus": "Detected"
+ }
+ ],
+ "domains": []
+ }
diff --git a/data_sources/nginx_access.yml b/data_sources/nginx_access.yml
index 052bfc81e4..e24bb4163c 100644
--- a/data_sources/nginx_access.yml
+++ b/data_sources/nginx_access.yml
@@ -1,78 +1,79 @@
name: Nginx Access
id: c716a418-eab3-4df5-9dff-5420174e3068
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs HTTP/S access events on an Nginx server, including details such as client IP, request method, URI, response status, and user agent.
+description: Logs HTTP/S access events on an Nginx server, including details such
+ as client IP, request method, URI, response status, and user agent.
mitre_components:
-- Network Traffic Content
-- Network Traffic Flow
-- Response Metadata
-- Application Log Content
-- User Account Metadata
+ - Network Traffic Content
+ - Network Traffic Flow
+ - Response Metadata
+ - Application Log Content
+ - User Account Metadata
source: /var/log/nginx/access.log
sourcetype: nginx:plus:kv
supported_TA: []
fields:
-- _time
-- action
-- app
-- bytes
-- bytes_in
-- bytes_out
-- category
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_ip
-- dest_port
-- eventtype
-- host
-- http_content_type
-- http_method
-- http_referer
-- http_user_agent
-- http_user_agent_length
-- http_x_forwarded_for
-- http_x_header
-- https
-- index
-- linecount
-- nginx_version
-- product
-- protocol
-- punct
-- request_time
-- response_time
-- server
-- site
-- source
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- status
-- status_description
-- status_type
-- tag
-- tag::eventtype
-- time_local
-- timeendpos
-- timestartpos
-- uri_path
-- url
-- url_domain
-- url_length
-- vendor
-- vendor_product
-- version
-- web_server
+ - _time
+ - action
+ - app
+ - bytes
+ - bytes_in
+ - bytes_out
+ - category
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_ip
+ - dest_port
+ - eventtype
+ - host
+ - http_content_type
+ - http_method
+ - http_referer
+ - http_user_agent
+ - http_user_agent_length
+ - http_x_forwarded_for
+ - http_x_header
+ - https
+ - index
+ - linecount
+ - nginx_version
+ - product
+ - protocol
+ - punct
+ - request_time
+ - response_time
+ - server
+ - site
+ - source
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - status
+ - status_description
+ - status_type
+ - tag
+ - tag::eventtype
+ - time_local
+ - timeendpos
+ - timestartpos
+ - uri_path
+ - url
+ - url_domain
+ - url_length
+ - vendor
+ - vendor_product
+ - version
+ - web_server
example_log: site="www.example.com" server="www.example.com" dest_port="443" dest_ip="192.0.2.1"
src="198.51.100.1" src_ip="198.51.100.1" user="-" time_local="22/Feb/2024:13:00:00
-0500" protocol="HTTP/1.1" status="200" bytes_out="1073741000" bytes_in="234" http_referer="-"
diff --git a/data_sources/o365.yml b/data_sources/o365.yml
index efbfc3ee05..3bda514d41 100644
--- a/data_sources/o365.yml
+++ b/data_sources/o365.yml
@@ -1,19 +1,20 @@
name: O365
id: b32de97d-0074-4cca-853c-db22c392b6c0
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs management activities in Microsoft 365, including administrative actions, user activities, and configuration changes across various services.
+description: Logs management activities in Microsoft 365, including administrative
+ actions, user activities, and configuration changes across various services.
mitre_components:
-- User Account Metadata
-- Cloud Service Modification
-- Application Log Content
-- Configuration Modification
-- Active Directory Object Modification
+ - User Account Metadata
+ - Cloud Service Modification
+ - Application Log Content
+ - Configuration Modification
+ - Active Directory Object Modification
source: o365
sourcetype: o365:management:activity
separator: Operation
supported_TA:
-- name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+ - name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
diff --git a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml
index 4c64614e57..a6e90c409a 100644
--- a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml
+++ b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml
@@ -1,92 +1,93 @@
name: O365 Add app role assignment grant to user.
id: ce1d7849-a1d2-47fd-b6eb-d7ef854a860c
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the assignment of an application role grant to a user in Microsoft 365, including details about the role, user, and application involved.
+description: Logs the assignment of an application role grant to a user in Microsoft
+ 365, including details about the role, user, and application involved.
mitre_components:
-- User Account Modification
-- Group Modification
-- Cloud Service Modification
-- Cloud Service Metadata
+ - User Account Modification
+ - Group Modification
+ - Cloud Service Modification
+ - Cloud Service Metadata
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Add app role assignment grant to user.
supported_TA:
-- name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+ - name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
-- _time
-- ActorContextId
-- ActorIpAddress
-- Actor{}.ID
-- Actor{}.Type
-- AzureActiveDirectoryEventType
-- ClientIP
-- CreationTime
-- ExtendedProperties{}.Name
-- ExtendedProperties{}.Value
-- Id
-- InterSystemsId
-- IntraSystemId
-- ModifiedProperties{}.Name
-- ModifiedProperties{}.NewValue
-- ModifiedProperties{}.OldValue
-- ObjectId
-- Operation
-- OrganizationId
-- RecordType
-- ResultStatus
-- SupportTicketId
-- TargetContextId
-- Target{}.ID
-- Target{}.Type
-- UserId
-- UserKey
-- UserType
-- Version
-- Workload
-- additionalDetails
-- app
-- authentication_service
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_name
-- dvc
-- event_type
-- extendedAuditEventCategory
-- extended_properties
-- host
-- index
-- linecount
-- object
-- punct
-- record_type
-- signature
-- source
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- src_user
-- status
-- timeendpos
-- timestartpos
-- user
-- user_id
-- user_type
-- vendor_account
-- vendor_product
+ - _time
+ - ActorContextId
+ - ActorIpAddress
+ - Actor{}.ID
+ - Actor{}.Type
+ - AzureActiveDirectoryEventType
+ - ClientIP
+ - CreationTime
+ - ExtendedProperties{}.Name
+ - ExtendedProperties{}.Value
+ - Id
+ - InterSystemsId
+ - IntraSystemId
+ - ModifiedProperties{}.Name
+ - ModifiedProperties{}.NewValue
+ - ModifiedProperties{}.OldValue
+ - ObjectId
+ - Operation
+ - OrganizationId
+ - RecordType
+ - ResultStatus
+ - SupportTicketId
+ - TargetContextId
+ - Target{}.ID
+ - Target{}.Type
+ - UserId
+ - UserKey
+ - UserType
+ - Version
+ - Workload
+ - additionalDetails
+ - app
+ - authentication_service
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_name
+ - dvc
+ - event_type
+ - extendedAuditEventCategory
+ - extended_properties
+ - host
+ - index
+ - linecount
+ - object
+ - punct
+ - record_type
+ - signature
+ - source
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - src_user
+ - status
+ - timeendpos
+ - timestartpos
+ - user
+ - user_id
+ - user_type
+ - vendor_account
+ - vendor_product
example_log: '{"Actor": [{"ID": "rodsoto@rodsoto.onmicrosoft.com", "Type": 5}, {"ID":
"10037FFEA938FB92", "Type": 3}, {"ID": "74658136-14ec-4630-ad9b-26e160ff0fc6", "Type":
2}, {"ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484", "Type": 2}, {"ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
diff --git a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml
index 1549f8b091..720652a539 100644
--- a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml
+++ b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml
@@ -1,91 +1,93 @@
name: O365 Add app role assignment to service principal.
id: 785ba57a-ba7b-474e-97c8-9474e6e00b3a
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the assignment of an application role to a service principal in Microsoft 365, including details about the role, service principal, and application involved.
+description: Logs the assignment of an application role to a service principal in
+ Microsoft 365, including details about the role, service principal, and application
+ involved.
mitre_components:
-- Cloud Service Modification
-- Cloud Service Metadata
-- User Account Metadata
-- Group Modification
+ - Cloud Service Modification
+ - Cloud Service Metadata
+ - User Account Metadata
+ - Group Modification
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Add app role assignment to service principal.
supported_TA:
-- name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+ - name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
-- _time
-- ActorContextId
-- Actor{}.ID
-- Actor{}.Type
-- AzureActiveDirectoryEventType
-- CreationTime
-- ExtendedProperties{}.Name
-- ExtendedProperties{}.Value
-- Id
-- InterSystemsId
-- IntraSystemId
-- ModifiedProperties{}.Name
-- ModifiedProperties{}.NewValue
-- ModifiedProperties{}.OldValue
-- ObjectId
-- Operation
-- OrganizationId
-- RecordType
-- ResultStatus
-- SupportTicketId
-- TargetContextId
-- Target{}.ID
-- Target{}.Type
-- UserId
-- UserKey
-- UserType
-- Version
-- Workload
-- additionalDetails
-- app
-- authentication_service
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_name
-- dvc
-- event_type
-- eventtype
-- extendedAuditEventCategory
-- host
-- index
-- linecount
-- object
-- punct
-- record_type
-- signature
-- source
-- sourcetype
-- splunk_server
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- user_agent
-- user_agent_change
-- user_id
-- user_type
-- vendor_account
-- vendor_product
+ - _time
+ - ActorContextId
+ - Actor{}.ID
+ - Actor{}.Type
+ - AzureActiveDirectoryEventType
+ - CreationTime
+ - ExtendedProperties{}.Name
+ - ExtendedProperties{}.Value
+ - Id
+ - InterSystemsId
+ - IntraSystemId
+ - ModifiedProperties{}.Name
+ - ModifiedProperties{}.NewValue
+ - ModifiedProperties{}.OldValue
+ - ObjectId
+ - Operation
+ - OrganizationId
+ - RecordType
+ - ResultStatus
+ - SupportTicketId
+ - TargetContextId
+ - Target{}.ID
+ - Target{}.Type
+ - UserId
+ - UserKey
+ - UserType
+ - Version
+ - Workload
+ - additionalDetails
+ - app
+ - authentication_service
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_name
+ - dvc
+ - event_type
+ - eventtype
+ - extendedAuditEventCategory
+ - host
+ - index
+ - linecount
+ - object
+ - punct
+ - record_type
+ - signature
+ - source
+ - sourcetype
+ - splunk_server
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - user_agent
+ - user_agent_change
+ - user_id
+ - user_type
+ - vendor_account
+ - vendor_product
example_log: '{"CreationTime": "2024-02-08T21:49:53", "Id": "a6bee61d-8b3f-42e1-b4fa-778fb05c43ac",
"Operation": "Add app role assignment to service principal.", "OrganizationId":
"75243ab2-44f8-435c-a7a6-b479385df6d4", "RecordType": 8, "ResultStatus": "Success",
diff --git a/data_sources/o365_add_mailboxpermission.yml b/data_sources/o365_add_mailboxpermission.yml
index e98765f07b..09a36817fe 100644
--- a/data_sources/o365_add_mailboxpermission.yml
+++ b/data_sources/o365_add_mailboxpermission.yml
@@ -1,83 +1,85 @@
name: O365 Add-MailboxPermission
id: 9c0babdb-bb15-449e-abba-0a9cdb3fc061
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the addition of mailbox permissions in Microsoft 365, including details about the mailbox, granted permissions, and the user or administrator performing the action.
+description: Logs the addition of mailbox permissions in Microsoft 365, including
+ details about the mailbox, granted permissions, and the user or administrator performing
+ the action.
mitre_components:
-- User Account Modification
-- User Account Metadata
-- Active Directory Object Modification
-- Application Log Content
+ - User Account Modification
+ - User Account Metadata
+ - Active Directory Object Modification
+ - Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Add-MailboxPermission
supported_TA:
-- name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+ - name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
-- _time
-- AccessRights
-- AppId
-- ClientAppId
-- ClientIP
-- CreationTime
-- ExternalAccess
-- Id
-- Identity
-- InheritanceType
-- ObjectId
-- Operation
-- OrganizationId
-- OrganizationName
-- OriginatingServer
-- Parameters{}.Name
-- Parameters{}.Value
-- RecordType
-- ResultStatus
-- SessionId
-- User
-- UserId
-- UserKey
-- UserType
-- Version
-- Workload
-- app
-- authentication_service
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_name
-- dvc
-- host
-- index
-- linecount
-- object
-- punct
-- record_type
-- signature
-- source
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- status
-- timeendpos
-- timestartpos
-- user
-- user_id
-- user_type
-- vendor_account
-- vendor_product
+ - _time
+ - AccessRights
+ - AppId
+ - ClientAppId
+ - ClientIP
+ - CreationTime
+ - ExternalAccess
+ - Id
+ - Identity
+ - InheritanceType
+ - ObjectId
+ - Operation
+ - OrganizationId
+ - OrganizationName
+ - OriginatingServer
+ - Parameters{}.Name
+ - Parameters{}.Value
+ - RecordType
+ - ResultStatus
+ - SessionId
+ - User
+ - UserId
+ - UserKey
+ - UserType
+ - Version
+ - Workload
+ - app
+ - authentication_service
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_name
+ - dvc
+ - host
+ - index
+ - linecount
+ - object
+ - punct
+ - record_type
+ - signature
+ - source
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - status
+ - timeendpos
+ - timestartpos
+ - user
+ - user_id
+ - user_type
+ - vendor_account
+ - vendor_product
example_log: '{"AppId": "", "ClientAppId": "", "ClientIP": "18.159.234.121:30395",
"CreationTime": "2020-12-15T10:18:53", "ExternalAccess": false, "Id": "bb6e31a3-e98f-493d-bbff-08d8a0e2d2b0",
"ObjectId": "jhernan", "Operation": "Add-MailboxPermission", "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
diff --git a/data_sources/o365_add_member_to_role_.yml b/data_sources/o365_add_member_to_role_.yml
index 3fc466dba1..7a6ea65406 100644
--- a/data_sources/o365_add_member_to_role_.yml
+++ b/data_sources/o365_add_member_to_role_.yml
@@ -1,94 +1,95 @@
name: O365 Add member to role.
id: 8b949f7c-4b5d-404f-9694-d7403c4ec096
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the addition of a member to a role in Microsoft 365, including details about the role, the added member, and the user or administrator performing the action.
+description: Logs the addition of a member to a role in Microsoft 365, including details
+ about the role, the added member, and the user or administrator performing the action.
mitre_components:
-- Group Modification
-- Group Metadata
-- User Account Metadata
-- Cloud Service Modification
+ - Group Modification
+ - Group Metadata
+ - User Account Metadata
+ - Cloud Service Modification
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Add member to role.
supported_TA:
-- name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+ - name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
-- _time
-- ActorContextId
-- Actor{}.ID
-- Actor{}.Type
-- AzureActiveDirectoryEventType
-- CreationTime
-- ExtendedProperties{}.Name
-- ExtendedProperties{}.Value
-- Id
-- InterSystemsId
-- IntraSystemId
-- ModifiedProperties{}.Name
-- ModifiedProperties{}.NewValue
-- ModifiedProperties{}.OldValue
-- ObjectId
-- Operation
-- OrganizationId
-- RecordType
-- ResultStatus
-- SupportTicketId
-- TargetContextId
-- Target{}.ID
-- Target{}.Type
-- UserId
-- UserKey
-- UserType
-- Version
-- Workload
-- action
-- additionalDetails
-- app
-- authentication_service
-- change_type
-- command
-- dataset_name
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_name
-- dvc
-- event_type
-- eventtype
-- extendedAuditEventCategory
-- host
-- index
-- linecount
-- object
-- object_attrs
-- object_category
-- punct
-- record_type
-- signature
-- source
-- sourcetype
-- splunk_server
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- user_id
-- user_type
-- vendor_account
-- vendor_product
+ - _time
+ - ActorContextId
+ - Actor{}.ID
+ - Actor{}.Type
+ - AzureActiveDirectoryEventType
+ - CreationTime
+ - ExtendedProperties{}.Name
+ - ExtendedProperties{}.Value
+ - Id
+ - InterSystemsId
+ - IntraSystemId
+ - ModifiedProperties{}.Name
+ - ModifiedProperties{}.NewValue
+ - ModifiedProperties{}.OldValue
+ - ObjectId
+ - Operation
+ - OrganizationId
+ - RecordType
+ - ResultStatus
+ - SupportTicketId
+ - TargetContextId
+ - Target{}.ID
+ - Target{}.Type
+ - UserId
+ - UserKey
+ - UserType
+ - Version
+ - Workload
+ - action
+ - additionalDetails
+ - app
+ - authentication_service
+ - change_type
+ - command
+ - dataset_name
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_name
+ - dvc
+ - event_type
+ - eventtype
+ - extendedAuditEventCategory
+ - host
+ - index
+ - linecount
+ - object
+ - object_attrs
+ - object_category
+ - punct
+ - record_type
+ - signature
+ - source
+ - sourcetype
+ - splunk_server
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - user_id
+ - user_type
+ - vendor_account
+ - vendor_product
example_log: '{"CreationTime": "2023-10-20T16:50:46", "Id": "30a8b107-b190-406c-9b80-c3f5c3a29129",
"Operation": "Add member to role.", "OrganizationId": "d8211c86-3244-409b-8c4f-ae27ed34b4a5",
"RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com",
diff --git a/data_sources/o365_add_owner_to_application_.yml b/data_sources/o365_add_owner_to_application_.yml
index 71caf3f806..5c3b3c7f4b 100644
--- a/data_sources/o365_add_owner_to_application_.yml
+++ b/data_sources/o365_add_owner_to_application_.yml
@@ -1,96 +1,98 @@
name: O365 Add owner to application.
id: da012cbf-af6e-40ee-a1ba-32a5f8da8f8a
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the addition of an owner to an application in Microsoft 365, including details about the application, the new owner, and the user or administrator performing the action.
+description: Logs the addition of an owner to an application in Microsoft 365, including
+ details about the application, the new owner, and the user or administrator performing
+ the action.
mitre_components:
-- User Account Modification
-- Group Modification
-- Cloud Service Modification
-- Cloud Service Metadata
+ - User Account Modification
+ - Group Modification
+ - Cloud Service Modification
+ - Cloud Service Metadata
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Add owner to application.
supported_TA:
-- name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+ - name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
-- _time
-- ActorContextId
-- Actor{}.ID
-- Actor{}.Type
-- AzureActiveDirectoryEventType
-- CreationTime
-- ExtendedProperties{}.Name
-- ExtendedProperties{}.Value
-- Id
-- InterSystemsId
-- IntraSystemId
-- ModifiedProperties{}.Name
-- ModifiedProperties{}.NewValue
-- ModifiedProperties{}.OldValue
-- ObjectId
-- Operation
-- OrganizationId
-- RecordType
-- ResultStatus
-- SupportTicketId
-- TargetContextId
-- Target{}.ID
-- Target{}.Type
-- UserId
-- UserKey
-- UserType
-- Version
-- Workload
-- action
-- additionalDetails
-- app
-- authentication_service
-- change_type
-- command
-- dataset_name
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_name
-- dvc
-- event_type
-- eventtype
-- extendedAuditEventCategory
-- host
-- index
-- linecount
-- object
-- object_attrs
-- object_category
-- punct
-- record_type
-- signature
-- source
-- sourcetype
-- splunk_server
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- user_agent
-- user_agent_change
-- user_id
-- user_type
-- vendor_account
-- vendor_product
+ - _time
+ - ActorContextId
+ - Actor{}.ID
+ - Actor{}.Type
+ - AzureActiveDirectoryEventType
+ - CreationTime
+ - ExtendedProperties{}.Name
+ - ExtendedProperties{}.Value
+ - Id
+ - InterSystemsId
+ - IntraSystemId
+ - ModifiedProperties{}.Name
+ - ModifiedProperties{}.NewValue
+ - ModifiedProperties{}.OldValue
+ - ObjectId
+ - Operation
+ - OrganizationId
+ - RecordType
+ - ResultStatus
+ - SupportTicketId
+ - TargetContextId
+ - Target{}.ID
+ - Target{}.Type
+ - UserId
+ - UserKey
+ - UserType
+ - Version
+ - Workload
+ - action
+ - additionalDetails
+ - app
+ - authentication_service
+ - change_type
+ - command
+ - dataset_name
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_name
+ - dvc
+ - event_type
+ - eventtype
+ - extendedAuditEventCategory
+ - host
+ - index
+ - linecount
+ - object
+ - object_attrs
+ - object_category
+ - punct
+ - record_type
+ - signature
+ - source
+ - sourcetype
+ - splunk_server
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - user_agent
+ - user_agent_change
+ - user_id
+ - user_type
+ - vendor_account
+ - vendor_product
example_log: '{"CreationTime": "2023-09-07T13:42:04", "Id": "6e2c723b-8f6e-47f4-8c60-fa23ef3fccee",
"Operation": "Add owner to application.", "OrganizationId": "48203edf-5d2c-45f2-8123-a368cc8b0e51",
"RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@contoso.onmicrosoft.com",
diff --git a/data_sources/o365_add_service_principal_.yml b/data_sources/o365_add_service_principal_.yml
index 8511ac4c76..806ce7eda5 100644
--- a/data_sources/o365_add_service_principal_.yml
+++ b/data_sources/o365_add_service_principal_.yml
@@ -1,96 +1,97 @@
name: O365 Add service principal.
id: 9c1ef9f5-bc30-4a47-a1bd-cb34484ee778
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the addition of a new service principal in Microsoft 365, including details about the associated application and the action initiator.
+description: Logs the addition of a new service principal in Microsoft 365, including
+ details about the associated application and the action initiator.
mitre_components:
-- Cloud Service Creation
-- Cloud Service Metadata
-- User Account Metadata
-- Active Directory Object Creation
+ - Cloud Service Creation
+ - Cloud Service Metadata
+ - User Account Metadata
+ - Active Directory Object Creation
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Add service principal.
supported_TA:
-- name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+ - name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
-- _time
-- ActorContextId
-- Actor{}.ID
-- Actor{}.Type
-- AzureActiveDirectoryEventType
-- CreationTime
-- ExtendedProperties{}.Name
-- ExtendedProperties{}.Value
-- Id
-- InterSystemsId
-- IntraSystemId
-- ModifiedProperties{}.Name
-- ModifiedProperties{}.NewValue
-- ModifiedProperties{}.OldValue
-- ObjectId
-- Operation
-- OrganizationId
-- RecordType
-- ResultStatus
-- SupportTicketId
-- TargetContextId
-- Target{}.ID
-- Target{}.Type
-- UserId
-- UserKey
-- UserType
-- Version
-- Workload
-- action
-- additionalDetails
-- app
-- authentication_service
-- change_type
-- command
-- dataset_name
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_name
-- dvc
-- event_type
-- eventtype
-- extendedAuditEventCategory
-- host
-- index
-- linecount
-- object_attrs
-- object_category
-- punct
-- record_type
-- signature
-- source
-- sourcetype
-- splunk_server
-- src_user
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- user_agent
-- user_agent_change
-- user_id
-- user_type
-- vendor_account
-- vendor_product
+ - _time
+ - ActorContextId
+ - Actor{}.ID
+ - Actor{}.Type
+ - AzureActiveDirectoryEventType
+ - CreationTime
+ - ExtendedProperties{}.Name
+ - ExtendedProperties{}.Value
+ - Id
+ - InterSystemsId
+ - IntraSystemId
+ - ModifiedProperties{}.Name
+ - ModifiedProperties{}.NewValue
+ - ModifiedProperties{}.OldValue
+ - ObjectId
+ - Operation
+ - OrganizationId
+ - RecordType
+ - ResultStatus
+ - SupportTicketId
+ - TargetContextId
+ - Target{}.ID
+ - Target{}.Type
+ - UserId
+ - UserKey
+ - UserType
+ - Version
+ - Workload
+ - action
+ - additionalDetails
+ - app
+ - authentication_service
+ - change_type
+ - command
+ - dataset_name
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_name
+ - dvc
+ - event_type
+ - eventtype
+ - extendedAuditEventCategory
+ - host
+ - index
+ - linecount
+ - object_attrs
+ - object_category
+ - punct
+ - record_type
+ - signature
+ - source
+ - sourcetype
+ - splunk_server
+ - src_user
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - user_agent
+ - user_agent_change
+ - user_id
+ - user_type
+ - vendor_account
+ - vendor_product
example_log: '{"CreationTime": "2024-02-07T22:31:14", "Id": "f624ed92-b4a2-4d42-aa8b-20a261d06b7f",
"Operation": "Add service principal.", "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com",
diff --git a/data_sources/o365_change_user_license_.yml b/data_sources/o365_change_user_license_.yml
index 2cceff2f8a..cec6ea1cc1 100644
--- a/data_sources/o365_change_user_license_.yml
+++ b/data_sources/o365_change_user_license_.yml
@@ -1,92 +1,93 @@
name: O365 Change user license.
id: 1029a20d-3d0d-4fb9-b5e2-22ac5380b20a
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs changes to user licenses in Microsoft 365, including additions, removals, or updates to service plans associated with a user account.
+description: Logs changes to user licenses in Microsoft 365, including additions,
+ removals, or updates to service plans associated with a user account.
mitre_components:
-- User Account Modification
-- User Account Metadata
-- Cloud Service Modification
-- Configuration Modification
+ - User Account Modification
+ - User Account Metadata
+ - Cloud Service Modification
+ - Configuration Modification
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Change user license.
supported_TA:
-- name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+ - name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
-- _time
-- ActorContextId
-- Actor{}.ID
-- Actor{}.Type
-- AzureActiveDirectoryEventType
-- CreationTime
-- ExtendedProperties{}.Name
-- ExtendedProperties{}.Value
-- Id
-- InterSystemsId
-- IntraSystemId
-- ObjectId
-- Operation
-- OrganizationId
-- RecordType
-- ResultStatus
-- SupportTicketId
-- TargetContextId
-- Target{}.ID
-- Target{}.Type
-- UserId
-- UserKey
-- UserType
-- Version
-- Workload
-- action
-- additionalDetails
-- app
-- authentication_service
-- change_type
-- command
-- dataset_name
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_name
-- dvc
-- event_type
-- eventtype
-- extendedAuditEventCategory
-- host
-- index
-- linecount
-- object
-- object_attrs
-- object_category
-- punct
-- record_type
-- signature
-- source
-- sourcetype
-- splunk_server
-- src_user
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- user_id
-- user_type
-- vendor_account
-- vendor_product
+ - _time
+ - ActorContextId
+ - Actor{}.ID
+ - Actor{}.Type
+ - AzureActiveDirectoryEventType
+ - CreationTime
+ - ExtendedProperties{}.Name
+ - ExtendedProperties{}.Value
+ - Id
+ - InterSystemsId
+ - IntraSystemId
+ - ObjectId
+ - Operation
+ - OrganizationId
+ - RecordType
+ - ResultStatus
+ - SupportTicketId
+ - TargetContextId
+ - Target{}.ID
+ - Target{}.Type
+ - UserId
+ - UserKey
+ - UserType
+ - Version
+ - Workload
+ - action
+ - additionalDetails
+ - app
+ - authentication_service
+ - change_type
+ - command
+ - dataset_name
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_name
+ - dvc
+ - event_type
+ - eventtype
+ - extendedAuditEventCategory
+ - host
+ - index
+ - linecount
+ - object
+ - object_attrs
+ - object_category
+ - punct
+ - record_type
+ - signature
+ - source
+ - sourcetype
+ - splunk_server
+ - src_user
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - user_id
+ - user_type
+ - vendor_account
+ - vendor_product
example_log: '{"CreationTime": "2023-09-11T15:55:46", "Id": "1e39f32d-081d-4494-994a-533b57f91df7",
"Operation": "Change user license.", "OrganizationId": "bbad9541-eb53-4533-bcef-2b76182c3b75",
"RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com",
diff --git a/data_sources/o365_consent_to_application_.yml b/data_sources/o365_consent_to_application_.yml
index a5df3bc9f2..9a8aacafcd 100644
--- a/data_sources/o365_consent_to_application_.yml
+++ b/data_sources/o365_consent_to_application_.yml
@@ -1,88 +1,90 @@
name: O365 Consent to application.
id: 0a15a464-ef51-4614-9a07-a216eb9817db
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs user or administrator consent to an application's permissions in Microsoft 365, including details about the application, granted permissions, and the consenting user or process.
+description: Logs user or administrator consent to an application's permissions in
+ Microsoft 365, including details about the application, granted permissions, and
+ the consenting user or process.
mitre_components:
-- User Account Modification
-- Cloud Service Modification
-- Cloud Service Metadata
-- Configuration Modification
+ - User Account Modification
+ - Cloud Service Modification
+ - Cloud Service Metadata
+ - Configuration Modification
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Consent to application.
supported_TA:
-- name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+ - name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
-- _time
-- ActorContextId
-- Actor{}.ID
-- Actor{}.Type
-- AzureActiveDirectoryEventType
-- CreationTime
-- ExtendedProperties{}.Name
-- ExtendedProperties{}.Value
-- Id
-- InterSystemsId
-- IntraSystemId
-- ModifiedProperties{}.Name
-- ModifiedProperties{}.NewValue
-- ModifiedProperties{}.OldValue
-- ObjectId
-- Operation
-- OrganizationId
-- RecordType
-- ResultStatus
-- SupportTicketId
-- TargetContextId
-- Target{}.ID
-- Target{}.Type
-- UserId
-- UserKey
-- UserType
-- Version
-- Workload
-- additionalDetails
-- app
-- authentication_service
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_name
-- dvc
-- event_type
-- extendedAuditEventCategory
-- host
-- index
-- linecount
-- object
-- punct
-- record_type
-- signature
-- source
-- sourcetype
-- splunk_server
-- status
-- timeendpos
-- timestartpos
-- user
-- user_agent
-- user_agent_change
-- user_id
-- user_type
-- vendor_account
-- vendor_product
+ - _time
+ - ActorContextId
+ - Actor{}.ID
+ - Actor{}.Type
+ - AzureActiveDirectoryEventType
+ - CreationTime
+ - ExtendedProperties{}.Name
+ - ExtendedProperties{}.Value
+ - Id
+ - InterSystemsId
+ - IntraSystemId
+ - ModifiedProperties{}.Name
+ - ModifiedProperties{}.NewValue
+ - ModifiedProperties{}.OldValue
+ - ObjectId
+ - Operation
+ - OrganizationId
+ - RecordType
+ - ResultStatus
+ - SupportTicketId
+ - TargetContextId
+ - Target{}.ID
+ - Target{}.Type
+ - UserId
+ - UserKey
+ - UserType
+ - Version
+ - Workload
+ - additionalDetails
+ - app
+ - authentication_service
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_name
+ - dvc
+ - event_type
+ - extendedAuditEventCategory
+ - host
+ - index
+ - linecount
+ - object
+ - punct
+ - record_type
+ - signature
+ - source
+ - sourcetype
+ - splunk_server
+ - status
+ - timeendpos
+ - timestartpos
+ - user
+ - user_agent
+ - user_agent_change
+ - user_id
+ - user_type
+ - vendor_account
+ - vendor_product
example_log: '{"CreationTime": "2023-09-05T21:05:31", "Id": "5822e126-1fbc-4269-9ad6-4c1879cdbcf3",
"Operation": "Consent to application.", "OrganizationId": "9c00a473-1b2c-4bc2-9215-84df3f57aee5",
"RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@contoso.onmicrosoft.com",
diff --git a/data_sources/o365_disable_strong_authentication_.yml b/data_sources/o365_disable_strong_authentication_.yml
index ea3fb70491..bd40f2eca5 100644
--- a/data_sources/o365_disable_strong_authentication_.yml
+++ b/data_sources/o365_disable_strong_authentication_.yml
@@ -1,89 +1,91 @@
name: O365 Disable Strong Authentication.
id: 235381c4-382a-4183-b818-a51c3ce12187
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the disabling of strong authentication (e.g., multi-factor authentication) for a user or group in Microsoft 365, including details about the affected accounts and the action initiator.
+description: Logs the disabling of strong authentication (e.g., multi-factor authentication)
+ for a user or group in Microsoft 365, including details about the affected accounts
+ and the action initiator.
mitre_components:
-- User Account Modification
-- Group Modification
-- Configuration Modification
-- Application Log Content
+ - User Account Modification
+ - Group Modification
+ - Configuration Modification
+ - Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Disable Strong Authentication.
supported_TA:
-- name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+ - name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
-- _time
-- ActorContextId
-- ActorIpAddress
-- Actor{}.ID
-- Actor{}.Type
-- AzureActiveDirectoryEventType
-- ClientIP
-- CreationTime
-- ExtendedProperties{}.Name
-- ExtendedProperties{}.Value
-- Id
-- InterSystemsId
-- IntraSystemId
-- ModifiedProperties{}.Name
-- ModifiedProperties{}.NewValue
-- ModifiedProperties{}.OldValue
-- ObjectId
-- Operation
-- OrganizationId
-- RecordType
-- ResultStatus
-- SupportTicketId
-- TargetContextId
-- Target{}.ID
-- Target{}.Type
-- UserId
-- UserKey
-- UserType
-- Version
-- Workload
-- additionalDetails
-- app
-- authentication_service
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_name
-- dvc
-- event_type
-- extendedAuditEventCategory
-- extended_properties
-- host
-- index
-- linecount
-- object
-- punct
-- record_type
-- signature
-- source
-- sourcetype
-- splunk_server
-- status
-- timeendpos
-- timestartpos
-- user
-- user_id
-- user_type
-- vendor_account
-- vendor_product
+ - _time
+ - ActorContextId
+ - ActorIpAddress
+ - Actor{}.ID
+ - Actor{}.Type
+ - AzureActiveDirectoryEventType
+ - ClientIP
+ - CreationTime
+ - ExtendedProperties{}.Name
+ - ExtendedProperties{}.Value
+ - Id
+ - InterSystemsId
+ - IntraSystemId
+ - ModifiedProperties{}.Name
+ - ModifiedProperties{}.NewValue
+ - ModifiedProperties{}.OldValue
+ - ObjectId
+ - Operation
+ - OrganizationId
+ - RecordType
+ - ResultStatus
+ - SupportTicketId
+ - TargetContextId
+ - Target{}.ID
+ - Target{}.Type
+ - UserId
+ - UserKey
+ - UserType
+ - Version
+ - Workload
+ - additionalDetails
+ - app
+ - authentication_service
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_name
+ - dvc
+ - event_type
+ - extendedAuditEventCategory
+ - extended_properties
+ - host
+ - index
+ - linecount
+ - object
+ - punct
+ - record_type
+ - signature
+ - source
+ - sourcetype
+ - splunk_server
+ - status
+ - timeendpos
+ - timestartpos
+ - user
+ - user_id
+ - user_type
+ - vendor_account
+ - vendor_product
example_log: '{"Actor": [{"ID": "rodsoto@rodsoto.onmicrosoft.com", "Type": 5}, {"ID":
"10037FFEA938FB92", "Type": 3}, {"ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2}, {"ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484", "Type": 2}, {"ID": "User",
diff --git a/data_sources/o365_mailitemsaccessed.yml b/data_sources/o365_mailitemsaccessed.yml
index bc03fd713a..49429c5898 100644
--- a/data_sources/o365_mailitemsaccessed.yml
+++ b/data_sources/o365_mailitemsaccessed.yml
@@ -1,85 +1,86 @@
name: O365 MailItemsAccessed
id: 3d5188eb-341a-4b46-9caa-aade4047d027
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs access to mailbox items in Microsoft 365, including details about the user accessing the items, the accessed content, and the method of access.
+description: Logs access to mailbox items in Microsoft 365, including details about
+ the user accessing the items, the accessed content, and the method of access.
mitre_components:
-- File Access
-- User Account Metadata
-- Application Log Content
-- Active Directory Object Access
+ - File Access
+ - User Account Metadata
+ - Application Log Content
+ - Active Directory Object Access
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: MailItemsAccessed
supported_TA:
-- name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+ - name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
-- _time
-- AppId
-- ClientAppId
-- ClientIPAddress
-- ClientInfoString
-- CreationTime
-- ExternalAccess
-- Folders{}.FolderItems{}.InternetMessageId
-- Folders{}.FolderItems{}.SizeInBytes
-- Folders{}.Id
-- Folders{}.Path
-- Id
-- InternalLogonType
-- IsThrottled
-- LogonType
-- LogonUserSid
-- MailAccessType
-- MailboxGuid
-- MailboxOwnerSid
-- MailboxOwnerUPN
-- Operation
-- OperationCount
-- OperationProperties{}.Name
-- OperationProperties{}.Value
-- OrganizationId
-- OrganizationName
-- OriginatingServer
-- RecordType
-- ResultStatus
-- UserId
-- UserKey
-- UserType
-- Version
-- Workload
-- app
-- authentication_service
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dvc
-- host
-- index
-- linecount
-- punct
-- signature
-- source
-- sourcetype
-- splunk_server
-- status
-- timeendpos
-- timestartpos
-- user
-- user_id
-- user_type
-- vendor_account
-- vendor_product
+ - _time
+ - AppId
+ - ClientAppId
+ - ClientIPAddress
+ - ClientInfoString
+ - CreationTime
+ - ExternalAccess
+ - Folders{}.FolderItems{}.InternetMessageId
+ - Folders{}.FolderItems{}.SizeInBytes
+ - Folders{}.Id
+ - Folders{}.Path
+ - Id
+ - InternalLogonType
+ - IsThrottled
+ - LogonType
+ - LogonUserSid
+ - MailAccessType
+ - MailboxGuid
+ - MailboxOwnerSid
+ - MailboxOwnerUPN
+ - Operation
+ - OperationCount
+ - OperationProperties{}.Name
+ - OperationProperties{}.Value
+ - OrganizationId
+ - OrganizationName
+ - OriginatingServer
+ - RecordType
+ - ResultStatus
+ - UserId
+ - UserKey
+ - UserType
+ - Version
+ - Workload
+ - app
+ - authentication_service
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dvc
+ - host
+ - index
+ - linecount
+ - punct
+ - signature
+ - source
+ - sourcetype
+ - splunk_server
+ - status
+ - timeendpos
+ - timestartpos
+ - user
+ - user_id
+ - user_type
+ - vendor_account
+ - vendor_product
example_log: '{"CreationTime": "2024-02-01T16:07:34", "Id": "9cef02e9-4bfa-4c73-be7d-9dad68b9cea8",
"Operation": "MailItemsAccessed", "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"RecordType": 50, "ResultStatus": "Succeeded", "UserKey": "100320030DF47B14", "UserType":
diff --git a/data_sources/o365_modifyfolderpermissions.yml b/data_sources/o365_modifyfolderpermissions.yml
index 76c4e10d20..aca4f79957 100644
--- a/data_sources/o365_modifyfolderpermissions.yml
+++ b/data_sources/o365_modifyfolderpermissions.yml
@@ -1,103 +1,104 @@
name: O365 ModifyFolderPermissions
id: 0a8c1080-68c2-46d7-8324-2e7d97bb6e2f
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs modifications to folder permissions in Microsoft 365, including updates to access levels, user assignments, and sharing settings.
+description: Logs modifications to folder permissions in Microsoft 365, including
+ updates to access levels, user assignments, and sharing settings.
mitre_components:
-- User Account Modification
-- File Access
-- Active Directory Object Modification
-- Application Log Content
+ - User Account Modification
+ - File Access
+ - Active Directory Object Modification
+ - Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: ModifyFolderPermissions
supported_TA:
-- name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+ - name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
-- _time
-- AppId
-- ClientIP
-- ClientIPAddress
-- ClientInfoString
-- CreationTime
-- ExternalAccess
-- Id
-- InternalLogonType
-- Item.Id
-- Item.ParentFolder.Id
-- Item.ParentFolder.MemberRights
-- Item.ParentFolder.MemberSid
-- Item.ParentFolder.MemberUpn
-- Item.ParentFolder.Name
-- Item.ParentFolder.Path
-- LogonType
-- LogonUserSid
-- MailboxGuid
-- MailboxOwnerSid
-- MailboxOwnerUPN
-- Operation
-- OrganizationId
-- OrganizationName
-- OriginatingServer
-- RecordType
-- ResultStatus
-- SessionId
-- UserId
-- UserKey
-- UserType
-- Version
-- Workload
-- action
-- app
-- authentication_service
-- change_type
-- client_info_str
-- command
-- dataset_name
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_name
-- dvc
-- eventtype
-- host
-- index
-- linecount
-- object
-- object_attrs
-- object_category
-- object_id
-- punct
-- record_type
-- result
-- signature
-- source
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- status
-- tag
-- tag::eventtype
-- tenant_id
-- timeendpos
-- timestartpos
-- user
-- user_agent
-- user_id
-- user_type
-- vendor_account
-- vendor_product
+ - _time
+ - AppId
+ - ClientIP
+ - ClientIPAddress
+ - ClientInfoString
+ - CreationTime
+ - ExternalAccess
+ - Id
+ - InternalLogonType
+ - Item.Id
+ - Item.ParentFolder.Id
+ - Item.ParentFolder.MemberRights
+ - Item.ParentFolder.MemberSid
+ - Item.ParentFolder.MemberUpn
+ - Item.ParentFolder.Name
+ - Item.ParentFolder.Path
+ - LogonType
+ - LogonUserSid
+ - MailboxGuid
+ - MailboxOwnerSid
+ - MailboxOwnerUPN
+ - Operation
+ - OrganizationId
+ - OrganizationName
+ - OriginatingServer
+ - RecordType
+ - ResultStatus
+ - SessionId
+ - UserId
+ - UserKey
+ - UserType
+ - Version
+ - Workload
+ - action
+ - app
+ - authentication_service
+ - change_type
+ - client_info_str
+ - command
+ - dataset_name
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_name
+ - dvc
+ - eventtype
+ - host
+ - index
+ - linecount
+ - object
+ - object_attrs
+ - object_category
+ - object_id
+ - punct
+ - record_type
+ - result
+ - signature
+ - source
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - status
+ - tag
+ - tag::eventtype
+ - tenant_id
+ - timeendpos
+ - timestartpos
+ - user
+ - user_agent
+ - user_id
+ - user_type
+ - vendor_account
+ - vendor_product
example_log: '{"CreationTime": "2023-09-07T18:19:07", "Id": "ff065c17-e638-4013-20ab-08dbafceeca1",
"Operation": "ModifyFolderPermissions", "OrganizationId": "e17879dd-24ec-44a6-be92-9dcbf6969220",
"RecordType": 2, "ResultStatus": "Succeeded", "UserKey": "10032002CC029AE9", "UserType":
diff --git a/data_sources/o365_set_company_information_.yml b/data_sources/o365_set_company_information_.yml
index 5fab124138..e3da9d7ddd 100644
--- a/data_sources/o365_set_company_information_.yml
+++ b/data_sources/o365_set_company_information_.yml
@@ -1,97 +1,98 @@
name: O365 Set Company Information.
id: 06c6d576-f032-41e3-b15d-80a434ce13d8
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs updates to organizational settings and company information in Microsoft 365, including changes to contact details, branding, and configuration policies.
+description: Logs updates to organizational settings and company information in Microsoft
+ 365, including changes to contact details, branding, and configuration policies.
mitre_components:
-- Cloud Service Modification
-- Configuration Modification
-- Cloud Service Metadata
-- Application Log Content
+ - Cloud Service Modification
+ - Configuration Modification
+ - Cloud Service Metadata
+ - Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Set Company Information.
supported_TA:
-- name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+ - name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
-- _time
-- ActorContextId
-- ActorIpAddress
-- Actor{}.ID
-- Actor{}.Type
-- AzureActiveDirectoryEventType
-- ClientIP
-- CreationTime
-- ExtendedProperties{}.Name
-- ExtendedProperties{}.Value
-- Id
-- InterSystemsId
-- IntraSystemId
-- ModifiedProperties{}.Name
-- ModifiedProperties{}.NewValue
-- ModifiedProperties{}.OldValue
-- ObjectId
-- Operation
-- OrganizationId
-- RecordType
-- ResultStatus
-- SupportTicketId
-- TargetContextId
-- Target{}.ID
-- Target{}.Type
-- UserId
-- UserKey
-- UserType
-- Version
-- Workload
-- action
-- additionalDetails
-- app
-- authentication_service
-- change_type
-- command
-- dataset_name
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_name
-- dvc
-- event_type
-- eventtype
-- extendedAuditEventCategory
-- extended_properties
-- host
-- index
-- linecount
-- object
-- object_attrs
-- object_category
-- punct
-- record_type
-- signature
-- source
-- sourcetype
-- splunk_server
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- user_id
-- user_type
-- vendor_account
-- vendor_product
+ - _time
+ - ActorContextId
+ - ActorIpAddress
+ - Actor{}.ID
+ - Actor{}.Type
+ - AzureActiveDirectoryEventType
+ - ClientIP
+ - CreationTime
+ - ExtendedProperties{}.Name
+ - ExtendedProperties{}.Value
+ - Id
+ - InterSystemsId
+ - IntraSystemId
+ - ModifiedProperties{}.Name
+ - ModifiedProperties{}.NewValue
+ - ModifiedProperties{}.OldValue
+ - ObjectId
+ - Operation
+ - OrganizationId
+ - RecordType
+ - ResultStatus
+ - SupportTicketId
+ - TargetContextId
+ - Target{}.ID
+ - Target{}.Type
+ - UserId
+ - UserKey
+ - UserType
+ - Version
+ - Workload
+ - action
+ - additionalDetails
+ - app
+ - authentication_service
+ - change_type
+ - command
+ - dataset_name
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_name
+ - dvc
+ - event_type
+ - eventtype
+ - extendedAuditEventCategory
+ - extended_properties
+ - host
+ - index
+ - linecount
+ - object
+ - object_attrs
+ - object_category
+ - punct
+ - record_type
+ - signature
+ - source
+ - sourcetype
+ - splunk_server
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - user_id
+ - user_type
+ - vendor_account
+ - vendor_product
example_log: '{"Actor": [{"ID": "bpatel@rodsoto.onmicrosoft.com", "Type": 5}, {"ID":
"100320010208B5DC", "Type": 3}, {"ID": "User_425b75db-38be-4c7b-a474-5f0709247370",
"Type": 2}, {"ID": "425b75db-38be-4c7b-a474-5f0709247370", "Type": 2}, {"ID": "User",
diff --git a/data_sources/o365_set_mailbox.yml b/data_sources/o365_set_mailbox.yml
index 6849ce100a..9da03f53f4 100644
--- a/data_sources/o365_set_mailbox.yml
+++ b/data_sources/o365_set_mailbox.yml
@@ -1,93 +1,94 @@
name: O365 Set-Mailbox
id: db798c5c-928c-4972-bb42-e5f90e35865f
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs changes to mailbox properties in Microsoft 365, including updates to permissions, storage quotas, and configuration settings.
+description: Logs changes to mailbox properties in Microsoft 365, including updates
+ to permissions, storage quotas, and configuration settings.
mitre_components:
-- User Account Modification
-- Active Directory Object Modification
-- User Account Metadata
-- Application Log Content
+ - User Account Modification
+ - Active Directory Object Modification
+ - User Account Metadata
+ - Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Set-Mailbox
supported_TA:
-- name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+ - name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
-- _time
-- AppId
-- ClientAppId
-- ClientIP
-- CreationTime
-- ExternalAccess
-- Id
-- Identity
-- ObjectId
-- Operation
-- OrganizationId
-- OrganizationName
-- OriginatingServer
-- Parameters{}.Name
-- Parameters{}.Value
-- Params
-- RecordType
-- ResultStatus
-- SessionId
-- UserId
-- UserKey
-- UserType
-- Version
-- Workload
-- action
-- app
-- authentication_service
-- change_type
-- command
-- dataset_name
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_name
-- dvc
-- eventtype
-- host
-- index
-- linecount
-- object
-- object_attrs
-- object_category
-- object_id
-- punct
-- record_type
-- result
-- signature
-- source
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- src_user
-- src_user_type
-- status
-- tag
-- tag::eventtype
-- tenant_id
-- timeendpos
-- timestartpos
-- user
-- user_id
-- vendor_account
-- vendor_product
+ - _time
+ - AppId
+ - ClientAppId
+ - ClientIP
+ - CreationTime
+ - ExternalAccess
+ - Id
+ - Identity
+ - ObjectId
+ - Operation
+ - OrganizationId
+ - OrganizationName
+ - OriginatingServer
+ - Parameters{}.Name
+ - Parameters{}.Value
+ - Params
+ - RecordType
+ - ResultStatus
+ - SessionId
+ - UserId
+ - UserKey
+ - UserType
+ - Version
+ - Workload
+ - action
+ - app
+ - authentication_service
+ - change_type
+ - command
+ - dataset_name
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_name
+ - dvc
+ - eventtype
+ - host
+ - index
+ - linecount
+ - object
+ - object_attrs
+ - object_category
+ - object_id
+ - punct
+ - record_type
+ - result
+ - signature
+ - source
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - src_user
+ - src_user_type
+ - status
+ - tag
+ - tag::eventtype
+ - tenant_id
+ - timeendpos
+ - timestartpos
+ - user
+ - user_id
+ - vendor_account
+ - vendor_product
example_log: '{"AppId": "", "ClientAppId": "", "ClientIP": "18.192.200.190:52816",
"CreationTime": "2020-12-16T12:32:28", "ExternalAccess": false, "Id": "a6a52406-0912-448d-36eb-08d8a1bea6be",
"ObjectId": "bpatel", "Operation": "Set-Mailbox", "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
diff --git a/data_sources/o365_update_application_.yml b/data_sources/o365_update_application_.yml
index 155f1353ca..2b04a3230b 100644
--- a/data_sources/o365_update_application_.yml
+++ b/data_sources/o365_update_application_.yml
@@ -1,96 +1,97 @@
name: O365 Update application.
id: 62159133-911b-4c63-9e30-a6a8c89195ca
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs updates made to applications in Microsoft 365, including changes to configurations, permissions, and role assignments.
+description: Logs updates made to applications in Microsoft 365, including changes
+ to configurations, permissions, and role assignments.
mitre_components:
-- Cloud Service Modification
-- Configuration Modification
-- Cloud Service Metadata
-- Application Log Content
+ - Cloud Service Modification
+ - Configuration Modification
+ - Cloud Service Metadata
+ - Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Update application.
supported_TA:
-- name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+ - name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
-- _time
-- ActorContextId
-- Actor{}.ID
-- Actor{}.Type
-- AzureActiveDirectoryEventType
-- CreationTime
-- ExtendedProperties{}.Name
-- ExtendedProperties{}.Value
-- Id
-- InterSystemsId
-- IntraSystemId
-- ModifiedProperties{}.Name
-- ModifiedProperties{}.NewValue
-- ModifiedProperties{}.OldValue
-- ObjectId
-- Operation
-- OrganizationId
-- RecordType
-- ResultStatus
-- SupportTicketId
-- TargetContextId
-- Target{}.ID
-- Target{}.Type
-- UserId
-- UserKey
-- UserType
-- Version
-- Workload
-- action
-- additionalDetails
-- app
-- authentication_service
-- change_type
-- command
-- dataset_name
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_name
-- dvc
-- event_type
-- eventtype
-- extendedAuditEventCategory
-- host
-- index
-- linecount
-- object
-- object_attrs
-- object_category
-- punct
-- record_type
-- signature
-- source
-- sourcetype
-- splunk_server
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- user_agent
-- user_agent_change
-- user_id
-- user_type
-- vendor_account
-- vendor_product
+ - _time
+ - ActorContextId
+ - Actor{}.ID
+ - Actor{}.Type
+ - AzureActiveDirectoryEventType
+ - CreationTime
+ - ExtendedProperties{}.Name
+ - ExtendedProperties{}.Value
+ - Id
+ - InterSystemsId
+ - IntraSystemId
+ - ModifiedProperties{}.Name
+ - ModifiedProperties{}.NewValue
+ - ModifiedProperties{}.OldValue
+ - ObjectId
+ - Operation
+ - OrganizationId
+ - RecordType
+ - ResultStatus
+ - SupportTicketId
+ - TargetContextId
+ - Target{}.ID
+ - Target{}.Type
+ - UserId
+ - UserKey
+ - UserType
+ - Version
+ - Workload
+ - action
+ - additionalDetails
+ - app
+ - authentication_service
+ - change_type
+ - command
+ - dataset_name
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_name
+ - dvc
+ - event_type
+ - eventtype
+ - extendedAuditEventCategory
+ - host
+ - index
+ - linecount
+ - object
+ - object_attrs
+ - object_category
+ - punct
+ - record_type
+ - signature
+ - source
+ - sourcetype
+ - splunk_server
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - user_agent
+ - user_agent_change
+ - user_id
+ - user_type
+ - vendor_account
+ - vendor_product
example_log: '{"CreationTime": "2023-09-01T17:16:20", "Id": "c428c85c-4fa0-4e97-9033-6a76d9dee45d",
"Operation": "Update application.", "OrganizationId": "58aee3b9-7433-46a0-b54e-2429487992a0",
"RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@contoso.onmicrosoft.com",
diff --git a/data_sources/o365_update_authorization_policy_.yml b/data_sources/o365_update_authorization_policy_.yml
index 2438a25b16..90825eca41 100644
--- a/data_sources/o365_update_authorization_policy_.yml
+++ b/data_sources/o365_update_authorization_policy_.yml
@@ -1,88 +1,89 @@
name: O365 Update authorization policy.
id: d40e6a20-4d64-404c-8351-2caae8228d34
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs changes to authorization policies in Microsoft 365, including updates to access controls, permissions, and security settings.
+description: Logs changes to authorization policies in Microsoft 365, including updates
+ to access controls, permissions, and security settings.
mitre_components:
-- Cloud Service Modification
-- Configuration Modification
-- User Account Metadata
-- Application Log Content
+ - Cloud Service Modification
+ - Configuration Modification
+ - User Account Metadata
+ - Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Update authorization policy.
supported_TA:
-- name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+ - name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
-- _time
-- ActorContextId
-- Actor{}.ID
-- Actor{}.Type
-- AzureActiveDirectoryEventType
-- CreationTime
-- ExtendedProperties{}.Name
-- ExtendedProperties{}.Value
-- Id
-- InterSystemsId
-- IntraSystemId
-- ModifiedProperties{}.Name
-- ModifiedProperties{}.NewValue
-- ModifiedProperties{}.OldValue
-- ObjectId
-- Operation
-- OrganizationId
-- RecordType
-- ResultStatus
-- SupportTicketId
-- TargetContextId
-- Target{}.ID
-- Target{}.Type
-- UserId
-- UserKey
-- UserType
-- Version
-- Workload
-- additionalDetails
-- app
-- authentication_service
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_name
-- dvc
-- event_type
-- extendedAuditEventCategory
-- host
-- index
-- linecount
-- object
-- punct
-- record_type
-- signature
-- source
-- sourcetype
-- splunk_server
-- status
-- timeendpos
-- timestartpos
-- user
-- user_agent
-- user_agent_change
-- user_id
-- user_type
-- vendor_account
-- vendor_product
+ - _time
+ - ActorContextId
+ - Actor{}.ID
+ - Actor{}.Type
+ - AzureActiveDirectoryEventType
+ - CreationTime
+ - ExtendedProperties{}.Name
+ - ExtendedProperties{}.Value
+ - Id
+ - InterSystemsId
+ - IntraSystemId
+ - ModifiedProperties{}.Name
+ - ModifiedProperties{}.NewValue
+ - ModifiedProperties{}.OldValue
+ - ObjectId
+ - Operation
+ - OrganizationId
+ - RecordType
+ - ResultStatus
+ - SupportTicketId
+ - TargetContextId
+ - Target{}.ID
+ - Target{}.Type
+ - UserId
+ - UserKey
+ - UserType
+ - Version
+ - Workload
+ - additionalDetails
+ - app
+ - authentication_service
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_name
+ - dvc
+ - event_type
+ - extendedAuditEventCategory
+ - host
+ - index
+ - linecount
+ - object
+ - punct
+ - record_type
+ - signature
+ - source
+ - sourcetype
+ - splunk_server
+ - status
+ - timeendpos
+ - timestartpos
+ - user
+ - user_agent
+ - user_agent_change
+ - user_id
+ - user_type
+ - vendor_account
+ - vendor_product
example_log: '{"CreationTime": "2023-10-26T19:22:20", "Id": "83774e72-313f-4d1f-8609-7d0c7bb3b4ff",
"Operation": "Update authorization policy.", "OrganizationId": "a417c578-c7ee-480d-a225-d48057e74df5",
"RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com",
diff --git a/data_sources/o365_update_user_.yml b/data_sources/o365_update_user_.yml
index 308a4ac7a4..f733a674a4 100644
--- a/data_sources/o365_update_user_.yml
+++ b/data_sources/o365_update_user_.yml
@@ -1,95 +1,96 @@
name: O365 Update user.
id: a05fd01e-34d9-4233-9089-11272416b531
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs updates to user account properties in Microsoft 365, including changes to roles, permissions, and profile information.
+description: Logs updates to user account properties in Microsoft 365, including changes
+ to roles, permissions, and profile information.
mitre_components:
-- User Account Modification
-- User Account Metadata
-- Active Directory Object Modification
-- Application Log Content
+ - User Account Modification
+ - User Account Metadata
+ - Active Directory Object Modification
+ - Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Update user.
supported_TA:
-- name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+ - name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
-- _time
-- ActorContextId
-- Actor{}.ID
-- Actor{}.Type
-- AzureActiveDirectoryEventType
-- CreationTime
-- ExtendedProperties{}.Name
-- ExtendedProperties{}.Value
-- Id
-- InterSystemsId
-- IntraSystemId
-- ModifiedProperties{}.Name
-- ModifiedProperties{}.NewValue
-- ModifiedProperties{}.OldValue
-- ObjectId
-- Operation
-- OrganizationId
-- RecordType
-- ResultStatus
-- SupportTicketId
-- TargetContextId
-- Target{}.ID
-- Target{}.Type
-- UserId
-- UserKey
-- UserType
-- Version
-- Workload
-- action
-- additionalDetails
-- app
-- authentication_service
-- change_type
-- command
-- dataset_name
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_name
-- dvc
-- event_type
-- eventtype
-- extendedAuditEventCategory
-- host
-- index
-- linecount
-- object
-- object_attrs
-- object_category
-- punct
-- record_type
-- signature
-- source
-- sourcetype
-- splunk_server
-- src_user
-- status
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- user_id
-- user_type
-- vendor_account
-- vendor_product
+ - _time
+ - ActorContextId
+ - Actor{}.ID
+ - Actor{}.Type
+ - AzureActiveDirectoryEventType
+ - CreationTime
+ - ExtendedProperties{}.Name
+ - ExtendedProperties{}.Value
+ - Id
+ - InterSystemsId
+ - IntraSystemId
+ - ModifiedProperties{}.Name
+ - ModifiedProperties{}.NewValue
+ - ModifiedProperties{}.OldValue
+ - ObjectId
+ - Operation
+ - OrganizationId
+ - RecordType
+ - ResultStatus
+ - SupportTicketId
+ - TargetContextId
+ - Target{}.ID
+ - Target{}.Type
+ - UserId
+ - UserKey
+ - UserType
+ - Version
+ - Workload
+ - action
+ - additionalDetails
+ - app
+ - authentication_service
+ - change_type
+ - command
+ - dataset_name
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_name
+ - dvc
+ - event_type
+ - eventtype
+ - extendedAuditEventCategory
+ - host
+ - index
+ - linecount
+ - object
+ - object_attrs
+ - object_category
+ - punct
+ - record_type
+ - signature
+ - source
+ - sourcetype
+ - splunk_server
+ - src_user
+ - status
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - user_id
+ - user_type
+ - vendor_account
+ - vendor_product
example_log: '{"CreationTime": "2023-10-20T19:32:59", "Id": "d06df1c6-b3f2-4595-90b9-99b8f91811c3",
"Operation": "Update user.", "OrganizationId": "99825d50-9544-4061-8e46-68923805cbf2",
"RecordType": 8, "ResultStatus": "Success", "UserKey": "10032002CC029AE9@splunkresearch1.onmicrosoft.com",
diff --git a/data_sources/o365_userloggedin.yml b/data_sources/o365_userloggedin.yml
index 3296cb188a..f9169deaee 100644
--- a/data_sources/o365_userloggedin.yml
+++ b/data_sources/o365_userloggedin.yml
@@ -1,95 +1,96 @@
name: O365 UserLoggedIn
id: ed29c8c4-4053-419c-b133-16abf2a1c4c9
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs successful login events by users in Microsoft 365, including details about the user account, IP address, and session metadata.
+description: Logs successful login events by users in Microsoft 365, including details
+ about the user account, IP address, and session metadata.
mitre_components:
-- User Account Authentication
-- Logon Session Creation
-- User Account Metadata
-- Logon Session Metadata
+ - User Account Authentication
+ - Logon Session Creation
+ - User Account Metadata
+ - Logon Session Metadata
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: UserLoggedIn
supported_TA:
-- name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+ - name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
-- _time
-- ActorContextId
-- ActorIpAddress
-- Actor{}.ID
-- Actor{}.Type
-- ApplicationId
-- AzureActiveDirectoryEventType
-- BrowserType
-- ClientIP
-- CreationTime
-- DeviceProperties{}.Name
-- DeviceProperties{}.Value
-- ErrorNumber
-- ExtendedProperties{}.Name
-- ExtendedProperties{}.Value
-- Id
-- InterSystemsId
-- IntraSystemId
-- OS
-- ObjectId
-- Operation
-- OrganizationId
-- RecordType
-- RequestType
-- ResultStatus
-- ResultStatusDetail
-- SessionId
-- SupportTicketId
-- TargetContextId
-- Target{}.ID
-- Target{}.Type
-- UserAgent
-- UserId
-- UserKey
-- UserType
-- Version
-- Workload
-- app
-- authentication_service
-- command
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_name
-- dvc
-- event_type
-- host
-- index
-- linecount
-- object
-- punct
-- record_type
-- signature
-- source
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- status
-- timeendpos
-- timestartpos
-- user
-- user_agent
-- user_type
-- vendor_account
-- vendor_product
+ - _time
+ - ActorContextId
+ - ActorIpAddress
+ - Actor{}.ID
+ - Actor{}.Type
+ - ApplicationId
+ - AzureActiveDirectoryEventType
+ - BrowserType
+ - ClientIP
+ - CreationTime
+ - DeviceProperties{}.Name
+ - DeviceProperties{}.Value
+ - ErrorNumber
+ - ExtendedProperties{}.Name
+ - ExtendedProperties{}.Value
+ - Id
+ - InterSystemsId
+ - IntraSystemId
+ - OS
+ - ObjectId
+ - Operation
+ - OrganizationId
+ - RecordType
+ - RequestType
+ - ResultStatus
+ - ResultStatusDetail
+ - SessionId
+ - SupportTicketId
+ - TargetContextId
+ - Target{}.ID
+ - Target{}.Type
+ - UserAgent
+ - UserId
+ - UserKey
+ - UserType
+ - Version
+ - Workload
+ - app
+ - authentication_service
+ - command
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_name
+ - dvc
+ - event_type
+ - host
+ - index
+ - linecount
+ - object
+ - punct
+ - record_type
+ - signature
+ - source
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - status
+ - timeendpos
+ - timestartpos
+ - user
+ - user_agent
+ - user_type
+ - vendor_account
+ - vendor_product
example_log: '{"CreationTime": "2023-12-04T20:42:05", "Id": "52d72a62-132b-487b-bb7f-c4c119f90700",
"Operation": "UserLoggedIn", "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"RecordType": 15, "ResultStatus": "Success", "UserKey": "2d2f9e2c-8350-4d98-852e-3f06daaf7185",
diff --git a/data_sources/o365_userloginfailed.yml b/data_sources/o365_userloginfailed.yml
index dfea247775..8f3df80a3f 100644
--- a/data_sources/o365_userloginfailed.yml
+++ b/data_sources/o365_userloginfailed.yml
@@ -1,104 +1,105 @@
name: O365 UserLoginFailed
id: 6099b33d-d581-43ed-8401-911862590361
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs failed login attempts by users in Microsoft 365, including details about the user account, IP address, and reason for failure.
+description: Logs failed login attempts by users in Microsoft 365, including details
+ about the user account, IP address, and reason for failure.
mitre_components:
-- User Account Authentication
-- Logon Session Metadata
-- User Account Metadata
-- Application Log Content
+ - User Account Authentication
+ - Logon Session Metadata
+ - User Account Metadata
+ - Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: UserLoginFailed
supported_TA:
-- name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+ - name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
-- _time
-- ActorContextId
-- ActorIpAddress
-- Actor{}.ID
-- Actor{}.Type
-- ApplicationId
-- AzureActiveDirectoryEventType
-- BrowserType
-- ClientIP
-- CreationTime
-- DeviceProperties{}.Name
-- DeviceProperties{}.Value
-- ErrorNumber
-- ExtendedProperties{}.Name
-- ExtendedProperties{}.Value
-- Id
-- InterSystemsId
-- IntraSystemId
-- IsCompliantAndManaged
-- LogonError
-- OS
-- ObjectId
-- Operation
-- OrganizationId
-- RecordType
-- RequestType
-- ResultStatus
-- ResultStatusDetail
-- SupportTicketId
-- TargetContextId
-- Target{}.ID
-- Target{}.Type
-- UserAgent
-- UserAuthenticationMethod
-- UserId
-- UserKey
-- UserType
-- Version
-- Workload
-- action
-- app
-- authentication_method
-- authentication_service
-- command
-- dataset_name
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_name
-- dvc
-- event_type
-- eventtype
-- host
-- index
-- linecount
-- object
-- punct
-- reason
-- record_type
-- result
-- signature
-- source
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- status
-- tag
-- tag::action
-- tag::eventtype
-- user
-- user_agent
-- user_type
-- vendor_account
-- vendor_product
+ - _time
+ - ActorContextId
+ - ActorIpAddress
+ - Actor{}.ID
+ - Actor{}.Type
+ - ApplicationId
+ - AzureActiveDirectoryEventType
+ - BrowserType
+ - ClientIP
+ - CreationTime
+ - DeviceProperties{}.Name
+ - DeviceProperties{}.Value
+ - ErrorNumber
+ - ExtendedProperties{}.Name
+ - ExtendedProperties{}.Value
+ - Id
+ - InterSystemsId
+ - IntraSystemId
+ - IsCompliantAndManaged
+ - LogonError
+ - OS
+ - ObjectId
+ - Operation
+ - OrganizationId
+ - RecordType
+ - RequestType
+ - ResultStatus
+ - ResultStatusDetail
+ - SupportTicketId
+ - TargetContextId
+ - Target{}.ID
+ - Target{}.Type
+ - UserAgent
+ - UserAuthenticationMethod
+ - UserId
+ - UserKey
+ - UserType
+ - Version
+ - Workload
+ - action
+ - app
+ - authentication_method
+ - authentication_service
+ - command
+ - dataset_name
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_name
+ - dvc
+ - event_type
+ - eventtype
+ - host
+ - index
+ - linecount
+ - object
+ - punct
+ - reason
+ - record_type
+ - result
+ - signature
+ - source
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - status
+ - tag
+ - tag::action
+ - tag::eventtype
+ - user
+ - user_agent
+ - user_type
+ - vendor_account
+ - vendor_product
example_log: '{"CreationTime": "2023-10-10T17:08:65", "Id": "4593aac8-855f-4341-9d2a-4289146eb800",
"Operation": "UserLoginFailed", "OrganizationId": "d541aae6-6b73-4a7c-aaf0-a4de30c872bc",
"RecordType": 15, "ResultStatus": "Failed", "UserKey": "57e4bd36-9722-4a4a-9729-7203d8e00b72",
diff --git a/data_sources/okta.yml b/data_sources/okta.yml
index 27417c8961..4c4de15b28 100644
--- a/data_sources/okta.yml
+++ b/data_sources/okta.yml
@@ -1,18 +1,19 @@
name: Okta
id: ec26febe-e760-4981-bbee-72e107c7b9d2
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs authentication and administrative activities captured by Okta, including user login attempts, session management, and configuration changes.
+description: Logs authentication and administrative activities captured by Okta, including
+ user login attempts, session management, and configuration changes.
mitre_components:
-- User Account Authentication
-- Logon Session Creation
-- User Account Metadata
-- Configuration Modification
-- Application Log Content
+ - User Account Authentication
+ - Logon Session Creation
+ - User Account Metadata
+ - Configuration Modification
+ - Application Log Content
source: Okta
sourcetype: OktaIM2:log
supported_TA:
-- name: Splunk Add-on for Okta Identity Cloud
- url: https://splunkbase.splunk.com/app/6553
- version: 3.0.0
+ - name: Splunk Add-on for Okta Identity Cloud
+ url: https://splunkbase.splunk.com/app/6553
+ version: 3.0.0
diff --git a/data_sources/osquery.yml b/data_sources/osquery.yml
index bd8cb58790..b2b1828e0f 100644
--- a/data_sources/osquery.yml
+++ b/data_sources/osquery.yml
@@ -1,72 +1,73 @@
name: osquery
id: 7ec4d7c8-c1d0-423a-9169-261f6adb74c0
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs system queries performed using osquery, including details about processes, file access, network activity, and system configurations.
+description: Logs system queries performed using osquery, including details about
+ processes, file access, network activity, and system configurations.
mitre_components:
-- Process Metadata
-- File Access
-- Network Traffic Content
-- Host Status
-- Application Log Content
+ - Process Metadata
+ - File Access
+ - Network Traffic Content
+ - Host Status
+ - Application Log Content
source: osquery
sourcetype: osquery:results
supported_TA: []
fields:
-- _time
-- calendarTime
-- columns.cdhash
-- columns.child_pid
-- columns.cmdline
-- columns.cmdline_count
-- columns.cwd
-- columns.egid
-- columns.env
-- columns.env_count
-- columns.euid
-- columns.event_type
-- columns.exit_code
-- columns.gid
-- columns.global_seq_num
-- columns.original_parent
-- columns.parent
-- columns.path
-- columns.pid
-- columns.platform_binary
-- columns.seq_num
-- columns.signing_id
-- columns.team_id
-- columns.time
-- columns.uid
-- columns.username
-- columns.version
-- counter
-- dest
-- epoch
-- eventtype
-- host
-- hostIdentifier
-- index
-- linecount
-- name
-- numerics
-- parent_process_id
-- process_current_directory
-- process_id
-- process_path
-- punct
-- source
-- sourcetype
-- splunk_server
-- src
-- subject
-- tag
-- tag::eventtype
-- timestamp
-- unixTime
-- user_id
-- vendor_product
+ - _time
+ - calendarTime
+ - columns.cdhash
+ - columns.child_pid
+ - columns.cmdline
+ - columns.cmdline_count
+ - columns.cwd
+ - columns.egid
+ - columns.env
+ - columns.env_count
+ - columns.euid
+ - columns.event_type
+ - columns.exit_code
+ - columns.gid
+ - columns.global_seq_num
+ - columns.original_parent
+ - columns.parent
+ - columns.path
+ - columns.pid
+ - columns.platform_binary
+ - columns.seq_num
+ - columns.signing_id
+ - columns.team_id
+ - columns.time
+ - columns.uid
+ - columns.username
+ - columns.version
+ - counter
+ - dest
+ - epoch
+ - eventtype
+ - host
+ - hostIdentifier
+ - index
+ - linecount
+ - name
+ - numerics
+ - parent_process_id
+ - process_current_directory
+ - process_id
+ - process_path
+ - punct
+ - source
+ - sourcetype
+ - splunk_server
+ - src
+ - subject
+ - tag
+ - tag::eventtype
+ - timestamp
+ - unixTime
+ - user_id
+ - vendor_product
example_log: '{"name":"es_process_events","hostIdentifier":"HackBook.local","calendarTime":"Tue
Mar 29 13:03:51 2022 UTC","unixTime":1648559031,"epoch":0,"counter":82,"numerics":false,"columns":{"cdhash":"f63c5fbfcf1484b20aa4407a26e087fe3fe28146","child_pid":"","cmdline":"plutil
--help ","cmdline_count":"2","cwd":"/Users/patrick","egid":"20","env":"TERM_SESSION_ID=w0t1p0:93AA9D79-7028-49F1-A93D-4EAEFB7BA6E3
diff --git a/data_sources/palo_alto_network_threat.yml b/data_sources/palo_alto_network_threat.yml
index d9c2937be9..48d799c14e 100644
--- a/data_sources/palo_alto_network_threat.yml
+++ b/data_sources/palo_alto_network_threat.yml
@@ -1,43 +1,45 @@
name: Palo Alto Network Threat
id: 375c2b0e-d216-41ad-9406-200464595209
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs detected threats identified by Palo Alto Networks devices, including details about malware, intrusion attempts, and malicious network activity.
+description: Logs detected threats identified by Palo Alto Networks devices, including
+ details about malware, intrusion attempts, and malicious network activity.
mitre_components:
-- Malware Metadata
-- Network Traffic Content
-- Network Traffic Flow
-- Application Log Content
-- Host Status
+ - Malware Metadata
+ - Network Traffic Content
+ - Network Traffic Flow
+ - Application Log Content
+ - Host Status
source: pan:threat
sourcetype: pan:threat
supported_TA:
-- name: Palo Alto Networks Add-on
- url: https://splunkbase.splunk.com/app/2757
- version: 8.1.3
+ - name: Palo Alto Networks Add-on
+ url: https://splunkbase.splunk.com/app/2757
+ version: 8.1.3
fields:
-- _time
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- host
-- index
-- linecount
-- punct
-- source
-- sourcetype
-- splunk_server
-- timeendpos
-- timestartpos
+ - _time
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - host
+ - index
+ - linecount
+ - punct
+ - source
+ - sourcetype
+ - splunk_server
+ - timeendpos
+ - timestartpos
example_log: May 10 11:08:39 sjc.example.com 1,2022/05/10 11:08:38,013201004583,THREAT,url,2305,2022/05/10
11:08:38,2.18.4.7,1.2.3.4,2.18.4.7,1.2.3.4,service-globalprotect,,,web-browsing,vsys1,UNTRUST,UNTRUST,ethernet1/20,loopback.1,Zero,2022/05/10
11:08:38,1535535,1,32880,443,32880,20077,0x1403000,tcp,allow,"sr.example.com/mgmt/tm/util/bash",(9999),allow-URL,informational,client-to-server,7081856864553612091,0xa000000000000000,United
States,United States,0,,0,,,1,"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.36
- (KHTML, like Gecko) Chrome/36.0.1944.0 Safari/537.36",,,,,,,0,177,204,178,382,,sjc1-fw-01,,,,post,0,,0,,N/A,unknown,AppThreat-0-0,0x0,0,4294967295,,"
+ (KHTML, like Gecko) Chrome/36.0.1944.0
+ Safari/537.36",,,,,,,0,177,204,178,382,,sjc1-fw-01,,,,post,0,,0,,N/A,unknown,AppThreat-0-0,0x0,0,4294967295,,"
allow-URL,computer-and-internet-info,low-risk",5283cb95-6902-41db-96c6-ef807361eba5,0,
diff --git a/data_sources/palo_alto_network_traffic.yml b/data_sources/palo_alto_network_traffic.yml
index 02afe2d863..c4673e3fe7 100644
--- a/data_sources/palo_alto_network_traffic.yml
+++ b/data_sources/palo_alto_network_traffic.yml
@@ -1,41 +1,44 @@
name: Palo Alto Network Traffic
id: 182a83bc-c31a-4817-8c7a-263744cec52a
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs network traffic events captured by Palo Alto Networks devices, including details about sessions, protocols, and source and destination IPs.
+description: Logs network traffic events captured by Palo Alto Networks devices, including
+ details about sessions, protocols, and source and destination IPs.
mitre_components:
-- Network Traffic Content
-- Network Traffic Flow
-- Network Connection Creation
-- Response Metadata
-- Application Log Content
+ - Network Traffic Content
+ - Network Traffic Flow
+ - Network Connection Creation
+ - Response Metadata
+ - Application Log Content
source: screenconnect_palo_traffic
sourcetype: pan:traffic
supported_TA:
-- name: Palo Alto Networks Add-on
- url: https://splunkbase.splunk.com/app/2757
- version: 8.1.3
+ - name: Palo Alto Networks Add-on
+ url: https://splunkbase.splunk.com/app/2757
+ version: 8.1.3
fields:
-- _time
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- host
-- index
-- linecount
-- punct
-- source
-- sourcetype
-- splunk_server
-- timeendpos
-- timestartpos
+ - _time
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - host
+ - index
+ - linecount
+ - punct
+ - source
+ - sourcetype
+ - splunk_server
+ - timeendpos
+ - timestartpos
example_log: 577 <14>1 2024-02-22T12:33:50-05:00 PALO220.ATTACK_RANGE.LAN - - - -
- 1,2024/02/22 12:33:50,012801036556,TRAFFIC,end,2305,2024/02/22 12:33:50,192.168.1.205,147.28.146.44,201.17.96.104,147.28.146.44,No_Vuln_Filtering_OUT,,,screenconnect,vsys1,Trust,Untrust,ethernet1/2,ethernet1/1,splunk_range,2024/02/22
+ 1,2024/02/22 12:33:50,012801036556,TRAFFIC,end,2305,2024/02/22
+ 12:33:50,192.168.1.205,147.28.146.44,201.17.96.104,147.28.146.44,No_Vuln_Filtering_OUT,,,screenconnect,vsys1,Trust,Untrust,ethernet1/2,ethernet1/1,splunk_range,2024/02/22
12:33:50,14740,1,50624,443,11024,443,0x40005e,tcp,allow,7419,6609,810,25,2024/02/22
- 12:32:29,65,any,0,376156893,0x0,192.168.0.0-192.168.255.255,United States,0,14,11,tcp-fin,0,0,0,0,,PALO220,from-policy,,,0,,0,,N/A,0,0,0,0,0862e58b-4a54-436b-b3ac-ea3eccf8403b,0,0,,,,,,,
+ 12:32:29,65,any,0,376156893,0x0,192.168.0.0-192.168.255.255,United
+ States,0,14,11,tcp-fin,0,0,0,0,,PALO220,from-policy,,,0,,0,,N/A,0,0,0,0,0862e58b-4a54-436b-b3ac-ea3eccf8403b,0,0,,,,,,,
diff --git a/data_sources/pingid.yml b/data_sources/pingid.yml
index 2b77686143..5b7648219f 100644
--- a/data_sources/pingid.yml
+++ b/data_sources/pingid.yml
@@ -1,45 +1,46 @@
name: PingID
id: 17890675-61c1-40bd-a88e-6a8e9e246b43
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs authentication and multi-factor authentication (MFA) events managed by PingID, including user logins, device enrollments, and MFA challenges.
+description: Logs authentication and multi-factor authentication (MFA) events managed
+ by PingID, including user logins, device enrollments, and MFA challenges.
mitre_components:
-- User Account Authentication
-- Logon Session Metadata
-- User Account Metadata
-- Application Log Content
-- Host Status
+ - User Account Authentication
+ - Logon Session Metadata
+ - User Account Metadata
+ - Application Log Content
+ - Host Status
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
supported_TA: []
fields:
-- _time
-- actors{}.name
-- actors{}.type
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- extracted_source
-- host
-- id
-- index
-- linecount
-- punct
-- recorded
-- resources{}.ipaddress
-- resources{}.websession
-- result.message
-- result.status
-- source
-- sourcetype
-- splunk_server
-- timeendpos
-- timestartpos
+ - _time
+ - actors{}.name
+ - actors{}.type
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - extracted_source
+ - host
+ - id
+ - index
+ - linecount
+ - punct
+ - recorded
+ - resources{}.ipaddress
+ - resources{}.websession
+ - result.message
+ - result.status
+ - source
+ - sourcetype
+ - splunk_server
+ - timeendpos
+ - timestartpos
example_log: '{"source":"PINGID","id":"b2eb1fef-651b-11ee-b38b-0ac7a554ed19","recorded":"2023-10-05T14:10:53.538Z","actors":[{"type":"user","name":"victim_user"}],"resources":[{"ipaddress":"174.235.80.142","websession":"webs_ijkF-T_bAC_G3w2TfvdpAEQeC545KFlqVFOsolCXdjo"}],"result":{"status":"SUCCESS","message":"Device
Paired SMS \"Mobile 1\""}}'
diff --git a/data_sources/powershell_installed_iis_modules.yml b/data_sources/powershell_installed_iis_modules.yml
index cf0b592d7b..3e466057a5 100644
--- a/data_sources/powershell_installed_iis_modules.yml
+++ b/data_sources/powershell_installed_iis_modules.yml
@@ -1,26 +1,27 @@
name: Powershell Installed IIS Modules
id: 4f2ccf42-3503-4417-a684-bfccf7f0d7b4
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the list of installed IIS modules retrieved using PowerShell, including details about their names and statuses.
+description: Logs the list of installed IIS modules retrieved using PowerShell, including
+ details about their names and statuses.
mitre_components:
-- Service Metadata
-- Configuration Modification
-- OS API Execution
-- Application Log Content
+ - Service Metadata
+ - Configuration Modification
+ - OS API Execution
+ - Application Log Content
source: powershell://AppCmdModules
sourcetype: Pwsh:InstalledIISModules
supported_TA: []
fields:
-- _time
-- Schema
-- host
-- index
-- linecount
-- punct
-- source
-- sourcetype
-- splunk_server
-- timestamp
+ - _time
+ - Schema
+ - host
+ - index
+ - linecount
+ - punct
+ - source
+ - sourcetype
+ - splunk_server
+ - timestamp
example_log: Schema="Microsoft.IIs.PowerShell.Framework.ConfigurationElementSchema"
diff --git a/data_sources/powershell_script_block_logging_4104.yml b/data_sources/powershell_script_block_logging_4104.yml
index b5aba9d7f7..67794c1e47 100644
--- a/data_sources/powershell_script_block_logging_4104.yml
+++ b/data_sources/powershell_script_block_logging_4104.yml
@@ -1,95 +1,97 @@
name: Powershell Script Block Logging 4104
id: 5cfd0c72-d989-47a0-92f9-6edc6f8d3564
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs detailed content of PowerShell script blocks as they are executed, including the full command text and context for the execution.
+description: Logs detailed content of PowerShell script blocks as they are executed,
+ including the full command text and context for the execution.
mitre_components:
-- Script Execution
-- Command Execution
-- Process Metadata
-- OS API Execution
-- Application Log Content
+ - Script Execution
+ - Command Execution
+ - Process Metadata
+ - OS API Execution
+ - Application Log Content
source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
sourcetype: xmlwineventlog
separator: EventID
separator_value: 4104
supported_TA:
-- name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+ - name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
-- _time
-- ActivityID
-- Channel
-- Computer
-- EventCode
-- EventData_Xml
-- EventID
-- EventRecordID
-- Guid
-- Keywords
-- Level
-- MessageNumber
-- MessageTotal
-- Name
-- Opcode
-- Path
-- ProcessID
-- RecordNumber
-- ScriptBlockId
-- ScriptBlockText
-- SystemTime
-- System_Props_Xml
-- Task
-- ThreadID
-- UserID
-- Version
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dvc
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- punct
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user_id
-- vendor_product
+ - _time
+ - ActivityID
+ - Channel
+ - Computer
+ - EventCode
+ - EventData_Xml
+ - EventID
+ - EventRecordID
+ - Guid
+ - Keywords
+ - Level
+ - MessageNumber
+ - MessageTotal
+ - Name
+ - Opcode
+ - Path
+ - ProcessID
+ - RecordNumber
+ - ScriptBlockId
+ - ScriptBlockText
+ - SystemTime
+ - System_Props_Xml
+ - Task
+ - ThreadID
+ - UserID
+ - Version
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dvc
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - punct
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user_id
+ - vendor_product
field_mappings:
-- data_model: cim
- data_set: Endpoint.Processes
- mapping:
- Computer: Processes.dest
- Path: Processes.process_path
- ScriptBlockId: Processes.process_id
- ScriptBlockText: Processes.process
- UserID: Processes.user_id
-- data_model: ocsf
- mapping:
- Computer: device.hostname
- Path: process.file.path
- ScriptBlockId: process.uid
- ScriptBlockText: process.cmd_line
- UserID: actor.user.uid
+ - data_model: cim
+ data_set: Endpoint.Processes
+ mapping:
+ Computer: Processes.dest
+ Path: Processes.process_path
+ ScriptBlockId: Processes.process_id
+ ScriptBlockText: Processes.process
+ UserID: Processes.user_id
+ - data_model: ocsf
+ mapping:
+ Computer: device.hostname
+ Path: process.file.path
+ ScriptBlockId: process.uid
+ ScriptBlockText: process.cmd_line
+ UserID: actor.user.uid
example_log: 4104152150x04104152150x0112748Microsoft-Windows-PowerShell/Operationalwin-dc-mhaag-attack-range-270.attackrange.local154100x80000000000000004522Microsoft-Windows-Sysmon/Operationalwin-dc-6764986.attackrange.local-2020-10-08\
- \ 11:03:46.615{96128EA2-F212-5F7E-E400-000000007F01}2296C:\\Windows\\System32\\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows\
- \ Command ProcessorMicrosoft\xAE Windows\xAE Operating\
- \ SystemMicrosoft CorporationCmd.Exe\"C:\\Windows\\system32\\cmd.exe\" /c \"reg save HKLM\\sam\
- \ %%temp%%\\sam & reg save HKLM\\system %%temp%%\\system & reg save HKLM\\\
- security %%temp%%\\security\" C:\\Users\\ADMINI~1\\\
- AppData\\Local\\Temp\\ATTACKRANGE\\Administrator{96128EA2-F210-5F7E-ACD4-080000000000}0x8d4ac0HighMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{96128EA2-F211-5F7E-DF00-000000007F01}4624C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADAAMwAuADAAMAAyACIAIAAtAEMAbwBuAGYAaQByAG0AOgAkAGYAYQBsAHMAZQAgAC0AVABpAG0AZQBvAHUAdABTAGUAYwBvAG4AZABzACAAMwAwADAAIAAtAEUAeABlAGMAdQB0AGkAbwBuAEwAbwBnAFAAYQB0AGgAIABDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAYQB0AGMAXwBlAHgAZQBjAHUAdABpAG8AbgAuAGMAcwB2AA=="
+ - data_source: Windows Event Log Security 4688
+ mapping:
+ ProcessId: NewProcessId
+ Image: NewProcessName
+ Image|endswith: NewProcessName|endswith
+ CommandLine: Process_Command_Line
+ User: SubjectUserSid
+ ParentProcessId: ProcessId
+ ParentImage: ParentProcessName
+ ParentImage|endswith: ParentProcessName|endswith
+ Computer: Computer
+ OriginalFileName: NewProcessName|endswith
+ - data_source: Crowdstrike Process
+ mapping:
+ ProcessId: RawProcessId
+ Image: ImageFileName
+ CommandLine: CommandLine
+ User: UserSid
+ ParentProcessId: ParentProcessId
+ ParentImage: ParentBaseFileName
+example_log: 154100x80000000000000004522Microsoft-Windows-Sysmon/Operationalwin-dc-6764986.attackrange.local-2020-10-08
+ 11:03:46.615{96128EA2-F212-5F7E-E400-000000007F01}2296C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows
+ Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.Exe"C:\Windows\system32\cmd.exe" /c "reg save HKLM\sam %%temp%%\sam
+ & reg save HKLM\system %%temp%%\system & reg save HKLM\security %%temp%%\security"
+ C:\Users\ADMINI~1\AppData\Local\Temp\ATTACKRANGE\Administrator{96128EA2-F210-5F7E-ACD4-080000000000}0x8d4ac0HighMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{96128EA2-F211-5F7E-DF00-000000007F01}4624C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"powershell.exe" -noninteractive -encodedcommand
+ WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADAAMwAuADAAMAAyACIAIAAtAEMAbwBuAGYAaQByAG0AOgAkAGYAYQBsAHMAZQAgAC0AVABpAG0AZQBvAHUAdABTAGUAYwBvAG4AZABzACAAMwAwADAAIAAtAEUAeABlAGMAdQB0AGkAbwBuAEwAbwBnAFAAYQB0AGgAIABDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAYQB0AGMAXwBlAHgAZQBjAHUAdABpAG8AbgAuAGMAcwB2AA==
diff --git a/data_sources/sysmon_eventid_10.yml b/data_sources/sysmon_eventid_10.yml
index 80713f8dc3..6197a6a241 100644
--- a/data_sources/sysmon_eventid_10.yml
+++ b/data_sources/sysmon_eventid_10.yml
@@ -1,106 +1,109 @@
name: Sysmon EventID 10
id: 659cd5a8-148a-4c59-ade1-05f41ac1b096
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs events where one process accesses another process, typically for memory reads or injections, including details about the source and target processes.
+description: Logs events where one process accesses another process, typically for
+ memory reads or injections, including details about the source and target processes.
mitre_components:
-- Process Access
-- Process Metadata
-- Application Log Content
-- OS API Execution
+ - Process Access
+ - Process Metadata
+ - Application Log Content
+ - OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
separator_value: 10
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
-- name: Splunk Add-on for Sysmon
- url: https://splunkbase.splunk.com/app/5709
- version: 4.0.2
+ - name: Splunk Add-on for Sysmon
+ url: https://splunkbase.splunk.com/app/5709
+ version: 4.0.2
fields:
-- _time
-- CallTrace
-- Channel
-- Computer
-- EventChannel
-- EventCode
-- EventData_Xml
-- EventDescription
-- EventID
-- EventRecordID
-- GrantedAccess
-- Guid
-- Keywords
-- Level
-- Name
-- Opcode
-- ProcessID
-- RecordID
-- RecordNumber
-- RuleName
-- SecurityID
-- SourceImage
-- SourceProcessGUID
-- SourceProcessId
-- SourceThreadId
-- SystemTime
-- System_Props_Xml
-- TargetImage
-- TargetProcessGUID
-- TargetProcessId
-- Task
-- ThreadID
-- TimeCreated
-- UserID
-- UtcTime
-- Version
-- action
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- dvc_nt_host
-- event_id
-- eventtype
-- granted_access
-- host
-- id
-- index
-- linecount
-- os
-- parent_process_exec
-- parent_process_guid
-- parent_process_id
-- parent_process_name
-- parent_process_path
-- process_exec
-- process_guid
-- process_id
-- process_name
-- process_path
-- punct
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user_id
-- vendor_product
+ - _time
+ - CallTrace
+ - Channel
+ - Computer
+ - EventChannel
+ - EventCode
+ - EventData_Xml
+ - EventDescription
+ - EventID
+ - EventRecordID
+ - GrantedAccess
+ - Guid
+ - Keywords
+ - Level
+ - Name
+ - Opcode
+ - ProcessID
+ - RecordID
+ - RecordNumber
+ - RuleName
+ - SecurityID
+ - SourceImage
+ - SourceProcessGUID
+ - SourceProcessId
+ - SourceThreadId
+ - SystemTime
+ - System_Props_Xml
+ - TargetImage
+ - TargetProcessGUID
+ - TargetProcessId
+ - Task
+ - ThreadID
+ - TimeCreated
+ - UserID
+ - UtcTime
+ - Version
+ - action
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - granted_access
+ - host
+ - id
+ - index
+ - linecount
+ - os
+ - parent_process_exec
+ - parent_process_guid
+ - parent_process_id
+ - parent_process_name
+ - parent_process_path
+ - process_exec
+ - process_guid
+ - process_id
+ - process_name
+ - process_path
+ - punct
+ - signature
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user_id
+ - vendor_product
example_log: 10341000x800000000000000010341000x8000000000000000150624412Microsoft-Windows-Sysmon/Operationalwin-dc-128.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-128.attackrange.local-2022-02-01
21:01:44.670{3BF36828-9F6D-61F9-390A-02000000CF01}1272956C:\Tools\Rubeus.exe11241100x800000000000000011241100x80000000000000007712490Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-84.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-84.attackrange.localDownloads2023-02-08 13:01:11.053{0F9A6540-A70E-63E2-3091-00000000BD02}9332C:\Users\Administrator\Downloads\mimikatz_trunk\x64\mimikatz.exe9332C:\Users\Administrator\Downloads\mimikatz_trunk\x64\mimikatz.exeC:\Users\Administrator\Downloads\mimikatz_trunk\x64\CURRENT_USER_My_4_atomic@art2.local.pfx2023-02-08 13:01:11.053
diff --git a/data_sources/sysmon_eventid_12.yml b/data_sources/sysmon_eventid_12.yml
index 665a69a98e..57e13fb712 100644
--- a/data_sources/sysmon_eventid_12.yml
+++ b/data_sources/sysmon_eventid_12.yml
@@ -1,103 +1,107 @@
name: Sysmon EventID 12
id: 3ef28798-8eaa-4fd2-b074-6f36d08a1b33
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the creation of a new registry key, including details about the key name, registry path, and associated process metadata.
+description: Logs the creation of a new registry key, including details about the
+ key name, registry path, and associated process metadata.
mitre_components:
-- Windows Registry Key Creation
-- Process Metadata
-- Application Log Content
-- OS API Execution
+ - Windows Registry Key Creation
+ - Process Metadata
+ - Application Log Content
+ - OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
separator_value: 12
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
-- name: Splunk Add-on for Sysmon
- url: https://splunkbase.splunk.com/app/5709
- version: 4.0.2
+ - name: Splunk Add-on for Sysmon
+ url: https://splunkbase.splunk.com/app/5709
+ version: 4.0.2
fields:
-- _time
-- Channel
-- Computer
-- EventChannel
-- EventCode
-- EventData_Xml
-- EventDescription
-- EventID
-- EventRecordID
-- EventType
-- Guid
-- Image
-- Keywords
-- Level
-- Name
-- Opcode
-- ProcessGuid
-- ProcessID
-- ProcessId
-- RecordID
-- RecordNumber
-- RuleName
-- SecurityID
-- SystemTime
-- System_Props_Xml
-- TargetObject
-- Task
-- ThreadID
-- TimeCreated
-- UserID
-- UtcTime
-- Version
-- action
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- object_category
-- object_path
-- process_exec
-- process_guid
-- process_id
-- process_name
-- process_path
-- punct
-- registry_hive
-- registry_key_name
-- registry_path
-- severity_id
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- status
-- tag
-- tag::eventtype
-- tag::object_category
-- timeendpos
-- timestartpos
-- user_id
-- vendor_product
+ - _time
+ - Channel
+ - Computer
+ - EventChannel
+ - EventCode
+ - EventData_Xml
+ - EventDescription
+ - EventID
+ - EventRecordID
+ - EventType
+ - Guid
+ - Image
+ - Keywords
+ - Level
+ - Name
+ - Opcode
+ - ProcessGuid
+ - ProcessID
+ - ProcessId
+ - RecordID
+ - RecordNumber
+ - RuleName
+ - SecurityID
+ - SystemTime
+ - System_Props_Xml
+ - TargetObject
+ - Task
+ - ThreadID
+ - TimeCreated
+ - UserID
+ - UtcTime
+ - Version
+ - action
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - object_category
+ - object_path
+ - process_exec
+ - process_guid
+ - process_id
+ - process_name
+ - process_path
+ - punct
+ - registry_hive
+ - registry_key_name
+ - registry_path
+ - severity_id
+ - signature
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - status
+ - tag
+ - tag::eventtype
+ - tag::object_category
+ - timeendpos
+ - timestartpos
+ - user_id
+ - vendor_product
example_log: 12241200x800000000000000012241200x80000000000000001055579Microsoft-Windows-Sysmon/Operationalwin-dc-890.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-890.attackrange.local-DeleteKey2021-07-12 08:10:32.592{466BC892-F8F2-60EB-107E-00000000CF01}10188C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10188C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-2333072374-3391925831-3197092227-1112_Classes\exefile\shell\runas\command
diff --git a/data_sources/sysmon_eventid_13.yml b/data_sources/sysmon_eventid_13.yml
index d7ed659f74..d533ac7a5c 100644
--- a/data_sources/sysmon_eventid_13.yml
+++ b/data_sources/sysmon_eventid_13.yml
@@ -1,118 +1,121 @@
name: Sysmon EventID 13
id: 19cd00ee-f65f-48ca-bb08-64aac28638ce
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs changes to a registry key, including details about the modified key, value, and associated process.
+description: Logs changes to a registry key, including details about the modified
+ key, value, and associated process.
mitre_components:
-- Windows Registry Key Modification
-- Process Metadata
-- Application Log Content
-- OS API Execution
+ - Windows Registry Key Modification
+ - Process Metadata
+ - Application Log Content
+ - OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
separator_value: 13
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
-- name: Splunk Add-on for Sysmon
- url: https://splunkbase.splunk.com/app/5709
- version: 4.0.2
+ - name: Splunk Add-on for Sysmon
+ url: https://splunkbase.splunk.com/app/5709
+ version: 4.0.2
fields:
-- _time
-- Channel
-- Computer
-- Details
-- EventChannel
-- EventCode
-- EventData_Xml
-- EventDescription
-- EventID
-- EventRecordID
-- EventType
-- Guid
-- Image
-- Keywords
-- Level
-- Name
-- Opcode
-- ProcessGuid
-- ProcessID
-- ProcessId
-- RecordID
-- RecordNumber
-- RegistryValueData
-- RegistryValueType
-- RuleName
-- SecurityID
-- SystemTime
-- System_Props_Xml
-- TargetObject
-- Task
-- ThreadID
-- TimeCreated
-- UserID
-- UtcTime
-- Version
-- action
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- object_category
-- object_path
-- process_exec
-- process_guid
-- process_id
-- process_name
-- process_path
-- punct
-- registry_hive
-- registry_key_name
-- registry_path
-- registry_value_data
-- registry_value_name
-- registry_value_type
-- severity_id
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- status
-- tag
-- tag::eventtype
-- tag::object_category
-- timeendpos
-- timestartpos
-- user_id
-- vendor_product
+ - _time
+ - Channel
+ - Computer
+ - Details
+ - EventChannel
+ - EventCode
+ - EventData_Xml
+ - EventDescription
+ - EventID
+ - EventRecordID
+ - EventType
+ - Guid
+ - Image
+ - Keywords
+ - Level
+ - Name
+ - Opcode
+ - ProcessGuid
+ - ProcessID
+ - ProcessId
+ - RecordID
+ - RecordNumber
+ - RegistryValueData
+ - RegistryValueType
+ - RuleName
+ - SecurityID
+ - SystemTime
+ - System_Props_Xml
+ - TargetObject
+ - Task
+ - ThreadID
+ - TimeCreated
+ - UserID
+ - UtcTime
+ - Version
+ - action
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - object_category
+ - object_path
+ - process_exec
+ - process_guid
+ - process_id
+ - process_name
+ - process_path
+ - punct
+ - registry_hive
+ - registry_key_name
+ - registry_path
+ - registry_value_data
+ - registry_value_name
+ - registry_value_type
+ - severity_id
+ - signature
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - status
+ - tag
+ - tag::eventtype
+ - tag::object_category
+ - timeendpos
+ - timestartpos
+ - user_id
+ - vendor_product
field_mappings:
-- data_model: cim
- data_set: Endpoint.Registry
- mapping:
- Computer: Registry.dest
- ProcessGuid: Registry.process_guid
- ProcessId: Registry.process_id
- TargetObject: Registry.registry_path
- Details: Registry.registry_value_data
+ - data_model: cim
+ data_set: Endpoint.Registry
+ mapping:
+ Computer: Registry.dest
+ ProcessGuid: Registry.process_guid
+ ProcessId: Registry.process_id
+ TargetObject: Registry.registry_path
+ Details: Registry.registry_value_data
example_log: 13241300x800000000000000013241300x8000000000000000810987Microsoft-Windows-Sysmon/Operationalwin-host-623.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-host-623.attackrange.local-SetValue2021-07-12 08:11:04.547{0C1E0330-048F-60E8-0B00-00000000D001}628C:\Windows\system32\lsass.exe15241500x800000000000000015241500x8000000000000000667860Microsoft-Windows-Sysmon/Operationalproject-mumbai-hostMicrosoft-Windows-Sysmon/Operationalproject-mumbai-host-2021-04-28
20:11:34.709{ED2ECF8A-C154-6089-F967-00000000BB01}7000C:\Users\DefaultAccount\AppData\Roaming\Telegram
Desktop\Telegram.exeC:\Users\DefaultAccount\Downloads\Telegram
Desktop\Good(NLA).txt:Zone.Identifier2021-04-28
- 20:11:33.238MD5=C785C55D5FA3443A11B8417209C4B524,SHA256=D07777E0DC36EBECCE3FA9644F0F44DC4A0B7EDE0CBC1F5D33E8D6CB07AF5B5C,IMPHASH=00000000000000000000000000000000MD5=C785C55D5FA3443A11B8417209C4B524,SHA256=D07777E0DC36EBECCE3FA9644F0F44DC4A0B7EDE0CBC1F5D33E8D6CB07AF5B5C,IMPHASH=00000000000000000000000000000000[ZoneTransfer] ZoneId=3
diff --git a/data_sources/sysmon_eventid_17.yml b/data_sources/sysmon_eventid_17.yml
index 221feadee2..17f9cba91f 100644
--- a/data_sources/sysmon_eventid_17.yml
+++ b/data_sources/sysmon_eventid_17.yml
@@ -1,94 +1,96 @@
name: Sysmon EventID 17
id: 08924246-c8e8-4c95-a9fc-633c43cc82df
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Sysmon EventID 17 logs details about the detection of a named pipe.
mitre_components:
-- Named Pipe Metadata
+ - Named Pipe Metadata
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
separator_value: 17
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
-- name: Splunk Add-on for Sysmon
- url: https://splunkbase.splunk.com/app/5709
- version: 4.0.2
+ - name: Splunk Add-on for Sysmon
+ url: https://splunkbase.splunk.com/app/5709
+ version: 4.0.2
fields:
-- _time
-- Channel
-- Computer
-- EventChannel
-- EventCode
-- EventData_Xml
-- EventDescription
-- EventID
-- EventRecordID
-- EventType
-- Guid
-- Image
-- Keywords
-- Level
-- Name
-- Opcode
-- PipeName
-- ProcessGuid
-- ProcessID
-- ProcessId
-- RecordID
-- RecordNumber
-- RuleName
-- SecurityID
-- SystemTime
-- System_Props_Xml
-- Task
-- ThreadID
-- TimeCreated
-- UserID
-- UtcTime
-- Version
-- action
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- os
-- pipe_name
-- process_exec
-- process_guid
-- process_id
-- process_name
-- process_path
-- punct
-- severity_id
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user_id
-- vendor_product
+ - _time
+ - Channel
+ - Computer
+ - EventChannel
+ - EventCode
+ - EventData_Xml
+ - EventDescription
+ - EventID
+ - EventRecordID
+ - EventType
+ - Guid
+ - Image
+ - Keywords
+ - Level
+ - Name
+ - Opcode
+ - PipeName
+ - ProcessGuid
+ - ProcessID
+ - ProcessId
+ - RecordID
+ - RecordNumber
+ - RuleName
+ - SecurityID
+ - SystemTime
+ - System_Props_Xml
+ - Task
+ - ThreadID
+ - TimeCreated
+ - UserID
+ - UtcTime
+ - Version
+ - action
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - os
+ - pipe_name
+ - process_exec
+ - process_guid
+ - process_id
+ - process_name
+ - process_path
+ - punct
+ - severity_id
+ - signature
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user_id
+ - vendor_product
example_log: 17141700x800000000000000017141700x8000000000000000162168Microsoft-Windows-Sysmon/Operationalwin-dc-982.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-982.attackrange.local-CreatePipe2021-04-19 21:00:18.288{761B69BB-EF62-607D-B211-00000000BA01}6960\MSSE-1516-server18141800x800000000000000018141800x8000000000000000162173Microsoft-Windows-Sysmon/Operationalwin-dc-982.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-982.attackrange.local-ConnectPipe2021-04-19 21:00:19.312{761B69BB-EF62-607D-B211-00000000BA01}6960\MSSE-1516-server20342000x800000000000000020342000x80000000000000006249Microsoft-Windows-Sysmon/Operationalwin-dc-935.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-935.attackrange.local-WmiConsumerEvent2020-12-08 13:54:48.514DeletedATTACKRANGE\Administrator "AtomicRedTeam-WMIPersistence-Example"21342100x800000000000000021342100x8000000000000000151644Microsoft-Windows-Sysmon/Operationalwin-host-14.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-host-14.attackrange.local-WmiBindingEvent2021-06-16 21:46:50.222ModifiedWIN-HOST-14\Administrator "CommandLineEventConsumer.Name=\"Evil
diff --git a/data_sources/sysmon_eventid_22.yml b/data_sources/sysmon_eventid_22.yml
index 5ed15373d4..a40a8dc863 100644
--- a/data_sources/sysmon_eventid_22.yml
+++ b/data_sources/sysmon_eventid_22.yml
@@ -1,96 +1,99 @@
name: Sysmon EventID 22
id: 911538b2-eba7-4d3e-85e8-d82d380c37bf
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs DNS query events, including details about the queried domain, source IP, query type, and response data.
+description: Logs DNS query events, including details about the queried domain, source
+ IP, query type, and response data.
mitre_components:
-- Passive DNS
-- Active DNS
-- Network Traffic Content
-- Network Traffic Flow
-- Application Log Content
+ - Passive DNS
+ - Active DNS
+ - Network Traffic Content
+ - Network Traffic Flow
+ - Application Log Content
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
separator_value: 22
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
-- name: Splunk Add-on for Sysmon
- url: https://splunkbase.splunk.com/app/5709
- version: 4.0.2
+ - name: Splunk Add-on for Sysmon
+ url: https://splunkbase.splunk.com/app/5709
+ version: 4.0.2
fields:
-- _time
-- Channel
-- Computer
-- EventChannel
-- EventCode
-- EventData_Xml
-- EventDescription
-- EventID
-- EventRecordID
-- Guid
-- Image
-- Keywords
-- Level
-- Name
-- Opcode
-- ProcessGuid
-- ProcessID
-- ProcessId
-- QueryName
-- QueryResults
-- QueryStatus
-- RecordID
-- RecordNumber
-- RuleName
-- SecurityID
-- SystemTime
-- System_Props_Xml
-- Task
-- ThreadID
-- TimeCreated
-- UserID
-- UtcTime
-- Version
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- process_exec
-- process_guid
-- process_name
-- punct
-- query
-- query_count
-- reply_code_id
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- src
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user_id
-- vendor_product
+ - _time
+ - Channel
+ - Computer
+ - EventChannel
+ - EventCode
+ - EventData_Xml
+ - EventDescription
+ - EventID
+ - EventRecordID
+ - Guid
+ - Image
+ - Keywords
+ - Level
+ - Name
+ - Opcode
+ - ProcessGuid
+ - ProcessID
+ - ProcessId
+ - QueryName
+ - QueryResults
+ - QueryStatus
+ - RecordID
+ - RecordNumber
+ - RuleName
+ - SecurityID
+ - SystemTime
+ - System_Props_Xml
+ - Task
+ - ThreadID
+ - TimeCreated
+ - UserID
+ - UtcTime
+ - Version
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - process_exec
+ - process_guid
+ - process_name
+ - punct
+ - query
+ - query_count
+ - reply_code_id
+ - signature
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - src
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user_id
+ - vendor_product
example_log: 22542200x800000000000000022542200x8000000000000000113892Microsoft-Windows-Sysmon/Operationalwin-dc-299.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-299.attackrange.local-2021-03-24
12:25:12.840{3CFDEE80-2F7D-605B-F50A-00000000AE01}717250.220.65.3.spam.dnsbl.sorbs.net23542300x800000000000000023542300x8000000000000000281771Microsoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-865.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-865.attackrange.local-2023-02-01
10:57:09.814{F522A29C-446D-63DA-9F01-00000000BB02}2428ATTACKRANGE\Administrator354300x8000000000000000354300x8000000000000000156837Microsoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-403.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-403.attackrange.local-2022-09-15
12:56:19.679{6820D070-1F1B-6323-E113-000000007402}5728C:\Temp\agent_tesla-deob.exe534500x8000000000000000534500x800000000000000039965Microsoft-Windows-Sysmon/Operationalwin-dc-654.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-654.attackrange.local-2021-03-16
14:01:44.004{26337912-BA32-6050-3506-00000000AE01}8672C:\Users\Public\steam.exe
diff --git a/data_sources/sysmon_eventid_6.yml b/data_sources/sysmon_eventid_6.yml
index 9cf7db46b6..d019cb51cf 100644
--- a/data_sources/sysmon_eventid_6.yml
+++ b/data_sources/sysmon_eventid_6.yml
@@ -1,98 +1,102 @@
name: Sysmon EventID 6
id: eadc297a-c20c-45a1-8fac-74ad54019767
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the loading of a driver into the kernel or user mode, including details about the driver name, file path, and associated process metadata.
+description: Logs the loading of a driver into the kernel or user mode, including
+ details about the driver name, file path, and associated process metadata.
mitre_components:
-- Driver Load
-- Process Metadata
-- Application Log Content
-- OS API Execution
+ - Driver Load
+ - Process Metadata
+ - Application Log Content
+ - OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
separator_value: 6
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
-- name: Splunk Add-on for Sysmon
- url: https://splunkbase.splunk.com/app/5709
- version: 4.0.2
+ - name: Splunk Add-on for Sysmon
+ url: https://splunkbase.splunk.com/app/5709
+ version: 4.0.2
fields:
-- _time
-- Channel
-- Computer
-- EventChannel
-- EventCode
-- EventData_Xml
-- EventDescription
-- EventID
-- EventRecordID
-- Guid
-- Hashes
-- ImageLoaded
-- Keywords
-- Level
-- MD5
-- Name
-- Opcode
-- ProcessID
-- RecordID
-- RecordNumber
-- RuleName
-- SHA256
-- SecurityID
-- Signature
-- SignatureStatus
-- Signed
-- SystemTime
-- System_Props_Xml
-- Task
-- ThreadID
-- TimeCreated
-- UserID
-- UtcTime
-- Version
-- action
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- os
-- process_hash
-- process_path
-- punct
-- service_signature_exists
-- service_signature_verified
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user_id
-- vendor_product
+ - _time
+ - Channel
+ - Computer
+ - EventChannel
+ - EventCode
+ - EventData_Xml
+ - EventDescription
+ - EventID
+ - EventRecordID
+ - Guid
+ - Hashes
+ - ImageLoaded
+ - Keywords
+ - Level
+ - MD5
+ - Name
+ - Opcode
+ - ProcessID
+ - RecordID
+ - RecordNumber
+ - RuleName
+ - SHA256
+ - SecurityID
+ - Signature
+ - SignatureStatus
+ - Signed
+ - SystemTime
+ - System_Props_Xml
+ - Task
+ - ThreadID
+ - TimeCreated
+ - UserID
+ - UtcTime
+ - Version
+ - action
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - os
+ - process_hash
+ - process_path
+ - punct
+ - service_signature_exists
+ - service_signature_verified
+ - signature
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user_id
+ - vendor_product
example_log: 644600x8000000000000000644600x800000000000000015708989Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-702.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-702.attackrange.local-2022-04-04
- 17:37:04.640C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\npf.sysC:\Program
+ Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\npf.sysMD5=DE7FCC77F4A503AF4CA6A47D49B3713D,SHA256=4BFAA99393F635CD05D91A64DE73EDB5639412C129E049F0FE34F88517A10FC6trueRiverbed Technology, Inc.Valid
diff --git a/data_sources/sysmon_eventid_7.yml b/data_sources/sysmon_eventid_7.yml
index 24d4800817..23a3dcf3a1 100644
--- a/data_sources/sysmon_eventid_7.yml
+++ b/data_sources/sysmon_eventid_7.yml
@@ -1,121 +1,125 @@
name: Sysmon EventID 7
id: 45512fa5-4d55-4088-9d51-f4dedc16fdff
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the loading of an image (module) into a process, including details about the image name, file path, and hash information.
+description: Logs the loading of an image (module) into a process, including details
+ about the image name, file path, and hash information.
mitre_components:
-- Module Load
-- Process Metadata
-- File Metadata
-- Application Log Content
-- OS API Execution
+ - Module Load
+ - Process Metadata
+ - File Metadata
+ - Application Log Content
+ - OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
separator_value: 7
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
-- name: Splunk Add-on for Sysmon
- url: https://splunkbase.splunk.com/app/5709
- version: 4.0.2
+ - name: Splunk Add-on for Sysmon
+ url: https://splunkbase.splunk.com/app/5709
+ version: 4.0.2
fields:
-- _time
-- Channel
-- Company
-- Computer
-- Description
-- EventChannel
-- EventCode
-- EventData_Xml
-- EventDescription
-- EventID
-- EventRecordID
-- FileVersion
-- Guid
-- Hashes
-- IMPHASH
-- Image
-- ImageLoaded
-- Keywords
-- Level
-- MD5
-- Name
-- Opcode
-- OriginalFileName
-- ProcessGuid
-- ProcessID
-- ProcessId
-- Product
-- RecordID
-- RecordNumber
-- RuleName
-- SHA256
-- SecurityID
-- Signature
-- SignatureStatus
-- Signed
-- SystemTime
-- System_Props_Xml
-- Task
-- ThreadID
-- TimeCreated
-- User
-- UserID
-- UtcTime
-- Version
-- action
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- os
-- parent_process_exec
-- parent_process_guid
-- parent_process_id
-- parent_process_name
-- parent_process_path
-- process_exec
-- process_hash
-- process_name
-- process_path
-- punct
-- service_dll_signature_exists
-- service_dll_signature_verified
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- tag
-- tag::action
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- user_id
-- vendor_product
+ - _time
+ - Channel
+ - Company
+ - Computer
+ - Description
+ - EventChannel
+ - EventCode
+ - EventData_Xml
+ - EventDescription
+ - EventID
+ - EventRecordID
+ - FileVersion
+ - Guid
+ - Hashes
+ - IMPHASH
+ - Image
+ - ImageLoaded
+ - Keywords
+ - Level
+ - MD5
+ - Name
+ - Opcode
+ - OriginalFileName
+ - ProcessGuid
+ - ProcessID
+ - ProcessId
+ - Product
+ - RecordID
+ - RecordNumber
+ - RuleName
+ - SHA256
+ - SecurityID
+ - Signature
+ - SignatureStatus
+ - Signed
+ - SystemTime
+ - System_Props_Xml
+ - Task
+ - ThreadID
+ - TimeCreated
+ - User
+ - UserID
+ - UtcTime
+ - Version
+ - action
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - os
+ - parent_process_exec
+ - parent_process_guid
+ - parent_process_id
+ - parent_process_name
+ - parent_process_path
+ - process_exec
+ - process_hash
+ - process_name
+ - process_path
+ - punct
+ - service_dll_signature_exists
+ - service_dll_signature_verified
+ - signature
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - tag
+ - tag::action
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - user_id
+ - vendor_product
example_log: 734700x8000000000000000734700x800000000000000045273Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.localMicrosoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-2023-09-12
08:06:31.433{8814F3F5-1C07-6500-9600-000000000E03}4440C:\Users\Administrator\AppData\Local\Temp\server.exeC:\Users\Administrator\AppData\Local\Temp\server.exe-----MD5=696CBE2CB6F7FAC5ED6262BCA51238BB,SHA256=43005D86607DC94C7D378AA1B8844947BAA03860652F2F2340266061AF12E524,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744--MD5=696CBE2CB6F7FAC5ED6262BCA51238BB,SHA256=43005D86607DC94C7D378AA1B8844947BAA03860652F2F2340266061AF12E524,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744false-UnavailableATTACKRANGE\Administrator
diff --git a/data_sources/sysmon_eventid_8.yml b/data_sources/sysmon_eventid_8.yml
index ff4dd0f046..086d972abf 100644
--- a/data_sources/sysmon_eventid_8.yml
+++ b/data_sources/sysmon_eventid_8.yml
@@ -1,108 +1,111 @@
name: Sysmon EventID 8
id: df7a786c-ade0-48f0-8596-26f10d169f7d
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the creation of a new thread in a process, including details about the thread ID, start address, and source process.
+description: Logs the creation of a new thread in a process, including details about
+ the thread ID, start address, and source process.
mitre_components:
-- Process Modification
-- Process Metadata
-- Application Log Content
-- OS API Execution
+ - Process Modification
+ - Process Metadata
+ - Application Log Content
+ - OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
separator_value: 8
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
-- name: Splunk Add-on for Sysmon
- url: https://splunkbase.splunk.com/app/5709
- version: 4.0.2
+ - name: Splunk Add-on for Sysmon
+ url: https://splunkbase.splunk.com/app/5709
+ version: 4.0.2
fields:
-- _time
-- Channel
-- Computer
-- EventChannel
-- EventCode
-- EventData_Xml
-- EventDescription
-- EventID
-- EventRecordID
-- Guid
-- Keywords
-- Level
-- Name
-- NewThreadId
-- Opcode
-- ProcessID
-- RecordID
-- RecordNumber
-- RuleName
-- SecurityID
-- SourceImage
-- SourceProcessGuid
-- SourceProcessId
-- StartAddress
-- StartFunction
-- StartModule
-- SystemTime
-- System_Props_Xml
-- TargetImage
-- TargetProcessGuid
-- TargetProcessId
-- Task
-- ThreadID
-- TimeCreated
-- UserID
-- UtcTime
-- Version
-- action
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- os
-- parent_process_exec
-- parent_process_guid
-- parent_process_id
-- parent_process_name
-- parent_process_path
-- process_exec
-- process_guid
-- process_id
-- process_name
-- process_path
-- punct
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- src_address
-- src_function
-- src_module
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user_id
-- vendor_product
+ - _time
+ - Channel
+ - Computer
+ - EventChannel
+ - EventCode
+ - EventData_Xml
+ - EventDescription
+ - EventID
+ - EventRecordID
+ - Guid
+ - Keywords
+ - Level
+ - Name
+ - NewThreadId
+ - Opcode
+ - ProcessID
+ - RecordID
+ - RecordNumber
+ - RuleName
+ - SecurityID
+ - SourceImage
+ - SourceProcessGuid
+ - SourceProcessId
+ - StartAddress
+ - StartFunction
+ - StartModule
+ - SystemTime
+ - System_Props_Xml
+ - TargetImage
+ - TargetProcessGuid
+ - TargetProcessId
+ - Task
+ - ThreadID
+ - TimeCreated
+ - UserID
+ - UtcTime
+ - Version
+ - action
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - os
+ - parent_process_exec
+ - parent_process_guid
+ - parent_process_id
+ - parent_process_name
+ - parent_process_path
+ - process_exec
+ - process_guid
+ - process_id
+ - process_name
+ - process_path
+ - punct
+ - signature
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - src_address
+ - src_function
+ - src_module
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user_id
+ - vendor_product
example_log: 824800x8000000000000000824800x8000000000000000362233Microsoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-487.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-487.attackrange.local-2022-10-27
13:59:12.427{3381F800-8EB0-635A-1306-000000008A02}4864C:\Windows\SysWOW64\wermgr.exe924900x8000000000000000924900x8000000000000000190607Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-478.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-478.attackrange.local-2022-02-25
12:25:33.359{414E8EDF-CABB-6218-F103-000000003702}6068C:\Temp\c.exe\Device\HarddiskVolume1
diff --git a/data_sources/sysmon_for_linux_eventid_1.yml b/data_sources/sysmon_for_linux_eventid_1.yml
index ac395956a2..5850fd83d6 100644
--- a/data_sources/sysmon_for_linux_eventid_1.yml
+++ b/data_sources/sysmon_for_linux_eventid_1.yml
@@ -1,115 +1,118 @@
name: Sysmon for Linux EventID 1
id: 93643652-30fe-4941-a1f7-6454f2948660
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs process creation events on Linux systems, including details about the process name, process ID, command line arguments, and parent process ID.
+description: Logs process creation events on Linux systems, including details about
+ the process name, process ID, command line arguments, and parent process ID.
mitre_components:
-- Process Creation
-- Command Execution
-- Process Metadata
-- OS API Execution
-- Application Log Content
+ - Process Creation
+ - Command Execution
+ - Process Metadata
+ - OS API Execution
+ - Application Log Content
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon:linux
separator: EventID
separator_value: 1
supported_TA:
-- name: Splunk Add-on for Sysmon for Linux
- url: https://splunkbase.splunk.com/app/6652
- version: 1.0.0
+ - name: Splunk Add-on for Sysmon for Linux
+ url: https://splunkbase.splunk.com/app/6652
+ version: 1.0.0
fields:
-- _time
-- Channel
-- CommandLine
-- Company
-- Computer
-- CurrentDirectory
-- Description
-- EventChannel
-- EventCode
-- EventData_Xml
-- EventDescription
-- EventID
-- EventRecordID
-- FileVersion
-- Guid
-- Hashes
-- Image
-- IntegrityLevel
-- Keywords
-- Level
-- LogonGuid
-- LogonId
-- Name
-- Opcode
-- OriginalFileName
-- ParentCommandLine
-- ParentImage
-- ParentProcessGuid
-- ParentProcessId
-- ParentUser
-- ProcessGuid
-- ProcessID
-- ProcessId
-- Product
-- RecordID
-- RuleName
-- SystemTime
-- System_Props_Xml
-- Task
-- TerminalSessionId
-- ThreadID
-- User
-- UserId
-- UtcTime
-- Version
-- action
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- eventtype
-- host
-- index
-- linecount
-- original_file_name
-- os
-- parent_process
-- parent_process_exec
-- parent_process_guid
-- parent_process_id
-- parent_process_name
-- parent_process_path
-- process
-- process_current_directory
-- process_exec
-- process_guid
-- process_hash
-- process_id
-- process_integrity_level
-- process_name
-- process_path
-- punct
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- vendor_product
-example_log: 154100x8000000000000000154100x80000000000000001926574Linux-Sysmon/Operationalar-linuxLinux-Sysmon/Operationalar-linux-2022-08-09
10:42:47.757{ec23eae3-3a27-62f2-085e-16549b550000}10268/usr/bin/sudo-11241100x800000000000000011241100x8000000000000000792913Linux-Sysmon/Operationalsysmonlinux-tcontreras-attack-range-4134Linux-Sysmon/Operationalsysmonlinux-tcontreras-attack-range-4134-2021-12-20
16:07:17.929{ec2c97d1-6aa9-61c0-3038-618238560000}5256/opt/splunkforwarder/bin/splunkd4688201331200x80200000000000004688201331200x8020000000000000362027Securityar-win-2.attackrange.localSecurityar-win-2.attackrange.localNT AUTHORITY\SYSTEMAR-WIN-2$ATTACKRANGE0x3e70xa44C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe228202000x80000000000000228202000x800000000000001001307Applicationwin-dc-exch01.attackrange.localc:\temp\msf.dllAMD64C1000000
+ ProcessID='0'
+ ThreadID='0'/>Applicationwin-dc-exch01.attackrange.localc:\temp\msf.dllAMD64C1000000
diff --git a/data_sources/windows_event_log_application_3000.yml b/data_sources/windows_event_log_application_3000.yml
index 9ec681c407..f7588b104a 100644
--- a/data_sources/windows_event_log_application_3000.yml
+++ b/data_sources/windows_event_log_application_3000.yml
@@ -1,72 +1,75 @@
name: Windows Event Log Application 3000
id: 3911945d-9222-408d-b851-9b1bce4c2d24
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the termination of a process, including details about the process, its termination code, and timestamp.
+description: Logs the termination of a process, including details about the process,
+ its termination code, and timestamp.
mitre_components:
-- Process Termination
-- Process Metadata
-- Application Log Content
-- OS API Execution
+ - Process Termination
+ - Process Metadata
+ - Application Log Content
+ - OS API Execution
source: XmlWinEventLog:Application
sourcetype: XmlWinEventLog
separator: EventCode
separator_value: 3000
supported_TA:
-- name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+ - name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
-- _time
-- Channel
-- Computer
-- Error_Code
-- EventCode
-- EventData_Xml
-- EventRecordID
-- EventSourceName
-- Guid
-- Keywords
-- Level
-- Name
-- Opcode
-- ProcessID
-- Qualifiers
-- RecordNumber
-- SystemTime
-- System_Props_Xml
-- Task
-- ThreadID
-- UserID
-- Version
-- dest
-- dvc
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- param1
-- param2
-- param3
-- punct
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- tag
-- tag::eventtype
-- timestamp
-- user_id
-- vendor_product
+ - _time
+ - Channel
+ - Computer
+ - Error_Code
+ - EventCode
+ - EventData_Xml
+ - EventRecordID
+ - EventSourceName
+ - Guid
+ - Keywords
+ - Level
+ - Name
+ - Opcode
+ - ProcessID
+ - Qualifiers
+ - RecordNumber
+ - SystemTime
+ - System_Props_Xml
+ - Task
+ - ThreadID
+ - UserID
+ - Version
+ - dest
+ - dvc
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - param1
+ - param2
+ - param3
+ - punct
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - tag
+ - tag::eventtype
+ - timestamp
+ - user_id
+ - vendor_product
example_log: 300004000x80000000000000300004000x8000000000000021334Applicationwin-host-mhaag-attack-range-117Applicationwin-host-mhaag-attack-range-117C:\Windows\System32\klist.exe001d8c3afcf370d13
diff --git a/data_sources/windows_event_log_capi2_70.yml b/data_sources/windows_event_log_capi2_70.yml
index 0ac0455e60..1ace202695 100644
--- a/data_sources/windows_event_log_capi2_70.yml
+++ b/data_sources/windows_event_log_capi2_70.yml
@@ -1,75 +1,78 @@
name: Windows Event Log CAPI2 70
id: 821de0a6-c5b4-491b-a27e-187552792817
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: This event log records events related to cryptographic operations, including the deletion and export of certificates.
+description: This event log records events related to cryptographic operations, including
+ the deletion and export of certificates.
mitre_components:
-- Certificate Registration
-- Process Metadata
-- Application Log Content
-- OS API Execution
-- Host Status
+ - Certificate Registration
+ - Process Metadata
+ - Application Log Content
+ - OS API Execution
+ - Host Status
source: XmlWinEventLog:Microsoft-Windows-CAPI2/Operational
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 70
supported_TA:
-- name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+ - name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
-- _time
-- Channel
-- Computer
-- EventCode
-- EventID
-- EventRecordID
-- Guid
-- Keywords
-- Level
-- Name
-- Opcode
-- ProcessID
-- RecordNumber
-- SystemTime
-- System_Props_Xml
-- Task
-- ThreadID
-- UserData_Xml
-- UserID
-- Version
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dvc
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- punct
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user_id
-- vendor_product
+ - _time
+ - Channel
+ - Computer
+ - EventCode
+ - EventID
+ - EventRecordID
+ - Guid
+ - Keywords
+ - Level
+ - Name
+ - Opcode
+ - ProcessID
+ - RecordNumber
+ - SystemTime
+ - System_Props_Xml
+ - Task
+ - ThreadID
+ - UserData_Xml
+ - UserID
+ - Version
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dvc
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - punct
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user_id
+ - vendor_product
example_log: 70047000x400000000000008070047000x4000000000000080308332Microsoft-Windows-CAPI2/Operationalwin-dc-mhaag-attack-range-84.attackrange.localMicrosoft-Windows-CAPI2/Operationalwin-dc-mhaag-attack-range-84.attackrange.local81028020x400000000000004081028020x40000000000000402400597Microsoft-Windows-CAPI2/Operationalmswin-server.attackrange.localMicrosoft-Windows-CAPI2/Operationalmswin-server.attackrange.local{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}WTD_UI_NONEWTD_STATEACTION_VERIFY2021-01-07T23:21:42.655Z2021-01-07T23:21:42.655ZThe digital signature of the object did not verify.100704000x8000000000000000100704000x80000000000000002Microsoft-Windows-CertificateServicesClient-Lifecycle-System/OperationalDESKTOP-92OQLA1112103000x8000000000000000112103000x80000000000000002975Microsoft-Windows-Windows Defender/Operationalresearchvmhaa112204000x8000000000000000112204000x80000000000000003701Microsoft-Windows-Windows Defender/Operationalresearchvmhaa500704000x8000000000000000500704000x80000000000000003726Microsoft-Windows-Windows Defender/OperationalresearchvmhaaMicrosoft Defender
diff --git a/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml b/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml
index 22e591d7a7..66a21053dc 100644
--- a/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml
+++ b/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml
@@ -1,64 +1,55 @@
name: Windows Event Log Microsoft Windows TerminalServices RDPClient 1024
id: 2490537e-5e0c-46f7-9209-f56f852aa217
-version: 1
-date: '2024-11-21'
+version: 2
+date: '2025-01-23'
author: Michael Haag, Splunk
-description: Logs an event when a Remote Desktop Protocol (RDP) client successfully connects to a remote host.
+description: Logs an event when a Remote Desktop Protocol (RDP) client successfully
+ connects to a remote host.
mitre_components:
-- Network Connection Creation
-- Logon Session Creation
+ - Network Connection Creation
+ - Logon Session Creation
source: WinEventLog:Microsoft-Windows-TerminalServices-RDPClient/Operational
sourcetype: WinEventLog
separator: EventCode
supported_TA: []
fields:
-- _time
-- Channel
-- Computer
-- EventCode
-- EventData
-- EventID
-- EventRecordID
-- EventType
-- Keywords
-- Level
-- Message
-- Opcode
-- ProcessID
-- RecordNumber
-- Security_ID
-- Src
-- Src_Host
-- Src_NT_Domain
-- Src_User
-- System_TimeCreated
-- Task
-- ThreadID
-- Type
-- User
-- UserID
-- Version
-- dest
-- dvc
-- event_id
-- host
-- source
-- sourcetype
-- tag
-- user
-example_log:
- 11/21/2024 06:09:16 PM
- LogName=Microsoft-Windows-TerminalServices-RDPClient/Operational
- EventCode=1024
- EventType=4
- ComputerName=ar-win-5.attackrange.local
- User=NOT_TRANSLATED
- Sid=S-1-5-21-1731938146-2314223186-1848411941-500
- SidType=0
- SourceName=Microsoft-Windows-TerminalServices-ClientActiveXCore
- Type=Information
- RecordNumber=95
- Keywords=None
- TaskCategory=Connection Sequence
- OpCode=This event is raised during the connection process
- Message=RDP ClientActiveX is trying to connect to the server (34.221.50.57)
\ No newline at end of file
+ - _time
+ - Channel
+ - Computer
+ - EventCode
+ - EventData
+ - EventID
+ - EventRecordID
+ - EventType
+ - Keywords
+ - Level
+ - Message
+ - Opcode
+ - ProcessID
+ - RecordNumber
+ - Security_ID
+ - Src
+ - Src_Host
+ - Src_NT_Domain
+ - Src_User
+ - System_TimeCreated
+ - Task
+ - ThreadID
+ - Type
+ - User
+ - UserID
+ - Version
+ - dest
+ - dvc
+ - event_id
+ - host
+ - source
+ - sourcetype
+ - tag
+ - user
+example_log: 11/21/2024 06:09:16 PM LogName=Microsoft-Windows-TerminalServices-RDPClient/Operational
+ EventCode=1024 EventType=4 ComputerName=ar-win-5.attackrange.local User=NOT_TRANSLATED
+ Sid=S-1-5-21-1731938146-2314223186-1848411941-500 SidType=0 SourceName=Microsoft-Windows-TerminalServices-ClientActiveXCore
+ Type=Information RecordNumber=95 Keywords=None TaskCategory=Connection Sequence
+ OpCode=This event is raised during the connection process Message=RDP ClientActiveX
+ is trying to connect to the server (34.221.50.57)
diff --git a/data_sources/windows_event_log_printservice_316.yml b/data_sources/windows_event_log_printservice_316.yml
index 507a925e5d..74eecb2f6a 100644
--- a/data_sources/windows_event_log_printservice_316.yml
+++ b/data_sources/windows_event_log_printservice_316.yml
@@ -1,63 +1,63 @@
name: Windows Event Log Printservice 316
id: 12f0be8b-22c0-4fdf-9468-b7ccca824d1d
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when printer drivers are installed or updated on the system.
mitre_components:
-- Driver Load
-- Driver Metadata
+ - Driver Load
+ - Driver Metadata
source: WinEventLog:Microsoft-Windows-PrintService/Admin
sourcetype: WinEventLog
separator: EventCode
separator_value: 316
supported_TA:
-- name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+ - name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
-- _time
-- ComputerName
-- EventCode
-- EventType
-- Keywords
-- LogName
-- Message
-- OpCode
-- RecordNumber
-- Sid
-- SidType
-- SourceName
-- TaskCategory
-- Type
-- User
-- category
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dvc
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- punct
-- severity
-- severity_id
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- vendor_product
+ - _time
+ - ComputerName
+ - EventCode
+ - EventType
+ - Keywords
+ - LogName
+ - Message
+ - OpCode
+ - RecordNumber
+ - Sid
+ - SidType
+ - SourceName
+ - TaskCategory
+ - Type
+ - User
+ - category
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dvc
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - punct
+ - severity
+ - severity_id
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - vendor_product
example_log: 07/01/2021 04:20:47 PM
diff --git a/data_sources/windows_event_log_printservice_808.yml b/data_sources/windows_event_log_printservice_808.yml
index ef717b2d20..3f73b548be 100644
--- a/data_sources/windows_event_log_printservice_808.yml
+++ b/data_sources/windows_event_log_printservice_808.yml
@@ -1,67 +1,68 @@
name: Windows Event Log Printservice 808
id: e3a26785-4389-4830-8d7b-3dad4252719e
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when the print spooler service fails to load a printer plug-in module.
+description: Logs an event when the print spooler service fails to load a printer
+ plug-in module.
mitre_components:
-- Module Load
-- Application Log Content
-- Service Metadata
+ - Module Load
+ - Application Log Content
+ - Service Metadata
source: WinEventLog:Microsoft-Windows-PrintService/Admin
sourcetype: WinEventLog
separator: EventCode
separator_value: 808
supported_TA:
-- name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+ - name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
-- _time
-- ComputerName
-- EventCode
-- EventType
-- Keywords
-- LogName
-- Message
-- OpCode
-- RecordNumber
-- Sid
-- SidType
-- SourceName
-- TaskCategory
-- Type
-- User
-- category
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dvc
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- name
-- punct
-- severity
-- severity_id
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- subject
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- vendor_product
+ - _time
+ - ComputerName
+ - EventCode
+ - EventType
+ - Keywords
+ - LogName
+ - Message
+ - OpCode
+ - RecordNumber
+ - Sid
+ - SidType
+ - SourceName
+ - TaskCategory
+ - Type
+ - User
+ - category
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dvc
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - name
+ - punct
+ - severity
+ - severity_id
+ - signature
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - subject
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - vendor_product
example_log: 07/01/2021 04:20:47 PM
diff --git a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml
index 14c3a6bc1a..00eb66eec2 100644
--- a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml
+++ b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml
@@ -1,64 +1,67 @@
name: Windows Event Log RemoteConnectionManager 1149
id: 08f9edb4-f95f-40be-b1dd-bc3a1cd95aaf
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when a Remote Desktop Service session is initialized.
mitre_components:
-- Network Connection Creation
-- Logon Session Creation
-- Logon Session Metadata
-source: WinEventLog:Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational
+ - Network Connection Creation
+ - Logon Session Creation
+ - Logon Session Metadata
+source:
+ WinEventLog:Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational
sourcetype: wineventlog
separator: EventCode
separator_value: 1149
supported_TA:
-- name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+ - name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
-- _time
-- ActivityID
-- Channel
-- Computer
-- EventCode
-- EventID
-- EventRecordID
-- Guid
-- Keywords
-- Level
-- Name
-- Opcode
-- ProcessID
-- RecordNumber
-- SystemTime
-- System_Props_Xml
-- Task
-- ThreadID
-- UserData_Xml
-- UserID
-- Version
-- dvc
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- punct
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- tag
-- tag::eventtype
-- timestamp
-- user_id
-- vendor_product
+ - _time
+ - ActivityID
+ - Channel
+ - Computer
+ - EventCode
+ - EventID
+ - EventRecordID
+ - Guid
+ - Keywords
+ - Level
+ - Name
+ - Opcode
+ - ProcessID
+ - RecordNumber
+ - SystemTime
+ - System_Props_Xml
+ - Task
+ - ThreadID
+ - UserData_Xml
+ - UserID
+ - Version
+ - dvc
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - punct
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - tag
+ - tag::eventtype
+ - timestamp
+ - user_id
+ - vendor_product
example_log: 114904000x1000000000000000114904000x10000000000000002064Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operationalar-win-1.attackrange.localAdministratorATTACKRANGE10.0.1.14
+ UserID='S-1-5-20'/>AdministratorATTACKRANGE10.0.1.14
diff --git a/data_sources/windows_event_log_security_1100.yml b/data_sources/windows_event_log_security_1100.yml
index 41e0c3fced..3c118a5dfc 100644
--- a/data_sources/windows_event_log_security_1100.yml
+++ b/data_sources/windows_event_log_security_1100.yml
@@ -1,84 +1,86 @@
name: Windows Event Log Security 1100
id: 2a25dafa-691e-4cb2-ae59-07a48867ed9a
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when the event logging service has shut down.
mitre_components:
-- Host Status
-- System Configuration Changes
+ - Host Status
+ - System Configuration Changes
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 1100
supported_TA:
-- name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+ - name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
-- _time
-- Channel
-- Computer
-- Error_Code
-- EventCode
-- EventID
-- EventRecordID
-- Guid
-- Keywords
-- Level
-- Name
-- Opcode
-- ProcessID
-- RecordNumber
-- SystemTime
-- System_Props_Xml
-- Task
-- ThreadID
-- UserData_Xml
-- Version
-- action
-- app
-- change_type
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- name
-- object_attrs
-- object_category
-- product
-- punct
-- service
-- service_name
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- status
-- subject
-- ta_windows_action
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- vendor
-- vendor_product
+ - _time
+ - Channel
+ - Computer
+ - Error_Code
+ - EventCode
+ - EventID
+ - EventRecordID
+ - Guid
+ - Keywords
+ - Level
+ - Name
+ - Opcode
+ - ProcessID
+ - RecordNumber
+ - SystemTime
+ - System_Props_Xml
+ - Task
+ - ThreadID
+ - UserData_Xml
+ - Version
+ - action
+ - app
+ - change_type
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - name
+ - object_attrs
+ - object_category
+ - product
+ - punct
+ - service
+ - service_name
+ - signature
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - status
+ - subject
+ - ta_windows_action
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - vendor
+ - vendor_product
example_log: 11000410300x402000000000000011000410300x4020000000000000140874Securityar-win-2Securityar-win-2
diff --git a/data_sources/windows_event_log_security_1102.yml b/data_sources/windows_event_log_security_1102.yml
index 50bcf53f6b..3e46c4323f 100644
--- a/data_sources/windows_event_log_security_1102.yml
+++ b/data_sources/windows_event_log_security_1102.yml
@@ -1,90 +1,92 @@
name: Windows Event Log Security 1102
id: 8db7b91a-6d7a-40e7-bfac-06f8e901a9cb
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when the audit log is cleared.
mitre_components:
-- User Account Modification
-- Logon Session Metadata
-- File Deletion
+ - User Account Modification
+ - Logon Session Metadata
+ - File Deletion
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 1102
supported_TA:
-- name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+ - name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
-- _time
-- Caller_User_Name
-- Channel
-- Computer
-- Error_Code
-- EventCode
-- EventID
-- EventRecordID
-- Guid
-- Keywords
-- Level
-- LogFileCleared_Xml
-- Name
-- Opcode
-- ProcessID
-- RecordNumber
-- SubjectDomainName
-- SubjectLogonId
-- SubjectUserName
-- SubjectUserSid
-- SystemTime
-- System_Props_Xml
-- Task
-- ThreadID
-- UserData_Xml
-- Version
-- action
-- app
-- change_type
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- name
-- object_attrs
-- object_category
-- product
-- punct
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- src_user
-- status
-- subject
-- ta_windows_action
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- vendor
-- vendor_product
+ - _time
+ - Caller_User_Name
+ - Channel
+ - Computer
+ - Error_Code
+ - EventCode
+ - EventID
+ - EventRecordID
+ - Guid
+ - Keywords
+ - Level
+ - LogFileCleared_Xml
+ - Name
+ - Opcode
+ - ProcessID
+ - RecordNumber
+ - SubjectDomainName
+ - SubjectLogonId
+ - SubjectUserName
+ - SubjectUserSid
+ - SystemTime
+ - System_Props_Xml
+ - Task
+ - ThreadID
+ - UserData_Xml
+ - Version
+ - action
+ - app
+ - change_type
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - name
+ - object_attrs
+ - object_category
+ - product
+ - punct
+ - signature
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - src_user
+ - status
+ - subject
+ - ta_windows_action
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - vendor
+ - vendor_product
example_log: 11020410400x402000000000000011020410400x40200000000000001826166Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localATTACKRANGE\AdministratorAdministratorATTACKRANGE0x34a3a27
diff --git a/data_sources/windows_event_log_security_4624.yml b/data_sources/windows_event_log_security_4624.yml
index 0faba24352..62d69f0c10 100644
--- a/data_sources/windows_event_log_security_4624.yml
+++ b/data_sources/windows_event_log_security_4624.yml
@@ -1,128 +1,129 @@
name: Windows Event Log Security 4624
id: 08682968-0366-4882-9559-fe4fe018a846
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when an account successfully logs on to a system.
mitre_components:
-- Logon Session Creation
-- User Account Authentication
-- Logon Session Metadata
+ - Logon Session Creation
+ - User Account Authentication
+ - Logon Session Metadata
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 4624
supported_TA:
-- name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+ - name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
-- _time
-- ActivityID
-- AuthenticationPackageName
-- Caller_Domain
-- Caller_User_Name
-- Channel
-- Computer
-- ElevatedToken
-- Error_Code
-- EventCode
-- EventData_Xml
-- EventID
-- EventRecordID
-- Guid
-- ImpersonationLevel
-- IpAddress
-- IpPort
-- KeyLength
-- Keywords
-- Level
-- LmPackageName
-- LogonGuid
-- LogonProcessName
-- LogonType
-- Logon_ID
-- Logon_Type
-- Name
-- Opcode
-- ProcessID
-- ProcessId
-- ProcessName
-- RecordNumber
-- RestrictedAdminMode
-- Source_Port
-- Source_Workstation
-- SubjectDomainName
-- SubjectLogonId
-- SubjectUserName
-- SubjectUserSid
-- SystemTime
-- System_Props_Xml
-- TargetDomainName
-- TargetLinkedLogonId
-- TargetLogonId
-- TargetOutboundDomainName
-- TargetOutboundUserName
-- TargetUserName
-- TargetUserSid
-- Target_Domain
-- Target_User_Name
-- Task
-- ThreadID
-- TransmittedServices
-- Version
-- VirtualAccount
-- WorkstationName
-- action
-- app
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_nt_domain
-- dvc
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- name
-- process
-- process_id
-- process_name
-- process_path
-- product
-- punct
-- session_id
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- src_ip
-- src_port
-- status
-- subject
-- ta_windows_action
-- tag
-- tag::action
-- tag::app
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- user_group
-- vendor
-- vendor_product
+ - _time
+ - ActivityID
+ - AuthenticationPackageName
+ - Caller_Domain
+ - Caller_User_Name
+ - Channel
+ - Computer
+ - ElevatedToken
+ - Error_Code
+ - EventCode
+ - EventData_Xml
+ - EventID
+ - EventRecordID
+ - Guid
+ - ImpersonationLevel
+ - IpAddress
+ - IpPort
+ - KeyLength
+ - Keywords
+ - Level
+ - LmPackageName
+ - LogonGuid
+ - LogonProcessName
+ - LogonType
+ - Logon_ID
+ - Logon_Type
+ - Name
+ - Opcode
+ - ProcessID
+ - ProcessId
+ - ProcessName
+ - RecordNumber
+ - RestrictedAdminMode
+ - Source_Port
+ - Source_Workstation
+ - SubjectDomainName
+ - SubjectLogonId
+ - SubjectUserName
+ - SubjectUserSid
+ - SystemTime
+ - System_Props_Xml
+ - TargetDomainName
+ - TargetLinkedLogonId
+ - TargetLogonId
+ - TargetOutboundDomainName
+ - TargetOutboundUserName
+ - TargetUserName
+ - TargetUserSid
+ - Target_Domain
+ - Target_User_Name
+ - Task
+ - ThreadID
+ - TransmittedServices
+ - Version
+ - VirtualAccount
+ - WorkstationName
+ - action
+ - app
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_nt_domain
+ - dvc
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - name
+ - process
+ - process_id
+ - process_name
+ - process_path
+ - product
+ - punct
+ - session_id
+ - signature
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - src_ip
+ - src_port
+ - status
+ - subject
+ - ta_windows_action
+ - tag
+ - tag::action
+ - tag::app
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - user_group
+ - vendor
+ - vendor_product
example_log: 4624201254400x80200000000000004624201254400x8020000000000000371886Securityar-win-7.attackrange.local4625001254400x80100000000000004625001254400x8010000000000000367348Securityar-win-8.attackrange.local4627001255400x80200000000000004627001255400x8020000000000000186260Securityar-win-dc.attackrange.local4648001254400x80200000000000004648001254400x8020000000000000336567Securitywin-host-mvelazco-02713-447.attackrange.local4662001408000x80100000000000004662001408000x801000000000000021623198276Securityattack_range_dc4663101280000x80200000000000004663101280000x802000000000000010525869Securityar-win-2.attackrange.localSecurityar-win-2.attackrange.localAR-WIN-2\AdministratorAdministratorAR-WIN-20x6cfe7SecurityFileC:\Program
diff --git a/data_sources/windows_event_log_security_4672.yml b/data_sources/windows_event_log_security_4672.yml
index 71facef2ee..9c507ba8bc 100644
--- a/data_sources/windows_event_log_security_4672.yml
+++ b/data_sources/windows_event_log_security_4672.yml
@@ -1,92 +1,94 @@
name: Windows Event Log Security 4672
id: 43f189b6-369d-4a32-a34c-57e0d38d92f1
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs an event when a user with administrative privileges logs on to a system.
+description: Logs an event when a user with administrative privileges logs on to a
+ system.
mitre_components:
-- Logon Session Creation
-- User Account Authentication
+ - Logon Session Creation
+ - User Account Authentication
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 4672
supported_TA:
-- name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+ - name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
-- _time
-- ActivityID
-- Caller_Domain
-- Caller_User_Name
-- Channel
-- Computer
-- Error_Code
-- EventCode
-- EventData_Xml
-- EventID
-- EventRecordID
-- Guid
-- Keywords
-- Level
-- Logon_ID
-- Name
-- Opcode
-- PrivilegeList
-- ProcessID
-- RecordNumber
-- SubjectDomainName
-- SubjectLogonId
-- SubjectUserName
-- SubjectUserSid
-- SystemTime
-- System_Props_Xml
-- Task
-- ThreadID
-- Version
-- action
-- app
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- name
-- product
-- punct
-- session_id
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- src_nt_domain
-- src_user
-- status
-- subject
-- ta_windows_action
-- tag
-- tag::action
-- tag::eventtype
-- timeendpos
-- timestartpos
-- vendor
-- vendor_product
+ - _time
+ - ActivityID
+ - Caller_Domain
+ - Caller_User_Name
+ - Channel
+ - Computer
+ - Error_Code
+ - EventCode
+ - EventData_Xml
+ - EventID
+ - EventRecordID
+ - Guid
+ - Keywords
+ - Level
+ - Logon_ID
+ - Name
+ - Opcode
+ - PrivilegeList
+ - ProcessID
+ - RecordNumber
+ - SubjectDomainName
+ - SubjectLogonId
+ - SubjectUserName
+ - SubjectUserSid
+ - SystemTime
+ - System_Props_Xml
+ - Task
+ - ThreadID
+ - Version
+ - action
+ - app
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - name
+ - product
+ - punct
+ - session_id
+ - signature
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - src_nt_domain
+ - src_user
+ - status
+ - subject
+ - ta_windows_action
+ - tag
+ - tag::action
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - vendor
+ - vendor_product
example_log: 4672001254800x80200000000000004672001254800x8020000000000000148946Securityar-win-6.attackrange.local4688201331200x80200000000000004688201331200x8020000000000000432820Securityar-win-1Securityar-win-1NT AUTHORITY\SYSTEMAR-WIN-1$WORKGROUP0x3e70xf84C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe4703001331700x80200000000000004703001331700x8020000000000000328761Securitywin-host-ctus-attack-range-115Securitywin-host-ctus-attack-range-115WIN-HOST-CTUS-A\AdministratorAdministratorWIN-HOST-CTUS-A0x288b91WIN-HOST-CTUS-A\AdministratorAdministrator4719001356800x80200000000000004719001356800x8020000000000000353597Securityar-win-dc.attackrange.local4724001382400x80200000000000004724001382400x8020000000000000276779Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localTRUMAN_CLEMENTSATTACKRANGEATTACKRANGE\TRUMAN_CLEMENTSATTACKRANGE\AdministratorAdministratorATTACKRANGE4725001382400x80200000000000004725001382400x8020000000000000278771Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localWILFORD_SUTTONATTACKRANGEATTACKRANGE\WILFORD_SUTTONATTACKRANGE\AdministratorAdministratorATTACKRANGE4726001382400x80200000000000004726001382400x8020000000000000279283Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localLYNN_WOLFATTACKRANGES-1-5-21-2851375338-1978525053-2422663219-2445ATTACKRANGE\AdministratorAdministratorATTACKRANGE4738001382400x80200000000000004738001382400x80200000000000006389713Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.local-unprivATTACKRANGES-1-5-21-945660386-2529346225-2932127451-1112S-1-5-21-945660386-2529346225-2932127451-500AdministratorATTACKRANGE4739001356900x80200000000000004739001356900x8020000000000000394176Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localLockout PolicyATTACKRANGEATTACKRANGE\NT AUTHORITY\SYSTEMAR-WIN-DC$ATTACKRANGE4741001382500x80200000000000004741001382500x8020000000000000143475Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localAR-WIN-2$ATTACKRANGEATTACKRANGE\AR-WIN-2$ATTACKRANGE\AdministratorAdministratorATTACKRANGE4742001382500x80200000000000004742001382500x8020000000000000901860Securitywin-dc-root-04195-428.attackrange.localSecuritywin-dc-root-04195-428.attackrange.local-WIN-HOST-ROOT-0$ATTACKRANGES-1-5-21-199921393-3534762603-6736986-1111S-1-5-21-199921393-3534762603-6736986-500Administrator4768001433900x80100000000000004768001433900x8010000000000000391562Securitywin-dc-mvelazco-02713-392.attackrange.localSecuritywin-dc-mvelazco-02713-392.attackrange.localRXETPKZHattackrange.localNULL SIDkrbtgt/attackrange.localNULL SID0x408100104769001433700x80200000000000004769001433700x8020000000000000148521Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localAR-WIN-2$@ATTACKRANGE.LOCALATTACKRANGE.LOCALAR-WIN-2$ATTACKRANGE\AR-WIN-2$0x408100000x174771001433900x80100000000000004771001433900x8010000000000000391511Securitywin-dc-mvelazco-02713-392.attackrange.localSecuritywin-dc-mvelazco-02713-392.attackrange.localALLISON_WATERSATTACKRANGE\ALLISON_WATERSkrbtgt/attackrange.local0x408100100x182::ffff:10.0.1.154776001433600x80100000000000004776001433600x8010000000000000391615Securitywin-dc-mvelazco-02713-392.attackrange.localSecuritywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0KSYLEFUAWIN-HOST-MVELAZ0xc0000064
diff --git a/data_sources/windows_event_log_security_4781.yml b/data_sources/windows_event_log_security_4781.yml
index 453217cdd0..eee4c4c3f3 100644
--- a/data_sources/windows_event_log_security_4781.yml
+++ b/data_sources/windows_event_log_security_4781.yml
@@ -1,110 +1,112 @@
name: Windows Event Log Security 4781
id: 9732ffe7-ebce-4557-865c-1725a0f633cb
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs changes made to the name of a computer account, including the old and new names and the user performing the action.
+description: Logs changes made to the name of a computer account, including the old
+ and new names and the user performing the action.
mitre_components:
-- User Account Modification
-- User Account Metadata
-- Active Directory Object Modification
-- Application Log Content
+ - User Account Modification
+ - User Account Metadata
+ - Active Directory Object Modification
+ - Application Log Content
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 4781
supported_TA:
-- name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+ - name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
-- _time
-- ActivityID
-- Caller_Domain
-- Caller_User_Name
-- CategoryString
-- Channel
-- Computer
-- Error_Code
-- EventCode
-- EventData_Xml
-- EventID
-- EventRecordID
-- Guid
-- Keywords
-- Level
-- Logon_ID
-- Name
-- NewTargetUserName
-- OldTargetUserName
-- Opcode
-- PrivilegeList
-- ProcessID
-- RecordNumber
-- SubjectDomainName
-- SubjectLogonId
-- SubjectUserName
-- SubjectUserSid
-- SystemTime
-- System_Props_Xml
-- TargetDomainName
-- TargetSid
-- Target_Domain
-- Task
-- ThreadID
-- Version
-- action
-- app
-- change_type
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dest_nt_domain
-- dvc
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- name
-- object
-- object_attrs
-- object_category
-- object_id
-- product
-- punct
-- result
-- session_id
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- src_nt_domain
-- src_user
-- src_user_name
-- status
-- subject
-- ta_windows_action
-- ta_windows_security_CategoryString
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user
-- user_name
-- vendor
-- vendor_product
+ - _time
+ - ActivityID
+ - Caller_Domain
+ - Caller_User_Name
+ - CategoryString
+ - Channel
+ - Computer
+ - Error_Code
+ - EventCode
+ - EventData_Xml
+ - EventID
+ - EventRecordID
+ - Guid
+ - Keywords
+ - Level
+ - Logon_ID
+ - Name
+ - NewTargetUserName
+ - OldTargetUserName
+ - Opcode
+ - PrivilegeList
+ - ProcessID
+ - RecordNumber
+ - SubjectDomainName
+ - SubjectLogonId
+ - SubjectUserName
+ - SubjectUserSid
+ - SystemTime
+ - System_Props_Xml
+ - TargetDomainName
+ - TargetSid
+ - Target_Domain
+ - Task
+ - ThreadID
+ - Version
+ - action
+ - app
+ - change_type
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dest_nt_domain
+ - dvc
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - name
+ - object
+ - object_attrs
+ - object_category
+ - object_id
+ - product
+ - punct
+ - result
+ - session_id
+ - signature
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - src_nt_domain
+ - src_user
+ - src_user_name
+ - status
+ - subject
+ - ta_windows_action
+ - ta_windows_security_CategoryString
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user
+ - user_name
+ - vendor
+ - vendor_product
example_log: 4781001382400x80200000000000004781001382400x8020000000000000148763Securityar-win-dc.attackrange.local4794001382400x80200000000000004794001382400x8020000000000000821077Securitywin-dc-root-17044-552.attackrange.local4798001382400x80200000000000004798001382400x8020000000000000386860Securityar-win-2.attackrange.local4876001280500x80200000000000004876001280500x802000000000000015379961Securitywin-dc-mhaag-attack-range-84.attackrange.local4886001280500x80200000000000004886001280500x802000000000000015379925Securitywin-dc-mhaag-attack-range-84.attackrange.local4887001280500x80200000000000004887001280500x80200000000000001830974609Securitycert_authority.attack_range.local5136001408100x80200000000000005136001408100x80200000000000001997365Securitywin-dc-mvelazco-02713-392.attackrange.local{73C96723-504B-4F15-830A-F4DDB1C48F2E}-ATTACKRANGE\AdministratorAdministratorATTACKRANGE0x95675attackrange.local%%14676CN=DANNIE_CERVANTES,OU=ServiceAccounts,OU=OGC,OU=Stage,DC=attackrange,DC=localattackrange.local%%14676CN=DANNIE_CERVANTES,OU=ServiceAccounts,OU=OGC,OU=Stage,DC=attackrange,DC=local{15AFB68A-679C-4F5B-AC18-4D988B3B3E44}userservicePrincipalName2.5.5.12adm/srv1.attackrange.local%%14674
diff --git a/data_sources/windows_event_log_security_5137.yml b/data_sources/windows_event_log_security_5137.yml
index 8787969fa8..9dc78ab362 100644
--- a/data_sources/windows_event_log_security_5137.yml
+++ b/data_sources/windows_event_log_security_5137.yml
@@ -1,103 +1,107 @@
name: Windows Event Log Security 5137
id: 64ed7bb1-9c3c-4355-ac08-b506ec3b053e
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the creation of a new Active Directory object, including details about the object name, type, and the user performing the action.
+description: Logs the creation of a new Active Directory object, including details
+ about the object name, type, and the user performing the action.
mitre_components:
-- Active Directory Object Creation
-- Active Directory Object Modification
-- User Account Metadata
-- Application Log Content
+ - Active Directory Object Creation
+ - Active Directory Object Modification
+ - User Account Metadata
+ - Application Log Content
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 5137
supported_TA:
-- name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+ - name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
-- _time
-- AppCorrelationID
-- Caller_Domain
-- Caller_User_Name
-- Channel
-- Computer
-- DSName
-- DSType
-- Error_Code
-- EventCode
-- EventData_Xml
-- EventID
-- EventRecordID
-- Guid
-- Keywords
-- Level
-- Logon_ID
-- Name
-- ObjectClass
-- ObjectDN
-- ObjectGUID
-- OpCorrelationID
-- Opcode
-- ProcessID
-- RecordNumber
-- SubjectDomainName
-- SubjectLogonId
-- SubjectUserName
-- SubjectUserSid
-- SystemTime
-- System_Props_Xml
-- Task
-- ThreadID
-- Version
-- action
-- app
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- name
-- product
-- punct
-- session_id
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- src_nt_domain
-- src_user
-- status
-- subject
-- ta_windows_action
-- tag
-- tag::action
-- tag::eventtype
-- timeendpos
-- timestartpos
-- vendor
-- vendor_product
+ - _time
+ - AppCorrelationID
+ - Caller_Domain
+ - Caller_User_Name
+ - Channel
+ - Computer
+ - DSName
+ - DSType
+ - Error_Code
+ - EventCode
+ - EventData_Xml
+ - EventID
+ - EventRecordID
+ - Guid
+ - Keywords
+ - Level
+ - Logon_ID
+ - Name
+ - ObjectClass
+ - ObjectDN
+ - ObjectGUID
+ - OpCorrelationID
+ - Opcode
+ - ProcessID
+ - RecordNumber
+ - SubjectDomainName
+ - SubjectLogonId
+ - SubjectUserName
+ - SubjectUserSid
+ - SystemTime
+ - System_Props_Xml
+ - Task
+ - ThreadID
+ - Version
+ - action
+ - app
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - name
+ - product
+ - punct
+ - session_id
+ - signature
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - src_nt_domain
+ - src_user
+ - status
+ - subject
+ - ta_windows_action
+ - tag
+ - tag::action
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - vendor
+ - vendor_product
example_log: 5137001408100x80200000000000005137001408100x8020000000000000170140Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.local{681cac8c-b5a4-48fd-be93-4339996bd94d}-ATTACKRANGE\AdministratorAdministratorATTACKRANGE0x8561aattackrange.local%%14676CN={2C4C7CD3-7AA5-4E84-89B5-CE9FC75611D4},CN=Policies,CN=System,DC=attackrange,DC=localattackrange.local%%14676CN={2C4C7CD3-7AA5-4E84-89B5-CE9FC75611D4},CN=Policies,CN=System,DC=attackrange,DC=local{3e7ae4de-29a6-41c1-b27c-bf9548b0444c}groupPolicyContainer
diff --git a/data_sources/windows_event_log_security_5140.yml b/data_sources/windows_event_log_security_5140.yml
index 8d1883d26c..4fb8bf8cc6 100644
--- a/data_sources/windows_event_log_security_5140.yml
+++ b/data_sources/windows_event_log_security_5140.yml
@@ -1,121 +1,124 @@
name: Windows Event Log Security 5140
id: 93e0ca09-e4b8-4da6-872a-d0127c4d2b22
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs access to a network share, including details about the user, share path, and the access type.
+description: Logs access to a network share, including details about the user, share
+ path, and the access type.
mitre_components:
-- Network Share Access
-- File Access
-- User Account Metadata
-- Application Log Content
+ - Network Share Access
+ - File Access
+ - User Account Metadata
+ - Application Log Content
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 5140
supported_TA:
-- name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+ - name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
-- _time
-- AccessList
-- AccessMask
-- Caller_Domain
-- Caller_User_Name
-- Channel
-- Computer
-- Error_Code
-- EventCode
-- EventData_Xml
-- EventID
-- EventRecordID
-- Guid
-- IpAddress
-- IpPort
-- Keywords
-- Level
-- Logon_ID
-- Name
-- ObjectType
-- Opcode
-- ProcessID
-- RecordNumber
-- ShareName
-- Source_Port
-- Source_Workstation
-- SubjectDomainName
-- SubjectLogonId
-- SubjectUserName
-- SubjectUserSid
-- SystemTime
-- System_Props_Xml
-- Task
-- ThreadID
-- Version
-- action
-- app
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- dvc_nt_host
-- event_id
-- eventtype
-- file_name
-- host
-- id
-- index
-- linecount
-- name
-- product
-- punct
-- session_id
-- signature
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- src
-- src_ip
-- src_nt_domain
-- src_nt_host
-- src_port
-- src_user
-- status
-- subject
-- ta_windows_action
-- tag
-- tag::action
-- tag::eventtype
-- timeendpos
-- timestartpos
-- vendor
-- vendor_product
+ - _time
+ - AccessList
+ - AccessMask
+ - Caller_Domain
+ - Caller_User_Name
+ - Channel
+ - Computer
+ - Error_Code
+ - EventCode
+ - EventData_Xml
+ - EventID
+ - EventRecordID
+ - Guid
+ - IpAddress
+ - IpPort
+ - Keywords
+ - Level
+ - Logon_ID
+ - Name
+ - ObjectType
+ - Opcode
+ - ProcessID
+ - RecordNumber
+ - ShareName
+ - Source_Port
+ - Source_Workstation
+ - SubjectDomainName
+ - SubjectLogonId
+ - SubjectUserName
+ - SubjectUserSid
+ - SystemTime
+ - System_Props_Xml
+ - Task
+ - ThreadID
+ - Version
+ - action
+ - app
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - file_name
+ - host
+ - id
+ - index
+ - linecount
+ - name
+ - product
+ - punct
+ - session_id
+ - signature
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - src
+ - src_ip
+ - src_nt_domain
+ - src_nt_host
+ - src_port
+ - src_user
+ - status
+ - subject
+ - ta_windows_action
+ - tag
+ - tag::action
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - vendor
+ - vendor_product
field_mappings:
-- data_model: ocsf
- mapping:
- AccessList: access_list
- AccessMask: access_mask
- AccessReason: access_result
- ShareLocalPath: file
- ObjectType: file.type
- IpAddress: src_endpoint.ip
- IpPort: src_endpoint.port
- SubjectDomainName: actor.user.domain
- SubjectUserName: actor.user.name
- SubjectLogonId: actor.session.uid
- SubjectUserSid: actor.user.uid
+ - data_model: ocsf
+ mapping:
+ AccessList: access_list
+ AccessMask: access_mask
+ AccessReason: access_result
+ ShareLocalPath: file
+ ObjectType: file.type
+ IpAddress: src_endpoint.ip
+ IpPort: src_endpoint.port
+ SubjectDomainName: actor.user.domain
+ SubjectUserName: actor.user.name
+ SubjectLogonId: actor.session.uid
+ SubjectUserSid: actor.user.uid
example_log: 5140101280800x80200000000000005140101280800x8020000000000000138541Securityar-win-66.attackrange.localSecurityar-win-66.attackrange.localATTACKRANGE\ELMER_SALASELMER_SALASATTACKRANGE0x2f259bFile10.0.1.16498645141001408100x80200000000000005141001408100x8020000000000000670908Securitywin-dc-range-02713-392.attackrange.local5145001281100x80200000000000005145001281100x80200000000000002018939Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localANONYMOUS LOGONANONYMOUS
LOGONATTACKRANGE0x13ef1bFile10.0.1.1550160703604000x8080000000000000703604000x8080000000000000168530Systemar-win-dc.attackrange.localsppsvcstopped7300700070007300760063002F0031000000
+ ProcessID='588'
+ ThreadID='2272'/>Systemar-win-dc.attackrange.localsppsvcstopped7300700070007300760063002F0031000000
diff --git a/data_sources/windows_event_log_system_7040.yml b/data_sources/windows_event_log_system_7040.yml
index e1d08e67e4..3a5f943ee0 100644
--- a/data_sources/windows_event_log_system_7040.yml
+++ b/data_sources/windows_event_log_system_7040.yml
@@ -1,88 +1,91 @@
name: Windows Event Log System 7040
id: 91738e9e-d112-41c9-b91b-e5868d8993d9
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs changes to the start type of a Windows service, including details about the service name, old start type, and new start type.
+description: Logs changes to the start type of a Windows service, including details
+ about the service name, old start type, and new start type.
mitre_components:
-- Service Modification
-- Service Metadata
-- OS API Execution
-- Application Log Content
+ - Service Modification
+ - Service Metadata
+ - OS API Execution
+ - Application Log Content
source: XmlWinEventLog:System
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 7040
supported_TA:
-- name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+ - name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
-- _time
-- Channel
-- Computer
-- Error_Code
-- EventCode
-- EventData_Xml
-- EventRecordID
-- EventSourceName
-- Guid
-- Keywords
-- Level
-- Name
-- Opcode
-- ProcessID
-- Qualifiers
-- RecordNumber
-- ServiceName
-- SystemTime
-- System_Props_Xml
-- Task
-- ThreadID
-- UserID
-- Version
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- param1
-- param2
-- param3
-- param4
-- product
-- punct
-- service
-- service_name
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- start_mode
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user_id
-- vendor
-- vendor_product
+ - _time
+ - Channel
+ - Computer
+ - Error_Code
+ - EventCode
+ - EventData_Xml
+ - EventRecordID
+ - EventSourceName
+ - Guid
+ - Keywords
+ - Level
+ - Name
+ - Opcode
+ - ProcessID
+ - Qualifiers
+ - RecordNumber
+ - ServiceName
+ - SystemTime
+ - System_Props_Xml
+ - Task
+ - ThreadID
+ - UserID
+ - Version
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - param1
+ - param2
+ - param3
+ - param4
+ - product
+ - punct
+ - service
+ - service_name
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - start_mode
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user_id
+ - vendor
+ - vendor_product
example_log: 704004000x8080000000000000704004000x8080000000000000168231Systemar-win-dc.attackrange.localSystemar-win-dc.attackrange.localPrint Spoolerdemand startdisabledSpooler
diff --git a/data_sources/windows_event_log_system_7045.yml b/data_sources/windows_event_log_system_7045.yml
index b7e8511470..a3f5ce006a 100644
--- a/data_sources/windows_event_log_system_7045.yml
+++ b/data_sources/windows_event_log_system_7045.yml
@@ -1,88 +1,91 @@
name: Windows Event Log System 7045
id: 614dedc8-8a14-4393-ba9b-6f093cbcd293
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the successful installation of a new Windows service, including details about the service name, executable path, and service type.
+description: Logs the successful installation of a new Windows service, including
+ details about the service name, executable path, and service type.
mitre_components:
-- Service Creation
-- Service Metadata
-- OS API Execution
-- Process Metadata
+ - Service Creation
+ - Service Metadata
+ - OS API Execution
+ - Process Metadata
source: XmlWinEventLog:System
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 7045
supported_TA:
-- name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+ - name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
-- _time
-- AccountName
-- Channel
-- Computer
-- Error_Code
-- EventCode
-- EventData_Xml
-- EventRecordID
-- EventSourceName
-- Guid
-- ImagePath
-- Keywords
-- Level
-- Name
-- Opcode
-- ProcessID
-- Qualifiers
-- RecordNumber
-- ServiceName
-- ServiceType
-- StartType
-- SystemTime
-- System_Props_Xml
-- Task
-- ThreadID
-- UserID
-- Version
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- product
-- punct
-- service
-- service_name
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- start_mode
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user_id
-- vendor
-- vendor_product
+ - _time
+ - AccountName
+ - Channel
+ - Computer
+ - Error_Code
+ - EventCode
+ - EventData_Xml
+ - EventRecordID
+ - EventSourceName
+ - Guid
+ - ImagePath
+ - Keywords
+ - Level
+ - Name
+ - Opcode
+ - ProcessID
+ - Qualifiers
+ - RecordNumber
+ - ServiceName
+ - ServiceType
+ - StartType
+ - SystemTime
+ - System_Props_Xml
+ - Task
+ - ThreadID
+ - UserID
+ - Version
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - product
+ - punct
+ - service
+ - service_name
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - start_mode
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user_id
+ - vendor
+ - vendor_product
example_log: 704504000x8080000000000000704504000x8080000000000000168145Systemar-win-dc.attackrange.localSystemar-win-dc.attackrange.localKrbSCMpowershell.exe -WindowStyle
Hiddenestno'
diff --git a/data_sources/windows_event_log_taskscheduler_200.yml b/data_sources/windows_event_log_taskscheduler_200.yml
index c7af8fd33b..4a29c55df5 100644
--- a/data_sources/windows_event_log_taskscheduler_200.yml
+++ b/data_sources/windows_event_log_taskscheduler_200.yml
@@ -1,83 +1,85 @@
name: Windows Event Log TaskScheduler 200
id: f8c777f8-e88a-4bba-ae8a-79b250212f23
-version: 1
-date: '2024-07-18'
+version: 2
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
-description: Logs the successful registration of a new scheduled task in Windows Task Scheduler, including task details and configurations.
+description: Logs the successful registration of a new scheduled task in Windows Task
+ Scheduler, including task details and configurations.
mitre_components:
-- Scheduled Job Creation
-- Scheduled Job Metadata
-- Service Creation
-- OS API Execution
+ - Scheduled Job Creation
+ - Scheduled Job Metadata
+ - Service Creation
+ - OS API Execution
source: WinEventLog:Microsoft-Windows-TaskScheduler/Operational
sourcetype: wineventlog
separator: EventCode
separator_value: 200
supported_TA:
-- name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+ - name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
-- _time
-- ActionName
-- ActivityID
-- Channel
-- Computer
-- EnginePID
-- Error_Code
-- EventCode
-- EventData_Xml
-- EventID
-- EventRecordID
-- Guid
-- Keywords
-- Level
-- Name
-- Opcode
-- ProcessID
-- RecordNumber
-- SystemTime
-- System_Props_Xml
-- Task
-- TaskInstanceId
-- TaskName
-- ThreadID
-- UserID
-- Version
-- app
-- date_hour
-- date_mday
-- date_minute
-- date_month
-- date_second
-- date_wday
-- date_year
-- date_zone
-- dest
-- dvc
-- dvc_nt_host
-- event_id
-- eventtype
-- host
-- id
-- index
-- linecount
-- product
-- punct
-- signature_id
-- source
-- sourcetype
-- splunk_server
-- ta_windows_action
-- tag
-- tag::eventtype
-- timeendpos
-- timestartpos
-- user_id
-- vendor
-- vendor_product
+ - _time
+ - ActionName
+ - ActivityID
+ - Channel
+ - Computer
+ - EnginePID
+ - Error_Code
+ - EventCode
+ - EventData_Xml
+ - EventID
+ - EventRecordID
+ - Guid
+ - Keywords
+ - Level
+ - Name
+ - Opcode
+ - ProcessID
+ - RecordNumber
+ - SystemTime
+ - System_Props_Xml
+ - Task
+ - TaskInstanceId
+ - TaskName
+ - ThreadID
+ - UserID
+ - Version
+ - app
+ - date_hour
+ - date_mday
+ - date_minute
+ - date_month
+ - date_second
+ - date_wday
+ - date_year
+ - date_zone
+ - dest
+ - dvc
+ - dvc_nt_host
+ - event_id
+ - eventtype
+ - host
+ - id
+ - index
+ - linecount
+ - product
+ - punct
+ - signature_id
+ - source
+ - sourcetype
+ - splunk_server
+ - ta_windows_action
+ - tag
+ - tag::eventtype
+ - timeendpos
+ - timestartpos
+ - user_id
+ - vendor
+ - vendor_product
example_log: 2001420010x80000000000000002001420010x80000000000000004323Microsoft-Windows-TaskScheduler/Operationalar-win-dc.attackrange.local
Date: Thu, 23 Jan 2025 10:09:09 -0700
Subject: [PATCH 03/67] Fix unintended spacing updates
---
data_sources/asl_aws_cloudtrail.yml | 30 +-
data_sources/aws_cloudfront.yml | 176 +-
.../aws_cloudtrail_assumerolewithsaml.yml | 194 +-
data_sources/aws_cloudtrail_consolelogin.yml | 170 +-
data_sources/aws_cloudtrail_copyobject.yml | 180 +-
.../aws_cloudtrail_createaccesskey.yml | 168 +-
data_sources/aws_cloudtrail_createkey.yml | 204 +-
.../aws_cloudtrail_createloginprofile.yml | 166 +-
.../aws_cloudtrail_createnetworkaclentry.yml | 198 +-
.../aws_cloudtrail_createpolicyversion.yml | 168 +-
.../aws_cloudtrail_createsnapshot.yml | 186 +-
data_sources/aws_cloudtrail_createtask.yml | 184 +-
.../aws_cloudtrail_createvirtualmfadevice.yml | 164 +-
.../aws_cloudtrail_deactivatemfadevice.yml | 164 +-
...cloudtrail_deleteaccountpasswordpolicy.yml | 162 +-
data_sources/aws_cloudtrail_deletealarms.yml | 232 +--
.../aws_cloudtrail_deletedetector.yml | 158 +-
data_sources/aws_cloudtrail_deletegroup.yml | 168 +-
data_sources/aws_cloudtrail_deleteipset.yml | 158 +-
.../aws_cloudtrail_deleteloggroup.yml | 162 +-
.../aws_cloudtrail_deletelogstream.yml | 164 +-
.../aws_cloudtrail_deletenetworkaclentry.yml | 176 +-
data_sources/aws_cloudtrail_deletepolicy.yml | 164 +-
data_sources/aws_cloudtrail_deleterule.yml | 164 +-
.../aws_cloudtrail_deletesnapshot.yml | 246 +--
data_sources/aws_cloudtrail_deletetrail.yml | 160 +-
.../aws_cloudtrail_deletevirtualmfadevice.yml | 160 +-
data_sources/aws_cloudtrail_deletewebacl.yml | 160 +-
...aws_cloudtrail_describeeventaggregates.yml | 152 +-
...s_cloudtrail_describeimagescanfindings.yml | 1826 ++++++++---------
...ws_cloudtrail_getaccountpasswordpolicy.yml | 158 +-
data_sources/aws_cloudtrail_getobject.yml | 176 +-
.../aws_cloudtrail_getpassworddata.yml | 178 +-
data_sources/aws_cloudtrail_jobcreated.yml | 130 +-
.../aws_cloudtrail_modifydbinstance.yml | 276 +--
.../aws_cloudtrail_modifyimageattribute.yml | 166 +-
...aws_cloudtrail_modifysnapshotattribute.yml | 156 +-
data_sources/aws_cloudtrail_putbucketacl.yml | 184 +-
.../aws_cloudtrail_putbucketlifecycle.yml | 186 +-
.../aws_cloudtrail_putbucketreplication.yml | 210 +-
.../aws_cloudtrail_putbucketversioning.yml | 192 +-
data_sources/aws_cloudtrail_putimage.yml | 172 +-
data_sources/aws_cloudtrail_putkeypolicy.yml | 172 +-
.../aws_cloudtrail_replacenetworkaclentry.yml | 188 +-
...aws_cloudtrail_setdefaultpolicyversion.yml | 158 +-
data_sources/aws_cloudtrail_stoplogging.yml | 148 +-
...cloudtrail_updateaccountpasswordpolicy.yml | 172 +-
.../aws_cloudtrail_updateloginprofile.yml | 156 +-
.../aws_cloudtrail_updatesamlprovider.yml | 339 ++-
data_sources/aws_cloudtrail_updatetrail.yml | 166 +-
data_sources/aws_cloudwatchlogs_vpcflow.yml | 116 +-
data_sources/aws_security_hub.yml | 220 +-
...p_role_assignment_to_service_principal.yml | 162 +-
...re_active_directory_add_member_to_role.yml | 114 +-
...ive_directory_add_owner_to_application.yml | 124 +-
...active_directory_add_service_principal.yml | 114 +-
...active_directory_add_unverified_domain.yml | 114 +-
...ctive_directory_consent_to_application.yml | 124 +-
...irectory_disable_strong_authentication.yml | 110 +-
.../azure_active_directory_enable_account.yml | 112 +-
..._active_directory_invite_external_user.yml | 110 +-
...ve_directory_reset_password_(by_admin).yml | 112 +-
...ve_directory_set_domain_authentication.yml | 112 +-
...zure_active_directory_sign_in_activity.yml | 212 +-
...re_active_directory_update_application.yml | 112 +-
..._directory_update_authorization_policy.yml | 114 +-
.../azure_active_directory_update_user.yml | 114 +-
...irectory_user_registered_security_info.yml | 106 +-
..._or_update_an_azure_automation_account.yml | 188 +-
..._or_update_an_azure_automation_runbook.yml | 186 +-
..._or_update_an_azure_automation_webhook.yml | 206 +-
data_sources/bro_conn.yml | 9 +-
data_sources/bro_dns.yml | 10 +-
data_sources/bro_files.yml | 10 +-
data_sources/bro_http.yml | 10 +-
data_sources/bro_loaded_scripts.yml | 8 +-
data_sources/bro_ntp.yml | 8 +-
data_sources/bro_ocsp.yml | 10 +-
data_sources/bro_ssl.yml | 10 +-
data_sources/bro_weird.yml | 10 +-
data_sources/bro_x509.yml | 10 +-
data_sources/circleci.yml | 120 +-
data_sources/crowdstrike_processrollup2.yml | 192 +-
data_sources/crushftp.yml | 14 +-
data_sources/g_suite_drive.yml | 78 +-
data_sources/g_suite_gmail.yml | 154 +-
data_sources/github.yml | 394 ++--
.../google_workspace_login_failure.yml | 84 +-
.../google_workspace_login_success.yml | 80 +-
data_sources/ivanti_vtm_audit.yml | 26 +-
data_sources/kubernetes_audit.yml | 104 +-
data_sources/kubernetes_falco.yml | 80 +-
data_sources/linux_auditd_add_user.yml | 56 +-
data_sources/linux_auditd_execve.yml | 24 +-
data_sources/linux_auditd_path.yml | 52 +-
data_sources/linux_auditd_proctitle.yml | 20 +-
data_sources/linux_auditd_service_stop.yml | 52 +-
data_sources/linux_auditd_syscall.yml | 92 +-
data_sources/linux_secure.yml | 80 +-
.../ms365_defender_incident_alerts.yml | 407 ++--
data_sources/ms_defender_atp_alerts.yml | 684 +++---
data_sources/nginx_access.yml | 128 +-
data_sources/o365.yml | 16 +-
...add_app_role_assignment_grant_to_user_.yml | 152 +-
..._role_assignment_to_service_principal_.yml | 150 +-
data_sources/o365_add_mailboxpermission.yml | 134 +-
data_sources/o365_add_member_to_role_.yml | 156 +-
.../o365_add_owner_to_application_.yml | 160 +-
data_sources/o365_add_service_principal_.yml | 160 +-
data_sources/o365_change_user_license_.yml | 152 +-
data_sources/o365_consent_to_application_.yml | 144 +-
.../o365_disable_strong_authentication_.yml | 146 +-
data_sources/o365_mailitemsaccessed.yml | 138 +-
data_sources/o365_modifyfolderpermissions.yml | 174 +-
.../o365_set_company_information_.yml | 162 +-
data_sources/o365_set_mailbox.yml | 154 +-
data_sources/o365_update_application_.yml | 160 +-
.../o365_update_authorization_policy_.yml | 144 +-
data_sources/o365_update_user_.yml | 158 +-
data_sources/o365_userloggedin.yml | 158 +-
data_sources/o365_userloginfailed.yml | 176 +-
data_sources/okta.yml | 16 +-
data_sources/osquery.yml | 116 +-
data_sources/palo_alto_network_threat.yml | 55 +-
data_sources/palo_alto_network_traffic.yml | 58 +-
data_sources/pingid.yml | 64 +-
.../powershell_installed_iis_modules.yml | 28 +-
.../powershell_script_block_logging_4104.yml | 155 +-
data_sources/powershell_sip_inventory.yml | 8 +-
data_sources/splunk.yml | 56 +-
data_sources/splunk_stream_http.yml | 106 +-
data_sources/splunk_stream_ip.yml | 139 +-
data_sources/splunk_stream_tcp.yml | 16 +-
data_sources/suricata.yml | 102 +-
data_sources/sysmon_eventid_1.yml | 293 ++-
data_sources/sysmon_eventid_10.yml | 176 +-
data_sources/sysmon_eventid_11.yml | 181 +-
data_sources/sysmon_eventid_12.yml | 171 +-
data_sources/sysmon_eventid_13.yml | 198 +-
data_sources/sysmon_eventid_15.yml | 177 +-
data_sources/sysmon_eventid_17.yml | 152 +-
data_sources/sysmon_eventid_18.yml | 158 +-
data_sources/sysmon_eventid_20.yml | 164 +-
data_sources/sysmon_eventid_21.yml | 168 +-
data_sources/sysmon_eventid_22.yml | 156 +-
data_sources/sysmon_eventid_23.yml | 180 +-
data_sources/sysmon_eventid_3.yml | 208 +-
data_sources/sysmon_eventid_5.yml | 152 +-
data_sources/sysmon_eventid_6.yml | 159 +-
data_sources/sysmon_eventid_7.yml | 199 +-
data_sources/sysmon_eventid_8.yml | 180 +-
data_sources/sysmon_eventid_9.yml | 154 +-
data_sources/sysmon_for_linux_eventid_1.yml | 198 +-
data_sources/sysmon_for_linux_eventid_11.yml | 154 +-
.../windows_active_directory_admon.yml | 96 +-
data_sources/windows_defender_alerts.yml | 100 +-
.../windows_event_log_application_2282.yml | 123 +-
.../windows_event_log_application_3000.yml | 108 +-
data_sources/windows_event_log_capi2_70.yml | 116 +-
data_sources/windows_event_log_capi2_81.yml | 122 +-
...ent_log_certificateservicesclient_1007.yml | 118 +-
.../windows_event_log_defender_1121.yml | 125 +-
.../windows_event_log_defender_1122.yml | 119 +-
.../windows_event_log_defender_1129.yml | 104 +-
.../windows_event_log_defender_5007.yml | 97 +-
...indows_terminalservices_rdpclient_1024.yml | 72 +-
.../windows_event_log_printservice_316.yml | 98 +-
.../windows_event_log_printservice_808.yml | 106 +-
...event_log_remoteconnectionmanager_1149.yml | 99 +-
.../windows_event_log_security_1100.yml | 138 +-
.../windows_event_log_security_1102.yml | 150 +-
.../windows_event_log_security_4624.yml | 223 +-
.../windows_event_log_security_4625.yml | 213 +-
.../windows_event_log_security_4627.yml | 171 +-
.../windows_event_log_security_4648.yml | 197 +-
.../windows_event_log_security_4662.yml | 171 +-
.../windows_event_log_security_4663.yml | 184 +-
.../windows_event_log_security_4672.yml | 151 +-
.../windows_event_log_security_4688.yml | 235 ++-
.../windows_event_log_security_4698.yml | 154 +-
.../windows_event_log_security_4699.yml | 152 +-
.../windows_event_log_security_4703.yml | 192 +-
.../windows_event_log_security_4719.yml | 163 +-
.../windows_event_log_security_4720.yml | 198 +-
.../windows_event_log_security_4724.yml | 182 +-
.../windows_event_log_security_4725.yml | 182 +-
.../windows_event_log_security_4726.yml | 184 +-
.../windows_event_log_security_4732.yml | 174 +-
.../windows_event_log_security_4738.yml | 222 +-
.../windows_event_log_security_4739.yml | 198 +-
.../windows_event_log_security_4741.yml | 224 +-
.../windows_event_log_security_4742.yml | 226 +-
.../windows_event_log_security_4768.yml | 186 +-
.../windows_event_log_security_4769.yml | 186 +-
.../windows_event_log_security_4771.yml | 174 +-
.../windows_event_log_security_4776.yml | 156 +-
.../windows_event_log_security_4781.yml | 187 +-
.../windows_event_log_security_4794.yml | 171 +-
.../windows_event_log_security_4798.yml | 167 +-
.../windows_event_log_security_4876.yml | 155 +-
.../windows_event_log_security_4886.yml | 139 +-
.../windows_event_log_security_4887.yml | 145 +-
.../windows_event_log_security_5136.yml | 178 +-
.../windows_event_log_security_5137.yml | 171 +-
.../windows_event_log_security_5140.yml | 206 +-
.../windows_event_log_security_5141.yml | 167 +-
.../windows_event_log_security_5145.yml | 246 ++-
.../windows_event_log_system_4720.yml | 204 +-
.../windows_event_log_system_4726.yml | 184 +-
.../windows_event_log_system_4728.yml | 184 +-
.../windows_event_log_system_7036.yml | 135 +-
.../windows_event_log_system_7040.yml | 140 +-
.../windows_event_log_system_7045.yml | 140 +-
.../windows_event_log_taskscheduler_200.yml | 133 +-
data_sources/windows_iis.yml | 14 +-
data_sources/windows_iis_29.yml | 46 +-
216 files changed, 16448 insertions(+), 16889 deletions(-)
diff --git a/data_sources/asl_aws_cloudtrail.yml b/data_sources/asl_aws_cloudtrail.yml
index 05767f098b..440735d18e 100644
--- a/data_sources/asl_aws_cloudtrail.yml
+++ b/data_sources/asl_aws_cloudtrail.yml
@@ -5,22 +5,22 @@ date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Represents AWS API dataset data collection from Amazon Security Lake.
mitre_components:
- - Cloud Service Metadata
- - Cloud Service Modification
- - Cloud Storage Access
- - Instance Creation
- - Instance Deletion
- - Instance Start
- - Instance Stop
- - Instance Modification
- - Cloud Storage Creation
- - Cloud Storage Deletion
- - Cloud Service Enumeration
- - Cloud Storage Enumeration
+- Cloud Service Metadata
+- Cloud Service Modification
+- Cloud Storage Access
+- Instance Creation
+- Instance Deletion
+- Instance Start
+- Instance Stop
+- Instance Modification
+- Cloud Storage Creation
+- Cloud Storage Deletion
+- Cloud Service Enumeration
+- Cloud Storage Enumeration
source: aws_asl
sourcetype: aws:asl
separator: api.operation
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
diff --git a/data_sources/aws_cloudfront.yml b/data_sources/aws_cloudfront.yml
index b8eb8a416b..f6df73faea 100644
--- a/data_sources/aws_cloudfront.yml
+++ b/data_sources/aws_cloudfront.yml
@@ -6,98 +6,98 @@ author: Patrick Bareiss, Splunk
description: Logs requests made to AWS CloudFront distributions, including details
on client access, response data, and performance metrics.
mitre_components:
- - Network Traffic Content
- - Network Traffic Flow
- - Response Metadata
- - Response Content
- - Logon Session Metadata
- - Cloud Service Metadata
+- Network Traffic Content
+- Network Traffic Flow
+- Response Metadata
+- Response Content
+- Logon Session Metadata
+- Cloud Service Metadata
source: aws
sourcetype: aws:cloudfront:accesslogs
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - bytes
- - bytes_in
- - bytes_out
- - c_ip
- - c_port
- - cached
- - category
- - client_ip
- - cs_bytes
- - cs_cookie
- - cs_host
- - cs_method
- - cs_protocol
- - cs_protocol_version
- - cs_referer
- - cs_uri_query
- - cs_uri_stem
- - cs_user_agent
- - date
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - duration
- - edge_location_name
- - eventtype
- - fle_encrypted_fields
- - fle_status
- - host
- - http_content_type
- - http_method
- - http_user_agent
- - http_user_agent_length
- - index
- - linecount
- - punct
- - response_time
- - sc_bytes
- - sc_content_len
- - sc_content_type
- - sc_range_end
- - sc_range_start
- - sc_status
- - source
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - src_port
- - ssl_cipher
- - ssl_protocol
- - status
- - tag
- - tag::eventtype
- - time
- - time_taken
- - time_to_first_byte
- - timeendpos
- - timestartpos
- - uri_path
- - url
- - url_domain
- - url_length
- - vendor_product
- - x_edge_detail_result_type
- - x_edge_location
- - x_edge_request_id
- - x_edge_response_result_type
- - x_edge_result_type
- - x_forwarded_for
- - x_host_header
+- _time
+- action
+- app
+- bytes
+- bytes_in
+- bytes_out
+- c_ip
+- c_port
+- cached
+- category
+- client_ip
+- cs_bytes
+- cs_cookie
+- cs_host
+- cs_method
+- cs_protocol
+- cs_protocol_version
+- cs_referer
+- cs_uri_query
+- cs_uri_stem
+- cs_user_agent
+- date
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- duration
+- edge_location_name
+- eventtype
+- fle_encrypted_fields
+- fle_status
+- host
+- http_content_type
+- http_method
+- http_user_agent
+- http_user_agent_length
+- index
+- linecount
+- punct
+- response_time
+- sc_bytes
+- sc_content_len
+- sc_content_type
+- sc_range_end
+- sc_range_start
+- sc_status
+- source
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- src_port
+- ssl_cipher
+- ssl_protocol
+- status
+- tag
+- tag::eventtype
+- time
+- time_taken
+- time_to_first_byte
+- timeendpos
+- timestartpos
+- uri_path
+- url
+- url_domain
+- url_length
+- vendor_product
+- x_edge_detail_result_type
+- x_edge_location
+- x_edge_request_id
+- x_edge_response_result_type
+- x_edge_result_type
+- x_forwarded_for
+- x_host_header
example_log: "2023-11-07\t16:58:21\tIAD55-P5\t921\t44.192.78.55\tGET\td3u5aue66f5ui4.cloudfront.net\t\
/plugins/servlet/com.jsos.shell/ShellServlet\t200\t-\tSlackbot-LinkExpanding%201.0%20(+https://api.slack.com/robots)\t\
-\t-\tLambdaGeneratedResponse\tsGwvFCkFU4qlMxatCoJRgW87P7Ee8bKQor3U6lRt6I6jaFvLC7vcPA==\t\
diff --git a/data_sources/aws_cloudtrail_assumerolewithsaml.yml b/data_sources/aws_cloudtrail_assumerolewithsaml.yml
index c9823cd2d7..c8b978c277 100644
--- a/data_sources/aws_cloudtrail_assumerolewithsaml.yml
+++ b/data_sources/aws_cloudtrail_assumerolewithsaml.yml
@@ -6,109 +6,109 @@ author: Patrick Bareiss, Splunk
description: Logs attempts to assume roles via SAML authentication in AWS, including
details of identity provider and role mapping.
mitre_components:
- - User Account Authentication
- - Logon Session Creation
- - User Account Metadata
- - Cloud Service Metadata
- - Instance Modification
+- User Account Authentication
+- Logon Session Creation
+- User Account Metadata
+- Cloud Service Metadata
+- Instance Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: AssumeRoleWithSAML
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - awsRegion
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.durationSeconds
- - requestParameters.principalArn
- - requestParameters.roleArn
- - requestParameters.roleSessionName
- - requestParameters.sAMLAssertionID
- - resources{}.ARN
- - resources{}.accountId
- - resources{}.type
- - responseElements.assumedRoleUser.arn
- - responseElements.assumedRoleUser.assumedRoleId
- - responseElements.audience
- - responseElements.credentials.accessKeyId
- - responseElements.credentials.expiration
- - responseElements.credentials.sessionToken
- - responseElements.issuer
- - responseElements.nameQualifier
- - responseElements.subject
- - responseElements.subjectType
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - src_user
- - src_user_id
- - src_user_type
- - start_time
- - status
- - tag
- - tag::action
- - tag::eventtype
- - temp_access_key
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.identityProvider
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - user_agent
- - user_arn
- - user_id
- - user_name
- - user_role
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- app
+- awsRegion
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.durationSeconds
+- requestParameters.principalArn
+- requestParameters.roleArn
+- requestParameters.roleSessionName
+- requestParameters.sAMLAssertionID
+- resources{}.ARN
+- resources{}.accountId
+- resources{}.type
+- responseElements.assumedRoleUser.arn
+- responseElements.assumedRoleUser.assumedRoleId
+- responseElements.audience
+- responseElements.credentials.accessKeyId
+- responseElements.credentials.expiration
+- responseElements.credentials.sessionToken
+- responseElements.issuer
+- responseElements.nameQualifier
+- responseElements.subject
+- responseElements.subjectType
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- src_user
+- src_user_id
+- src_user_type
+- start_time
+- status
+- tag
+- tag::action
+- tag::eventtype
+- temp_access_key
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.identityProvider
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- user_agent
+- user_arn
+- user_id
+- user_name
+- user_role
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "SAMLUser", "principalId":
"ZRu9MRAjiG9tvi1QBNfdI664G5A=:rodsoto@rodsoto.onmicrosoft.com", "userName": "rodsoto@rodsoto.onmicrosoft.com",
"identityProvider": "ZRu9MRAjiG9tvi1QBNfdI664G5A="}, "eventTime": "2021-01-22T03:44:16Z",
diff --git a/data_sources/aws_cloudtrail_consolelogin.yml b/data_sources/aws_cloudtrail_consolelogin.yml
index 0d05cff28d..441afb6cea 100644
--- a/data_sources/aws_cloudtrail_consolelogin.yml
+++ b/data_sources/aws_cloudtrail_consolelogin.yml
@@ -6,97 +6,97 @@ author: Patrick Bareiss, Splunk
description: Logs attempts to sign in to the AWS Management Console, including successful
and failed login events.
mitre_components:
- - User Account Authentication
- - Logon Session Creation
- - User Account Metadata
- - Logon Session Metadata
- - Cloud Service Metadata
+- User Account Authentication
+- Logon Session Creation
+- User Account Metadata
+- Logon Session Metadata
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: ConsoleLogin
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - additionalEventData.LoginTo
- - additionalEventData.MFAUsed
- - additionalEventData.MobileVersion
- - app
- - authentication_method
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - desc
- - dest
- - dvc
- - errorCode
- - errorMessage
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - reason
- - recipientAccountId
- - region
- - requestParameters
- - responseElements.ConsoleLogin
- - result
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - status
- - tag
- - tag::action
- - tag::eventtype
- - timeendpos
- - timestartpos
- - tlsDetails.cipherSuite
- - tlsDetails.clientProvidedHostHeader
- - tlsDetails.tlsVersion
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.type
- - userIdentity.userName
- - user_access_key
- - user_agent
- - user_group_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- additionalEventData.LoginTo
+- additionalEventData.MFAUsed
+- additionalEventData.MobileVersion
+- app
+- authentication_method
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- desc
+- dest
+- dvc
+- errorCode
+- errorMessage
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- reason
+- recipientAccountId
+- region
+- requestParameters
+- responseElements.ConsoleLogin
+- result
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- status
+- tag
+- tag::action
+- tag::eventtype
+- timeendpos
+- timestartpos
+- tlsDetails.cipherSuite
+- tlsDetails.clientProvidedHostHeader
+- tlsDetails.tlsVersion
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.type
+- userIdentity.userName
+- user_access_key
+- user_agent
+- user_group_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "accountId":
"140429656527", "accessKeyId": "", "userName": "HIDDEN_DUE_TO_SECURITY_REASONS"},
"eventTime": "2022-10-19T20:33:38Z", "eventSource": "signin.amazonaws.com", "eventName":
diff --git a/data_sources/aws_cloudtrail_copyobject.yml b/data_sources/aws_cloudtrail_copyobject.yml
index 9edd40bb4d..93ea12c92f 100644
--- a/data_sources/aws_cloudtrail_copyobject.yml
+++ b/data_sources/aws_cloudtrail_copyobject.yml
@@ -6,102 +6,102 @@ author: Patrick Bareiss, Splunk
description: Logs operations that copy objects within or between AWS S3 buckets, including
details of source and destination.
mitre_components:
- - Cloud Storage Access
- - Cloud Storage Modification
- - Cloud Storage Metadata
- - Instance Modification
+- Cloud Storage Access
+- Cloud Storage Modification
+- Cloud Storage Metadata
+- Instance Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_values: CopyObject
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - additionalEventData.AuthenticationMethod
- - additionalEventData.CipherSuite
- - additionalEventData.SSEApplied
- - additionalEventData.SignatureVersion
- - additionalEventData.bytesTransferredIn
- - additionalEventData.bytesTransferredOut
- - additionalEventData.x-amz-id-2
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.Host
- - requestParameters.bucketName
- - requestParameters.key
- - requestParameters.x-amz-copy-source
- - requestParameters.x-amz-server-side-encryption
- - requestParameters.x-amz-server-side-encryption-aws-kms-key-id
- - resources{}.ARN
- - resources{}.accountId
- - resources{}.type
- - responseElements.x-amz-server-side-encryption
- - responseElements.x-amz-server-side-encryption-aws-kms-key-id
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- additionalEventData.AuthenticationMethod
+- additionalEventData.CipherSuite
+- additionalEventData.SSEApplied
+- additionalEventData.SignatureVersion
+- additionalEventData.bytesTransferredIn
+- additionalEventData.bytesTransferredOut
+- additionalEventData.x-amz-id-2
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.Host
+- requestParameters.bucketName
+- requestParameters.key
+- requestParameters.x-amz-copy-source
+- requestParameters.x-amz-server-side-encryption
+- requestParameters.x-amz-server-side-encryption-aws-kms-key-id
+- resources{}.ARN
+- resources{}.accountId
+- resources{}.type
+- responseElements.x-amz-server-side-encryption
+- responseElements.x-amz-server-side-encryption-aws-kms-key-id
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLNALZHZ6KX", "arn": "arn:aws:iam::111111111111:user/patrick_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLJ2OYSF6E", "userName": "patrick_cli"},
diff --git a/data_sources/aws_cloudtrail_createaccesskey.yml b/data_sources/aws_cloudtrail_createaccesskey.yml
index d72354f779..e32d68ce5f 100644
--- a/data_sources/aws_cloudtrail_createaccesskey.yml
+++ b/data_sources/aws_cloudtrail_createaccesskey.yml
@@ -6,96 +6,96 @@ author: Patrick Bareiss, Splunk
description: Logs the creation of new AWS access keys, including details of the associated
user and permissions.
mitre_components:
- - User Account Creation
- - User Account Metadata
- - Cloud Service Modification
- - Cloud Service Metadata
+- User Account Creation
+- User Account Metadata
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreateAccessKey
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.userName
- - responseElements.accessKey.accessKeyId
- - responseElements.accessKey.createDate
- - responseElements.accessKey.status
- - responseElements.accessKey.userName
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - src_user_name
- - start_time
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.userName
+- responseElements.accessKey.accessKeyId
+- responseElements.accessKey.createDate
+- responseElements.accessKey.status
+- responseElements.accessKey.userName
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- src_user_name
+- start_time
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::121521347698:user/bhavin_cli", "accountId":
"121521347698", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
diff --git a/data_sources/aws_cloudtrail_createkey.yml b/data_sources/aws_cloudtrail_createkey.yml
index 293ecba3cd..c6c31a41a3 100644
--- a/data_sources/aws_cloudtrail_createkey.yml
+++ b/data_sources/aws_cloudtrail_createkey.yml
@@ -6,114 +6,114 @@ author: Patrick Bareiss, Splunk
description: Logs the creation of new AWS KMS keys, including details of key properties
and associated metadata.
mitre_components:
- - Cloud Service Creation
- - Cloud Service Metadata
- - Instance Creation
- - Volume Metadata
+- Cloud Service Creation
+- Cloud Service Metadata
+- Instance Creation
+- Volume Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreateKey
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.bypassPolicyLockoutSafetyCheck
- - requestParameters.customerMasterKeySpec
- - requestParameters.description
- - requestParameters.keyUsage
- - requestParameters.origin
- - requestParameters.policy
- - resources{}.ARN
- - resources{}.accountId
- - resources{}.type
- - responseElements.keyMetadata.aWSAccountId
- - responseElements.keyMetadata.arn
- - responseElements.keyMetadata.creationDate
- - responseElements.keyMetadata.customerMasterKeySpec
- - responseElements.keyMetadata.description
- - responseElements.keyMetadata.enabled
- - responseElements.keyMetadata.encryptionAlgorithms{}
- - responseElements.keyMetadata.keyId
- - responseElements.keyMetadata.keyManager
- - responseElements.keyMetadata.keyState
- - responseElements.keyMetadata.keyUsage
- - responseElements.keyMetadata.origin
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.sessionContext.sessionIssuer.accountId
- - userIdentity.sessionContext.sessionIssuer.arn
- - userIdentity.sessionContext.sessionIssuer.principalId
- - userIdentity.sessionContext.sessionIssuer.type
- - userIdentity.sessionContext.sessionIssuer.userName
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.bypassPolicyLockoutSafetyCheck
+- requestParameters.customerMasterKeySpec
+- requestParameters.description
+- requestParameters.keyUsage
+- requestParameters.origin
+- requestParameters.policy
+- resources{}.ARN
+- resources{}.accountId
+- resources{}.type
+- responseElements.keyMetadata.aWSAccountId
+- responseElements.keyMetadata.arn
+- responseElements.keyMetadata.creationDate
+- responseElements.keyMetadata.customerMasterKeySpec
+- responseElements.keyMetadata.description
+- responseElements.keyMetadata.enabled
+- responseElements.keyMetadata.encryptionAlgorithms{}
+- responseElements.keyMetadata.keyId
+- responseElements.keyMetadata.keyManager
+- responseElements.keyMetadata.keyState
+- responseElements.keyMetadata.keyUsage
+- responseElements.keyMetadata.origin
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.sessionContext.sessionIssuer.accountId
+- userIdentity.sessionContext.sessionIssuer.arn
+- userIdentity.sessionContext.sessionIssuer.principalId
+- userIdentity.sessionContext.sessionIssuer.type
+- userIdentity.sessionContext.sessionIssuer.userName
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLK74OPBDR", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_createloginprofile.yml b/data_sources/aws_cloudtrail_createloginprofile.yml
index df6b04e40d..243ad0b5c5 100644
--- a/data_sources/aws_cloudtrail_createloginprofile.yml
+++ b/data_sources/aws_cloudtrail_createloginprofile.yml
@@ -6,95 +6,95 @@ author: Patrick Bareiss, Splunk
description: Logs the creation of login profiles for IAM users, including associated
metadata and authentication settings.
mitre_components:
- - User Account Creation
- - User Account Metadata
- - Logon Session Metadata
- - Cloud Service Metadata
+- User Account Creation
+- User Account Metadata
+- Logon Session Metadata
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreateLoginProfile
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.passwordResetRequired
- - requestParameters.userName
- - responseElements.loginProfile.createDate
- - responseElements.loginProfile.passwordResetRequired
- - responseElements.loginProfile.userName
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.passwordResetRequired
+- requestParameters.userName
+- responseElements.loginProfile.createDate
+- responseElements.loginProfile.passwordResetRequired
+- responseElements.loginProfile.userName
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
diff --git a/data_sources/aws_cloudtrail_createnetworkaclentry.yml b/data_sources/aws_cloudtrail_createnetworkaclentry.yml
index 993b03197a..3f98c6329c 100644
--- a/data_sources/aws_cloudtrail_createnetworkaclentry.yml
+++ b/data_sources/aws_cloudtrail_createnetworkaclentry.yml
@@ -6,111 +6,111 @@ author: Patrick Bareiss, Splunk
description: Logs the creation of new entries in a network ACL, including rules to
allow or deny specific network traffic.
mitre_components:
- - Firewall Rule Modification
- - Network Connection Creation
- - Cloud Service Modification
- - Cloud Service Metadata
+- Firewall Rule Modification
+- Network Connection Creation
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreateNetworkAclEntry
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - direction
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object
- - object_category
- - object_id
- - product
- - protocol
- - protocol_code
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.aclProtocol
- - requestParameters.cidrBlock
- - requestParameters.egress
- - requestParameters.networkAclId
- - requestParameters.ruleAction
- - requestParameters.ruleNumber
- - responseElements._return
- - responseElements.requestId
- - rule_action
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - src_ip_range
- - start_time
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.sessionContext.sessionIssuer.accountId
- - userIdentity.sessionContext.sessionIssuer.arn
- - userIdentity.sessionContext.sessionIssuer.principalId
- - userIdentity.sessionContext.sessionIssuer.type
- - userIdentity.sessionContext.sessionIssuer.userName
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- direction
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object
+- object_category
+- object_id
+- product
+- protocol
+- protocol_code
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.aclProtocol
+- requestParameters.cidrBlock
+- requestParameters.egress
+- requestParameters.networkAclId
+- requestParameters.ruleAction
+- requestParameters.ruleNumber
+- responseElements._return
+- responseElements.requestId
+- rule_action
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- src_ip_range
+- start_time
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.sessionContext.sessionIssuer.accountId
+- userIdentity.sessionContext.sessionIssuer.arn
+- userIdentity.sessionContext.sessionIssuer.principalId
+- userIdentity.sessionContext.sessionIssuer.type
+- userIdentity.sessionContext.sessionIssuer.userName
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_createpolicyversion.yml b/data_sources/aws_cloudtrail_createpolicyversion.yml
index 2973c651b0..88b3b2aeb7 100644
--- a/data_sources/aws_cloudtrail_createpolicyversion.yml
+++ b/data_sources/aws_cloudtrail_createpolicyversion.yml
@@ -6,96 +6,96 @@ author: Patrick Bareiss, Splunk
description: Logs the creation of new versions of IAM policies, including changes
to permissions and attached roles or resources.
mitre_components:
- - Cloud Service Modification
- - Cloud Service Metadata
- - User Account Metadata
- - Group Modification
+- Cloud Service Modification
+- Cloud Service Metadata
+- User Account Metadata
+- Group Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreatePolicyVersion
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.policyArn
- - requestParameters.policyDocument
- - requestParameters.setAsDefault
- - responseElements.policyVersion.createDate
- - responseElements.policyVersion.isDefaultVersion
- - responseElements.policyVersion.versionId
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.policyArn
+- requestParameters.policyDocument
+- requestParameters.setAsDefault
+- responseElements.policyVersion.createDate
+- responseElements.policyVersion.isDefaultVersion
+- responseElements.policyVersion.versionId
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLNMCDVJZAY", "arn": "arn:aws:iam::111111111111:user/rhino_escalate",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLHSQZPZFZ", "userName":
diff --git a/data_sources/aws_cloudtrail_createsnapshot.yml b/data_sources/aws_cloudtrail_createsnapshot.yml
index ae5c392552..0d724bfada 100644
--- a/data_sources/aws_cloudtrail_createsnapshot.yml
+++ b/data_sources/aws_cloudtrail_createsnapshot.yml
@@ -6,105 +6,105 @@ author: Patrick Bareiss, Splunk
description: Logs the creation of a new snapshot of a cloud resource, such as an Amazon
EBS volume, including details about the snapshot ID and resource type.
mitre_components:
- - Snapshot Creation
- - Snapshot Metadata
- - Volume Metadata
- - Cloud Service Metadata
+- Snapshot Creation
+- Snapshot Metadata
+- Volume Metadata
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreateSnapshot
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.tagSpecificationSet.items{}.resourceType
- - requestParameters.tagSpecificationSet.items{}.tags{}.key
- - requestParameters.tagSpecificationSet.items{}.tags{}.value
- - requestParameters.volumeId
- - responseElements.encrypted
- - responseElements.ownerId
- - responseElements.requestId
- - responseElements.snapshotId
- - responseElements.startTime
- - responseElements.status
- - responseElements.tagSet.items{}.key
- - responseElements.tagSet.items{}.value
- - responseElements.volumeId
- - responseElements.volumeSize
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - tlsDetails.cipherSuite
- - tlsDetails.clientProvidedHostHeader
- - tlsDetails.tlsVersion
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.tagSpecificationSet.items{}.resourceType
+- requestParameters.tagSpecificationSet.items{}.tags{}.key
+- requestParameters.tagSpecificationSet.items{}.tags{}.value
+- requestParameters.volumeId
+- responseElements.encrypted
+- responseElements.ownerId
+- responseElements.requestId
+- responseElements.snapshotId
+- responseElements.startTime
+- responseElements.status
+- responseElements.tagSet.items{}.key
+- responseElements.tagSet.items{}.value
+- responseElements.volumeId
+- responseElements.volumeSize
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- tlsDetails.cipherSuite
+- tlsDetails.clientProvidedHostHeader
+- tlsDetails.tlsVersion
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/bhavin_console",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName":
diff --git a/data_sources/aws_cloudtrail_createtask.yml b/data_sources/aws_cloudtrail_createtask.yml
index 7808c2b9cc..3db15c7370 100644
--- a/data_sources/aws_cloudtrail_createtask.yml
+++ b/data_sources/aws_cloudtrail_createtask.yml
@@ -6,104 +6,104 @@ author: Patrick Bareiss, Splunk
description: Logs the creation of a new task in AWS services, such as ECS, including
details about the task definition and resource allocation.
mitre_components:
- - Scheduled Job Creation
- - Scheduled Job Metadata
- - Cloud Service Metadata
- - Instance Creation
+- Scheduled Job Creation
+- Scheduled Job Metadata
+- Cloud Service Metadata
+- Instance Creation
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_name: CreateTask
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.cloudWatchLogGroupArn
- - requestParameters.destinationLocationArn
- - requestParameters.options.logLevel
- - requestParameters.options.verifyMode
- - requestParameters.schedule.scheduleExpression
- - requestParameters.sourceLocationArn
- - responseElements.taskArn
- - sessionCredentialFromConsole
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - tlsDetails.cipherSuite
- - tlsDetails.clientProvidedHostHeader
- - tlsDetails.tlsVersion
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.sessionContext.sessionIssuer.accountId
- - userIdentity.sessionContext.sessionIssuer.arn
- - userIdentity.sessionContext.sessionIssuer.principalId
- - userIdentity.sessionContext.sessionIssuer.type
- - userIdentity.sessionContext.sessionIssuer.userName
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.cloudWatchLogGroupArn
+- requestParameters.destinationLocationArn
+- requestParameters.options.logLevel
+- requestParameters.options.verifyMode
+- requestParameters.schedule.scheduleExpression
+- requestParameters.sourceLocationArn
+- responseElements.taskArn
+- sessionCredentialFromConsole
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- tlsDetails.cipherSuite
+- tlsDetails.clientProvidedHostHeader
+- tlsDetails.tlsVersion
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.sessionContext.sessionIssuer.accountId
+- userIdentity.sessionContext.sessionIssuer.arn
+- userIdentity.sessionContext.sessionIssuer.principalId
+- userIdentity.sessionContext.sessionIssuer.type
+- userIdentity.sessionContext.sessionIssuer.userName
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLDF6WQQQQQ:abc@acme.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/abc@acme.com",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLOB2GM111", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml
index 7b6b181672..f76f14d9c1 100644
--- a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml
+++ b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml
@@ -6,94 +6,94 @@ author: Patrick Bareiss, Splunk
description: Logs the creation of a new virtual multi-factor authentication (MFA)
device, including details about the associated user and configuration.
mitre_components:
- - User Account Creation
- - User Account Metadata
- - Cloud Service Creation
- - Cloud Service Metadata
+- User Account Creation
+- User Account Metadata
+- Cloud Service Creation
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreateVirtualMFADevice
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.path
- - requestParameters.virtualMFADeviceName
- - responseElements.virtualMFADevice.serialNumber
- - sessionCredentialFromConsole
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.path
+- requestParameters.virtualMFADeviceName
+- responseElements.virtualMFADevice.serialNumber
+- sessionCredentialFromConsole
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
"140429656527", "arn": "arn:aws:iam::140429656527:root", "accountId": "140429656527",
"accessKeyId": "ASIASBMSCQHH2YXNXJBU", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
diff --git a/data_sources/aws_cloudtrail_deactivatemfadevice.yml b/data_sources/aws_cloudtrail_deactivatemfadevice.yml
index e53018b544..06d7103bfe 100644
--- a/data_sources/aws_cloudtrail_deactivatemfadevice.yml
+++ b/data_sources/aws_cloudtrail_deactivatemfadevice.yml
@@ -6,94 +6,94 @@ author: Patrick Bareiss, Splunk
description: Logs the deactivation of a multi-factor authentication (MFA) device,
including details about the associated user and the device.
mitre_components:
- - User Account Modification
- - User Account Metadata
- - Cloud Service Modification
- - Cloud Service Metadata
+- User Account Modification
+- User Account Metadata
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeactivateMFADevice
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.serialNumber
- - requestParameters.userName
- - responseElements
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.serialNumber
+- requestParameters.userName
+- responseElements
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
"111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111",
"accessKeyId": "ASIASBMSCQHHWAIHMHUX", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
diff --git a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml
index 9d10c7443a..feeaa4fd66 100644
--- a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml
+++ b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml
@@ -6,93 +6,93 @@ author: Patrick Bareiss, Splunk
description: Logs the deletion of an account-level password policy in AWS, including
details about the account and policy being removed.
mitre_components:
- - Cloud Service Modification
- - Cloud Service Metadata
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteAccountPasswordPolicy
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - desc
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters
- - responseElements
- - sessionCredentialFromConsole
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- desc
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters
+- responseElements
+- sessionCredentialFromConsole
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
"111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111",
"accessKeyId": "ASIASBMSCQHHWMDJXSE6", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
diff --git a/data_sources/aws_cloudtrail_deletealarms.yml b/data_sources/aws_cloudtrail_deletealarms.yml
index 7babfa595c..8b11625dfe 100644
--- a/data_sources/aws_cloudtrail_deletealarms.yml
+++ b/data_sources/aws_cloudtrail_deletealarms.yml
@@ -6,128 +6,128 @@ author: Bhavin Patel, Splunk
description: Logs the deletion of CloudWatch alarms, including details about the alarm
names and associated monitoring configurations.
mitre_components:
- - Cloud Service Modification
- - Cloud Service Metadata
- - Application Log Content
- - Host Status
+- Cloud Service Modification
+- Cloud Service Metadata
+- Application Log Content
+- Host Status
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteAlarms
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - authentication_method
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - desc
- - dest
- - dest_ip_range
- - dest_port_range
- - direction
- - dvc
- - errorCode
- - errorMessage
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - image_id
- - index
- - instance_type
- - linecount
- - managementEvent
- - msg
- - object
- - object_attrs
- - object_category
- - object_id
- - product
- - protocol
- - protocol_code
- - punct
- - readOnly
- - reason
- - recipientAccountId
- - region
- - requestID
- - requestParameters.alarmNames{}
- - responseElements
- - result
- - result_id
- - rule_action
- - sessionCredentialFromConsole
- - signature
- - source
- - sourceIPAddress
- - splunk_server
- - splunk_server_group
- - src
- - src_ip
- - src_ip_range
- - src_port_range
- - src_user
- - src_user_id
- - src_user_name
- - src_user_role
- - src_user_type
- - start_time
- - status
- - tag
- - tag::action
- - tag::eventtype
- - tag::object_category
- - temp_access_key
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.invokedBy
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.sessionContext.sessionIssuer.accountId
- - userIdentity.sessionContext.sessionIssuer.arn
- - userIdentity.sessionContext.sessionIssuer.principalId
- - userIdentity.sessionContext.sessionIssuer.type
- - userIdentity.sessionContext.sessionIssuer.userName
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_role
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- app
+- authentication_method
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- desc
+- dest
+- dest_ip_range
+- dest_port_range
+- direction
+- dvc
+- errorCode
+- errorMessage
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- image_id
+- index
+- instance_type
+- linecount
+- managementEvent
+- msg
+- object
+- object_attrs
+- object_category
+- object_id
+- product
+- protocol
+- protocol_code
+- punct
+- readOnly
+- reason
+- recipientAccountId
+- region
+- requestID
+- requestParameters.alarmNames{}
+- responseElements
+- result
+- result_id
+- rule_action
+- sessionCredentialFromConsole
+- signature
+- source
+- sourceIPAddress
+- splunk_server
+- splunk_server_group
+- src
+- src_ip
+- src_ip_range
+- src_port_range
+- src_user
+- src_user_id
+- src_user_name
+- src_user_role
+- src_user_type
+- start_time
+- status
+- tag
+- tag::action
+- tag::eventtype
+- tag::object_category
+- temp_access_key
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.invokedBy
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.sessionContext.sessionIssuer.accountId
+- userIdentity.sessionContext.sessionIssuer.arn
+- userIdentity.sessionContext.sessionIssuer.principalId
+- userIdentity.sessionContext.sessionIssuer.type
+- userIdentity.sessionContext.sessionIssuer.userName
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_role
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLKZK7JIDWN:AutoScaling-ManageAlarms", "arn": "arn:aws:sts::111111111111:assumed-role/AWSServiceRoleForApplicationAutoScaling_DynamoDBTable/AutoScaling-ManageAlarms",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLJ7ZZZZZZZ", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_deletedetector.yml b/data_sources/aws_cloudtrail_deletedetector.yml
index f20cba230e..1046a8b7db 100644
--- a/data_sources/aws_cloudtrail_deletedetector.yml
+++ b/data_sources/aws_cloudtrail_deletedetector.yml
@@ -6,91 +6,91 @@ author: Patrick Bareiss, Splunk
description: Logs the deletion of an Amazon GuardDuty detector, including details
about the detector ID and associated configurations.
mitre_components:
- - Cloud Service Modification
- - Cloud Service Metadata
- - Host Status
- - Application Log Content
+- Cloud Service Modification
+- Cloud Service Metadata
+- Host Status
+- Application Log Content
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteDetector
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.detectorId
- - responseElements.__type
- - responseElements.message
- - result_id
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.detectorId
+- responseElements.__type
+- responseElements.message
+- result_id
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
diff --git a/data_sources/aws_cloudtrail_deletegroup.yml b/data_sources/aws_cloudtrail_deletegroup.yml
index e2bd256da6..e8e98628b6 100644
--- a/data_sources/aws_cloudtrail_deletegroup.yml
+++ b/data_sources/aws_cloudtrail_deletegroup.yml
@@ -6,96 +6,96 @@ author: Patrick Bareiss, Splunk
description: Logs the deletion of an IAM group in AWS, including details about the
group name and its associated policies or members.
mitre_components:
- - Group Modification
- - Group Metadata
- - User Account Metadata
- - Cloud Service Modification
+- Group Modification
+- Group Metadata
+- User Account Metadata
+- Cloud Service Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteGroup
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - errorMessage
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - reason
- - recipientAccountId
- - region
- - requestID
- - requestParameters.groupName
- - responseElements
- - result
- - result_id
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- errorMessage
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- reason
+- recipientAccountId
+- region
+- requestID
+- requestParameters.groupName
+- responseElements
+- result
+- result_id
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::121522247101:user/bhavin_cli", "accountId":
"121522247101", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
diff --git a/data_sources/aws_cloudtrail_deleteipset.yml b/data_sources/aws_cloudtrail_deleteipset.yml
index ce670c3006..3f00e45f4d 100644
--- a/data_sources/aws_cloudtrail_deleteipset.yml
+++ b/data_sources/aws_cloudtrail_deleteipset.yml
@@ -6,91 +6,91 @@ author: Patrick Bareiss, Splunk
description: Logs the deletion of an IP set in AWS WAF or GuardDuty, including details
about the IP set ID and its associated configurations.
mitre_components:
- - Cloud Service Modification
- - Cloud Service Metadata
- - Firewall Rule Modification
+- Cloud Service Modification
+- Cloud Service Metadata
+- Firewall Rule Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteIPSet
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.detectorId
- - requestParameters.ipSetId
- - responseElements.__type
- - responseElements.message
- - result_id
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.detectorId
+- requestParameters.ipSetId
+- responseElements.__type
+- responseElements.message
+- result_id
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"},
diff --git a/data_sources/aws_cloudtrail_deleteloggroup.yml b/data_sources/aws_cloudtrail_deleteloggroup.yml
index 3aafeff30a..8e4206a1fb 100644
--- a/data_sources/aws_cloudtrail_deleteloggroup.yml
+++ b/data_sources/aws_cloudtrail_deleteloggroup.yml
@@ -6,93 +6,93 @@ author: Patrick Bareiss, Splunk
description: Logs the deletion of a CloudWatch log group, including details about
the log group name and associated resources.
mitre_components:
- - Cloud Service Modification
- - Cloud Service Metadata
- - Application Log Content
- - Host Status
+- Cloud Service Modification
+- Cloud Service Metadata
+- Application Log Content
+- Host Status
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteLogGroup
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - apiVersion
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.logGroupName
- - responseElements
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - tlsDetails.cipherSuite
- - tlsDetails.clientProvidedHostHeader
- - tlsDetails.tlsVersion
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- apiVersion
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.logGroupName
+- responseElements
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- tlsDetails.cipherSuite
+- tlsDetails.clientProvidedHostHeader
+- tlsDetails.tlsVersion
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
diff --git a/data_sources/aws_cloudtrail_deletelogstream.yml b/data_sources/aws_cloudtrail_deletelogstream.yml
index 7f4805833e..66ce8c87ec 100644
--- a/data_sources/aws_cloudtrail_deletelogstream.yml
+++ b/data_sources/aws_cloudtrail_deletelogstream.yml
@@ -6,94 +6,94 @@ author: Patrick Bareiss, Splunk
description: Logs the deletion of a log stream within a CloudWatch log group, including
details about the stream name and associated log group.
mitre_components:
- - Cloud Service Modification
- - Cloud Service Metadata
- - Application Log Content
- - Host Status
+- Cloud Service Modification
+- Cloud Service Metadata
+- Application Log Content
+- Host Status
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteLogStream
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - apiVersion
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.logGroupName
- - requestParameters.logStreamName
- - responseElements
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - tlsDetails.cipherSuite
- - tlsDetails.clientProvidedHostHeader
- - tlsDetails.tlsVersion
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- apiVersion
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.logGroupName
+- requestParameters.logStreamName
+- responseElements
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- tlsDetails.cipherSuite
+- tlsDetails.clientProvidedHostHeader
+- tlsDetails.tlsVersion
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
diff --git a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml
index deca786012..860acf5cb3 100644
--- a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml
+++ b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml
@@ -6,100 +6,100 @@ author: Patrick Bareiss, Splunk
description: Logs the deletion of a network ACL entry in AWS, including details about
the rule number and associated network ACL.
mitre_components:
- - Firewall Rule Modification
- - Cloud Service Modification
- - Cloud Service Metadata
+- Firewall Rule Modification
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteNetworkAclEntry
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - direction
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.egress
- - requestParameters.networkAclId
- - requestParameters.ruleNumber
- - responseElements._return
- - responseElements.requestId
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.sessionContext.sessionIssuer.accountId
- - userIdentity.sessionContext.sessionIssuer.arn
- - userIdentity.sessionContext.sessionIssuer.principalId
- - userIdentity.sessionContext.sessionIssuer.type
- - userIdentity.sessionContext.sessionIssuer.userName
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- direction
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.egress
+- requestParameters.networkAclId
+- requestParameters.ruleNumber
+- responseElements._return
+- responseElements.requestId
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.sessionContext.sessionIssuer.accountId
+- userIdentity.sessionContext.sessionIssuer.arn
+- userIdentity.sessionContext.sessionIssuer.principalId
+- userIdentity.sessionContext.sessionIssuer.type
+- userIdentity.sessionContext.sessionIssuer.userName
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_deletepolicy.yml b/data_sources/aws_cloudtrail_deletepolicy.yml
index 62fa46bbd0..1eb13dccc6 100644
--- a/data_sources/aws_cloudtrail_deletepolicy.yml
+++ b/data_sources/aws_cloudtrail_deletepolicy.yml
@@ -6,94 +6,94 @@ author: Patrick Bareiss, Splunk
description: Logs the deletion of an IAM policy in AWS, including details about the
policy name and its associated roles or users.
mitre_components:
- - Cloud Service Modification
- - Cloud Service Metadata
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeletePolicy
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - errorMessage
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - reason
- - recipientAccountId
- - region
- - requestID
- - requestParameters.policyArn
- - responseElements
- - result
- - result_id
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- errorMessage
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- reason
+- recipientAccountId
+- region
+- requestID
+- requestParameters.policyArn
+- responseElements
+- result
+- result_id
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::151521547504:user/bhavin_cli", "accountId":
"151521547504", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
diff --git a/data_sources/aws_cloudtrail_deleterule.yml b/data_sources/aws_cloudtrail_deleterule.yml
index b5f3c819fa..8cc54b2ae9 100644
--- a/data_sources/aws_cloudtrail_deleterule.yml
+++ b/data_sources/aws_cloudtrail_deleterule.yml
@@ -6,94 +6,94 @@ author: Patrick Bareiss, Splunk
description: Logs the deletion of an event rule in AWS EventBridge, including details
about the rule name and its associated targets or schedules.
mitre_components:
- - Cloud Service Modification
- - Cloud Service Metadata
- - Scheduled Job Modification
- - Application Log Content
+- Cloud Service Modification
+- Cloud Service Metadata
+- Scheduled Job Modification
+- Application Log Content
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteRule
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - apiVersion
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.changeToken
- - requestParameters.ruleId
- - responseElements.changeToken
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - tlsDetails.cipherSuite
- - tlsDetails.clientProvidedHostHeader
- - tlsDetails.tlsVersion
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- apiVersion
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.changeToken
+- requestParameters.ruleId
+- responseElements.changeToken
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- tlsDetails.cipherSuite
+- tlsDetails.clientProvidedHostHeader
+- tlsDetails.tlsVersion
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
diff --git a/data_sources/aws_cloudtrail_deletesnapshot.yml b/data_sources/aws_cloudtrail_deletesnapshot.yml
index 62a075237d..6d802d417f 100644
--- a/data_sources/aws_cloudtrail_deletesnapshot.yml
+++ b/data_sources/aws_cloudtrail_deletesnapshot.yml
@@ -6,135 +6,135 @@ author: Bhavin Patel, Splunk
description: Logs the deletion of a cloud resource snapshot, such as an Amazon EBS
snapshot, including details about the snapshot ID and associated resource.
mitre_components:
- - Snapshot Deletion
- - Snapshot Metadata
- - Cloud Service Modification
- - Cloud Service Metadata
+- Snapshot Deletion
+- Snapshot Metadata
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteSnapshot
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - authentication_method
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - desc
- - dest
- - dest_ip_range
- - dest_port_range
- - direction
- - dvc
- - errorCode
- - errorMessage
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - image_id
- - index
- - instance_type
- - linecount
- - managementEvent
- - msg
- - object
- - object_attrs
- - object_category
- - object_id
- - product
- - protocol
- - protocol_code
- - punct
- - readOnly
- - reason
- - recipientAccountId
- - region
- - requestID
- - requestParameters.force
- - requestParameters.snapshotId
- - responseElements
- - responseElements._return
- - responseElements.requestId
- - result
- - result_id
- - rule_action
- - sessionCredentialFromConsole
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - splunk_server_group
- - src
- - src_ip
- - src_ip_range
- - src_port_range
- - src_user
- - src_user_id
- - src_user_name
- - src_user_role
- - src_user_type
- - start_time
- - status
- - tag
- - tag::action
- - tag::eventtype
- - tag::object_category
- - temp_access_key
- - timeendpos
- - timestartpos
- - tlsDetails.cipherSuite
- - tlsDetails.clientProvidedHostHeader
- - tlsDetails.tlsVersion
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.sessionContext.sessionIssuer.accountId
- - userIdentity.sessionContext.sessionIssuer.arn
- - userIdentity.sessionContext.sessionIssuer.principalId
- - userIdentity.sessionContext.sessionIssuer.type
- - userIdentity.sessionContext.sessionIssuer.userName
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_role
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- app
+- authentication_method
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- desc
+- dest
+- dest_ip_range
+- dest_port_range
+- direction
+- dvc
+- errorCode
+- errorMessage
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- image_id
+- index
+- instance_type
+- linecount
+- managementEvent
+- msg
+- object
+- object_attrs
+- object_category
+- object_id
+- product
+- protocol
+- protocol_code
+- punct
+- readOnly
+- reason
+- recipientAccountId
+- region
+- requestID
+- requestParameters.force
+- requestParameters.snapshotId
+- responseElements
+- responseElements._return
+- responseElements.requestId
+- result
+- result_id
+- rule_action
+- sessionCredentialFromConsole
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- splunk_server_group
+- src
+- src_ip
+- src_ip_range
+- src_port_range
+- src_user
+- src_user_id
+- src_user_name
+- src_user_role
+- src_user_type
+- start_time
+- status
+- tag
+- tag::action
+- tag::eventtype
+- tag::object_category
+- temp_access_key
+- timeendpos
+- timestartpos
+- tlsDetails.cipherSuite
+- tlsDetails.clientProvidedHostHeader
+- tlsDetails.tlsVersion
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.sessionContext.sessionIssuer.accountId
+- userIdentity.sessionContext.sessionIssuer.arn
+- userIdentity.sessionContext.sessionIssuer.principalId
+- userIdentity.sessionContext.sessionIssuer.type
+- userIdentity.sessionContext.sessionIssuer.userName
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_role
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.09", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLDF6WPXXXX:daftpunk@splunk.com", "arn": "arn:aws:sts::11111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/daftpunk@splunk.com",
"accountId": "11111111111111", "accessKeyId": "AAAAAAAAAAAAAAAAAA", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_deletetrail.yml b/data_sources/aws_cloudtrail_deletetrail.yml
index 2d077d3400..1ab9032017 100644
--- a/data_sources/aws_cloudtrail_deletetrail.yml
+++ b/data_sources/aws_cloudtrail_deletetrail.yml
@@ -6,92 +6,92 @@ author: Patrick Bareiss, Splunk
description: Logs the deletion of an AWS CloudTrail trail, including details about
the trail name and its associated logging configurations.
mitre_components:
- - Cloud Service Modification
- - Cloud Service Metadata
- - Application Log Content
- - Host Status
+- Cloud Service Modification
+- Cloud Service Metadata
+- Application Log Content
+- Host Status
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteTrail
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.name
- - responseElements
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - tlsDetails.cipherSuite
- - tlsDetails.clientProvidedHostHeader
- - tlsDetails.tlsVersion
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.name
+- responseElements
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- tlsDetails.cipherSuite
+- tlsDetails.clientProvidedHostHeader
+- tlsDetails.tlsVersion
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"},
diff --git a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml
index ba7bd9f0b0..4a7caa655b 100644
--- a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml
+++ b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml
@@ -6,92 +6,92 @@ author: Patrick Bareiss, Splunk
description: Logs an event when a virtual Multi-Factor Authentication (MFA) device
is deleted in AWS CloudTrail.
mitre_components:
- - User Account Authentication
- - User Account Deletion
+- User Account Authentication
+- User Account Deletion
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteVirtualMFADevice
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.serialNumber
- - responseElements
- - sessionCredentialFromConsole
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.serialNumber
+- responseElements
+- sessionCredentialFromConsole
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
"111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111",
"accessKeyId": "ASIASBMSCQHHWAIHMHUX", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
diff --git a/data_sources/aws_cloudtrail_deletewebacl.yml b/data_sources/aws_cloudtrail_deletewebacl.yml
index dad7353b3b..8386aa1d15 100644
--- a/data_sources/aws_cloudtrail_deletewebacl.yml
+++ b/data_sources/aws_cloudtrail_deletewebacl.yml
@@ -6,92 +6,92 @@ author: Patrick Bareiss, Splunk
description: Logs an event when a Web Access Control List (WebACL) is deleted in AWS
CloudTrail.
mitre_components:
- - Cloud Service Modification
- - Cloud Service Metadata
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteWebACL
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - apiVersion
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.changeToken
- - requestParameters.webACLId
- - responseElements.changeToken
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - tlsDetails.cipherSuite
- - tlsDetails.clientProvidedHostHeader
- - tlsDetails.tlsVersion
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- apiVersion
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.changeToken
+- requestParameters.webACLId
+- responseElements.changeToken
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- tlsDetails.cipherSuite
+- tlsDetails.clientProvidedHostHeader
+- tlsDetails.tlsVersion
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
diff --git a/data_sources/aws_cloudtrail_describeeventaggregates.yml b/data_sources/aws_cloudtrail_describeeventaggregates.yml
index 51c3b5464a..4ad39a0e97 100644
--- a/data_sources/aws_cloudtrail_describeeventaggregates.yml
+++ b/data_sources/aws_cloudtrail_describeeventaggregates.yml
@@ -6,88 +6,88 @@ author: Patrick Bareiss, Splunk
description: Logs an event when aggregate details about AWS events are queried, often
for analysis.
mitre_components:
- - Cloud Service Enumeration
- - Cloud Service Metadata
+- Cloud Service Enumeration
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DescribeEventAggregates
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.aggregateField
- - requestParameters.filter.eventStatusCodes{}
- - requestParameters.filter.startTimes{}.from
- - responseElements
- - sessionCredentialFromConsole
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.aggregateField
+- requestParameters.filter.eventStatusCodes{}
+- requestParameters.filter.startTimes{}.from
+- responseElements
+- sessionCredentialFromConsole
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
"140429656527", "arn": "arn:aws:iam::140429656527:root", "accountId": "140429656527",
"accessKeyId": "ASIASBMSCQHHQQ6LB24V", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
diff --git a/data_sources/aws_cloudtrail_describeimagescanfindings.yml b/data_sources/aws_cloudtrail_describeimagescanfindings.yml
index fab3a5b39f..e91321536e 100644
--- a/data_sources/aws_cloudtrail_describeimagescanfindings.yml
+++ b/data_sources/aws_cloudtrail_describeimagescanfindings.yml
@@ -6,980 +6,896 @@ author: Patrick Bareiss, Splunk
description: Logs an event when findings from an image vulnerability scan are described
using the DescribeImageScanFindings operation in AWS CloudTrail.
mitre_components:
- - Image Metadata
- - Image Modification
- - Malware Metadata
+- Image Metadata
+- Image Modification
+- Malware Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DescribeImageScanFindings
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.imageId.imageDigest
- - requestParameters.maxResults
- - requestParameters.repositoryName
- - responseElements.imageId.imageDigest
- - responseElements.imageScanFindings.findingSeverityCounts.HIGH
- - responseElements.imageScanFindings.findingSeverityCounts.INFORMATIONAL
- - responseElements.imageScanFindings.findingSeverityCounts.LOW
- - responseElements.imageScanFindings.findingSeverityCounts.MEDIUM
- - responseElements.imageScanFindings.findingSeverityCounts.UNDEFINED
- - responseElements.imageScanFindings.findings{}.attributes{}.key
- - responseElements.imageScanFindings.findings{}.attributes{}.value
- - responseElements.imageScanFindings.findings{}.description
- - responseElements.imageScanFindings.findings{}.name
- - responseElements.imageScanFindings.findings{}.severity
- - responseElements.imageScanFindings.findings{}.uri
- - responseElements.imageScanFindings.imageScanCompletedAt
- - responseElements.imageScanFindings.vulnerabilitySourceUpdatedAt
- - responseElements.imageScanStatus.description
- - responseElements.imageScanStatus.status
- - responseElements.registryId
- - responseElements.repositoryName
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.sessionContext.sessionIssuer.accountId
- - userIdentity.sessionContext.sessionIssuer.arn
- - userIdentity.sessionContext.sessionIssuer.principalId
- - userIdentity.sessionContext.sessionIssuer.type
- - userIdentity.sessionContext.sessionIssuer.userName
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
-example_log: "{\"eventVersion\": \"1.08\", \"userIdentity\": {\"type\": \"AssumedRole\"\
- , \"principalId\": \"AAAAAAAAAAAAAAAAAAAAA:test@test.com\", \"arn\": \"arn:aws:sts::111111111111:assumed-role/role_name/test@test.com\"\
- , \"accountId\": \"111111111111\", \"accessKeyId\": \"AKIAIOSFODNN7EXAMPLE\", \"\
- sessionContext\": {\"sessionIssuer\": {\"type\": \"Role\", \"principalId\": \"AKIAIOSFODNN7EXAMPLE\"\
- , \"arn\": \"arn:aws:iam::111111111111:role/aws-reserved/test/region/group\", \"\
- accountId\": \"111111111111\", \"userName\": \"test\"}, \"webIdFederationData\"
- : {}, \"attributes\": {\"creationDate\": \"2021-08-11T09:42:53Z\", \"mfaAuthenticated\"\
- : \"false\"}}}, \"eventTime\": \"2021-08-11T11:52:27Z\", \"eventSource\": \"ecr.amazonaws.com\"\
- , \"eventName\": \"DescribeImageScanFindings\", \"awsRegion\": \"eu-central-1\"
- , \"sourceIPAddress\": \"154.16.165.133\", \"userAgent\": \"aws-internal/3 aws-sdk-java/1.11.1030
- Linux/4.9.273-0.1.ac.226.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.302-b08
- java/1.8.0_302 vendor/Oracle_Corporation cfg/retry-mode/legacy\", \"requestParameters\"\
- : {\"repositoryName\": \"devsecops/cat_dog_client\", \"imageId\": {\"imageDigest\"\
- : \"sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6\"},
- \"maxResults\": 1000}, \"responseElements\": {\"registryId\": \"111111111111\",
- \"repositoryName\": \"devsecops/cat_dog_client\", \"imageId\": {\"imageDigest\"
- : \"sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6\"},
- \"imageScanStatus\": {\"status\": \"COMPLETE\", \"description\": \"The scan was
- completed successfully.\"}, \"imageScanFindings\": {\"imageScanCompletedAt\": \"\
- Aug 11, 2021, 11:30:16 AM\", \"vulnerabilitySourceUpdatedAt\": \"Aug 11, 2021, 1:17:52
- AM\", \"findings\": [{\"name\": \"CVE-2019-25013\", \"description\": \"The iconv
- feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing
- invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.\"\
- , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-25013\", \"severity\"\
- : \"HIGH\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.28-10\"\
- }, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\
- , \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:C\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
- : \"7.1\"}]}, {\"name\": \"CVE-2021-33574\", \"description\": \"The mq_notify function
- in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It
- may use the notification thread attributes object (passed through its struct sigevent
- parameter) after it has been freed by the caller, leading to a denial of service
- (application crash) or possibly unspecified other impact.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-33574\"\
- , \"severity\": \"HIGH\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"7.5\"}]}, {\"name\": \"CVE-2018-12886\", \"description\": \"stack_protect_prologue
- in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection
- (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences
- when targeting ARM targets that spill the address of the stack protector guard,
- which allows an attacker to bypass the protection of -fstack-protector, -fstack-protector-all,
- -fstack-protector-strong, and -fstack-protector-explicit against stack overflow
- by controlling what the stack canary is compared against.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-12886\"\
- , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"8.3.0-6\"}, {\"key\": \"package_name\", \"value\": \"gcc-8\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-1751\", \"description\": \"An out-of-bounds
- write vulnerability was found in glibc before 2.31 when handling signal trampolines
- on PowerPC. Specifically, the backtrace function did not properly check the array
- bounds when storing the frame address, resulting in a denial of service or potential
- code execution. The highest threat from this vulnerability is to system availability.\"\
- , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-1751\", \"severity\"\
- : \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.28-10\"\
- }, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\
- , \"value\": \"AV:L/AC:M/Au:N/C:P/I:P/A:C\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
- : \"5.9\"}]}, {\"name\": \"CVE-2021-3326\", \"description\": \"The iconv function
- in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid
- input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path
- and aborts the program, potentially resulting in a denial of service.\", \"uri\"\
- : \"https://security-tracker.debian.org/tracker/CVE-2021-3326\", \"severity\": \"\
- MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.28-10\"\
- }, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\
- , \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
- : \"5\"}]}, {\"name\": \"CVE-2021-35942\", \"description\": \"The wordexp function
- in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory
- in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern,
- potentially resulting in a denial of service or disclosure of information. This
- occurs because atoi was used but strtoul should have been used to ensure correct
- calculations.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-35942\"\
- , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"6.4\"}]}, {\"name\": \"CVE-2019-12904\", \"description\": \"In Libgcrypt
- 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel
- attack because physical addresses are available to other processes. (The C implementation
- is used on platforms where an assembly-language implementation is unavailable.)\"\
- , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-12904\", \"severity\"\
- : \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"1.8.4-5+deb10u1\"\
- }, {\"key\": \"package_name\", \"value\": \"libgcrypt20\"}, {\"key\": \"CVSS2_VECTOR\"\
- , \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
- : \"4.3\"}]}, {\"name\": \"CVE-2017-6363\", \"description\": \"** DISPUTED ** In
- the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer
- over-read in tiffWriter in gd_tiff.c. NOTE: the vendor says \\\"In my opinion this
- issue should not have a CVE, since the GD and GD2 formats are documented to be 'obsolete,
- and should only be used for development and testing purposes.'\\\"\", \"uri\": \"\
- https://security-tracker.debian.org/tracker/CVE-2017-6363\", \"severity\": \"MEDIUM\"\
- , \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.2.5-5.2\"}, {\"\
- key\": \"package_name\", \"value\": \"libgd2\"}, {\"key\": \"CVSS2_VECTOR\", \"\
- value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\":
- \"5.8\"}]}, {\"name\": \"CVE-2019-12290\", \"description\": \"GNU libidn2 before
- 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when
- converting A-labels to U-labels. This makes it possible in some circumstances for
- one domain to impersonate another. By creating a malicious domain that matches a
- target domain except for the inclusion of certain punycoded Unicode characters (that
- would be discarded when converted first to a Unicode label and then back to an ASCII
- label), arbitrary domains can be impersonated.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-12290\"\
- , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"2.0.5-1+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libidn2\"}, {\"\
- key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"\
- CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2019-13115\", \"description\"\
- : \"In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange
+- _time
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.imageId.imageDigest
+- requestParameters.maxResults
+- requestParameters.repositoryName
+- responseElements.imageId.imageDigest
+- responseElements.imageScanFindings.findingSeverityCounts.HIGH
+- responseElements.imageScanFindings.findingSeverityCounts.INFORMATIONAL
+- responseElements.imageScanFindings.findingSeverityCounts.LOW
+- responseElements.imageScanFindings.findingSeverityCounts.MEDIUM
+- responseElements.imageScanFindings.findingSeverityCounts.UNDEFINED
+- responseElements.imageScanFindings.findings{}.attributes{}.key
+- responseElements.imageScanFindings.findings{}.attributes{}.value
+- responseElements.imageScanFindings.findings{}.description
+- responseElements.imageScanFindings.findings{}.name
+- responseElements.imageScanFindings.findings{}.severity
+- responseElements.imageScanFindings.findings{}.uri
+- responseElements.imageScanFindings.imageScanCompletedAt
+- responseElements.imageScanFindings.vulnerabilitySourceUpdatedAt
+- responseElements.imageScanStatus.description
+- responseElements.imageScanStatus.status
+- responseElements.registryId
+- responseElements.repositoryName
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.sessionContext.sessionIssuer.accountId
+- userIdentity.sessionContext.sessionIssuer.arn
+- userIdentity.sessionContext.sessionIssuer.principalId
+- userIdentity.sessionContext.sessionIssuer.type
+- userIdentity.sessionContext.sessionIssuer.userName
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
+example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
+ "AAAAAAAAAAAAAAAAAAAAA:test@test.com", "arn": "arn:aws:sts::111111111111:assumed-role/role_name/test@test.com",
+ "accountId": "111111111111", "accessKeyId": "AKIAIOSFODNN7EXAMPLE", "sessionContext":
+ {"sessionIssuer": {"type": "Role", "principalId": "AKIAIOSFODNN7EXAMPLE", "arn":
+ "arn:aws:iam::111111111111:role/aws-reserved/test/region/group", "accountId": "111111111111",
+ "userName": "test"}, "webIdFederationData" : {}, "attributes": {"creationDate":
+ "2021-08-11T09:42:53Z", "mfaAuthenticated": "false"}}}, "eventTime": "2021-08-11T11:52:27Z",
+ "eventSource": "ecr.amazonaws.com", "eventName": "DescribeImageScanFindings", "awsRegion":
+ "eu-central-1" , "sourceIPAddress": "154.16.165.133", "userAgent": "aws-internal/3
+ aws-sdk-java/1.11.1030 Linux/4.9.273-0.1.ac.226.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.302-b08
+ java/1.8.0_302 vendor/Oracle_Corporation cfg/retry-mode/legacy", "requestParameters":
+ {"repositoryName": "devsecops/cat_dog_client", "imageId": {"imageDigest": "sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6"},
+ "maxResults": 1000}, "responseElements": {"registryId": "111111111111", "repositoryName":
+ "devsecops/cat_dog_client", "imageId": {"imageDigest" : "sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6"},
+ "imageScanStatus": {"status": "COMPLETE", "description": "The scan was completed
+ successfully."}, "imageScanFindings": {"imageScanCompletedAt": "Aug 11, 2021, 11:30:16
+ AM", "vulnerabilitySourceUpdatedAt": "Aug 11, 2021, 1:17:52 AM", "findings": [{"name":
+ "CVE-2019-25013", "description": "The iconv feature in the GNU C Library (aka glibc
+ or libc6) through 2.32, when processing invalid multi-byte input sequences in the
+ EUC-KR encoding, may have a buffer over-read.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-25013",
+ "severity": "HIGH", "attributes": [{"key": "package_version", "value": "2.28-10"},
+ {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:C"},
+ {"key": "CVSS2_SCORE", "value": "7.1"}]}, {"name": "CVE-2021-33574", "description":
+ "The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33
+ has a use-after-free. It may use the notification thread attributes object (passed
+ through its struct sigevent parameter) after it has been freed by the caller, leading
+ to a denial of service (application crash) or possibly unspecified other impact.",
+ "uri": "https://security-tracker.debian.org/tracker/CVE-2021-33574", "severity":
+ "HIGH", "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
+ "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"},
+ {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2018-12886", "description":
+ "stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c
+ in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate
+ instruction sequences when targeting ARM targets that spill the address of the stack
+ protector guard, which allows an attacker to bypass the protection of -fstack-protector,
+ -fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit
+ against stack overflow by controlling what the stack canary is compared against.",
+ "uri": "https://security-tracker.debian.org/tracker/CVE-2018-12886", "severity":
+ "MEDIUM", "attributes": [{"key": "package_version", "value": "8.3.0-6"}, {"key":
+ "package_name", "value": "gcc-8"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
+ {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2020-1751", "description":
+ "An out-of-bounds write vulnerability was found in glibc before 2.31 when handling
+ signal trampolines on PowerPC. Specifically, the backtrace function did not properly
+ check the array bounds when storing the frame address, resulting in a denial of
+ service or potential code execution. The highest threat from this vulnerability
+ is to system availability.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-1751",
+ "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.28-10"},
+ {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:P/I:P/A:C"},
+ {"key": "CVSS2_SCORE", "value": "5.9"}]}, {"name": "CVE-2021-3326", "description":
+ "The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier,
+ when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an
+ assertion in the code path and aborts the program, potentially resulting in a denial
+ of service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-3326",
+ "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.28-10"},
+ {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2021-35942", "description":
+ "The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or
+ read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted,
+ crafted pattern, potentially resulting in a denial of service or disclosure of information.
+ This occurs because atoi was used but strtoul should have been used to ensure correct
+ calculations.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-35942",
+ "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.28-10"},
+ {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "6.4"}]}, {"name": "CVE-2019-12904", "description":
+ "In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload
+ side-channel attack because physical addresses are available to other processes.
+ (The C implementation is used on platforms where an assembly-language implementation
+ is unavailable.)", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-12904",
+ "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "1.8.4-5+deb10u1"},
+ {"key": "package_name", "value": "libgcrypt20"}, {"key": "CVSS2_VECTOR", "value":
+ "AV:N/AC:M/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name":
+ "CVE-2017-6363", "description": "** DISPUTED ** In the GD Graphics Library (aka
+ LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c.
+ NOTE: the vendor says \"In my opinion this issue should not have a CVE, since the
+ GD and GD2 formats are documented to be ''obsolete, and should only be used for
+ development and testing purposes.''\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-6363",
+ "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.2.5-5.2"},
+ {"key": "package_name", "value": "libgd2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2019-12290", "description":
+ "GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490
+ Section 4.2 when converting A-labels to U-labels. This makes it possible in some
+ circumstances for one domain to impersonate another. By creating a malicious domain
+ that matches a target domain except for the inclusion of certain punycoded Unicode
+ characters (that would be discarded when converted first to a Unicode label and
+ then back to an ASCII label), arbitrary domains can be impersonated.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-12290",
+ "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.0.5-1+deb10u1"},
+ {"key": "package_name", "value": "libidn2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"},
+ {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2019-13115", "description":
+ "In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange
in kex.c has an integer overflow that could lead to an out-of-bounds read in the
way packets are read from the server. A remote attacker who compromises a SSH server
may be able to disclose sensitive information or cause a denial of service condition
on the client system when a user connects to the server. This is related to an _libssh2_check_length
- mistake, and is different from the various issues fixed in 1.8.1, such as CVE-2019-3855.\"\
- , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-13115\", \"severity\"\
- : \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"1.8.0-2.1\"\
- }, {\"key\": \"package_name\", \"value\": \"libssh2\"}, {\"key\": \"CVSS2_VECTOR\"\
- , \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
- : \"5.8\"}]}, {\"name\": \"CVE-2016-9318\", \"description\": \"libxml2 2.9.4 and
- earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer
- a flag directly indicating that the current document may be read but other files
- may not be opened, which makes it easier for remote attackers to conduct XML External
- Entity (XXE) attacks via a crafted document.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2016-9318\"\
- , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"2.9.4+dfsg1-7+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"libxml2\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:N\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-16932\", \"description\"\
- : \"parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter
- entities.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-16932\"\
- , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"2.9.4+dfsg1-7+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"libxml2\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2020-36309\", \"description\"\
- : \"ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows
- unsafe characters in an argument when using the API to mutate a URI, or a request
- or response header.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-36309\"\
- , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"1.21.1-1~buster\"}, {\"key\": \"package_name\", \"value\": \"nginx\"}, {\"key\"\
- : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"5\"}]}, {\"name\": \"CVE-2020-14155\", \"description\": \"libpcre
- in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.\"\
- , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-14155\", \"severity\"\
- : \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2:8.39-12\"\
- }, {\"key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"CVSS2_VECTOR\"\
- , \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
- : \"5\"}]}, {\"name\": \"CVE-2019-3843\", \"description\": \"It was discovered that
- a systemd service that uses DynamicUser property can create a SUID/SGID binary that
- would be allowed to run as the transient service UID/GID even after the service
- is terminated. A local attacker may use this flaw to access resources that will
- be owned by a potentially different service in the future, when the UID/GID will
- be recycled.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-3843\"\
- , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"}, {\"key\"\
- : \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"4.6\"}]}, {\"name\": \"CVE-2019-3844\", \"description\": \"It was
- discovered that a systemd service that uses DynamicUser property can get new privileges
- through the execution of SUID binaries, which would allow to create binaries owned
- by the service transient group with the setgid bit set. A local attacker may use
- this flaw to access resources that will be owned by a potentially different service
- in the future, when the GID will be recycled.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-3844\"\
- , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"}, {\"key\"\
- : \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"4.6\"}]}, {\"name\": \"CVE-2016-2781\", \"description\": \"chroot
- in GNU coreutils, when used with --userspec, allows local users to escape to the
- parent session via a crafted TIOCSTI ioctl call, which pushes characters to the
- terminal's input buffer.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2016-2781\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"8.30-3\"}, {\"key\": \"package_name\", \"value\": \"coreutils\"}, {\"key\":
- \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-22898\", \"description\": \"curl
- 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command
- line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content
- pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV
- variables, libcurl could be made to pass on uninitialized data from a stack based
- buffer to the server, resulting in potentially revealing sensitive internal information
- to the server using a clear-text network protocol.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-22898\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"7.64.0-4+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"curl\"}, {\"key\"\
- : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:H/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"2.6\"}]}, {\"name\": \"CVE-2019-15847\", \"description\": \"The POWER9
- backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple
- calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy
- of the random number generator. This occurred because a volatile operation was not
- specified. For example, within a single execution of a program, the output of every
- __builtin_darn() call may be the same.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-15847\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"8.3.0-6\"}, {\"key\": \"package_name\", \"value\": \"gcc-8\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"5\"}]}, {\"name\": \"CVE-2020-1752\", \"description\": \"A use-after-free
- vulnerability introduced in glibc upstream version 2.14 was found in the way the
- tilde expansion was carried out. Directory paths containing an initial tilde followed
- by a valid username were affected by this issue. A local attacker could exploit
- this flaw by creating a specially crafted path that, when processed by the glob
- function, would potentially lead to arbitrary code execution. This was fixed in
- version 2.32.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-1752\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:L/AC:H/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"3.7\"}]}, {\"name\": \"CVE-2020-6096\", \"description\": \"An exploitable
- signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU
- glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation)
- with a negative value for the 'num' parameter results in a signed comparison vulnerability.
- If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could
- lead to undefined behavior such as writing to out-of-bounds memory and potentially
- remote code execution. Furthermore, this memcpy() implementation allows for program
- execution to continue in scenarios where a segmentation fault or crash should have
- occurred. The dangers occur in that subsequent execution and iterations of this
- code will be executed with this corrupted data.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-6096\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-10029\", \"description\": \"The GNU
- C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during
- range reduction if an input to an 80-bit long double function contains a non-canonical
- bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets.
- This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-10029\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2020-27618\", \"description\": \"The iconv
- function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing
- invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399
- encodings, fails to advance the input state, which could lead to an infinite loop
- in applications, resulting in a denial of service, a different vulnerability from
- CVE-2016-10228.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-27618\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2016-10228\", \"description\": \"The iconv
- program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked
- with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with
- the -c option, enters an infinite loop when processing invalid multi-byte input
- sequences, leading to a denial of service.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2016-10228\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2019-19126\", \"description\": \"On the
- x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the
- LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security
- transition, allowing local attackers to restrict the possible mapping addresses
- for loaded libraries and thus bypass ASLR for a setuid program.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-19126\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-27645\", \"description\": \"The nameserver
- caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33,
- when processing a request for netgroup lookup, may crash due to a double-free, potentially
- resulting in degraded service or Denial of Service on the local system. This is
- related to netgroupcache.c.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-27645\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"1.9\"}]}, {\"name\": \"CVE-2019-14855\", \"description\": \"A flaw
- was found in the way certificate signatures could be forged using collisions found
- in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate
- signatures. This issue affects GnuPG versions before 2.2.18.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-14855\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"2.2.12-1+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"gnupg2\"}, {\"\
- key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"\
- CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2019-13627\", \"description\"\
- : \"It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic
+ mistake, and is different from the various issues fixed in 1.8.1, such as CVE-2019-3855.",
+ "uri": "https://security-tracker.debian.org/tracker/CVE-2019-13115", "severity":
+ "MEDIUM", "attributes": [{"key": "package_version", "value": "1.8.0-2.1"}, {"key":
+ "package_name", "value": "libssh2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2016-9318", "description":
+ "libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products,
+ does not offer a flag directly indicating that the current document may be read
+ but other files may not be opened, which makes it easier for remote attackers to
+ conduct XML External Entity (XXE) attacks via a crafted document.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-9318",
+ "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.9.4+dfsg1-7+deb10u2"},
+ {"key": "package_name", "value": "libxml2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:N"},
+ {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2017-16932", "description":
+ "parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter
+ entities.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-16932",
+ "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.9.4+dfsg1-7+deb10u2"},
+ {"key": "package_name", "value": "libxml2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2020-36309", "description":
+ "ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe
+ characters in an argument when using the API to mutate a URI, or a request or response
+ header.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-36309", "severity":
+ "MEDIUM", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"},
+ {"key": "package_name", "value": "nginx"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"},
+ {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2020-14155", "description":
+ "libpcre in PCRE before 8.44 allows an integer overflow via a large number after
+ a (?C substring.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-14155",
+ "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2:8.39-12"},
+ {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2019-3843", "description":
+ "It was discovered that a systemd service that uses DynamicUser property can create
+ a SUID/SGID binary that would be allowed to run as the transient service UID/GID
+ even after the service is terminated. A local attacker may use this flaw to access
+ resources that will be owned by a potentially different service in the future, when
+ the UID/GID will be recycled.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-3843",
+ "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"},
+ {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:P/I:P/A:P"},
+ {"key": "CVSS2_SCORE", "value": "4.6"}]}, {"name": "CVE-2019-3844", "description":
+ "It was discovered that a systemd service that uses DynamicUser property can get
+ new privileges through the execution of SUID binaries, which would allow to create
+ binaries owned by the service transient group with the setgid bit set. A local attacker
+ may use this flaw to access resources that will be owned by a potentially different
+ service in the future, when the GID will be recycled.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-3844",
+ "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"},
+ {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:P/I:P/A:P"},
+ {"key": "CVSS2_SCORE", "value": "4.6"}]}, {"name": "CVE-2016-2781", "description":
+ "chroot in GNU coreutils, when used with --userspec, allows local users to escape
+ to the parent session via a crafted TIOCSTI ioctl call, which pushes characters
+ to the terminal''s input buffer.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-2781",
+ "severity": "LOW", "attributes": [{"key": "package_version", "value": "8.30-3"},
+ {"key": "package_name", "value": "coreutils"}, {"key": "CVSS2_VECTOR", "value":
+ "AV:L/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name":
+ "CVE-2021-22898", "description": "curl 7.7 through 7.76.1 suffers from an information
+ disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in
+ libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw
+ in the option parser for sending NEW_ENV variables, libcurl could be made to pass
+ on uninitialized data from a stack based buffer to the server, resulting in potentially
+ revealing sensitive internal information to the server using a clear-text network
+ protocol.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22898",
+ "severity": "LOW", "attributes": [{"key": "package_version", "value": "7.64.0-4+deb10u2"},
+ {"key": "package_name", "value": "curl"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:H/Au:N/C:P/I:N/A:N"},
+ {"key": "CVSS2_SCORE", "value": "2.6"}]}, {"name": "CVE-2019-15847", "description":
+ "The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize
+ multiple calls of the __builtin_darn intrinsic into a single call, thus reducing
+ the entropy of the random number generator. This occurred because a volatile operation
+ was not specified. For example, within a single execution of a program, the output
+ of every __builtin_darn() call may be the same.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-15847",
+ "severity": "LOW", "attributes": [{"key": "package_version", "value": "8.3.0-6"},
+ {"key": "package_name", "value": "gcc-8"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"},
+ {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2020-1752", "description":
+ "A use-after-free vulnerability introduced in glibc upstream version 2.14 was found
+ in the way the tilde expansion was carried out. Directory paths containing an initial
+ tilde followed by a valid username were affected by this issue. A local attacker
+ could exploit this flaw by creating a specially crafted path that, when processed
+ by the glob function, would potentially lead to arbitrary code execution. This was
+ fixed in version 2.32.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-1752",
+ "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"},
+ {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:H/Au:N/C:P/I:P/A:P"},
+ {"key": "CVSS2_SCORE", "value": "3.7"}]}, {"name": "CVE-2020-6096", "description":
+ "An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation
+ of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU
+ glibc implementation) with a negative value for the ''num'' parameter results in
+ a signed comparison vulnerability. If an attacker underflows the ''num'' parameter
+ to memcpy(), this vulnerability could lead to undefined behavior such as writing
+ to out-of-bounds memory and potentially remote code execution. Furthermore, this
+ memcpy() implementation allows for program execution to continue in scenarios where
+ a segmentation fault or crash should have occurred. The dangers occur in that subsequent
+ execution and iterations of this code will be executed with this corrupted data.",
+ "uri": "https://security-tracker.debian.org/tracker/CVE-2020-6096", "severity":
+ "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
+ "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
+ {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2020-10029", "description":
+ "The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer
+ during range reduction if an input to an 80-bit long double function contains a
+ non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to
+ sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.",
+ "uri": "https://security-tracker.debian.org/tracker/CVE-2020-10029", "severity":
+ "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
+ "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2020-27618", "description":
+ "The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier,
+ when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388,
+ IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead
+ to an infinite loop in applications, resulting in a denial of service, a different
+ vulnerability from CVE-2016-10228.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-27618",
+ "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"},
+ {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2016-10228", "description":
+ "The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when
+ invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE)
+ along with the -c option, enters an infinite loop when processing invalid multi-byte
+ input sequences, leading to a denial of service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-10228",
+ "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"},
+ {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2019-19126", "description":
+ "On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to
+ ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution
+ after a security transition, allowing local attackers to restrict the possible mapping
+ addresses for loaded libraries and thus bypass ASLR for a setuid program.", "uri":
+ "https://security-tracker.debian.org/tracker/CVE-2019-19126", "severity": "LOW",
+ "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
+ "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:P/I:N/A:N"},
+ {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-27645", "description":
+ "The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6)
+ 2.29 through 2.33, when processing a request for netgroup lookup, may crash due
+ to a double-free, potentially resulting in degraded service or Denial of Service
+ on the local system. This is related to netgroupcache.c.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-27645",
+ "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"},
+ {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:N/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "1.9"}]}, {"name": "CVE-2019-14855", "description":
+ "A flaw was found in the way certificate signatures could be forged using collisions
+ found in the SHA-1 algorithm. An attacker could use this weakness to create forged
+ certificate signatures. This issue affects GnuPG versions before 2.2.18.", "uri":
+ "https://security-tracker.debian.org/tracker/CVE-2019-14855", "severity": "LOW",
+ "attributes": [{"key": "package_version", "value": "2.2.12-1+deb10u1"}, {"key":
+ "package_name", "value": "gnupg2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"},
+ {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2019-13627", "description":
+ "It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic
library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions
- fixed: 1.8.5-2 and 1.6.3-2+deb8u7.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-13627\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"1.8.4-5+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libgcrypt20\"},
- {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:H/Au:N/C:P/I:P/A:N\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"2.6\"}]}, {\"name\": \"CVE-2018-14553\", \"description\"\
- : \"gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference
- allowing attackers to crash an application via a specific function call sequence.
- Only affects PHP when linked with an external libgd (not bundled).\", \"uri\": \"\
- https://security-tracker.debian.org/tracker/CVE-2018-14553\", \"severity\": \"LOW\"\
- , \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.2.5-5.2\"}, {\"\
- key\": \"package_name\", \"value\": \"libgd2\"}, {\"key\": \"CVSS2_VECTOR\", \"\
- value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\":
- \"5\"}]}, {\"name\": \"CVE-2021-36086\", \"description\": \"The CIL compiler in
- SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set
- and cil_reset_classperms_list).\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36086\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"2.8-1\"}, {\"key\": \"package_name\", \"value\": \"libsepol\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-36085\", \"description\": \"The CIL
- compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called
- from __verify_map_perm_classperms and hashtab_map).\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36085\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"2.8-1\"}, {\"key\": \"package_name\", \"value\": \"libsepol\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-36087\", \"description\": \"The CIL
- compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any (called
- indirectly from cil_check_neverallow). This occurs because there is sometimes a
- lack of checks for invalid statements in an optional block.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36087\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"2.8-1\"}, {\"key\": \"package_name\", \"value\": \"libsepol\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-36084\", \"description\": \"The CIL
- compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called
- from __cil_verify_classpermission and __cil_pre_verify_helper).\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36084\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"2.8-1\"}, {\"key\": \"package_name\", \"value\": \"libsepol\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2019-17498\", \"description\": \"In libssh2
- v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer
- overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds)
- offset for a subsequent memory read. A crafted SSH server may be able to disclose
- sensitive information or cause a denial of service condition on the client system
- when a user connects to the server.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-17498\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"1.8.0-2.1\"}, {\"key\": \"package_name\", \"value\": \"libssh2\"}, {\"key\"
- : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"5.8\"}]}, {\"name\": \"CVE-2019-17543\", \"description\": \"LZ4 before
- 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize),
+ fixed: 1.8.5-2 and 1.6.3-2+deb8u7.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-13627",
+ "severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.4-5+deb10u1"},
+ {"key": "package_name", "value": "libgcrypt20"}, {"key": "CVSS2_VECTOR", "value":
+ "AV:L/AC:H/Au:N/C:P/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "2.6"}]}, {"name":
+ "CVE-2018-14553", "description": "gdImageClone in gd.c in libgd 2.1.0-rc2 through
+ 2.2.5 has a NULL pointer dereference allowing attackers to crash an application
+ via a specific function call sequence. Only affects PHP when linked with an external
+ libgd (not bundled).", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-14553",
+ "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.2.5-5.2"},
+ {"key": "package_name", "value": "libgd2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2021-36086", "description":
+ "The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission
+ (called from cil_reset_classperms_set and cil_reset_classperms_list).", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36086",
+ "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.8-1"},
+ {"key": "package_name", "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-36085", "description":
+ "The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms
+ (called from __verify_map_perm_classperms and hashtab_map).", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36085",
+ "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.8-1"},
+ {"key": "package_name", "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-36087", "description":
+ "The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any
+ (called indirectly from cil_check_neverallow). This occurs because there is sometimes
+ a lack of checks for invalid statements in an optional block.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36087",
+ "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.8-1"},
+ {"key": "package_name", "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-36084", "description":
+ "The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms
+ (called from __cil_verify_classpermission and __cil_pre_verify_helper).", "uri":
+ "https://security-tracker.debian.org/tracker/CVE-2021-36084", "severity": "LOW",
+ "attributes": [{"key": "package_version", "value": "2.8-1"}, {"key": "package_name",
+ "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2019-17498", "description":
+ "In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c
+ has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary
+ (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be
+ able to disclose sensitive information or cause a denial of service condition on
+ the client system when a user connects to the server.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-17498",
+ "severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.0-2.1"},
+ {"key": "package_name", "value": "libssh2"}, {"key" : "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2019-17543", "description":
+ "LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize),
affecting applications that call LZ4_compress_fast with a large input. (This issue
- can also lead to data corruption.) NOTE: the vendor states \\\"only a few specific
- / uncommon usages of the API are at risk.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-17543\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"1.8.3-1+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"lz4\"}, {\"key\"\
- : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2013-0337\", \"description\": \"The default
- configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions
- for the (1) access.log and (2) error.log files, which allows local users to obtain
- sensitive information by reading the files.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2013-0337\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"1.21.1-1~buster\"}, {\"key\": \"package_name\", \"value\": \"nginx\"}, {\"key\"\
- : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"7.5\"}]}, {\"name\": \"CVE-2018-7169\", \"description\": \"An issue
- was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an
- unprivileged user to be placed in a user namespace where setgroups(2) is permitted.
- This allows an attacker to remove themselves from a supplementary group, which may
- allow access to certain filesystem paths if the administrator has used \\\"group
- blacklisting\\\" (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively
- reverts a security feature in the kernel (in particular, the /proc/self/setgroups
- knob) to prevent this sort of privilege escalation.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-7169\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"1:4.5-1.1\"}, {\"key\": \"package_name\", \"value\": \"shadow\"}, {\"key\":
- \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"5\"}]}, {\"name\": \"CVE-2021-37600\", \"description\": \"An integer
- overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if
- an attacker were able to use system resources in a way that leads to a large number
- in the /proc/sysvipc/sem file.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-37600\"\
- , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\
- : \"2.33.1-0.1\"}, {\"key\": \"package_name\", \"value\": \"util-linux\"}, {\"key\"\
- : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"7.5\"}]}, {\"name\": \"CVE-2011-3374\", \"description\": \"It was
- found that apt-key in apt, all versions, do not correctly validate gpg keys with
- the master keyring, leading to a potential man-in-the-middle attack.\", \"uri\"
- : \"https://security-tracker.debian.org/tracker/CVE-2011-3374\", \"severity\": \"\
- INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"1.8.2.3\"\
- }, {\"key\": \"package_name\", \"value\": \"apt\"}, {\"key\": \"CVSS2_VECTOR\",
- \"value\": \"AV:N/AC:M/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
- : \"4.3\"}]}, {\"name\": \"CVE-2019-18276\", \"description\": \"An issue was discovered
- in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if
- Bash is run with its effective UID not equal to its real UID, it will drop privileges
- by setting its effective UID to its real UID. However, it does so incorrectly. On
- Linux and other systems that support \\\"saved UID\\\" functionality, the saved
- UID is not dropped. An attacker with command execution in the shell can use \\\"\
- enable -f\\\" for runtime loading of a new builtin, which can be a shared object
- that calls setuid() and therefore regains privileges. However, binaries running
- with an effective UID of 0 are unaffected.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-18276\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"5.0-4\"}, {\"key\": \"package_name\", \"value\": \"bash\"}, {\"key\"\
- : \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:C/I:C/A:C\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"7.2\"}]}, {\"name\": \"CVE-2017-18018\", \"description\": \"In GNU
- Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement
- of a plain file with a symlink during use of the POSIX \\\"-R -L\\\" options, which
- allows local users to modify the ownership of arbitrary files by leveraging a race
- condition.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-18018\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"8.30-3\"}, {\"key\": \"package_name\", \"value\": \"coreutils\"},
- {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:N/I:P/A:N\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"1.9\"}]}, {\"name\": \"CVE-2021-22923\", \"description\"\
- : \"When curl is instructed to get content using the metalink feature, and a user
- name and password are used to download the metalink XML file, those same credentials
- are then subsequently passed on to each of the servers from which curl will download
- or try to download the contents from. Often contrary to the user's expectations
- and intentions and without telling the user it happened.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-22923\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"7.64.0-4+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"curl\"\
- }]}, {\"name\": \"CVE-2021-22922\", \"description\": \"When curl is instructed to
- download content using the metalink feature, thecontents is verified against a hash
- provided in the metalink XML file.The metalink XML file points out to the client
- how to get the same contentfrom a set of different URLs, potentially hosted by different
- servers and theclient can then download the file from one or several of them. In
- a serial orparallel manner.If one of the servers hosting the contents has been breached
- and the contentsof the specific file on that server is replaced with a modified
- payload, curlshould detect this when the hash of the file mismatches after a completeddownload.
- It should remove the contents and instead try getting the contentsfrom another URL.
- This is not done, and instead such a hash mismatch is onlymentioned in text and
- the potentially malicious content is kept in the file ondisk.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-22922\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"7.64.0-4+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"curl\"\
- }]}, {\"name\": \"CVE-2013-0340\", \"description\": \"expat 2.1.0 and earlier does
- not properly handle entities expansion unless an application developer uses the
- XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial
- of service (resource consumption), send HTTP requests to intranet servers, or read
- arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue.\
- \ NOTE: it could be argued that because expat already provides the ability to disable
- external entity expansion, the responsibility for resolving this issue lies with
- application developers; according to this argument, this entry should be REJECTed,
- and each affected application would need its own CVE.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2013-0340\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"2.2.6-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"expat\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2019-1010023\", \"description\"\
- : \"** DISPUTED ** GNU Libc current is affected by: Re-mapping current loaded library
+ can also lead to data corruption.) NOTE: the vendor states \"only a few specific
+ / uncommon usages of the API are at risk.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-17543",
+ "severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.3-1+deb10u1"},
+ {"key": "package_name", "value": "lz4"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
+ {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2013-0337", "description":
+ "The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable
+ permissions for the (1) access.log and (2) error.log files, which allows local users
+ to obtain sensitive information by reading the files.", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-0337",
+ "severity": "LOW", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"},
+ {"key": "package_name", "value": "nginx"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"},
+ {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2018-7169", "description":
+ "An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and
+ allows an unprivileged user to be placed in a user namespace where setgroups(2)
+ is permitted. This allows an attacker to remove themselves from a supplementary
+ group, which may allow access to certain filesystem paths if the administrator has
+ used \"group blacklisting\" (e.g., chmod g-rwx) to restrict access to paths. This
+ flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups
+ knob) to prevent this sort of privilege escalation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-7169",
+ "severity": "LOW", "attributes": [{"key": "package_version", "value": "1:4.5-1.1"},
+ {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"},
+ {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2021-37600", "description":
+ "An integer overflow in util-linux through 2.37.1 can potentially cause a buffer
+ overflow if an attacker were able to use system resources in a way that leads to
+ a large number in the /proc/sysvipc/sem file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-37600",
+ "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.33.1-0.1"},
+ {"key": "package_name", "value": "util-linux"}, {"key": "CVSS2_VECTOR", "value":
+ "AV:N/AC:L/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name":
+ "CVE-2011-3374", "description": "It was found that apt-key in apt, all versions,
+ do not correctly validate gpg keys with the master keyring, leading to a potential
+ man-in-the-middle attack.", "uri" : "https://security-tracker.debian.org/tracker/CVE-2011-3374",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "1.8.2.3"}, {"key": "package_name", "value": "apt"}, {"key": "CVSS2_VECTOR", "value":
+ "AV:N/AC:M/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name":
+ "CVE-2019-18276", "description": "An issue was discovered in disable_priv_mode in
+ shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective
+ UID not equal to its real UID, it will drop privileges by setting its effective
+ UID to its real UID. However, it does so incorrectly. On Linux and other systems
+ that support \"saved UID\" functionality, the saved UID is not dropped. An attacker
+ with command execution in the shell can use \"enable -f\" for runtime loading of
+ a new builtin, which can be a shared object that calls setuid() and therefore regains
+ privileges. However, binaries running with an effective UID of 0 are unaffected.",
+ "uri": "https://security-tracker.debian.org/tracker/CVE-2019-18276", "severity":
+ "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "5.0-4"}, {"key":
+ "package_name", "value": "bash"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:C/I:C/A:C"},
+ {"key": "CVSS2_SCORE", "value": "7.2"}]}, {"name": "CVE-2017-18018", "description":
+ "In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent
+ replacement of a plain file with a symlink during use of the POSIX \"-R -L\" options,
+ which allows local users to modify the ownership of arbitrary files by leveraging
+ a race condition.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-18018",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "8.30-3"}, {"key": "package_name", "value": "coreutils"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:L/AC:M/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "1.9"}]},
+ {"name": "CVE-2021-22923", "description": "When curl is instructed to get content
+ using the metalink feature, and a user name and password are used to download the
+ metalink XML file, those same credentials are then subsequently passed on to each
+ of the servers from which curl will download or try to download the contents from.
+ Often contrary to the user''s expectations and intentions and without telling the
+ user it happened.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22923",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "7.64.0-4+deb10u2"}, {"key": "package_name", "value": "curl"}]}, {"name": "CVE-2021-22922",
+ "description": "When curl is instructed to download content using the metalink feature,
+ thecontents is verified against a hash provided in the metalink XML file.The metalink
+ XML file points out to the client how to get the same contentfrom a set of different
+ URLs, potentially hosted by different servers and theclient can then download the
+ file from one or several of them. In a serial orparallel manner.If one of the servers
+ hosting the contents has been breached and the contentsof the specific file on that
+ server is replaced with a modified payload, curlshould detect this when the hash
+ of the file mismatches after a completeddownload. It should remove the contents
+ and instead try getting the contentsfrom another URL. This is not done, and instead
+ such a hash mismatch is onlymentioned in text and the potentially malicious content
+ is kept in the file ondisk.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22922",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "7.64.0-4+deb10u2"}, {"key": "package_name", "value": "curl"}]}, {"name": "CVE-2013-0340",
+ "description": "expat 2.1.0 and earlier does not properly handle entities expansion
+ unless an application developer uses the XML_SetEntityDeclHandler function, which
+ allows remote attackers to cause a denial of service (resource consumption), send
+ HTTP requests to intranet servers, or read arbitrary files via a crafted XML document,
+ aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat
+ already provides the ability to disable external entity expansion, the responsibility
+ for resolving this issue lies with application developers; according to this argument,
+ this entry should be REJECTed, and each affected application would need its own
+ CVE.", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-0340", "severity":
+ "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "2.2.6-2+deb10u1"},
+ {"key": "package_name", "value": "expat"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
+ {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2019-1010023", "description":
+ "** DISPUTED ** GNU Libc current is affected by: Re-mapping current loaded library
with malicious ELF file. The impact is: In worst case attacker may evaluate privileges.
The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim
- and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \\\
- \"this is being treated as a non-security bug and no real threat.\\\"\", \"uri\"\
- : \"https://security-tracker.debian.org/tracker/CVE-2019-1010023\", \"severity\"\
- : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
- \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\
- , \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
- : \"6.8\"}]}, {\"name\": \"CVE-2010-4051\", \"description\": \"The regcomp implementation
- in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2,
- allows context-dependent attackers to cause a denial of service (application crash)
- via a regular expression containing adjacent bounded repetitions that bypass the
- intended RE_DUP_MAX limitation, as demonstrated by a {10,}{10,}{10,}{10,}{10,} sequence
- in the proftpd.gnu.c exploit for ProFTPD, related to a \\\"RE_DUP_MAX overflow.\\\
- \"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2010-4051\", \"\
- severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"\
- value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\"\
- : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"5\"}]}, {\"name\": \"CVE-2019-1010022\", \"description\": \"** DISPUTED
- ** GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may
- bypass stack guard protection. The component is: nptl. The attack vector is: Exploit
- stack buffer overflow vulnerability and use this bypass vulnerability to bypass
- stack guard. NOTE: Upstream comments indicate \\\"this is being treated as a non-security
- bug and no real threat.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-1010022\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\
- key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"\
- CVSS2_SCORE\", \"value\": \"7.5\"}]}, {\"name\": \"CVE-2010-4052\", \"description\"\
- : \"Stack consumption vulnerability in the regcomp implementation in the GNU C Library
+ and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this
+ is being treated as a non-security bug and no real threat.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-1010023",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
+ "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name":
+ "CVE-2010-4051", "description": "The regcomp implementation in the GNU C Library
+ (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent
+ attackers to cause a denial of service (application crash) via a regular expression
+ containing adjacent bounded repetitions that bypass the intended RE_DUP_MAX limitation,
+ as demonstrated by a {10,}{10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit
+ for ProFTPD, related to a \"RE_DUP_MAX overflow.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-4051",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
+ "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
+ "CVE-2019-1010022", "description": "** DISPUTED ** GNU Libc current is affected
+ by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection.
+ The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability
+ and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments
+ indicate \"this is being treated as a non-security bug and no real threat.\"", "uri":
+ "https://security-tracker.debian.org/tracker/CVE-2019-1010022", "severity": "INFORMATIONAL",
+ "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
+ "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"},
+ {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2010-4052", "description":
+ "Stack consumption vulnerability in the regcomp implementation in the GNU C Library
(aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent
attackers to cause a denial of service (resource exhaustion) via a regular expression
containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,}
- sequence in the proftpd.gnu.c exploit for ProFTPD.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2010-4052\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\
- key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"\
- CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2019-1010024\", \"description\"\
- : \"** DISPUTED ** GNU Libc current is affected by: Mitigation bypass. The impact
- is: Attacker may bypass ASLR using cache of thread stack and heap. The component
- is: glibc. NOTE: Upstream comments indicate \\\"this is being treated as a non-security
- bug and no real threat.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-1010024\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\
- key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"\
- CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2010-4756\", \"description\"\
- : \"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote
- authenticated users to cause a denial of service (CPU and memory consumption) via
- crafted glob expressions that do not match any pathnames, as demonstrated by glob
- expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.\"\
- , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2010-4756\", \"severity\"\
- : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
- \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\
- , \"value\": \"AV:N/AC:L/Au:S/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
- : \"4\"}]}, {\"name\": \"CVE-2019-1010025\", \"description\": \"** DISPUTED ** GNU
- Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess
- the heap addresses of pthread_created thread. The component is: glibc. NOTE: the
- vendor's position is \\\"ASLR bypass itself is not a vulnerability.\\\"\", \"uri\"\
- : \"https://security-tracker.debian.org/tracker/CVE-2019-1010025\", \"severity\"\
- : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
- \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\
- , \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
- : \"5\"}]}, {\"name\": \"CVE-2018-20796\", \"description\": \"In the GNU C Library
- (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c
- has Uncontrolled Recursion, as demonstrated by '(\\\\227|)(\\\\\\\\1\\\\\\\\1|t1|\\\
- \\\\\\\\\\2537)+' in grep.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-20796\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\
- key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"\
- CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2019-9192\", \"description\"\
- : \"** DISPUTED ** In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1
- in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\\\\\\
- 1\\\\\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software
- maintainer disputes that this is a vulnerability because the behavior occurs only
- with a crafted pattern.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-9192\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\
- key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"\
- CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2011-3389\", \"description\"\
- : \"The SSL protocol, as used in certain configurations in Microsoft Windows and
- Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products,
- encrypts data by using CBC mode with chained initialization vectors, which allows
- man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary
- attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses
- (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight
- WebClient API, aka a \\\"BEAST\\\" attack.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2011-3389\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"3.6.7-4+deb10u7\"}, {\"key\": \"package_name\", \"value\": \"gnutls28\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:N\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2021-30535\", \"description\"\
- : \"Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker
- to potentially exploit heap corruption via a crafted HTML page.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-30535\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"63.1-6+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"icu\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2017-9937\", \"description\"\
- : \"In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted
- TIFF document can lead to an abort resulting in a remote denial of service attack.\"\
- , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-9937\", \"severity\"\
- : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
- \"2.1-3.1\"}, {\"key\": \"package_name\", \"value\": \"jbigkit\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2018-5709\", \"description\": \"An issue
- was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \\\
- \"dbentry->n_key_data\\\" in kadmin/dbutil/dump.c that can store 16-bit data but
- unknowingly the developer has assigned a \\\"u4\\\" variable to it, which is for
- 32-bit data. An attacker can use this vulnerability to affect other artifacts of
- the database as we know that a Kerberos database dump file contains trusted data.\"\
- , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-5709\", \"severity\"\
- : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
- \"1.17-3+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"krb5\"}, {\"key\"
- : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"5\"}]}, {\"name\": \"CVE-2021-36222\", \"description\": \"ec_verify
- in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka
- krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a
- NULL pointer dereference and daemon crash. This occurs because a return value is
- not properly managed in a certain situation.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36222\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"1.17-3+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"krb5\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2004-0971\", \"description\"\
- : \"The krb5-send-pr script in the kerberos5 (krb5) package in Trustix Secure Linux
- 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite
- files via a symlink attack on temporary files.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2004-0971\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"1.17-3+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"krb5\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"2.1\"}]}, {\"name\": \"CVE-2018-6829\", \"description\"\
- : \"cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly,
+ sequence in the proftpd.gnu.c exploit for ProFTPD.", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-4052",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
+ "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
+ "CVE-2019-1010024", "description": "** DISPUTED ** GNU Libc current is affected
+ by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread
+ stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this
+ is being treated as a non-security bug and no real threat.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-1010024",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
+ "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
+ "CVE-2010-4756", "description": "The glob implementation in the GNU C Library (aka
+ glibc or libc6) allows remote authenticated users to cause a denial of service (CPU
+ and memory consumption) via crafted glob expressions that do not match any pathnames,
+ as demonstrated by glob expressions in STAT commands to an FTP daemon, a different
+ vulnerability than CVE-2010-2632.", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-4756",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
+ "AV:N/AC:L/Au:S/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4"}]}, {"name":
+ "CVE-2019-1010025", "description": "** DISPUTED ** GNU Libc current is affected
+ by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created
+ thread. The component is: glibc. NOTE: the vendor''s position is \"ASLR bypass itself
+ is not a vulnerability.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-1010025",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
+ "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
+ "CVE-2018-20796", "description": "In the GNU C Library (aka glibc or libc6) through
+ 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion,
+ as demonstrated by ''(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+'' in grep.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-20796",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
+ "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
+ "CVE-2019-9192", "description": "** DISPUTED ** In the GNU C Library (aka glibc
+ or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled
+ Recursion, as demonstrated by ''(|)(\\\\1\\\\1)*'' in grep, a different issue than
+ CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability
+ because the behavior occurs only with a crafted pattern.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-9192",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
+ "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
+ "CVE-2011-3389", "description": "The SSL protocol, as used in certain configurations
+ in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome,
+ Opera, and other products, encrypts data by using CBC mode with chained initialization
+ vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers
+ via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction
+ with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection
+ API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2011-3389",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "3.6.7-4+deb10u7"}, {"key": "package_name", "value": "gnutls28"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:N/AC:M/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
+ {"name": "CVE-2021-30535", "description": "Double free in ICU in Google Chrome prior
+ to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption
+ via a crafted HTML page.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-30535",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "63.1-6+deb10u1"}, {"key": "package_name", "value": "icu"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]},
+ {"name": "CVE-2017-9937", "description": "In LibTIFF 4.0.8, there is a memory malloc
+ failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in
+ a remote denial of service attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-9937",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "2.1-3.1"}, {"key": "package_name", "value": "jbigkit"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
+ {"name": "CVE-2018-5709", "description": "An issue was discovered in MIT Kerberos
+ 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c
+ that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable
+ to it, which is for 32-bit data. An attacker can use this vulnerability to affect
+ other artifacts of the database as we know that a Kerberos database dump file contains
+ trusted data.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-5709",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "1.17-3+deb10u1"}, {"key": "package_name", "value": "krb5"}, {"key" : "CVSS2_VECTOR",
+ "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
+ {"name": "CVE-2021-36222", "description": "ec_verify in kdc/kdc_preauth_ec.c in
+ the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and
+ 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference
+ and daemon crash. This occurs because a return value is not properly managed in
+ a certain situation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36222",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "1.17-3+deb10u1"}, {"key": "package_name", "value": "krb5"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]},
+ {"name": "CVE-2004-0971", "description": "The krb5-send-pr script in the kerberos5
+ (krb5) package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating
+ systems, allows local users to overwrite files via a symlink attack on temporary
+ files.", "uri": "https://security-tracker.debian.org/tracker/CVE-2004-0971", "severity":
+ "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "1.17-3+deb10u1"},
+ {"key": "package_name", "value": "krb5"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:P/A:N"},
+ {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2018-6829", "description":
+ "cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly,
improperly encodes plaintexts, which allows attackers to obtain sensitive information
by reading ciphertext data (i.e., it does not have semantic security in face of
a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not
- hold for Libgcrypt's ElGamal implementation.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-6829\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"1.8.4-5+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libgcrypt20\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2018-11813\", \"description\"\
- : \"libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.\"\
- , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-11813\", \"severity\"\
- : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
- \"1:1.5.2-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libjpeg-turbo\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2020-17541\", \"description\"\
- : \"Libjpeg-turbo all version have a stack-based buffer overflow in the \\\"transform\\\
- \" component. A remote attacker can send a malformed jpeg file to the service and
- cause arbitrary code execution or denial of service of the target service.\", \"\
- uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-17541\", \"severity\"\
- : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
- \"1:1.5.2-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libjpeg-turbo\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2017-15232\", \"description\"\
- : \"libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c
- via a crafted JPEG file.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-15232\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"1:1.5.2-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libjpeg-turbo\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2018-14048\", \"description\"\
- : \"An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data
- in png.c, related to the recommended error handling for png_read_image.\", \"uri\"\
- : \"https://security-tracker.debian.org/tracker/CVE-2018-14048\", \"severity\":
- \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"\
- 1.6.36-6\"}, {\"key\": \"package_name\", \"value\": \"libpng1.6\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2019-6129\", \"description\": \"** DISPUTED
- ** png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated
- by pngcp. NOTE: a third party has stated \\\"I don't think it is libpng's job to
- free this buffer.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-6129\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"1.6.36-6\"}, {\"key\": \"package_name\", \"value\": \"libpng1.6\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2018-14550\", \"description\"\
- : \"An issue has been found in third-party PNM decoding associated with libpng 1.6.35.
- It is a stack-based buffer overflow in the function get_token in pnm2png.c in pnm2png.\"\
- , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-14550\", \"severity\"\
- : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
- \"1.6.36-6\"}, {\"key\": \"package_name\", \"value\": \"libpng1.6\"}, {\"key\":
- \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2019-9893\", \"description\": \"libseccomp
- before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using
- the arithmetic operators (LT, GT, LE, GE), which might able to lead to bypassing
- seccomp filters and potential privilege escalations.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-9893\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"2.3.3-4\"}, {\"key\": \"package_name\", \"value\": \"libseccomp\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"7.5\"}]}, {\"name\": \"CVE-2018-1000654\", \"description\"\
- : \"GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains
- a DoS, specifically CPU usage will reach 100% when running asn1Paser against the
- POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program
- will be killed. This attack appears to be exploitable via parsing a crafted file.\"\
- , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-1000654\", \"\
- severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"\
- value\": \"4.13-3\"}, {\"key\": \"package_name\", \"value\": \"libtasn1-6\"}, {\"\
- key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:C\"}, {\"key\": \"\
- CVSS2_SCORE\", \"value\": \"7.1\"}]}, {\"name\": \"CVE-2016-9085\", \"description\"\
- : \"Multiple integer overflows in libwebp allows attackers to have unspecified impact
- via unknown vectors.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2016-9085\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"0.6.1-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libwebp\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"2.1\"}]}, {\"name\": \"CVE-2015-9019\", \"description\"\
- : \"In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized
- with a random seed during startup, which could cause usage of this function to produce
- predictable outputs.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2015-9019\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"1.1.32-2.2~deb10u1\"}, {\"key\": \"package_name\", \"value\": \"\
- libxslt\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"\
- }, {\"key\": \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2009-4487\"
- , \"description\": \"nginx 0.7.64 writes data to a log file without sanitizing non-printable
- characters, which might allow remote attackers to modify a window's title, or possibly
- execute arbitrary commands or overwrite files, via an HTTP request containing an
- escape sequence for a terminal emulator.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2009-4487\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"1.21.1-1~buster\"}, {\"key\": \"package_name\", \"value\": \"nginx\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-15719\", \"description\"\
- : \"libldap in certain third-party OpenLDAP packages has a certificate-validation
- flaw when the third-party package is asserting RFC6125 support. It considers CN
- even when there is a non-matching subjectAltName (SAN). This is fixed in, for example,
- openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-15719\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"2.4.47+dfsg-3+deb10u6\"}, {\"key\": \"package_name\", \"value\":
- \"openldap\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:H/Au:N/C:P/I:P/A:N\"\
- }, {\"key\": \"CVSS2_SCORE\", \"value\": \"4\"}]}, {\"name\": \"CVE-2015-3276\"
- , \"description\": \"The nss_parse_ciphers function in libraries/libldap/tls_m.c
- in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings,
- which might cause a weaker than intended cipher to be used and allow remote attackers
- to have unspecified impact via unknown vectors.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2015-3276\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"2.4.47+dfsg-3+deb10u6\"}, {\"key\": \"package_name\", \"value\":
- \"openldap\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"\
- }, {\"key\": \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2017-14159\"\
- , \"description\": \"slapd in OpenLDAP 2.4.45 and earlier creates a PID file after
- dropping privileges to a non-root account, which might allow local users to kill
- arbitrary processes by leveraging access to this non-root account for PID file modification
- before a root script executes a \\\"kill `cat /pathname`\\\" command, as demonstrated
- by openldap-initscript.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-14159\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"2.4.47+dfsg-3+deb10u6\"}, {\"key\": \"package_name\", \"value\":
- \"openldap\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:N/I:N/A:P\"\
- }, {\"key\": \"CVSS2_SCORE\", \"value\": \"1.9\"}]}, {\"name\": \"CVE-2017-17740\"\
- , \"description\": \"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45,
- when both the nops module and the memberof overlay are enabled, attempts to free
- a buffer that was allocated on the stack, which allows remote attackers to cause
- a denial of service (slapd crash) via a member MODDN operation.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-17740\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"2.4.47+dfsg-3+deb10u6\"}, {\"key\": \"package_name\", \"value\":
- \"openldap\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"\
- }, {\"key\": \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2010-0928\"
- , \"description\": \"OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx
- Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain
- signature calculations, and does not verify the signature before providing it to
- a caller, which makes it easier for physically proximate attackers to determine
- the private key via a modified supply voltage for the microprocessor, related to
- a \\\"fault-based attack.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2010-0928\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"1.1.1d-0+deb10u6\"}, {\"key\": \"package_name\", \"value\": \"openssl\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:H/Au:N/C:C/I:N/A:N\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"4\"}]}, {\"name\": \"CVE-2007-6755\", \"description\"\
- : \"The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic
- Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a
- possible relationship to certain \\\"skeleton key\\\" values, which might allow
- context-dependent attackers to defeat cryptographic protection mechanisms by leveraging
- knowledge of those values. NOTE: this is a preliminary CVE for Dual_EC_DRBG; future
- research may provide additional details about point Q and associated attacks, and
- could potentially lead to a RECAST or REJECT of this CVE.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2007-6755\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"1.1.1d-0+deb10u6\"}, {\"key\": \"package_name\", \"value\": \"openssl\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:N\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"5.8\"}]}, {\"name\": \"CVE-2017-7246\", \"description\"\
- : \"Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c
+ hold for Libgcrypt''s ElGamal implementation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-6829",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "1.8.4-5+deb10u1"}, {"key": "package_name", "value": "libgcrypt20"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
+ {"name": "CVE-2018-11813", "description": "libjpeg 9c has a large loop because read_pixel
+ in rdtarga.c mishandles EOF.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-11813",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "1:1.5.2-2+deb10u1"}, {"key": "package_name", "value": "libjpeg-turbo"}, {"key":
+ "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
+ "5"}]}, {"name": "CVE-2020-17541", "description": "Libjpeg-turbo all version have
+ a stack-based buffer overflow in the \"transform\" component. A remote attacker
+ can send a malformed jpeg file to the service and cause arbitrary code execution
+ or denial of service of the target service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-17541",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "1:1.5.2-2+deb10u1"}, {"key": "package_name", "value": "libjpeg-turbo"}, {"key":
+ "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value":
+ "6.8"}]}, {"name": "CVE-2017-15232", "description": "libjpeg-turbo 1.5.2 has a NULL
+ Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.", "uri":
+ "https://security-tracker.debian.org/tracker/CVE-2017-15232", "severity": "INFORMATIONAL",
+ "attributes": [{"key": "package_version", "value": "1:1.5.2-2+deb10u1"}, {"key":
+ "package_name", "value": "libjpeg-turbo"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2018-14048", "description":
+ "An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data
+ in png.c, related to the recommended error handling for png_read_image.", "uri":
+ "https://security-tracker.debian.org/tracker/CVE-2018-14048", "severity": "INFORMATIONAL",
+ "attributes": [{"key": "package_version", "value": "1.6.36-6"}, {"key": "package_name",
+ "value": "libpng1.6"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2019-6129", "description":
+ "** DISPUTED ** png_create_info_struct in png.c in libpng 1.6.36 has a memory leak,
+ as demonstrated by pngcp. NOTE: a third party has stated \"I don''t think it is
+ libpng''s job to free this buffer.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-6129",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "1.6.36-6"}, {"key": "package_name", "value": "libpng1.6"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
+ {"name": "CVE-2018-14550", "description": "An issue has been found in third-party
+ PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow
+ in the function get_token in pnm2png.c in pnm2png.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-14550",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "1.6.36-6"}, {"key": "package_name", "value": "libpng1.6"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]},
+ {"name": "CVE-2019-9893", "description": "libseccomp before 2.4.0 did not correctly
+ generate 64-bit syscall argument comparisons using the arithmetic operators (LT,
+ GT, LE, GE), which might able to lead to bypassing seccomp filters and potential
+ privilege escalations.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-9893",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "2.3.3-4"}, {"key": "package_name", "value": "libseccomp"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "7.5"}]},
+ {"name": "CVE-2018-1000654", "description": "GNU Libtasn1-4.13 libtasn1-4.13 version
+ libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100%
+ when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree),
+ after a long time, the program will be killed. This attack appears to be exploitable
+ via parsing a crafted file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-1000654",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "4.13-3"}, {"key": "package_name", "value": "libtasn1-6"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:N/AC:M/Au:N/C:N/I:N/A:C"}, {"key": "CVSS2_SCORE", "value": "7.1"}]},
+ {"name": "CVE-2016-9085", "description": "Multiple integer overflows in libwebp
+ allows attackers to have unspecified impact via unknown vectors.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-9085",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "0.6.1-2+deb10u1"}, {"key": "package_name", "value": "libwebp"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "2.1"}]},
+ {"name": "CVE-2015-9019", "description": "In libxslt 1.1.29 and earlier, the EXSLT
+ math.random function was not initialized with a random seed during startup, which
+ could cause usage of this function to produce predictable outputs.", "uri": "https://security-tracker.debian.org/tracker/CVE-2015-9019",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "1.1.32-2.2~deb10u1"}, {"key": "package_name", "value": "libxslt"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
+ {"name": "CVE-2009-4487" , "description": "nginx 0.7.64 writes data to a log file
+ without sanitizing non-printable characters, which might allow remote attackers
+ to modify a window''s title, or possibly execute arbitrary commands or overwrite
+ files, via an HTTP request containing an escape sequence for a terminal emulator.",
+ "uri": "https://security-tracker.debian.org/tracker/CVE-2009-4487", "severity":
+ "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"},
+ {"key": "package_name", "value": "nginx"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
+ {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2020-15719", "description":
+ "libldap in certain third-party OpenLDAP packages has a certificate-validation flaw
+ when the third-party package is asserting RFC6125 support. It considers CN even
+ when there is a non-matching subjectAltName (SAN). This is fixed in, for example,
+ openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-15719",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "2.4.47+dfsg-3+deb10u6"}, {"key": "package_name", "value": "openldap"}, {"key":
+ "CVSS2_VECTOR", "value": "AV:N/AC:H/Au:N/C:P/I:P/A:N"}, {"key": "CVSS2_SCORE", "value":
+ "4"}]}, {"name": "CVE-2015-3276" , "description": "The nss_parse_ciphers function
+ in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword
+ mode cipher strings, which might cause a weaker than intended cipher to be used
+ and allow remote attackers to have unspecified impact via unknown vectors.", "uri":
+ "https://security-tracker.debian.org/tracker/CVE-2015-3276", "severity": "INFORMATIONAL",
+ "attributes": [{"key": "package_version", "value": "2.4.47+dfsg-3+deb10u6"}, {"key":
+ "package_name", "value": "openldap"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"},
+ {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2017-14159", "description":
+ "slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges
+ to a non-root account, which might allow local users to kill arbitrary processes
+ by leveraging access to this non-root account for PID file modification before a
+ root script executes a \"kill `cat /pathname`\" command, as demonstrated by openldap-initscript.",
+ "uri": "https://security-tracker.debian.org/tracker/CVE-2017-14159", "severity":
+ "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "2.4.47+dfsg-3+deb10u6"},
+ {"key": "package_name", "value": "openldap"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:N/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "1.9"}]}, {"name": "CVE-2017-17740", "description":
+ "contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops
+ module and the memberof overlay are enabled, attempts to free a buffer that was
+ allocated on the stack, which allows remote attackers to cause a denial of service
+ (slapd crash) via a member MODDN operation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-17740",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "2.4.47+dfsg-3+deb10u6"}, {"key": "package_name", "value": "openldap"}, {"key":
+ "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
+ "5"}]}, {"name": "CVE-2010-0928" , "description": "OpenSSL 0.9.8i on the Gaisler
+ Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation
+ (FWE) algorithm for certain signature calculations, and does not verify the signature
+ before providing it to a caller, which makes it easier for physically proximate
+ attackers to determine the private key via a modified supply voltage for the microprocessor,
+ related to a \"fault-based attack.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-0928",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "1.1.1d-0+deb10u6"}, {"key": "package_name", "value": "openssl"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:L/AC:H/Au:N/C:C/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4"}]},
+ {"name": "CVE-2007-6755", "description": "The NIST SP 800-90A default statement
+ of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm
+ contains point Q constants with a possible relationship to certain \"skeleton key\"
+ values, which might allow context-dependent attackers to defeat cryptographic protection
+ mechanisms by leveraging knowledge of those values. NOTE: this is a preliminary
+ CVE for Dual_EC_DRBG; future research may provide additional details about point
+ Q and associated attacks, and could potentially lead to a RECAST or REJECT of this
+ CVE.", "uri": "https://security-tracker.debian.org/tracker/CVE-2007-6755", "severity":
+ "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "1.1.1d-0+deb10u6"},
+ {"key": "package_name", "value": "openssl"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:N"},
+ {"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2017-7246", "description":
+ "Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c
in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE
- of size 268) or possibly have unspecified other impact via a crafted file.\", \"\
- uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-7246\", \"severity\"\
- : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
- \"2:8.39-12\"}, {\"key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2019-20838\", \"description\": \"libpcre
- in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled,
- and \\\\X or \\\\R has more than one fixed quantifier, a related issue to CVE-2019-20454.\"\
- , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-20838\", \"severity\"\
- : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
- \"2:8.39-12\"}, {\"key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-7245\", \"description\": \"Stack-based
- buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1
- in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size
- 4) or possibly have unspecified other impact via a crafted file.\", \"uri\": \"\
- https://security-tracker.debian.org/tracker/CVE-2017-7245\", \"severity\": \"INFORMATIONAL\"\
- , \"attributes\": [{\"key\": \"package_version\", \"value\": \"2:8.39-12\"}, {\"\
- key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"CVSS2_VECTOR\", \"value\"\
- : \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\": \"6.8\"\
- }]}, {\"name\": \"CVE-2017-16231\", \"description\": \"** DISPUTED ** In PCRE 8.41,
- after compiling, a pcretest load test PoC produces a crash overflow in the function
- match() in pcre_exec.c because of a self-recursive call. NOTE: third parties dispute
- the relevance of this report, noting that there are options that can be used to
- limit the amount of stack that is used.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-16231\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"2:8.39-12\"}, {\"key\": \"package_name\", \"value\": \"pcre3\"},
- {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"2.1\"}]}, {\"name\": \"CVE-2017-11164\", \"description\"\
- : \"In PCRE 8.41, the OP_KETRMAX feature in the match function in pcre_exec.c allows
- stack exhaustion (uncontrolled recursion) when processing a crafted regular expression.\"\
- , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-11164\", \"severity\"\
- : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
- \"2:8.39-12\"}, {\"key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:C\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"7.8\"}]}, {\"name\": \"CVE-2011-4116\", \"description\": \"_is_safe
- in the File::Temp module for Perl does not properly handle symlinks.\", \"uri\"
- : \"https://security-tracker.debian.org/tracker/CVE-2011-4116\", \"severity\": \"\
- INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"5.28.1-6+deb10u1\"\
- }, {\"key\": \"package_name\", \"value\": \"perl\"}, {\"key\": \"CVSS2_VECTOR\"
- , \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\
- : \"5\"}]}, {\"name\": \"CVE-2019-19882\", \"description\": \"shadow 4.8, in certain
- circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local
- users to obtain root access because setuid programs are misconfigured. Specifically,
- this affects shadow 4.8 when compiled using --with-libpam but without explicitly
- passing --disable-account-tools-setuid, and without a PAM configuration suitable
- for use with setuid account management tools. This combination leads to account
- management tools (groupadd, groupdel, groupmod, useradd, userdel, usermod) that
- can easily be used by unprivileged local users to escalate privileges to root in
- multiple ways. This issue became much more relevant in approximately December 2019
- when an unrelated bug was fixed (i.e., the chmod calls to suidusbins were fixed
- in the upstream Makefile which is now included in the release version 4.8).\", \"\
- uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-19882\", \"severity\"\
- : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
- \"1:4.5-1.1\"}, {\"key\": \"package_name\", \"value\": \"shadow\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:C/I:C/A:C\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"6.9\"}]}, {\"name\": \"CVE-2007-5686\", \"description\": \"initscripts
- in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows
- local users to obtain sensitive information regarding authentication attempts. \
- \ NOTE: because sshd detects the insecure permissions and does not log certain events,
- this also prevents sshd from logging failed authentication attempts by remote attackers.\"\
- , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2007-5686\", \"severity\"\
- : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
- \"1:4.5-1.1\"}, {\"key\": \"package_name\", \"value\": \"shadow\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:C/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"4.9\"}]}, {\"name\": \"CVE-2013-4235\", \"description\": \"shadow:
- TOCTOU (time-of-check time-of-use) race condition when copying and removing directory
- trees\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2013-4235\"
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"1:4.5-1.1\"}, {\"key\": \"package_name\", \"value\": \"shadow\"},
- {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:N/I:P/A:P\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"3.3\"}]}, {\"name\": \"CVE-2020-13529\", \"description\"\
- : \"An exploitable denial-of-service vulnerability exists in Systemd 245. A specially
- crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be
- vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW
- and DCHP ACK packets to reconfigure the server.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-13529\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:A/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"2.9\"}]}, {\"name\": \"CVE-2013-4392\", \"description\"\
- : \"systemd, when updating file permissions, allows local users to change the permissions
+ of size 268) or possibly have unspecified other impact via a crafted file.", "uri":
+ "https://security-tracker.debian.org/tracker/CVE-2017-7246", "severity": "INFORMATIONAL",
+ "attributes": [{"key": "package_version", "value": "2:8.39-12"}, {"key": "package_name",
+ "value": "pcre3"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
+ {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2019-20838", "description":
+ "libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is
+ disabled, and \\X or \\R has more than one fixed quantifier, a related issue to
+ CVE-2019-20454.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-20838",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
+ {"name": "CVE-2017-7245", "description": "Stack-based buffer overflow in the pcre32_copy_substring
+ function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause
+ a denial of service (WRITE of size 4) or possibly have unspecified other impact
+ via a crafted file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-7245",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]},
+ {"name": "CVE-2017-16231", "description": "** DISPUTED ** In PCRE 8.41, after compiling,
+ a pcretest load test PoC produces a crash overflow in the function match() in pcre_exec.c
+ because of a self-recursive call. NOTE: third parties dispute the relevance of this
+ report, noting that there are options that can be used to limit the amount of stack
+ that is used.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-16231",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "2.1"}]},
+ {"name": "CVE-2017-11164", "description": "In PCRE 8.41, the OP_KETRMAX feature
+ in the match function in pcre_exec.c allows stack exhaustion (uncontrolled recursion)
+ when processing a crafted regular expression.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-11164",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:N/AC:L/Au:N/C:N/I:N/A:C"}, {"key": "CVSS2_SCORE", "value": "7.8"}]},
+ {"name": "CVE-2011-4116", "description": "_is_safe in the File::Temp module for
+ Perl does not properly handle symlinks.", "uri" : "https://security-tracker.debian.org/tracker/CVE-2011-4116",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "5.28.1-6+deb10u1"}, {"key": "package_name", "value": "perl"}, {"key": "CVSS2_VECTOR"
+ , "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
+ {"name": "CVE-2019-19882", "description": "shadow 4.8, in certain circumstances
+ affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain
+ root access because setuid programs are misconfigured. Specifically, this affects
+ shadow 4.8 when compiled using --with-libpam but without explicitly passing --disable-account-tools-setuid,
+ and without a PAM configuration suitable for use with setuid account management
+ tools. This combination leads to account management tools (groupadd, groupdel, groupmod,
+ useradd, userdel, usermod) that can easily be used by unprivileged local users to
+ escalate privileges to root in multiple ways. This issue became much more relevant
+ in approximately December 2019 when an unrelated bug was fixed (i.e., the chmod
+ calls to suidusbins were fixed in the upstream Makefile which is now included in
+ the release version 4.8).", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-19882",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:L/AC:M/Au:N/C:C/I:C/A:C"}, {"key": "CVSS2_SCORE", "value": "6.9"}]},
+ {"name": "CVE-2007-5686", "description": "initscripts in rPath Linux 1 sets insecure
+ permissions for the /var/log/btmp file, which allows local users to obtain sensitive
+ information regarding authentication attempts. NOTE: because sshd detects the insecure
+ permissions and does not log certain events, this also prevents sshd from logging
+ failed authentication attempts by remote attackers.", "uri": "https://security-tracker.debian.org/tracker/CVE-2007-5686",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:L/AC:L/Au:N/C:C/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.9"}]},
+ {"name": "CVE-2013-4235", "description": "shadow: TOCTOU (time-of-check time-of-use)
+ race condition when copying and removing directory trees", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-4235"
+ , "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:L/AC:M/Au:N/C:N/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "3.3"}]},
+ {"name": "CVE-2020-13529", "description": "An exploitable denial-of-service vulnerability
+ exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server
+ running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker
+ can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server.",
+ "uri": "https://security-tracker.debian.org/tracker/CVE-2020-13529", "severity":
+ "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"},
+ {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:A/AC:M/Au:N/C:N/I:N/A:P"},
+ {"key": "CVSS2_SCORE", "value": "2.9"}]}, {"name": "CVE-2013-4392", "description":
+ "systemd, when updating file permissions, allows local users to change the permissions
and SELinux security contexts for arbitrary files via a symlink attack on unspecified
- files.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2013-4392\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:P/I:P/A:N\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"3.3\"}]}, {\"name\": \"CVE-2020-13776\", \"description\"\
- : \"systemd through v245 mishandles numerical usernames such as ones composed of
- decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges
- when privileges of the 0x0 user account were intended. NOTE: this issue exists because
- of an incomplete fix for CVE-2017-1000082.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-13776\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"\
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:H/Au:N/C:C/I:C/A:C\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"6.2\"}]}, {\"name\": \"CVE-2019-20386\", \"description\"\
- : \"An issue was discovered in button_open in login/logind-button.c in systemd before
- 243. When executing the udevadm trigger command, a memory leak may occur.\", \"\
- uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-20386\", \"severity\"\
- : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
- \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"}, {\"key\"\
- : \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2019-9923\", \"description\": \"pax_decode_header
- in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain
- archives that have malformed extended headers.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-9923\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"1.30+dfsg-6\"}, {\"key\": \"package_name\", \"value\": \"tar\"},
- {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2005-2541\", \"description\"\
- : \"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid
- files, which may allow local users or remote attackers to gain privileges.\", \"\
- uri\": \"https://security-tracker.debian.org/tracker/CVE-2005-2541\", \"severity\"\
- : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
- \"1.30+dfsg-6\"}, {\"key\": \"package_name\", \"value\": \"tar\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:C/I:C/A:C\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"10\"}]}, {\"name\": \"CVE-2021-20193\", \"description\": \"A flaw
- was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker
- who can submit a crafted input file to tar to cause uncontrolled consumption of
- memory. The highest threat from this vulnerability is to system availability.\"
- , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-20193\", \"severity\"\
- : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
- \"1.30+dfsg-6\"}, {\"key\": \"package_name\", \"value\": \"tar\"}, {\"key\": \"\
- CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\
- , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-17973\", \"description\": \"** DISPUTED
- ** In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function
- in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this
- issue.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-17973\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\
- : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"\
- }, {\"key\": \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-35521\"\
- , \"description\": \"A flaw was found in libtiff. Due to a memory allocation failure
- in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of
- service.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-35521\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\
- : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"\
- }, {\"key\": \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2014-8130\"\
- , \"description\": \"The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does
- not reject a zero size, which allows remote attackers to cause a denial of service
- (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled
- by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.\"\
- , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2014-8130\", \"severity\"\
- : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
- \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\": \"tiff\"
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-5563\", \"description\"\
- : \"LibTIFF version 4.0.7 is vulnerable to a heap-based buffer over-read in tif_lzw.c
- resulting in DoS or code execution via a crafted bmp image to tools/bmp2tiff.\"
- , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-5563\", \"severity\"\
- : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
- \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\": \"tiff\"
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-35522\", \"description\"\
- : \"In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF
- document can lead to an abort, resulting in a remote denial of service attack.\"\
- , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-35522\", \"severity\"\
- : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\":
- \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\": \"tiff\"
- }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\
- : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-9117\", \"description\"\
- : \"In LibTIFF 4.0.7, the program processes BMP images without verifying that biWidth
- and biHeight in the bitmap-information header match the actual input, leading to
- a heap-based buffer over-read in bmp2tiff.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-9117\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\
- : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"\
- }, {\"key\": \"CVSS2_SCORE\", \"value\": \"7.5\"}]}, {\"name\": \"CVE-2017-16232\"\
- , \"description\": \"** DISPUTED ** LibTIFF 4.0.8 has multiple memory leak vulnerabilities,
- which allow attackers to cause a denial of service (memory consumption), as demonstrated
- by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce
- the issue.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-16232\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\
- : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"\
- }, {\"key\": \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2018-10126\"\
- , \"description\": \"LibTIFF 4.0.9 has a NULL pointer dereference in the jpeg_fdct_16x16
- function in jfdctint.c.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-10126\"\
- , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\
- , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\
- : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"\
- }, {\"key\": \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2021-22924\"\
- , \"description\": \"libcurl keeps previously used connections in a connection pool
- for subsequenttransfers to reuse, if one of them matches the setup.Due to errors
- in the logic, the config matching function did not take 'issuercert' into account
- and it compared the involved paths *case insensitively*,which could lead to libcurl
- reusing wrong connections.File paths are, or can be, case sensitive on many systems
- but not all, and caneven vary depending on used file systems.The comparison also
- didn't include the 'issuer cert' which a transfer can setto qualify how to verify
- the server certificate.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-22924\"\
- , \"severity\": \"UNDEFINED\", \"attributes\": [{\"key\": \"package_version\", \"\
- value\": \"7.64.0-4+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"curl\"
- }]}, {\"name\": \"CVE-2021-38115\", \"description\": \"read_header_tga in gd_tga.c
- in the GD Graphics Library (aka LibGD) through 2.3.2 allows remote attackers to
- cause a denial of service (out-of-bounds read) via a crafted TGA file.\", \"uri\"\
- : \"https://security-tracker.debian.org/tracker/CVE-2021-38115\", \"severity\":
- \"UNDEFINED\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.2.5-5.2\"\
- }, {\"key\": \"package_name\", \"value\": \"libgd2\"}]}, {\"name\": \"CVE-2021-3618\"\
- , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-3618\", \"severity\"\
- : \"UNDEFINED\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"1.21.1-1~buster\"\
- }, {\"key\": \"package_name\", \"value\": \"nginx\"}]}], \"findingSeverityCounts\"\
- : {\"HIGH\": 2, \"MEDIUM\": 14, \"INFORMATIONAL\": 63, \"LOW\": 22, \"UNDEFINED\"\
- : 3}}}, \"requestID\": \"23c19e2d-c48b-4265-b4eb-853e7b325780\", \"eventID\": \"\
- 6c94a9b2-36dc-43f8-a6dd-4ec839ded8af\", \"readOnly\": true, \"eventType\": \"AwsApiCall\"\
- , \"managementEvent\": true, \"recipientAccountId\": \"111111111111\", \"eventCategory\"\
- : \"Management\"}"
+ files.", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-4392", "severity":
+ "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"},
+ {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:P/I:P/A:N"},
+ {"key": "CVSS2_SCORE", "value": "3.3"}]}, {"name": "CVE-2020-13776", "description":
+ "systemd through v245 mishandles numerical usernames such as ones composed of decimal
+ digits or 0x followed by hex digits, as demonstrated by use of root privileges when
+ privileges of the 0x0 user account were intended. NOTE: this issue exists because
+ of an incomplete fix for CVE-2017-1000082.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-13776",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "241-7~deb10u8"}, {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:L/AC:H/Au:N/C:C/I:C/A:C"}, {"key": "CVSS2_SCORE", "value": "6.2"}]},
+ {"name": "CVE-2019-20386", "description": "An issue was discovered in button_open
+ in login/logind-button.c in systemd before 243. When executing the udevadm trigger
+ command, a memory leak may occur.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-20386",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "241-7~deb10u8"}, {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "2.1"}]},
+ {"name": "CVE-2019-9923", "description": "pax_decode_header in sparse.c in GNU Tar
+ before 1.32 had a NULL pointer dereference when parsing certain archives that have
+ malformed extended headers.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-9923",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]},
+ {"name": "CVE-2005-2541", "description": "Tar 1.15.1 does not properly warn the
+ user when extracting setuid or setgid files, which may allow local users or remote
+ attackers to gain privileges.", "uri": "https://security-tracker.debian.org/tracker/CVE-2005-2541",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:N/AC:L/Au:N/C:C/I:C/A:C"}, {"key": "CVSS2_SCORE", "value": "10"}]},
+ {"name": "CVE-2021-20193", "description": "A flaw was found in the src/list.c of
+ tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input
+ file to tar to cause uncontrolled consumption of memory. The highest threat from
+ this vulnerability is to system availability." , "uri": "https://security-tracker.debian.org/tracker/CVE-2021-20193",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR",
+ "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
+ {"name": "CVE-2017-17973", "description": "** DISPUTED ** In LibTIFF 4.0.8, there
+ is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE:
+ there is a third-party report of inability to reproduce this issue.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-17973",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
+ "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value":
+ "6.8"}]}, {"name": "CVE-2020-35521", "description": "A flaw was found in libtiff.
+ Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to
+ an abort, resulting in denial of service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-35521",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
+ "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
+ "4.3"}]}, {"name": "CVE-2014-8130", "description": "The _TIFFmalloc function in
+ tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers
+ to cause a denial of service (divide-by-zero error and application crash) via a
+ crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c,
+ as demonstrated by tiffdither.", "uri": "https://security-tracker.debian.org/tracker/CVE-2014-8130",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff" }, {"key":
+ "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
+ "4.3"}]}, {"name": "CVE-2017-5563", "description": "LibTIFF version 4.0.7 is vulnerable
+ to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution
+ via a crafted bmp image to tools/bmp2tiff." , "uri": "https://security-tracker.debian.org/tracker/CVE-2017-5563",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff" }, {"key":
+ "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value":
+ "6.8"}]}, {"name": "CVE-2020-35522", "description": "In LibTIFF, there is a memory
+ malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort,
+ resulting in a remote denial of service attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-35522",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff" }, {"key":
+ "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
+ "4.3"}]}, {"name": "CVE-2017-9117", "description": "In LibTIFF 4.0.7, the program
+ processes BMP images without verifying that biWidth and biHeight in the bitmap-information
+ header match the actual input, leading to a heap-based buffer over-read in bmp2tiff.",
+ "uri": "https://security-tracker.debian.org/tracker/CVE-2017-9117", "severity":
+ "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "4.1.0+git191117-2~deb10u2"},
+ {"key": "package_name", "value": "tiff"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"},
+ {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2017-16232", "description":
+ "** DISPUTED ** LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow
+ attackers to cause a denial of service (memory consumption), as demonstrated by
+ tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce
+ the issue.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-16232",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
+ "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
+ "5"}]}, {"name": "CVE-2018-10126", "description": "LibTIFF 4.0.9 has a NULL pointer
+ dereference in the jpeg_fdct_16x16 function in jfdctint.c.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-10126",
+ "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
+ "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
+ "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
+ "4.3"}]}, {"name": "CVE-2021-22924", "description": "libcurl keeps previously used
+ connections in a connection pool for subsequenttransfers to reuse, if one of them
+ matches the setup.Due to errors in the logic, the config matching function did not
+ take ''issuercert'' into account and it compared the involved paths *case insensitively*,which
+ could lead to libcurl reusing wrong connections.File paths are, or can be, case
+ sensitive on many systems but not all, and caneven vary depending on used file systems.The
+ comparison also didn''t include the ''issuer cert'' which a transfer can setto qualify
+ how to verify the server certificate.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22924",
+ "severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "7.64.0-4+deb10u2"},
+ {"key": "package_name", "value": "curl" }]}, {"name": "CVE-2021-38115", "description":
+ "read_header_tga in gd_tga.c in the GD Graphics Library (aka LibGD) through 2.3.2
+ allows remote attackers to cause a denial of service (out-of-bounds read) via a
+ crafted TGA file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-38115",
+ "severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "2.2.5-5.2"},
+ {"key": "package_name", "value": "libgd2"}]}, {"name": "CVE-2021-3618", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-3618",
+ "severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"},
+ {"key": "package_name", "value": "nginx"}]}], "findingSeverityCounts": {"HIGH":
+ 2, "MEDIUM": 14, "INFORMATIONAL": 63, "LOW": 22, "UNDEFINED": 3}}}, "requestID":
+ "23c19e2d-c48b-4265-b4eb-853e7b325780", "eventID": "6c94a9b2-36dc-43f8-a6dd-4ec839ded8af",
+ "readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
+ "111111111111", "eventCategory": "Management"}'
diff --git a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml
index 56fa1914b9..0a63249da0 100644
--- a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml
+++ b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml
@@ -6,91 +6,91 @@ author: Patrick Bareiss, Splunk
description: Logs an event when a request is made to get the account password policy
in AWS CloudTrail.
mitre_components:
- - User Account Authentication
- - User Account Metadata
+- User Account Authentication
+- User Account Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: GetAccountPasswordPolicy
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - desc
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters
- - responseElements
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - status
- - timeendpos
- - timestartpos
- - tlsDetails.cipherSuite
- - tlsDetails.clientProvidedHostHeader
- - tlsDetails.tlsVersion
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- desc
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters
+- responseElements
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- status
+- timeendpos
+- timestartpos
+- tlsDetails.cipherSuite
+- tlsDetails.clientProvidedHostHeader
+- tlsDetails.tlsVersion
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDASBMSCQHHTH5NDF4GD", "arn": "arn:aws:iam::111111111111:user/strt_fonder", "accountId":
"111111111111", "accessKeyId": "AKIASBMSCQHH5A5NJDM5", "userName": "strt_fonder"},
diff --git a/data_sources/aws_cloudtrail_getobject.yml b/data_sources/aws_cloudtrail_getobject.yml
index d303eb012c..2e9608547a 100644
--- a/data_sources/aws_cloudtrail_getobject.yml
+++ b/data_sources/aws_cloudtrail_getobject.yml
@@ -6,100 +6,100 @@ author: Patrick Bareiss, Splunk
description: Logs an event when a request is made to access an object stored in an
AWS S3 bucket.
mitre_components:
- - Cloud Storage Access
- - Cloud Storage Metadata
- - Cloud Storage Enumeration
+- Cloud Storage Access
+- Cloud Storage Metadata
+- Cloud Storage Enumeration
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: GetObject
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - additionalEventData.AuthenticationMethod
- - additionalEventData.CipherSuite
- - additionalEventData.SignatureVersion
- - additionalEventData.bytesTransferredIn
- - additionalEventData.bytesTransferredOut
- - additionalEventData.x-amz-id-2
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.Host
- - requestParameters.bucketName
- - requestParameters.key
- - requestParameters.x-amz-request-payer
- - resources{}.ARN
- - resources{}.accountId
- - resources{}.type
- - responseElements
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - timeendpos
- - timestartpos
- - tlsDetails.cipherSuite
- - tlsDetails.clientProvidedHostHeader
- - tlsDetails.tlsVersion
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- additionalEventData.AuthenticationMethod
+- additionalEventData.CipherSuite
+- additionalEventData.SignatureVersion
+- additionalEventData.bytesTransferredIn
+- additionalEventData.bytesTransferredOut
+- additionalEventData.x-amz-id-2
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.Host
+- requestParameters.bucketName
+- requestParameters.key
+- requestParameters.x-amz-request-payer
+- resources{}.ARN
+- resources{}.accountId
+- resources{}.type
+- responseElements
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- timeendpos
+- timestartpos
+- tlsDetails.cipherSuite
+- tlsDetails.clientProvidedHostHeader
+- tlsDetails.tlsVersion
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/console", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName": "console"}, "eventTime":
diff --git a/data_sources/aws_cloudtrail_getpassworddata.yml b/data_sources/aws_cloudtrail_getpassworddata.yml
index 6644109837..ca47e32ca9 100644
--- a/data_sources/aws_cloudtrail_getpassworddata.yml
+++ b/data_sources/aws_cloudtrail_getpassworddata.yml
@@ -6,101 +6,101 @@ author: Patrick Bareiss, Splunk
description: Logs an event when a request is made to retrieve the administrator password
of an EC2 instance.
mitre_components:
- - Instance Metadata
- - User Account Authentication
+- Instance Metadata
+- User Account Authentication
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: GetPasswordData
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - errorMessage
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - reason
- - recipientAccountId
- - region
- - requestID
- - requestParameters.instanceId
- - responseElements
- - result
- - result_id
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - tlsDetails.cipherSuite
- - tlsDetails.clientProvidedHostHeader
- - tlsDetails.tlsVersion
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.sessionContext.sessionIssuer.accountId
- - userIdentity.sessionContext.sessionIssuer.arn
- - userIdentity.sessionContext.sessionIssuer.principalId
- - userIdentity.sessionContext.sessionIssuer.type
- - userIdentity.sessionContext.sessionIssuer.userName
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- errorMessage
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- reason
+- recipientAccountId
+- region
+- requestID
+- requestParameters.instanceId
+- responseElements
+- result
+- result_id
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- tlsDetails.cipherSuite
+- tlsDetails.clientProvidedHostHeader
+- tlsDetails.tlsVersion
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.sessionContext.sessionIssuer.accountId
+- userIdentity.sessionContext.sessionIssuer.arn
+- userIdentity.sessionContext.sessionIssuer.principalId
+- userIdentity.sessionContext.sessionIssuer.type
+- userIdentity.sessionContext.sessionIssuer.userName
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLP5AASA6I5:aws-go-sdk-1660169051746043000", "arn": "arn:aws:sts::111111111111:assumed-role/sample-role-used-by-stratus-for-ec2-password-data/aws-go-sdk-1660169051746043000",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLLY5RQXEF", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_jobcreated.yml b/data_sources/aws_cloudtrail_jobcreated.yml
index 2278f224a5..d0fbf8d5a8 100644
--- a/data_sources/aws_cloudtrail_jobcreated.yml
+++ b/data_sources/aws_cloudtrail_jobcreated.yml
@@ -5,77 +5,77 @@ date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when a new job is created in AWS CloudTrail.
mitre_components:
- - Scheduled Job Creation
- - Cloud Service Metadata
+- Scheduled Job Creation
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: JobCreated
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - desc
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestParameters
- - responseElements
- - serviceEventDetails.jobArn
- - serviceEventDetails.jobEventId
- - serviceEventDetails.jobId
- - serviceEventDetails.status
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - timeendpos
- - timestartpos
- - userAgent
- - userIdentity.accountId
- - userIdentity.invokedBy
- - user_agent
- - user_group_id
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- desc
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestParameters
+- responseElements
+- serviceEventDetails.jobArn
+- serviceEventDetails.jobEventId
+- serviceEventDetails.jobId
+- serviceEventDetails.status
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- timeendpos
+- timestartpos
+- userAgent
+- userIdentity.accountId
+- userIdentity.invokedBy
+- user_agent
+- user_group_id
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"accountId": "111111111111",
"invokedBy": "s3.amazonaws.com"}, "eventTime": "2023-04-24T23:51:17Z", "eventSource":
"s3.amazonaws.com", "eventName": "JobCreated", "awsRegion": "us-west-2", "sourceIPAddress":
diff --git a/data_sources/aws_cloudtrail_modifydbinstance.yml b/data_sources/aws_cloudtrail_modifydbinstance.yml
index 99cb79f0b2..156008b8c1 100644
--- a/data_sources/aws_cloudtrail_modifydbinstance.yml
+++ b/data_sources/aws_cloudtrail_modifydbinstance.yml
@@ -6,150 +6,150 @@ author: Patrick Bareiss, Splunk
description: Logs an event when a modification is made to an AWS database instance,
such as parameters or configurations.
mitre_components:
- - Instance Modification
- - Cloud Service Modification
- - Instance Metadata
+- Instance Modification
+- Cloud Service Modification
+- Instance Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: ModifyDBInstance
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.allowMajorVersionUpgrade
- - requestParameters.applyImmediately
- - requestParameters.dBInstanceIdentifier
- - requestParameters.deletionProtection
- - requestParameters.masterUserPassword
- - responseElements.allocatedStorage
- - responseElements.autoMinorVersionUpgrade
- - responseElements.availabilityZone
- - responseElements.backupRetentionPeriod
- - responseElements.backupTarget
- - responseElements.cACertificateIdentifier
- - responseElements.copyTagsToSnapshot
- - responseElements.customerOwnedIpEnabled
- - responseElements.dBInstanceArn
- - responseElements.dBInstanceClass
- - responseElements.dBInstanceIdentifier
- - responseElements.dBInstanceStatus
- - responseElements.dBParameterGroups{}.dBParameterGroupName
- - responseElements.dBParameterGroups{}.parameterApplyStatus
- - responseElements.dBSubnetGroup.dBSubnetGroupDescription
- - responseElements.dBSubnetGroup.dBSubnetGroupName
- - responseElements.dBSubnetGroup.subnetGroupStatus
- - responseElements.dBSubnetGroup.subnets{}.subnetAvailabilityZone.name
- - responseElements.dBSubnetGroup.subnets{}.subnetIdentifier
- - responseElements.dBSubnetGroup.subnets{}.subnetStatus
- - responseElements.dBSubnetGroup.vpcId
- - responseElements.dbInstancePort
- - responseElements.dbiResourceId
- - responseElements.deletionProtection
- - responseElements.endpoint.address
- - responseElements.endpoint.hostedZoneId
- - responseElements.endpoint.port
- - responseElements.engine
- - responseElements.engineVersion
- - responseElements.enhancedMonitoringResourceArn
- - responseElements.httpEndpointEnabled
- - responseElements.iAMDatabaseAuthenticationEnabled
- - responseElements.instanceCreateTime
- - responseElements.kmsKeyId
- - responseElements.latestRestorableTime
- - responseElements.licenseModel
- - responseElements.masterUsername
- - responseElements.monitoringInterval
- - responseElements.monitoringRoleArn
- - responseElements.multiAZ
- - responseElements.networkType
- - responseElements.optionGroupMemberships{}.optionGroupName
- - responseElements.optionGroupMemberships{}.status
- - responseElements.pendingModifiedValues.masterUserPassword
- - responseElements.performanceInsightsEnabled
- - responseElements.performanceInsightsKMSKeyId
- - responseElements.performanceInsightsRetentionPeriod
- - responseElements.preferredBackupWindow
- - responseElements.preferredMaintenanceWindow
- - responseElements.publiclyAccessible
- - responseElements.storageEncrypted
- - responseElements.storageThroughput
- - responseElements.storageType
- - responseElements.vpcSecurityGroups{}.status
- - responseElements.vpcSecurityGroups{}.vpcSecurityGroupId
- - sessionCredentialFromConsole
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.sessionContext.sessionIssuer.accountId
- - userIdentity.sessionContext.sessionIssuer.arn
- - userIdentity.sessionContext.sessionIssuer.principalId
- - userIdentity.sessionContext.sessionIssuer.type
- - userIdentity.sessionContext.sessionIssuer.userName
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.allowMajorVersionUpgrade
+- requestParameters.applyImmediately
+- requestParameters.dBInstanceIdentifier
+- requestParameters.deletionProtection
+- requestParameters.masterUserPassword
+- responseElements.allocatedStorage
+- responseElements.autoMinorVersionUpgrade
+- responseElements.availabilityZone
+- responseElements.backupRetentionPeriod
+- responseElements.backupTarget
+- responseElements.cACertificateIdentifier
+- responseElements.copyTagsToSnapshot
+- responseElements.customerOwnedIpEnabled
+- responseElements.dBInstanceArn
+- responseElements.dBInstanceClass
+- responseElements.dBInstanceIdentifier
+- responseElements.dBInstanceStatus
+- responseElements.dBParameterGroups{}.dBParameterGroupName
+- responseElements.dBParameterGroups{}.parameterApplyStatus
+- responseElements.dBSubnetGroup.dBSubnetGroupDescription
+- responseElements.dBSubnetGroup.dBSubnetGroupName
+- responseElements.dBSubnetGroup.subnetGroupStatus
+- responseElements.dBSubnetGroup.subnets{}.subnetAvailabilityZone.name
+- responseElements.dBSubnetGroup.subnets{}.subnetIdentifier
+- responseElements.dBSubnetGroup.subnets{}.subnetStatus
+- responseElements.dBSubnetGroup.vpcId
+- responseElements.dbInstancePort
+- responseElements.dbiResourceId
+- responseElements.deletionProtection
+- responseElements.endpoint.address
+- responseElements.endpoint.hostedZoneId
+- responseElements.endpoint.port
+- responseElements.engine
+- responseElements.engineVersion
+- responseElements.enhancedMonitoringResourceArn
+- responseElements.httpEndpointEnabled
+- responseElements.iAMDatabaseAuthenticationEnabled
+- responseElements.instanceCreateTime
+- responseElements.kmsKeyId
+- responseElements.latestRestorableTime
+- responseElements.licenseModel
+- responseElements.masterUsername
+- responseElements.monitoringInterval
+- responseElements.monitoringRoleArn
+- responseElements.multiAZ
+- responseElements.networkType
+- responseElements.optionGroupMemberships{}.optionGroupName
+- responseElements.optionGroupMemberships{}.status
+- responseElements.pendingModifiedValues.masterUserPassword
+- responseElements.performanceInsightsEnabled
+- responseElements.performanceInsightsKMSKeyId
+- responseElements.performanceInsightsRetentionPeriod
+- responseElements.preferredBackupWindow
+- responseElements.preferredMaintenanceWindow
+- responseElements.publiclyAccessible
+- responseElements.storageEncrypted
+- responseElements.storageThroughput
+- responseElements.storageType
+- responseElements.vpcSecurityGroups{}.status
+- responseElements.vpcSecurityGroups{}.vpcSecurityGroupId
+- sessionCredentialFromConsole
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.sessionContext.sessionIssuer.accountId
+- userIdentity.sessionContext.sessionIssuer.arn
+- userIdentity.sessionContext.sessionIssuer.principalId
+- userIdentity.sessionContext.sessionIssuer.type
+- userIdentity.sessionContext.sessionIssuer.userName
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLDF6WP4HD6:gowthamarajr@splunk.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/gowthamarajr@splunk.com",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLAKJDBQGB", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_modifyimageattribute.yml b/data_sources/aws_cloudtrail_modifyimageattribute.yml
index 67fd0edb8a..ab8bb25d87 100644
--- a/data_sources/aws_cloudtrail_modifyimageattribute.yml
+++ b/data_sources/aws_cloudtrail_modifyimageattribute.yml
@@ -6,95 +6,95 @@ author: Patrick Bareiss, Splunk
description: Logs an event when the attributes of an Amazon Machine Image (AMI) are
modified.
mitre_components:
- - Image Modification
- - Image Metadata
+- Image Modification
+- Image Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: ModifyImageAttribute
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.attributeType
- - requestParameters.imageId
- - requestParameters.launchPermission.add.items{}.userId
- - responseElements._return
- - responseElements.requestId
- - sessionCredentialFromConsole
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.sessionContext.sessionIssuer.accountId
- - userIdentity.sessionContext.sessionIssuer.arn
- - userIdentity.sessionContext.sessionIssuer.principalId
- - userIdentity.sessionContext.sessionIssuer.type
- - userIdentity.sessionContext.sessionIssuer.userName
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.attributeType
+- requestParameters.imageId
+- requestParameters.launchPermission.add.items{}.userId
+- responseElements._return
+- responseElements.requestId
+- sessionCredentialFromConsole
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.sessionContext.sessionIssuer.accountId
+- userIdentity.sessionContext.sessionIssuer.arn
+- userIdentity.sessionContext.sessionIssuer.principalId
+- userIdentity.sessionContext.sessionIssuer.type
+- userIdentity.sessionContext.sessionIssuer.userName
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLDF6WP4HD6:bonobo@bo.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/bonobo@bo.com",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLBHIEEEPN", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml
index d44c5fa436..0dec70fdf0 100644
--- a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml
+++ b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml
@@ -6,90 +6,90 @@ author: Patrick Bareiss, Splunk
description: Logs an event when modifications are made to the attributes of a snapshot
in AWS CloudTrail.
mitre_components:
- - Snapshot Modification
+- Snapshot Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: ModifySnapshotAttribute
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.attributeType
- - requestParameters.createVolumePermission.add.items{}.userId
- - requestParameters.snapshotId
- - responseElements._return
- - responseElements.requestId
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - timeendpos
- - timestartpos
- - tlsDetails.cipherSuite
- - tlsDetails.clientProvidedHostHeader
- - tlsDetails.tlsVersion
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.attributeType
+- requestParameters.createVolumePermission.add.items{}.userId
+- requestParameters.snapshotId
+- responseElements._return
+- responseElements.requestId
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- timeendpos
+- timestartpos
+- tlsDetails.cipherSuite
+- tlsDetails.clientProvidedHostHeader
+- tlsDetails.tlsVersion
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/bhavin_console",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName":
diff --git a/data_sources/aws_cloudtrail_putbucketacl.yml b/data_sources/aws_cloudtrail_putbucketacl.yml
index 715cb571cb..c531275617 100644
--- a/data_sources/aws_cloudtrail_putbucketacl.yml
+++ b/data_sources/aws_cloudtrail_putbucketacl.yml
@@ -6,104 +6,104 @@ author: Patrick Bareiss, Splunk
description: Logs an event when an ACL is set or modified for an S3 bucket in AWS
CloudTrail.
mitre_components:
- - Cloud Storage Modification
- - Cloud Storage Metadata
+- Cloud Storage Modification
+- Cloud Storage Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: PutBucketAcl
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - additionalEventData.AuthenticationMethod
- - additionalEventData.CipherSuite
- - additionalEventData.SignatureVersion
- - additionalEventData.bytesTransferredIn
- - additionalEventData.bytesTransferredOut
- - additionalEventData.x-amz-id-2
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object
- - object_category
- - object_id
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.Host
- - requestParameters.accessControlList.x-amz-grant-write-acp
- - requestParameters.acl
- - requestParameters.bucketName
- - resources{}.ARN
- - resources{}.accountId
- - resources{}.type
- - responseElements
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - src_user
- - start_time
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- additionalEventData.AuthenticationMethod
+- additionalEventData.CipherSuite
+- additionalEventData.SignatureVersion
+- additionalEventData.bytesTransferredIn
+- additionalEventData.bytesTransferredOut
+- additionalEventData.x-amz-id-2
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object
+- object_category
+- object_id
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.Host
+- requestParameters.accessControlList.x-amz-grant-write-acp
+- requestParameters.acl
+- requestParameters.bucketName
+- resources{}.ARN
+- resources{}.accountId
+- resources{}.type
+- responseElements
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- src_user
+- start_time
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLNALZHZ6KX", "arn": "arn:aws:iam::111111111111:user/patrick_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLJ2OYSF6E", "userName": "patrick_cli"},
diff --git a/data_sources/aws_cloudtrail_putbucketlifecycle.yml b/data_sources/aws_cloudtrail_putbucketlifecycle.yml
index e5108f5812..aa74257621 100644
--- a/data_sources/aws_cloudtrail_putbucketlifecycle.yml
+++ b/data_sources/aws_cloudtrail_putbucketlifecycle.yml
@@ -6,105 +6,105 @@ author: Patrick Bareiss, Splunk
description: Logs an event when a lifecycle configuration is added to an S3 bucket
in AWS CloudTrail.
mitre_components:
- - Cloud Storage Modification
- - Cloud Storage Metadata
+- Cloud Storage Modification
+- Cloud Storage Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: PutBucketLifecycle
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - additionalEventData.AuthenticationMethod
- - additionalEventData.CipherSuite
- - additionalEventData.SignatureVersion
- - additionalEventData.bytesTransferredIn
- - additionalEventData.bytesTransferredOut
- - additionalEventData.x-amz-id-2
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object
- - object_category
- - object_id
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.Host
- - requestParameters.LifecycleConfiguration.Rule.Expiration.Days
- - requestParameters.LifecycleConfiguration.Rule.Filter.Prefix
- - requestParameters.LifecycleConfiguration.Rule.ID
- - requestParameters.LifecycleConfiguration.Rule.Status
- - requestParameters.LifecycleConfiguration.xmlns
- - requestParameters.bucketName
- - requestParameters.lifecycle
- - resources{}.ARN
- - resources{}.accountId
- - resources{}.type
- - responseElements
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - timeendpos
- - timestartpos
- - tlsDetails.cipherSuite
- - tlsDetails.clientProvidedHostHeader
- - tlsDetails.tlsVersion
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- additionalEventData.AuthenticationMethod
+- additionalEventData.CipherSuite
+- additionalEventData.SignatureVersion
+- additionalEventData.bytesTransferredIn
+- additionalEventData.bytesTransferredOut
+- additionalEventData.x-amz-id-2
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object
+- object_category
+- object_id
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.Host
+- requestParameters.LifecycleConfiguration.Rule.Expiration.Days
+- requestParameters.LifecycleConfiguration.Rule.Filter.Prefix
+- requestParameters.LifecycleConfiguration.Rule.ID
+- requestParameters.LifecycleConfiguration.Rule.Status
+- requestParameters.LifecycleConfiguration.xmlns
+- requestParameters.bucketName
+- requestParameters.lifecycle
+- resources{}.ARN
+- resources{}.accountId
+- resources{}.type
+- responseElements
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- timeendpos
+- timestartpos
+- tlsDetails.cipherSuite
+- tlsDetails.clientProvidedHostHeader
+- tlsDetails.tlsVersion
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"},
diff --git a/data_sources/aws_cloudtrail_putbucketreplication.yml b/data_sources/aws_cloudtrail_putbucketreplication.yml
index 779545c3e7..0da2860b07 100644
--- a/data_sources/aws_cloudtrail_putbucketreplication.yml
+++ b/data_sources/aws_cloudtrail_putbucketreplication.yml
@@ -6,117 +6,117 @@ author: Patrick Bareiss, Splunk
description: Logs an event when replication configurations are added or modified for
an S3 bucket.
mitre_components:
- - Cloud Storage Modification
+- Cloud Storage Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: PutBucketReplication
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - additionalEventData.AuthenticationMethod
- - additionalEventData.CipherSuite
- - additionalEventData.SignatureVersion
- - additionalEventData.bytesTransferredIn
- - additionalEventData.bytesTransferredOut
- - additionalEventData.x-amz-id-2
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object
- - object_category
- - object_id
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.Host
- - requestParameters.ReplicationConfiguration.Role
- - requestParameters.ReplicationConfiguration.Rule.DeleteMarkerReplication.Status
- - requestParameters.ReplicationConfiguration.Rule.Destination.Bucket
- - requestParameters.ReplicationConfiguration.Rule.Filter
- - requestParameters.ReplicationConfiguration.Rule.ID
- - requestParameters.ReplicationConfiguration.Rule.Priority
- - requestParameters.ReplicationConfiguration.Rule.Status
- - requestParameters.ReplicationConfiguration.xmlns
- - requestParameters.bucketName
- - requestParameters.replication
- - resources{}.ARN
- - resources{}.accountId
- - resources{}.type
- - responseElements
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - tlsDetails.cipherSuite
- - tlsDetails.clientProvidedHostHeader
- - tlsDetails.tlsVersion
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.sessionContext.sessionIssuer.accountId
- - userIdentity.sessionContext.sessionIssuer.arn
- - userIdentity.sessionContext.sessionIssuer.principalId
- - userIdentity.sessionContext.sessionIssuer.type
- - userIdentity.sessionContext.sessionIssuer.userName
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
- - vpcEndpointId
+- _time
+- additionalEventData.AuthenticationMethod
+- additionalEventData.CipherSuite
+- additionalEventData.SignatureVersion
+- additionalEventData.bytesTransferredIn
+- additionalEventData.bytesTransferredOut
+- additionalEventData.x-amz-id-2
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object
+- object_category
+- object_id
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.Host
+- requestParameters.ReplicationConfiguration.Role
+- requestParameters.ReplicationConfiguration.Rule.DeleteMarkerReplication.Status
+- requestParameters.ReplicationConfiguration.Rule.Destination.Bucket
+- requestParameters.ReplicationConfiguration.Rule.Filter
+- requestParameters.ReplicationConfiguration.Rule.ID
+- requestParameters.ReplicationConfiguration.Rule.Priority
+- requestParameters.ReplicationConfiguration.Rule.Status
+- requestParameters.ReplicationConfiguration.xmlns
+- requestParameters.bucketName
+- requestParameters.replication
+- resources{}.ARN
+- resources{}.accountId
+- resources{}.type
+- responseElements
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- tlsDetails.cipherSuite
+- tlsDetails.clientProvidedHostHeader
+- tlsDetails.tlsVersion
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.sessionContext.sessionIssuer.accountId
+- userIdentity.sessionContext.sessionIssuer.arn
+- userIdentity.sessionContext.sessionIssuer.principalId
+- userIdentity.sessionContext.sessionIssuer.type
+- userIdentity.sessionContext.sessionIssuer.userName
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
+- vpcEndpointId
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLDF6WP4H11:bpatel@splunk.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/bpatel@splunk.com",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLJOVYQHW2", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_putbucketversioning.yml b/data_sources/aws_cloudtrail_putbucketversioning.yml
index 1d727cc4d1..a0b031cda4 100644
--- a/data_sources/aws_cloudtrail_putbucketversioning.yml
+++ b/data_sources/aws_cloudtrail_putbucketversioning.yml
@@ -6,108 +6,108 @@ author: Patrick Bareiss, Splunk
description: Logs an event when the bucket versioning state is modified in an AWS
S3 bucket.
mitre_components:
- - Cloud Storage Modification
+- Cloud Storage Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: PutBucketVersioning
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - additionalEventData.AuthenticationMethod
- - additionalEventData.CipherSuite
- - additionalEventData.SignatureVersion
- - additionalEventData.bytesTransferredIn
- - additionalEventData.bytesTransferredOut
- - additionalEventData.x-amz-id-2
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object
- - object_category
- - object_id
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.Host
- - requestParameters.VersioningConfiguration.Status
- - requestParameters.VersioningConfiguration.xmlns
- - requestParameters.bucketName
- - requestParameters.versioning
- - resources{}.ARN
- - resources{}.accountId
- - resources{}.type
- - responseElements
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - timeendpos
- - timestartpos
- - tlsDetails.cipherSuite
- - tlsDetails.clientProvidedHostHeader
- - tlsDetails.tlsVersion
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.sessionContext.sessionIssuer.accountId
- - userIdentity.sessionContext.sessionIssuer.arn
- - userIdentity.sessionContext.sessionIssuer.principalId
- - userIdentity.sessionContext.sessionIssuer.type
- - userIdentity.sessionContext.sessionIssuer.userName
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
- - vpcEndpointId
+- _time
+- additionalEventData.AuthenticationMethod
+- additionalEventData.CipherSuite
+- additionalEventData.SignatureVersion
+- additionalEventData.bytesTransferredIn
+- additionalEventData.bytesTransferredOut
+- additionalEventData.x-amz-id-2
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object
+- object_category
+- object_id
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.Host
+- requestParameters.VersioningConfiguration.Status
+- requestParameters.VersioningConfiguration.xmlns
+- requestParameters.bucketName
+- requestParameters.versioning
+- resources{}.ARN
+- resources{}.accountId
+- resources{}.type
+- responseElements
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- timeendpos
+- timestartpos
+- tlsDetails.cipherSuite
+- tlsDetails.clientProvidedHostHeader
+- tlsDetails.tlsVersion
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.sessionContext.sessionIssuer.accountId
+- userIdentity.sessionContext.sessionIssuer.arn
+- userIdentity.sessionContext.sessionIssuer.principalId
+- userIdentity.sessionContext.sessionIssuer.type
+- userIdentity.sessionContext.sessionIssuer.userName
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
+- vpcEndpointId
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLDF6WP4HD6:daftpunk@splunk.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/daftpunk@splunk.com",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLAQ5VXXXX", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_putimage.yml b/data_sources/aws_cloudtrail_putimage.yml
index 713ed667e1..f5ba052aa0 100644
--- a/data_sources/aws_cloudtrail_putimage.yml
+++ b/data_sources/aws_cloudtrail_putimage.yml
@@ -6,98 +6,98 @@ author: Patrick Bareiss, Splunk
description: Logs an event when a container image is uploaded to a repository in AWS
CloudTrail.
mitre_components:
- - Image Creation
- - Image Metadata
+- Image Creation
+- Image Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: PutImage
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.imageManifest
- - requestParameters.imageManifestMediaType
- - requestParameters.imageTag
- - requestParameters.registryId
- - requestParameters.repositoryName
- - resources{}.ARN
- - resources{}.accountId
- - responseElements.image.imageId.imageDigest
- - responseElements.image.imageId.imageTag
- - responseElements.image.imageManifest
- - responseElements.image.imageManifestMediaType
- - responseElements.image.registryId
- - responseElements.image.repositoryName
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.invokedBy
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.imageManifest
+- requestParameters.imageManifestMediaType
+- requestParameters.imageTag
+- requestParameters.registryId
+- requestParameters.repositoryName
+- resources{}.ARN
+- resources{}.accountId
+- responseElements.image.imageId.imageDigest
+- responseElements.image.imageId.imageTag
+- responseElements.image.imageManifest
+- responseElements.image.imageManifestMediaType
+- responseElements.image.registryId
+- responseElements.image.repositoryName
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.invokedBy
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AAAAAAAAAAAAAAAAAAAAA", "arn": "arn:aws:iam::111111111111:user/test", "accountId":
"111111111111", "accessKeyId": "AAAAAAAAAAAAAAAAAAAAA", "userName": "test", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_putkeypolicy.yml b/data_sources/aws_cloudtrail_putkeypolicy.yml
index d291365312..597af6e6cb 100644
--- a/data_sources/aws_cloudtrail_putkeypolicy.yml
+++ b/data_sources/aws_cloudtrail_putkeypolicy.yml
@@ -9,94 +9,94 @@ source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.bypassPolicyLockoutSafetyCheck
- - requestParameters.keyId
- - requestParameters.policy
- - requestParameters.policyName
- - resources{}.ARN
- - resources{}.accountId
- - resources{}.type
- - responseElements
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.sessionContext.sessionIssuer.accountId
- - userIdentity.sessionContext.sessionIssuer.arn
- - userIdentity.sessionContext.sessionIssuer.principalId
- - userIdentity.sessionContext.sessionIssuer.type
- - userIdentity.sessionContext.sessionIssuer.userName
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.bypassPolicyLockoutSafetyCheck
+- requestParameters.keyId
+- requestParameters.policy
+- requestParameters.policyName
+- resources{}.ARN
+- resources{}.accountId
+- resources{}.type
+- responseElements
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.sessionContext.sessionIssuer.accountId
+- userIdentity.sessionContext.sessionIssuer.arn
+- userIdentity.sessionContext.sessionIssuer.principalId
+- userIdentity.sessionContext.sessionIssuer.type
+- userIdentity.sessionContext.sessionIssuer.userName
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
mitre_components:
- - Cloud Service Modification
+- Cloud Service Modification
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLK74OPBDR", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml
index 4e7c3f9359..fb1752d56b 100644
--- a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml
+++ b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml
@@ -5,106 +5,106 @@ date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when a network ACL entry is replaced within the AWS CloudTrail.
mitre_components:
- - Firewall Rule Modification
- - Cloud Service Modification
+- Firewall Rule Modification
+- Cloud Service Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: ReplaceNetworkAclEntry
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - direction
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - protocol
- - protocol_code
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.aclProtocol
- - requestParameters.cidrBlock
- - requestParameters.egress
- - requestParameters.networkAclId
- - requestParameters.ruleAction
- - requestParameters.ruleNumber
- - responseElements._return
- - responseElements.requestId
- - rule_action
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - src_ip_range
- - start_time
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.sessionContext.sessionIssuer.accountId
- - userIdentity.sessionContext.sessionIssuer.arn
- - userIdentity.sessionContext.sessionIssuer.principalId
- - userIdentity.sessionContext.sessionIssuer.type
- - userIdentity.sessionContext.sessionIssuer.userName
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- direction
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- protocol
+- protocol_code
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.aclProtocol
+- requestParameters.cidrBlock
+- requestParameters.egress
+- requestParameters.networkAclId
+- requestParameters.ruleAction
+- requestParameters.ruleNumber
+- responseElements._return
+- responseElements.requestId
+- rule_action
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- src_ip_range
+- start_time
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.sessionContext.sessionIssuer.accountId
+- userIdentity.sessionContext.sessionIssuer.arn
+- userIdentity.sessionContext.sessionIssuer.principalId
+- userIdentity.sessionContext.sessionIssuer.type
+- userIdentity.sessionContext.sessionIssuer.userName
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext":
diff --git a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml
index d5c2a78694..b8e4d54281 100644
--- a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml
+++ b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml
@@ -6,91 +6,91 @@ author: Patrick Bareiss, Splunk
description: Logs an event when the default version of a resource policy in AWS is
set or changed.
mitre_components:
- - Cloud Service Modification
- - Cloud Service Metadata
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: SetDefaultPolicyVersion
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.policyArn
- - requestParameters.versionId
- - responseElements
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.policyArn
+- requestParameters.versionId
+- responseElements
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLESDK2NOSX", "arn": "arn:aws:iam::111111111111:user/AtomicRedTeam",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLKMZDMPVA", "userName":
diff --git a/data_sources/aws_cloudtrail_stoplogging.yml b/data_sources/aws_cloudtrail_stoplogging.yml
index 934920e8fb..00d6b018a9 100644
--- a/data_sources/aws_cloudtrail_stoplogging.yml
+++ b/data_sources/aws_cloudtrail_stoplogging.yml
@@ -6,86 +6,86 @@ author: Patrick Bareiss, Splunk
description: Logs an event when a cloud service in AWS, such as CloudTrail, is deactivated
or stopped.
mitre_components:
- - Cloud Service Disable
+- Cloud Service Disable
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: StopLogging
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.name
- - responseElements
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - timeendpos
- - timestartpos
- - tlsDetails.cipherSuite
- - tlsDetails.clientProvidedHostHeader
- - tlsDetails.tlsVersion
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.name
+- responseElements
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- timeendpos
+- timestartpos
+- tlsDetails.cipherSuite
+- tlsDetails.clientProvidedHostHeader
+- tlsDetails.tlsVersion
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"},
diff --git a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml
index 6fd33c83e7..9c9fee7893 100644
--- a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml
+++ b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml
@@ -5,98 +5,98 @@ date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when an AWS account's password policy is updated.
mitre_components:
- - User Account Modification
- - Cloud Service Modification
+- User Account Modification
+- Cloud Service Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: UpdateAccountPasswordPolicy
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.allowUsersToChangePassword
- - requestParameters.hardExpiry
- - requestParameters.minimumPasswordLength
- - requestParameters.requireLowercaseCharacters
- - requestParameters.requireNumbers
- - requestParameters.requireSymbols
- - requestParameters.requireUppercaseCharacters
- - responseElements
- - sessionCredentialFromConsole
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.allowUsersToChangePassword
+- requestParameters.hardExpiry
+- requestParameters.minimumPasswordLength
+- requestParameters.requireLowercaseCharacters
+- requestParameters.requireNumbers
+- requestParameters.requireSymbols
+- requestParameters.requireUppercaseCharacters
+- responseElements
+- sessionCredentialFromConsole
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
"111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111",
"accessKeyId": "ASIASBMSCQHHZZ4THONS", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
diff --git a/data_sources/aws_cloudtrail_updateloginprofile.yml b/data_sources/aws_cloudtrail_updateloginprofile.yml
index 911021b6d6..ee8d48a0d4 100644
--- a/data_sources/aws_cloudtrail_updateloginprofile.yml
+++ b/data_sources/aws_cloudtrail_updateloginprofile.yml
@@ -5,90 +5,90 @@ date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when an IAM user's login profile is updated.
mitre_components:
- - User Account Modification
- - User Account Authentication
+- User Account Modification
+- User Account Authentication
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: UpdateLoginProfile
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.userName
- - responseElements
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- action
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.userName
+- responseElements
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
diff --git a/data_sources/aws_cloudtrail_updatesamlprovider.yml b/data_sources/aws_cloudtrail_updatesamlprovider.yml
index 3c7f55c5ea..55fb18209d 100644
--- a/data_sources/aws_cloudtrail_updatesamlprovider.yml
+++ b/data_sources/aws_cloudtrail_updatesamlprovider.yml
@@ -5,207 +5,188 @@ date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when a SAML provider is updated in AWS.
mitre_components:
- - Cloud Service Modification
- - User Account Modification
- - Cloud Service Metadata
+- Cloud Service Modification
+- User Account Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: UpdateSAMLProvider
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - action
- - app
- - awsRegion
- - aws_account_id
- - change_type
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - eventtype
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.sAMLMetadataDocument
- - requestParameters.sAMLProviderArn
- - responseElements.sAMLProviderArn
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.sessionContext.attributes.creationDate
- - userIdentity.sessionContext.attributes.mfaAuthenticated
- - userIdentity.sessionContext.sessionIssuer.accountId
- - userIdentity.sessionContext.sessionIssuer.arn
- - userIdentity.sessionContext.sessionIssuer.principalId
- - userIdentity.sessionContext.sessionIssuer.type
- - userIdentity.sessionContext.sessionIssuer.userName
- - userIdentity.type
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
-example_log: "{\"eventVersion\": \"1.08\", \"userIdentity\": {\"type\": \"AssumedRole\"\
- , \"principalId\": \"AROAYTOGP2RLKFUVAQAIJ:rodsoto@rodsoto.onmicrosoft.com\", \"\
- arn\": \"arn:aws:sts::111111111111:assumed-role/rodonmicrotestrole/rodsoto@rodsoto.onmicrosoft.com\"\
- , \"accountId\": \"111111111111\", \"accessKeyId\": \"ASIAYTOGP2RLMZGPIW6C\", \"\
- sessionContext\": {\"sessionIssuer\": {\"type\": \"Role\", \"principalId\": \"AROAYTOGP2RLKFUVAQAIJ\"\
- , \"arn\": \"arn:aws:iam::111111111111:role/rodonmicrotestrole\", \"accountId\"
- : \"111111111111\", \"userName\": \"rodonmicrotestrole\"}, \"webIdFederationData\"\
- : {}, \"attributes\": {\"mfaAuthenticated\": \"false\", \"creationDate\": \"2021-01-20T03:10:32Z\"\
- }}}, \"eventTime\": \"2021-01-20T03:12:39Z\", \"eventSource\": \"iam.amazonaws.com\"\
- , \"eventName\": \"UpdateSAMLProvider\", \"awsRegion\": \"us-east-1\", \"sourceIPAddress\"\
- : \"66.176.252.11\", \"userAgent\": \"aws-internal/3 aws-sdk-java/1.11.930 Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64
- OpenJDK_64-Bit_Server_VM/25.275-b01 java/1.8.0_275 vendor/Oracle_Corporation\",
- \"requestParameters\": {\"sAMLMetadataDocument\": \"ncp+pf0e75KdoRTy1PQeu74OKXjcVNM+bnT7Ns6cwQI=J9PRCq201gGMzMtt4Ye+gsM7xOgrNvDg/usqIMvsyUy2r/MeTBz5FKCK+Okjwm49vyTWUoUioYGiwm/TD2Knv59g1zy+/OjZcmBJgDrCmksFJdkwG/fDlOZQNGuj2qh1CEKL5n6Ipy2z1dQ9XUmhhndtXNnjdZ0fJ9QWufWoxveSCLHcU7eUB9obwq96pbAp+6as0XreMNC/xPv5gDdHfKaIppsXtEwcZY7m1c25jDWqPUTQrtbVC0uryffg1Yu0JLTr646GMTzxulBSpQGRfNf5UT0bUiLtKngi++UHrngKdv3ovWwpVmY82JhG7rMDhkuWZu3LdEFvY3svNxGtsQ==MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KNNameThe
+- _time
+- action
+- app
+- awsRegion
+- aws_account_id
+- change_type
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- eventtype
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.sAMLMetadataDocument
+- requestParameters.sAMLProviderArn
+- responseElements.sAMLProviderArn
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.sessionContext.attributes.creationDate
+- userIdentity.sessionContext.attributes.mfaAuthenticated
+- userIdentity.sessionContext.sessionIssuer.accountId
+- userIdentity.sessionContext.sessionIssuer.arn
+- userIdentity.sessionContext.sessionIssuer.principalId
+- userIdentity.sessionContext.sessionIssuer.type
+- userIdentity.sessionContext.sessionIssuer.userName
+- userIdentity.type
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
+example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
+ "AROAYTOGP2RLKFUVAQAIJ:rodsoto@rodsoto.onmicrosoft.com", "arn": "arn:aws:sts::111111111111:assumed-role/rodonmicrotestrole/rodsoto@rodsoto.onmicrosoft.com",
+ "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLMZGPIW6C", "sessionContext":
+ {"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLKFUVAQAIJ", "arn":
+ "arn:aws:iam::111111111111:role/rodonmicrotestrole", "accountId" : "111111111111",
+ "userName": "rodonmicrotestrole"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated":
+ "false", "creationDate": "2021-01-20T03:10:32Z"}}}, "eventTime": "2021-01-20T03:12:39Z",
+ "eventSource": "iam.amazonaws.com", "eventName": "UpdateSAMLProvider", "awsRegion":
+ "us-east-1", "sourceIPAddress": "66.176.252.11", "userAgent": "aws-internal/3 aws-sdk-java/1.11.930
+ Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.275-b01
+ java/1.8.0_275 vendor/Oracle_Corporation", "requestParameters": {"sAMLMetadataDocument":
+ "ncp+pf0e75KdoRTy1PQeu74OKXjcVNM+bnT7Ns6cwQI=J9PRCq201gGMzMtt4Ye+gsM7xOgrNvDg/usqIMvsyUy2r/MeTBz5FKCK+Okjwm49vyTWUoUioYGiwm/TD2Knv59g1zy+/OjZcmBJgDrCmksFJdkwG/fDlOZQNGuj2qh1CEKL5n6Ipy2z1dQ9XUmhhndtXNnjdZ0fJ9QWufWoxveSCLHcU7eUB9obwq96pbAp+6as0XreMNC/xPv5gDdHfKaIppsXtEwcZY7m1c25jDWqPUTQrtbVC0uryffg1Yu0JLTr646GMTzxulBSpQGRfNf5UT0bUiLtKngi++UHrngKdv3ovWwpVmY82JhG7rMDhkuWZu3LdEFvY3svNxGtsQ==MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KNNameThe
mutable display name of the user.SubjectAn
+ Uri=\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">SubjectAn
immutable, globally unique, non-reusable identifier of the user that is unique to
the application for which a token is issued.Given
+ Uri=\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">Given
NameFirst name of the user.SurnameLast
- name of the user.Display
+ Uri=\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">SurnameLast
+ name of the user.Display
NameDisplay name of the user.Nick
+ Uri=\"http://schemas.microsoft.com/identity/claims/nickname\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">Nick
NameNick name of the user.Authentication
+ Uri=\"http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant\"
+ xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">Authentication
InstantThe time (UTC) when the user is authenticated
to Windows Azure Active Directory.Authentication
+ Uri=\"http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod\"
+ xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">Authentication
MethodThe method that Windows Azure Active
Directory uses to authenticate users.ObjectIdentifierPrimary
+ Uri=\"http://schemas.microsoft.com/identity/claims/objectidentifier\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">ObjectIdentifierPrimary
identifier for the user in the directory. Immutable, globally unique, non-reusable.TenantIdIdentifier
- for the user's tenant.IdentityProviderIdentity
- provider for the user.EmailEmail
- address of the user.GroupsGroups
- of the user.External
+ Uri=\"http://schemas.microsoft.com/identity/claims/tenantid\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">TenantIdIdentifier
+ for the user''s tenant.IdentityProviderIdentity
+ provider for the user.EmailEmail
+ address of the user.GroupsGroups
+ of the user.External
Access TokenAccess token issued by external
- identity provider.External
+ identity provider.External
Access Token ExpirationUTC expiration time
of access token issued by external identity provider.External
+ Uri=\"http://schemas.microsoft.com/identity/claims/openid2_id\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">External
OpenID 2.0 IdentifierOpenID 2.0 identifier
issued by external identity provider.GroupsOverageClaimIssued
- when number of user's group claims exceeds return limit.Role
+ Uri=\"http://schemas.microsoft.com/claims/groups.link\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">GroupsOverageClaimIssued
+ when number of user''s group claims exceeds return limit.Role
ClaimRoles that the user or Service Principal
- is attached toRoleTemplate
+ is attached toRoleTemplate
Id ClaimRole template id of the Built-in Directory
Roles that the user is a member ofhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedMIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KNhttps://sts.windows.net/0e8108b1-18e9-41a4-961b-dfcddf92ef08/https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedMIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KN\", \"sAMLProviderArn\": \"arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft\"\
- }, \"responseElements\": {\"sAMLProviderArn\": \"arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft\"\
- }, \"requestID\": \"83d621ad-5b33-4ff0-acf4-0043cb432844\", \"eventID\": \"51b6d859-0cc4-4591-ba76-3494f3f43832\"\
- , \"readOnly\": false, \"eventType\": \"AwsApiCall\", \"managementEvent\": true,
- \"eventCategory\": \"Management\", \"recipientAccountId\": \"111111111111\"}"
+ xmlns:wsa=\"http://www.w3.org/2005/08/addressing\">https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedMIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KNhttps://sts.windows.net/0e8108b1-18e9-41a4-961b-dfcddf92ef08/https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedMIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KN", "sAMLProviderArn": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"},
+ "responseElements": {"sAMLProviderArn": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"},
+ "requestID": "83d621ad-5b33-4ff0-acf4-0043cb432844", "eventID": "51b6d859-0cc4-4591-ba76-3494f3f43832",
+ "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
+ "Management", "recipientAccountId": "111111111111"}'
diff --git a/data_sources/aws_cloudtrail_updatetrail.yml b/data_sources/aws_cloudtrail_updatetrail.yml
index 6020310ebe..33813ccfec 100644
--- a/data_sources/aws_cloudtrail_updatetrail.yml
+++ b/data_sources/aws_cloudtrail_updatetrail.yml
@@ -6,95 +6,95 @@ author: Patrick Bareiss, Splunk
description: Logs an event when an AWS CloudTrail trail is updated, typically involving
changes to settings or configuration.
mitre_components:
- - Cloud Service Modification
- - Cloud Service Metadata
+- Cloud Service Modification
+- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: UpdateTrail
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - app
- - awsRegion
- - aws_account_id
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - errorCode
- - eventCategory
- - eventID
- - eventName
- - eventSource
- - eventTime
- - eventType
- - eventVersion
- - host
- - index
- - linecount
- - managementEvent
- - msg
- - object_category
- - product
- - punct
- - readOnly
- - recipientAccountId
- - region
- - requestID
- - requestParameters.includeGlobalServiceEvents
- - requestParameters.isMultiRegionTrail
- - requestParameters.name
- - responseElements.includeGlobalServiceEvents
- - responseElements.isMultiRegionTrail
- - responseElements.isOrganizationTrail
- - responseElements.logFileValidationEnabled
- - responseElements.name
- - responseElements.s3BucketName
- - responseElements.trailARN
- - signature
- - source
- - sourceIPAddress
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - start_time
- - timeendpos
- - timestartpos
- - tlsDetails.cipherSuite
- - tlsDetails.clientProvidedHostHeader
- - tlsDetails.tlsVersion
- - user
- - userAgent
- - userIdentity.accessKeyId
- - userIdentity.accountId
- - userIdentity.arn
- - userIdentity.principalId
- - userIdentity.type
- - userIdentity.userName
- - userName
- - user_access_key
- - user_agent
- - user_arn
- - user_group_id
- - user_id
- - user_name
- - user_type
- - vendor
- - vendor_account
- - vendor_product
- - vendor_region
+- _time
+- app
+- awsRegion
+- aws_account_id
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- errorCode
+- eventCategory
+- eventID
+- eventName
+- eventSource
+- eventTime
+- eventType
+- eventVersion
+- host
+- index
+- linecount
+- managementEvent
+- msg
+- object_category
+- product
+- punct
+- readOnly
+- recipientAccountId
+- region
+- requestID
+- requestParameters.includeGlobalServiceEvents
+- requestParameters.isMultiRegionTrail
+- requestParameters.name
+- responseElements.includeGlobalServiceEvents
+- responseElements.isMultiRegionTrail
+- responseElements.isOrganizationTrail
+- responseElements.logFileValidationEnabled
+- responseElements.name
+- responseElements.s3BucketName
+- responseElements.trailARN
+- signature
+- source
+- sourceIPAddress
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- start_time
+- timeendpos
+- timestartpos
+- tlsDetails.cipherSuite
+- tlsDetails.clientProvidedHostHeader
+- tlsDetails.tlsVersion
+- user
+- userAgent
+- userIdentity.accessKeyId
+- userIdentity.accountId
+- userIdentity.arn
+- userIdentity.principalId
+- userIdentity.type
+- userIdentity.userName
+- userName
+- user_access_key
+- user_agent
+- user_arn
+- user_group_id
+- user_id
+- user_name
+- user_type
+- vendor
+- vendor_account
+- vendor_product
+- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
diff --git a/data_sources/aws_cloudwatchlogs_vpcflow.yml b/data_sources/aws_cloudwatchlogs_vpcflow.yml
index 6cd8b1cec1..535431134a 100644
--- a/data_sources/aws_cloudwatchlogs_vpcflow.yml
+++ b/data_sources/aws_cloudwatchlogs_vpcflow.yml
@@ -7,67 +7,67 @@ description: Logs an event when network traffic flow information such as source
destination IPs, ports, protocol, and action (allow/deny) is captured for VPC in
AWS.
mitre_components:
- - Network Traffic Flow
- - Network Connection Creation
+- Network Traffic Flow
+- Network Connection Creation
source: aws_cloudwatchlogs_vpcflow
sourcetype: aws:cloudwatchlogs:vpcflow
supported_TA:
- - name: Splunk Add-on for AWS
- version: 7.9.0
- url: https://splunkbase.splunk.com/app/1876
+- name: Splunk Add-on for AWS
+ version: 7.9.0
+ url: https://splunkbase.splunk.com/app/1876
fields:
- - _raw
- - _time
- - account_id
- - action
- - app
- - aws_account_id
- - bytes
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_ip
- - dest_port
- - duration
- - dvc
- - end_time
- - eventtype
- - host
- - index
- - interface_id
- - linecount
- - log_status
- - packets
- - protocol
- - protocol_code
- - protocol_full_name
- - protocol_version
- - punct
- - region
- - source
- - sourcetype
- - splunk_server
- - splunk_server_group
- - src
- - src_ip
- - src_port
- - start_time
- - tag
- - tag::action
- - tag::eventtype
- - timeendpos
- - timestartpos
- - transport
- - user_id
- - vendor_account
- - vendor_product
- - version
- - vpcflow_action
+- _raw
+- _time
+- account_id
+- action
+- app
+- aws_account_id
+- bytes
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_ip
+- dest_port
+- duration
+- dvc
+- end_time
+- eventtype
+- host
+- index
+- interface_id
+- linecount
+- log_status
+- packets
+- protocol
+- protocol_code
+- protocol_full_name
+- protocol_version
+- punct
+- region
+- source
+- sourcetype
+- splunk_server
+- splunk_server_group
+- src
+- src_ip
+- src_port
+- start_time
+- tag
+- tag::action
+- tag::eventtype
+- timeendpos
+- timestartpos
+- transport
+- user_id
+- vendor_account
+- vendor_product
+- version
+- vpcflow_action
example_log: 2 123397614277 eni-0b0f9f261f45e6489 10.0.1.30 10.0.1.1 47254 22 17 2
98 1697608042 1697608070 ACCEPT OK
diff --git a/data_sources/aws_security_hub.yml b/data_sources/aws_security_hub.yml
index 0173357cdf..c5ff1ade29 100644
--- a/data_sources/aws_security_hub.yml
+++ b/data_sources/aws_security_hub.yml
@@ -6,120 +6,120 @@ author: Patrick Bareiss, Splunk
description: Logs an event when AWS Security Hub identifies potential security risks
or deviations from configured best practices across AWS accounts.
mitre_components:
- - Cloud Service Metadata
- - Cloud Service Enumeration
- - Cloud Service Modification
- - Cloud Service Disable
+- Cloud Service Metadata
+- Cloud Service Enumeration
+- Cloud Service Modification
+- Cloud Service Disable
source: aws_securityhub_finding
sourcetype: aws:securityhub:finding
supported_TA:
- - name: Splunk Add-on for AWS
- url: https://splunkbase.splunk.com/app/1876
- version: 7.9.0
+- name: Splunk Add-on for AWS
+ url: https://splunkbase.splunk.com/app/1876
+ version: 7.9.0
fields:
- - _time
- - AwsAccountId
- - CreatedAt
- - Description
- - FirstObservedAt
- - GeneratorId
- - Id
- - LastObservedAt
- - ProductArn
- - ProductFields.aws/guardduty/service/action/actionType
- - ProductFields.aws/guardduty/service/action/awsApiCallAction/affectedResources/AWS::S3::Bucket
- - ProductFields.aws/guardduty/service/action/awsApiCallAction/api
- - ProductFields.aws/guardduty/service/action/awsApiCallAction/callerType
- - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/city/cityName
- - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/country/countryName
- - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lat
- - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lon
- - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/ipAddressV4
- - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asn
- - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asnOrg
- - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/isp
- - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/org
- - ProductFields.aws/guardduty/service/action/awsApiCallAction/serviceName
- - ProductFields.aws/guardduty/service/additionalInfo/sample
- - ProductFields.aws/guardduty/service/additionalInfo/unusual/hoursOfDay.0_
- - ProductFields.aws/guardduty/service/additionalInfo/unusual/userNames.0_
- - ProductFields.aws/guardduty/service/archived
- - ProductFields.aws/guardduty/service/count
- - ProductFields.aws/guardduty/service/detectorId
- - ProductFields.aws/guardduty/service/eventFirstSeen
- - ProductFields.aws/guardduty/service/eventLastSeen
- - ProductFields.aws/guardduty/service/resourceRole
- - ProductFields.aws/guardduty/service/serviceName
- - ProductFields.aws/securityhub/CompanyName
- - ProductFields.aws/securityhub/FindingId
- - ProductFields.aws/securityhub/ProductName
- - RecordState
- - Resources{}.Details.AwsEc2Instance.IamInstanceProfileArn
- - Resources{}.Details.AwsEc2Instance.ImageId
- - Resources{}.Details.AwsEc2Instance.IpV4Addresses{}
- - Resources{}.Details.AwsEc2Instance.LaunchedAt
- - Resources{}.Details.AwsEc2Instance.SubnetId
- - Resources{}.Details.AwsEc2Instance.Type
- - Resources{}.Details.AwsEc2Instance.VpcId
- - Resources{}.Details.AwsIamAccessKey.PrincipalId
- - Resources{}.Details.AwsIamAccessKey.PrincipalName
- - Resources{}.Details.AwsIamAccessKey.PrincipalType
- - Resources{}.Details.AwsS3Bucket.CreatedAt
- - Resources{}.Details.AwsS3Bucket.OwnerId
- - Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.KMSMasterKeyID
- - Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.SSEAlgorithm
- - Resources{}.Id
- - Resources{}.Partition
- - Resources{}.Region
- - Resources{}.Tags.GeneratedFindingInstaceTag1
- - Resources{}.Tags.GeneratedFindingInstaceTag2
- - Resources{}.Tags.GeneratedFindingInstaceTag3
- - Resources{}.Tags.GeneratedFindingInstaceTag4
- - Resources{}.Tags.GeneratedFindingInstaceTag5
- - Resources{}.Tags.GeneratedFindingInstaceTag6
- - Resources{}.Tags.GeneratedFindingInstaceTag7
- - Resources{}.Tags.GeneratedFindingInstaceTag8
- - Resources{}.Tags.GeneratedFindingInstaceTag9
- - Resources{}.Tags.foo
- - Resources{}.Type
- - SchemaVersion
- - Severity.Label
- - Severity.Normalized
- - Severity.Product
- - SourceUrl
- - Title
- - Types{}
- - UpdatedAt
- - Workflow.Status
- - WorkflowState
- - accesskey_extract
- - app
- - body
- - description
- - dest
- - dest_type
- - eventtype
- - host
- - id
- - index
- - instance_extract
- - linecount
- - punct
- - s3bucket_extract
- - severity
- - severity_id
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - subject
- - tag
- - tag::eventtype
- - timestamp
- - type
- - vendor_account
- - vendor_region
+- _time
+- AwsAccountId
+- CreatedAt
+- Description
+- FirstObservedAt
+- GeneratorId
+- Id
+- LastObservedAt
+- ProductArn
+- ProductFields.aws/guardduty/service/action/actionType
+- ProductFields.aws/guardduty/service/action/awsApiCallAction/affectedResources/AWS::S3::Bucket
+- ProductFields.aws/guardduty/service/action/awsApiCallAction/api
+- ProductFields.aws/guardduty/service/action/awsApiCallAction/callerType
+- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/city/cityName
+- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/country/countryName
+- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lat
+- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lon
+- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/ipAddressV4
+- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asn
+- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asnOrg
+- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/isp
+- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/org
+- ProductFields.aws/guardduty/service/action/awsApiCallAction/serviceName
+- ProductFields.aws/guardduty/service/additionalInfo/sample
+- ProductFields.aws/guardduty/service/additionalInfo/unusual/hoursOfDay.0_
+- ProductFields.aws/guardduty/service/additionalInfo/unusual/userNames.0_
+- ProductFields.aws/guardduty/service/archived
+- ProductFields.aws/guardduty/service/count
+- ProductFields.aws/guardduty/service/detectorId
+- ProductFields.aws/guardduty/service/eventFirstSeen
+- ProductFields.aws/guardduty/service/eventLastSeen
+- ProductFields.aws/guardduty/service/resourceRole
+- ProductFields.aws/guardduty/service/serviceName
+- ProductFields.aws/securityhub/CompanyName
+- ProductFields.aws/securityhub/FindingId
+- ProductFields.aws/securityhub/ProductName
+- RecordState
+- Resources{}.Details.AwsEc2Instance.IamInstanceProfileArn
+- Resources{}.Details.AwsEc2Instance.ImageId
+- Resources{}.Details.AwsEc2Instance.IpV4Addresses{}
+- Resources{}.Details.AwsEc2Instance.LaunchedAt
+- Resources{}.Details.AwsEc2Instance.SubnetId
+- Resources{}.Details.AwsEc2Instance.Type
+- Resources{}.Details.AwsEc2Instance.VpcId
+- Resources{}.Details.AwsIamAccessKey.PrincipalId
+- Resources{}.Details.AwsIamAccessKey.PrincipalName
+- Resources{}.Details.AwsIamAccessKey.PrincipalType
+- Resources{}.Details.AwsS3Bucket.CreatedAt
+- Resources{}.Details.AwsS3Bucket.OwnerId
+- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.KMSMasterKeyID
+- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.SSEAlgorithm
+- Resources{}.Id
+- Resources{}.Partition
+- Resources{}.Region
+- Resources{}.Tags.GeneratedFindingInstaceTag1
+- Resources{}.Tags.GeneratedFindingInstaceTag2
+- Resources{}.Tags.GeneratedFindingInstaceTag3
+- Resources{}.Tags.GeneratedFindingInstaceTag4
+- Resources{}.Tags.GeneratedFindingInstaceTag5
+- Resources{}.Tags.GeneratedFindingInstaceTag6
+- Resources{}.Tags.GeneratedFindingInstaceTag7
+- Resources{}.Tags.GeneratedFindingInstaceTag8
+- Resources{}.Tags.GeneratedFindingInstaceTag9
+- Resources{}.Tags.foo
+- Resources{}.Type
+- SchemaVersion
+- Severity.Label
+- Severity.Normalized
+- Severity.Product
+- SourceUrl
+- Title
+- Types{}
+- UpdatedAt
+- Workflow.Status
+- WorkflowState
+- accesskey_extract
+- app
+- body
+- description
+- dest
+- dest_type
+- eventtype
+- host
+- id
+- index
+- instance_extract
+- linecount
+- punct
+- s3bucket_extract
+- severity
+- severity_id
+- signature
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- subject
+- tag
+- tag::eventtype
+- timestamp
+- type
+- vendor_account
+- vendor_region
example_log: '{"ProductArn":"arn:aws:securityhub:us-east-1::product/aws/guardduty","Types":["Software
and Configuration Checks/Exfiltration:S3.ObjectRead.Unusual"],"SourceUrl":"https://us-east-1.console.aws.amazon.com/guardduty/home?region=us-east-1#/findings?macros=current&fId=6aba6b696aea10606e8b336f68d98819","Description":"Principal
GeneratedFindingUserName read objects from S3 bucket GeneratedFindingS3Bucket in
diff --git a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml
index b0f85d0cb5..034f25fb98 100644
--- a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml
+++ b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml
@@ -7,93 +7,93 @@ description: Logs the addition of an application role assignment to a service pr
in Azure Active Directory, including details about the role, service principal,
and the user or process performing the action.
mitre_components:
- - User Account Modification
- - Group Modification
- - Cloud Service Modification
- - Cloud Service Metadata
+- User Account Modification
+- Group Modification
+- Cloud Service Modification
+- Cloud Service Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Add app role assignment to service principal
supported_TA:
- - name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+- name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
- - _time
- - Level
- - additional_details
- - additional_details_name
- - additional_details_value
- - category
- - command
- - correlationId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_type
- - durationMs
- - dvc
- - eventtype
- - host
- - id
- - identity
- - index
- - linecount
- - object_attrs
- - object_id
- - operationName
- - operationVersion
- - path_from_resourceId
- - properties.activityDateTime
- - properties.activityDisplayName
- - properties.additionalDetails{}.key
- - properties.additionalDetails{}.value
- - properties.category
- - properties.correlationId
- - properties.id
- - properties.initiatedBy.app.appId
- - properties.initiatedBy.app.displayName
- - properties.initiatedBy.app.servicePrincipalId
- - properties.initiatedBy.app.servicePrincipalName
- - properties.loggedByService
- - properties.operationType
- - properties.result
- - properties.resultReason
- - properties.targetResources{}.displayName
- - properties.targetResources{}.id
- - properties.targetResources{}.modifiedProperties{}.displayName
- - properties.targetResources{}.modifiedProperties{}.newValue
- - properties.targetResources{}.modifiedProperties{}.oldValue
- - properties.targetResources{}.type
- - properties.userAgent
- - punct
- - resourceId
- - result
- - resultSignature
- - result_id
- - signature
- - source
- - sourcetype
- - splunk_server
- - src_user_type
- - status
- - tag
- - tag::eventtype
- - tenantId
- - time
- - timeendpos
- - timestartpos
- - user_agent
- - user_type
- - vendor_account
- - vendor_product
+- _time
+- Level
+- additional_details
+- additional_details_name
+- additional_details_value
+- category
+- command
+- correlationId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_type
+- durationMs
+- dvc
+- eventtype
+- host
+- id
+- identity
+- index
+- linecount
+- object_attrs
+- object_id
+- operationName
+- operationVersion
+- path_from_resourceId
+- properties.activityDateTime
+- properties.activityDisplayName
+- properties.additionalDetails{}.key
+- properties.additionalDetails{}.value
+- properties.category
+- properties.correlationId
+- properties.id
+- properties.initiatedBy.app.appId
+- properties.initiatedBy.app.displayName
+- properties.initiatedBy.app.servicePrincipalId
+- properties.initiatedBy.app.servicePrincipalName
+- properties.loggedByService
+- properties.operationType
+- properties.result
+- properties.resultReason
+- properties.targetResources{}.displayName
+- properties.targetResources{}.id
+- properties.targetResources{}.modifiedProperties{}.displayName
+- properties.targetResources{}.modifiedProperties{}.newValue
+- properties.targetResources{}.modifiedProperties{}.oldValue
+- properties.targetResources{}.type
+- properties.userAgent
+- punct
+- resourceId
+- result
+- resultSignature
+- result_id
+- signature
+- source
+- sourcetype
+- splunk_server
+- src_user_type
+- status
+- tag
+- tag::eventtype
+- tenantId
+- time
+- timeendpos
+- timestartpos
+- user_agent
+- user_type
+- vendor_account
+- vendor_product
example_log: '{"time": "2024-02-08T21:49:53.7643129Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam",
"operationName": "Add app role assignment to service principal", "operationVersion":
"1.0", "category": "AuditLogs", "tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
diff --git a/data_sources/azure_active_directory_add_member_to_role.yml b/data_sources/azure_active_directory_add_member_to_role.yml
index 8a977d8625..579bd563b7 100644
--- a/data_sources/azure_active_directory_add_member_to_role.yml
+++ b/data_sources/azure_active_directory_add_member_to_role.yml
@@ -7,69 +7,69 @@ description: Logs the addition of a member to a directory role in Azure Active D
including details about the role, the member added, and the user or process performing
the action.
mitre_components:
- - Group Modification
- - Group Metadata
- - User Account Metadata
- - Cloud Service Modification
+- Group Modification
+- Group Metadata
+- User Account Metadata
+- Cloud Service Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Add member to role
supported_TA:
- - name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+- name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
- - _time
- - Level
- - callerIpAddress
- - category
- - correlationId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - durationMs
- - host
- - index
- - linecount
- - operationName
- - operationVersion
- - properties.activityDateTime
- - properties.activityDisplayName
- - properties.category
- - properties.correlationId
- - properties.id
- - properties.initiatedBy.user.displayName
- - properties.initiatedBy.user.id
- - properties.initiatedBy.user.ipAddress
- - properties.initiatedBy.user.userPrincipalName
- - properties.loggedByService
- - properties.operationType
- - properties.result
- - properties.resultReason
- - properties.targetResources{}.displayName
- - properties.targetResources{}.id
- - properties.targetResources{}.modifiedProperties{}.displayName
- - properties.targetResources{}.modifiedProperties{}.newValue
- - properties.targetResources{}.modifiedProperties{}.oldValue
- - properties.targetResources{}.type
- - properties.targetResources{}.userPrincipalName
- - properties.userAgent
- - punct
- - resourceId
- - resultSignature
- - source
- - sourcetype
- - splunk_server
- - tenantId
- - time
- - timeendpos
- - timestartpos
+- _time
+- Level
+- callerIpAddress
+- category
+- correlationId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- durationMs
+- host
+- index
+- linecount
+- operationName
+- operationVersion
+- properties.activityDateTime
+- properties.activityDisplayName
+- properties.category
+- properties.correlationId
+- properties.id
+- properties.initiatedBy.user.displayName
+- properties.initiatedBy.user.id
+- properties.initiatedBy.user.ipAddress
+- properties.initiatedBy.user.userPrincipalName
+- properties.loggedByService
+- properties.operationType
+- properties.result
+- properties.resultReason
+- properties.targetResources{}.displayName
+- properties.targetResources{}.id
+- properties.targetResources{}.modifiedProperties{}.displayName
+- properties.targetResources{}.modifiedProperties{}.newValue
+- properties.targetResources{}.modifiedProperties{}.oldValue
+- properties.targetResources{}.type
+- properties.targetResources{}.userPrincipalName
+- properties.userAgent
+- punct
+- resourceId
+- resultSignature
+- source
+- sourcetype
+- splunk_server
+- tenantId
+- time
+- timeendpos
+- timestartpos
example_log: '{"time": "2023-04-28T16:39:51.9312625Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Add member to role", "operationVersion": "1.0", "category": "AuditLogs",
"tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs":
diff --git a/data_sources/azure_active_directory_add_owner_to_application.yml b/data_sources/azure_active_directory_add_owner_to_application.yml
index 70948b2b1f..fb97560390 100644
--- a/data_sources/azure_active_directory_add_owner_to_application.yml
+++ b/data_sources/azure_active_directory_add_owner_to_application.yml
@@ -7,74 +7,74 @@ description: Logs the addition of an owner to an application in Azure Active Dir
including details about the application, the owner added, and the user or process
performing the action.
mitre_components:
- - User Account Modification
- - Group Modification
- - Cloud Service Modification
- - Cloud Service Metadata
+- User Account Modification
+- Group Modification
+- Cloud Service Modification
+- Cloud Service Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Add owner to application
supported_TA:
- - name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+- name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
- - _time
- - Level
- - callerIpAddress
- - category
- - correlationId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - durationMs
- - eventtype
- - host
- - index
- - linecount
- - operationName
- - operationVersion
- - properties.activityDateTime
- - properties.activityDisplayName
- - properties.additionalDetails{}.key
- - properties.additionalDetails{}.value
- - properties.category
- - properties.correlationId
- - properties.id
- - properties.initiatedBy.user.displayName
- - properties.initiatedBy.user.id
- - properties.initiatedBy.user.ipAddress
- - properties.initiatedBy.user.userPrincipalName
- - properties.loggedByService
- - properties.operationType
- - properties.result
- - properties.resultReason
- - properties.targetResources{}.displayName
- - properties.targetResources{}.id
- - properties.targetResources{}.modifiedProperties{}.displayName
- - properties.targetResources{}.modifiedProperties{}.newValue
- - properties.targetResources{}.modifiedProperties{}.oldValue
- - properties.targetResources{}.type
- - properties.targetResources{}.userPrincipalName
- - properties.userAgent
- - punct
- - resourceId
- - resultSignature
- - source
- - sourcetype
- - splunk_server
- - tag
- - tag::eventtype
- - tenantId
- - time
- - timeendpos
- - timestartpos
+- _time
+- Level
+- callerIpAddress
+- category
+- correlationId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- durationMs
+- eventtype
+- host
+- index
+- linecount
+- operationName
+- operationVersion
+- properties.activityDateTime
+- properties.activityDisplayName
+- properties.additionalDetails{}.key
+- properties.additionalDetails{}.value
+- properties.category
+- properties.correlationId
+- properties.id
+- properties.initiatedBy.user.displayName
+- properties.initiatedBy.user.id
+- properties.initiatedBy.user.ipAddress
+- properties.initiatedBy.user.userPrincipalName
+- properties.loggedByService
+- properties.operationType
+- properties.result
+- properties.resultReason
+- properties.targetResources{}.displayName
+- properties.targetResources{}.id
+- properties.targetResources{}.modifiedProperties{}.displayName
+- properties.targetResources{}.modifiedProperties{}.newValue
+- properties.targetResources{}.modifiedProperties{}.oldValue
+- properties.targetResources{}.type
+- properties.targetResources{}.userPrincipalName
+- properties.userAgent
+- punct
+- resourceId
+- resultSignature
+- source
+- sourcetype
+- splunk_server
+- tag
+- tag::eventtype
+- tenantId
+- time
+- timeendpos
+- timestartpos
example_log: '{"time": "2023-06-20T15:54:13.2420879Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Add owner to application", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
diff --git a/data_sources/azure_active_directory_add_service_principal.yml b/data_sources/azure_active_directory_add_service_principal.yml
index 46f3c3d7d9..c3d937cb44 100644
--- a/data_sources/azure_active_directory_add_service_principal.yml
+++ b/data_sources/azure_active_directory_add_service_principal.yml
@@ -7,69 +7,69 @@ description: Logs the creation of a new service principal in Azure Active Direct
including details about the service principal, associated application, and the user
or process performing the action.
mitre_components:
- - Cloud Service Creation
- - Cloud Service Metadata
- - User Account Metadata
- - Active Directory Object Creation
+- Cloud Service Creation
+- Cloud Service Metadata
+- User Account Metadata
+- Active Directory Object Creation
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Add service principal
supported_TA:
- - name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+- name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
- - _time
- - Level
- - category
- - correlationId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - durationMs
- - host
- - index
- - linecount
- - operationName
- - operationVersion
- - properties.activityDateTime
- - properties.activityDisplayName
- - properties.additionalDetails{}.key
- - properties.additionalDetails{}.value
- - properties.category
- - properties.correlationId
- - properties.id
- - properties.initiatedBy.user.displayName
- - properties.initiatedBy.user.id
- - properties.initiatedBy.user.ipAddress
- - properties.initiatedBy.user.userPrincipalName
- - properties.loggedByService
- - properties.operationType
- - properties.result
- - properties.resultReason
- - properties.targetResources{}.displayName
- - properties.targetResources{}.id
- - properties.targetResources{}.modifiedProperties{}.displayName
- - properties.targetResources{}.modifiedProperties{}.newValue
- - properties.targetResources{}.modifiedProperties{}.oldValue
- - properties.targetResources{}.type
- - properties.userAgent
- - punct
- - resourceId
- - resultSignature
- - source
- - sourcetype
- - splunk_server
- - tenantId
- - time
- - timeendpos
- - timestartpos
+- _time
+- Level
+- category
+- correlationId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- durationMs
+- host
+- index
+- linecount
+- operationName
+- operationVersion
+- properties.activityDateTime
+- properties.activityDisplayName
+- properties.additionalDetails{}.key
+- properties.additionalDetails{}.value
+- properties.category
+- properties.correlationId
+- properties.id
+- properties.initiatedBy.user.displayName
+- properties.initiatedBy.user.id
+- properties.initiatedBy.user.ipAddress
+- properties.initiatedBy.user.userPrincipalName
+- properties.loggedByService
+- properties.operationType
+- properties.result
+- properties.resultReason
+- properties.targetResources{}.displayName
+- properties.targetResources{}.id
+- properties.targetResources{}.modifiedProperties{}.displayName
+- properties.targetResources{}.modifiedProperties{}.newValue
+- properties.targetResources{}.modifiedProperties{}.oldValue
+- properties.targetResources{}.type
+- properties.userAgent
+- punct
+- resourceId
+- resultSignature
+- source
+- sourcetype
+- splunk_server
+- tenantId
+- time
+- timeendpos
+- timestartpos
example_log: '{"time": "2024-02-07T22:31:14.4970418Z", "resourceId": "/tenants/a417c578-c7ee-480d-a225-d48057e74df5/providers/Microsoft.aadiam",
"operationName": "Add service principal", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "a417c578-c7ee-480d-a225-d48057e74df5", "resultSignature":
diff --git a/data_sources/azure_active_directory_add_unverified_domain.yml b/data_sources/azure_active_directory_add_unverified_domain.yml
index 444d3e1a6f..01badc54df 100644
--- a/data_sources/azure_active_directory_add_unverified_domain.yml
+++ b/data_sources/azure_active_directory_add_unverified_domain.yml
@@ -6,69 +6,69 @@ author: Patrick Bareiss, Splunk
description: Logs the addition of an unverified domain to Azure Active Directory,
including details about the domain name and the user or process performing the action.
mitre_components:
- - Domain Registration
- - Cloud Service Modification
- - Cloud Service Metadata
- - Configuration Modification
+- Domain Registration
+- Cloud Service Modification
+- Cloud Service Metadata
+- Configuration Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Add unverified domain
supported_TA:
- - name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+- name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
- - _time
- - Level
- - callerIpAddress
- - category
- - correlationId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - durationMs
- - host
- - index
- - linecount
- - operationName
- - operationVersion
- - properties.activityDateTime
- - properties.activityDisplayName
- - properties.additionalDetails{}.key
- - properties.additionalDetails{}.value
- - properties.category
- - properties.correlationId
- - properties.id
- - properties.initiatedBy.user.displayName
- - properties.initiatedBy.user.id
- - properties.initiatedBy.user.ipAddress
- - properties.initiatedBy.user.userPrincipalName
- - properties.loggedByService
- - properties.operationType
- - properties.result
- - properties.resultReason
- - properties.targetResources{}.displayName
- - properties.targetResources{}.id
- - properties.targetResources{}.modifiedProperties{}.displayName
- - properties.targetResources{}.modifiedProperties{}.newValue
- - properties.targetResources{}.modifiedProperties{}.oldValue
- - properties.userAgent
- - punct
- - resourceId
- - resultSignature
- - source
- - sourcetype
- - splunk_server
- - tenantId
- - time
- - timeendpos
- - timestartpos
+- _time
+- Level
+- callerIpAddress
+- category
+- correlationId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- durationMs
+- host
+- index
+- linecount
+- operationName
+- operationVersion
+- properties.activityDateTime
+- properties.activityDisplayName
+- properties.additionalDetails{}.key
+- properties.additionalDetails{}.value
+- properties.category
+- properties.correlationId
+- properties.id
+- properties.initiatedBy.user.displayName
+- properties.initiatedBy.user.id
+- properties.initiatedBy.user.ipAddress
+- properties.initiatedBy.user.userPrincipalName
+- properties.loggedByService
+- properties.operationType
+- properties.result
+- properties.resultReason
+- properties.targetResources{}.displayName
+- properties.targetResources{}.id
+- properties.targetResources{}.modifiedProperties{}.displayName
+- properties.targetResources{}.modifiedProperties{}.newValue
+- properties.targetResources{}.modifiedProperties{}.oldValue
+- properties.userAgent
+- punct
+- resourceId
+- resultSignature
+- source
+- sourcetype
+- splunk_server
+- tenantId
+- time
+- timeendpos
+- timestartpos
example_log: '{"time": "2023-07-26T13:45:54.1582053Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Add unverified domain", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
diff --git a/data_sources/azure_active_directory_consent_to_application.yml b/data_sources/azure_active_directory_consent_to_application.yml
index 4222ab6a7c..4bc104a119 100644
--- a/data_sources/azure_active_directory_consent_to_application.yml
+++ b/data_sources/azure_active_directory_consent_to_application.yml
@@ -7,74 +7,74 @@ description: Logs user or admin consent to an application's permissions in Azure
Directory, including details about the application, granted permissions, and the
consenting user or process.
mitre_components:
- - User Account Modification
- - Cloud Service Modification
- - Cloud Service Metadata
- - Configuration Modification
+- User Account Modification
+- Cloud Service Modification
+- Cloud Service Metadata
+- Configuration Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Consent to application
supported_TA:
- - name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+- name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
- - _time
- - Level
- - callerIpAddress
- - category
- - correlationId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - durationMs
- - eventtype
- - host
- - index
- - linecount
- - operationName
- - operationVersion
- - properties.activityDateTime
- - properties.activityDisplayName
- - properties.additionalDetails{}.key
- - properties.additionalDetails{}.value
- - properties.category
- - properties.correlationId
- - properties.id
- - properties.initiatedBy.user.displayName
- - properties.initiatedBy.user.id
- - properties.initiatedBy.user.ipAddress
- - properties.initiatedBy.user.userPrincipalName
- - properties.loggedByService
- - properties.operationType
- - properties.result
- - properties.resultReason
- - properties.targetResources{}.displayName
- - properties.targetResources{}.id
- - properties.targetResources{}.modifiedProperties{}.displayName
- - properties.targetResources{}.modifiedProperties{}.newValue
- - properties.targetResources{}.modifiedProperties{}.oldValue
- - properties.targetResources{}.type
- - properties.userAgent
- - punct
- - resourceId
- - resultDescription
- - resultSignature
- - source
- - sourcetype
- - splunk_server
- - tag
- - tag::eventtype
- - tenantId
- - time
- - timeendpos
- - timestartpos
+- _time
+- Level
+- callerIpAddress
+- category
+- correlationId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- durationMs
+- eventtype
+- host
+- index
+- linecount
+- operationName
+- operationVersion
+- properties.activityDateTime
+- properties.activityDisplayName
+- properties.additionalDetails{}.key
+- properties.additionalDetails{}.value
+- properties.category
+- properties.correlationId
+- properties.id
+- properties.initiatedBy.user.displayName
+- properties.initiatedBy.user.id
+- properties.initiatedBy.user.ipAddress
+- properties.initiatedBy.user.userPrincipalName
+- properties.loggedByService
+- properties.operationType
+- properties.result
+- properties.resultReason
+- properties.targetResources{}.displayName
+- properties.targetResources{}.id
+- properties.targetResources{}.modifiedProperties{}.displayName
+- properties.targetResources{}.modifiedProperties{}.newValue
+- properties.targetResources{}.modifiedProperties{}.oldValue
+- properties.targetResources{}.type
+- properties.userAgent
+- punct
+- resourceId
+- resultDescription
+- resultSignature
+- source
+- sourcetype
+- splunk_server
+- tag
+- tag::eventtype
+- tenantId
+- time
+- timeendpos
+- timestartpos
example_log: '{"time": "2023-10-27T16:14:14.9747033Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam",
"operationName": "Consent to application", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "resultSignature":
diff --git a/data_sources/azure_active_directory_disable_strong_authentication.yml b/data_sources/azure_active_directory_disable_strong_authentication.yml
index 6c329d8872..72d6e69e4c 100644
--- a/data_sources/azure_active_directory_disable_strong_authentication.yml
+++ b/data_sources/azure_active_directory_disable_strong_authentication.yml
@@ -6,67 +6,67 @@ author: Patrick Bareiss, Splunk
description: Logs an event when strong authentication methods are disabled in Azure
Active Directory.
mitre_components:
- - User Account Authentication
- - User Account Modification
- - Cloud Service Modification
+- User Account Authentication
+- User Account Modification
+- Cloud Service Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Disable Strong Authentication
supported_TA:
- - name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+- name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
- - _time
- - Level
- - category
- - correlationId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - durationMs
- - host
- - index
- - linecount
- - operationName
- - operationVersion
- - properties.activityDateTime
- - properties.activityDisplayName
- - properties.category
- - properties.correlationId
- - properties.id
- - properties.initiatedBy.user.displayName
- - properties.initiatedBy.user.id
- - properties.initiatedBy.user.ipAddress
- - properties.initiatedBy.user.userPrincipalName
- - properties.loggedByService
- - properties.operationType
- - properties.result
- - properties.resultReason
- - properties.targetResources{}.displayName
- - properties.targetResources{}.id
- - properties.targetResources{}.modifiedProperties{}.displayName
- - properties.targetResources{}.modifiedProperties{}.newValue
- - properties.targetResources{}.modifiedProperties{}.oldValue
- - properties.targetResources{}.type
- - properties.targetResources{}.userPrincipalName
- - properties.userAgent
- - punct
- - resourceId
- - resultSignature
- - source
- - sourcetype
- - splunk_server
- - tenantId
- - time
- - timeendpos
- - timestartpos
+- _time
+- Level
+- category
+- correlationId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- durationMs
+- host
+- index
+- linecount
+- operationName
+- operationVersion
+- properties.activityDateTime
+- properties.activityDisplayName
+- properties.category
+- properties.correlationId
+- properties.id
+- properties.initiatedBy.user.displayName
+- properties.initiatedBy.user.id
+- properties.initiatedBy.user.ipAddress
+- properties.initiatedBy.user.userPrincipalName
+- properties.loggedByService
+- properties.operationType
+- properties.result
+- properties.resultReason
+- properties.targetResources{}.displayName
+- properties.targetResources{}.id
+- properties.targetResources{}.modifiedProperties{}.displayName
+- properties.targetResources{}.modifiedProperties{}.newValue
+- properties.targetResources{}.modifiedProperties{}.oldValue
+- properties.targetResources{}.type
+- properties.targetResources{}.userPrincipalName
+- properties.userAgent
+- punct
+- resourceId
+- resultSignature
+- source
+- sourcetype
+- splunk_server
+- tenantId
+- time
+- timeendpos
+- timestartpos
example_log: '{"time": "2023-07-11T00:01:35.0251899Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Disable Strong Authentication", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
diff --git a/data_sources/azure_active_directory_enable_account.yml b/data_sources/azure_active_directory_enable_account.yml
index 2e3380277d..5d5105fbcb 100644
--- a/data_sources/azure_active_directory_enable_account.yml
+++ b/data_sources/azure_active_directory_enable_account.yml
@@ -5,68 +5,68 @@ date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when an Azure Active Directory account is enabled.
mitre_components:
- - User Account Modification
- - User Account Authentication
- - User Account Metadata
+- User Account Modification
+- User Account Authentication
+- User Account Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Enable account
supported_TA:
- - name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+- name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
- - _time
- - Level
- - callerIpAddress
- - category
- - correlationId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - durationMs
- - host
- - index
- - linecount
- - operationName
- - operationVersion
- - properties.activityDateTime
- - properties.activityDisplayName
- - properties.category
- - properties.correlationId
- - properties.id
- - properties.initiatedBy.user.displayName
- - properties.initiatedBy.user.id
- - properties.initiatedBy.user.ipAddress
- - properties.initiatedBy.user.userPrincipalName
- - properties.loggedByService
- - properties.operationType
- - properties.result
- - properties.resultReason
- - properties.targetResources{}.displayName
- - properties.targetResources{}.id
- - properties.targetResources{}.modifiedProperties{}.displayName
- - properties.targetResources{}.modifiedProperties{}.newValue
- - properties.targetResources{}.modifiedProperties{}.oldValue
- - properties.targetResources{}.type
- - properties.targetResources{}.userPrincipalName
- - properties.userAgent
- - punct
- - resourceId
- - resultSignature
- - source
- - sourcetype
- - splunk_server
- - tenantId
- - time
- - timeendpos
- - timestartpos
+- _time
+- Level
+- callerIpAddress
+- category
+- correlationId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- durationMs
+- host
+- index
+- linecount
+- operationName
+- operationVersion
+- properties.activityDateTime
+- properties.activityDisplayName
+- properties.category
+- properties.correlationId
+- properties.id
+- properties.initiatedBy.user.displayName
+- properties.initiatedBy.user.id
+- properties.initiatedBy.user.ipAddress
+- properties.initiatedBy.user.userPrincipalName
+- properties.loggedByService
+- properties.operationType
+- properties.result
+- properties.resultReason
+- properties.targetResources{}.displayName
+- properties.targetResources{}.id
+- properties.targetResources{}.modifiedProperties{}.displayName
+- properties.targetResources{}.modifiedProperties{}.newValue
+- properties.targetResources{}.modifiedProperties{}.oldValue
+- properties.targetResources{}.type
+- properties.targetResources{}.userPrincipalName
+- properties.userAgent
+- punct
+- resourceId
+- resultSignature
+- source
+- sourcetype
+- splunk_server
+- tenantId
+- time
+- timeendpos
+- timestartpos
example_log: '{"time": "2023-07-24T14:28:15.2223487Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Enable account", "operationVersion": "1.0", "category": "AuditLogs",
"tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs":
diff --git a/data_sources/azure_active_directory_invite_external_user.yml b/data_sources/azure_active_directory_invite_external_user.yml
index 08726897f3..a7f115be50 100644
--- a/data_sources/azure_active_directory_invite_external_user.yml
+++ b/data_sources/azure_active_directory_invite_external_user.yml
@@ -6,67 +6,67 @@ author: Patrick Bareiss, Splunk
description: Logs an event when an external user is invited to join an Azure Active
Directory tenant.
mitre_components:
- - Active Directory Object Creation
- - User Account Creation
- - User Account Authentication
+- Active Directory Object Creation
+- User Account Creation
+- User Account Authentication
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Invite external user
supported_TA:
- - name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+- name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
- - _time
- - Level
- - callerIpAddress
- - category
- - correlationId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - durationMs
- - host
- - index
- - linecount
- - operationName
- - operationVersion
- - properties.activityDateTime
- - properties.activityDisplayName
- - properties.additionalDetails{}.key
- - properties.additionalDetails{}.value
- - properties.category
- - properties.correlationId
- - properties.id
- - properties.initiatedBy.user.displayName
- - properties.initiatedBy.user.id
- - properties.initiatedBy.user.ipAddress
- - properties.initiatedBy.user.userPrincipalName
- - properties.loggedByService
- - properties.operationType
- - properties.result
- - properties.resultReason
- - properties.targetResources{}.displayName
- - properties.targetResources{}.id
- - properties.targetResources{}.type
- - properties.targetResources{}.userPrincipalName
- - properties.userAgent
- - punct
- - resourceId
- - resultSignature
- - source
- - sourcetype
- - splunk_server
- - tenantId
- - time
- - timeendpos
- - timestartpos
+- _time
+- Level
+- callerIpAddress
+- category
+- correlationId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- durationMs
+- host
+- index
+- linecount
+- operationName
+- operationVersion
+- properties.activityDateTime
+- properties.activityDisplayName
+- properties.additionalDetails{}.key
+- properties.additionalDetails{}.value
+- properties.category
+- properties.correlationId
+- properties.id
+- properties.initiatedBy.user.displayName
+- properties.initiatedBy.user.id
+- properties.initiatedBy.user.ipAddress
+- properties.initiatedBy.user.userPrincipalName
+- properties.loggedByService
+- properties.operationType
+- properties.result
+- properties.resultReason
+- properties.targetResources{}.displayName
+- properties.targetResources{}.id
+- properties.targetResources{}.type
+- properties.targetResources{}.userPrincipalName
+- properties.userAgent
+- punct
+- resourceId
+- resultSignature
+- source
+- sourcetype
+- splunk_server
+- tenantId
+- time
+- timeendpos
+- timestartpos
example_log: '{"time": "2023-07-13T00:29:59.5100003Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Invite external user", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
diff --git a/data_sources/azure_active_directory_reset_password_(by_admin).yml b/data_sources/azure_active_directory_reset_password_(by_admin).yml
index 54208cb250..9e2eacf0f5 100644
--- a/data_sources/azure_active_directory_reset_password_(by_admin).yml
+++ b/data_sources/azure_active_directory_reset_password_(by_admin).yml
@@ -6,68 +6,68 @@ author: Patrick Bareiss, Splunk
description: Logs an event when an admin resets a user's password in Azure Active
Directory.
mitre_components:
- - User Account Authentication
- - User Account Modification
- - Active Directory Object Modification
+- User Account Authentication
+- User Account Modification
+- Active Directory Object Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Reset password (by admin)
supported_TA:
- - name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+- name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
- - _time
- - Level
- - callerIpAddress
- - category
- - correlationId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - durationMs
- - host
- - index
- - linecount
- - operationName
- - operationVersion
- - properties.activityDateTime
- - properties.activityDisplayName
- - properties.additionalDetails{}.key
- - properties.additionalDetails{}.value
- - properties.category
- - properties.correlationId
- - properties.id
- - properties.initiatedBy.user.displayName
- - properties.initiatedBy.user.id
- - properties.initiatedBy.user.ipAddress
- - properties.initiatedBy.user.userPrincipalName
- - properties.loggedByService
- - properties.operationType
- - properties.result
- - properties.resultReason
- - properties.targetResources{}.displayName
- - properties.targetResources{}.id
- - properties.targetResources{}.type
- - properties.targetResources{}.userPrincipalName
- - properties.userAgent
- - punct
- - resourceId
- - resultDescription
- - resultSignature
- - source
- - sourcetype
- - splunk_server
- - tenantId
- - time
- - timeendpos
- - timestartpos
+- _time
+- Level
+- callerIpAddress
+- category
+- correlationId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- durationMs
+- host
+- index
+- linecount
+- operationName
+- operationVersion
+- properties.activityDateTime
+- properties.activityDisplayName
+- properties.additionalDetails{}.key
+- properties.additionalDetails{}.value
+- properties.category
+- properties.correlationId
+- properties.id
+- properties.initiatedBy.user.displayName
+- properties.initiatedBy.user.id
+- properties.initiatedBy.user.ipAddress
+- properties.initiatedBy.user.userPrincipalName
+- properties.loggedByService
+- properties.operationType
+- properties.result
+- properties.resultReason
+- properties.targetResources{}.displayName
+- properties.targetResources{}.id
+- properties.targetResources{}.type
+- properties.targetResources{}.userPrincipalName
+- properties.userAgent
+- punct
+- resourceId
+- resultDescription
+- resultSignature
+- source
+- sourcetype
+- splunk_server
+- tenantId
+- time
+- timeendpos
+- timestartpos
example_log: '{"time": "2023-07-24T14:28:55.0648789Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Reset password (by admin)", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
diff --git a/data_sources/azure_active_directory_set_domain_authentication.yml b/data_sources/azure_active_directory_set_domain_authentication.yml
index c29183d14e..939da08d9f 100644
--- a/data_sources/azure_active_directory_set_domain_authentication.yml
+++ b/data_sources/azure_active_directory_set_domain_authentication.yml
@@ -6,68 +6,68 @@ author: Patrick Bareiss, Splunk
description: Logs an event when the authentication method for a domain in Azure Active
Directory is set or modified.
mitre_components:
- - Active Directory Object Modification
- - User Account Authentication
- - Cloud Service Modification
+- Active Directory Object Modification
+- User Account Authentication
+- Cloud Service Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Set domain authentication
supported_TA:
- - name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+- name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
- - _time
- - Level
- - callerIpAddress
- - category
- - correlationId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - durationMs
- - host
- - index
- - linecount
- - operationName
- - operationVersion
- - properties.activityDateTime
- - properties.activityDisplayName
- - properties.additionalDetails{}.key
- - properties.additionalDetails{}.value
- - properties.category
- - properties.correlationId
- - properties.id
- - properties.initiatedBy.user.displayName
- - properties.initiatedBy.user.id
- - properties.initiatedBy.user.ipAddress
- - properties.initiatedBy.user.userPrincipalName
- - properties.loggedByService
- - properties.operationType
- - properties.result
- - properties.resultReason
- - properties.targetResources{}.displayName
- - properties.targetResources{}.id
- - properties.targetResources{}.modifiedProperties{}.displayName
- - properties.targetResources{}.modifiedProperties{}.newValue
- - properties.targetResources{}.modifiedProperties{}.oldValue
- - properties.userAgent
- - punct
- - resourceId
- - resultSignature
- - source
- - sourcetype
- - splunk_server
- - tenantId
- - time
- - timeendpos
- - timestartpos
+- _time
+- Level
+- callerIpAddress
+- category
+- correlationId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- durationMs
+- host
+- index
+- linecount
+- operationName
+- operationVersion
+- properties.activityDateTime
+- properties.activityDisplayName
+- properties.additionalDetails{}.key
+- properties.additionalDetails{}.value
+- properties.category
+- properties.correlationId
+- properties.id
+- properties.initiatedBy.user.displayName
+- properties.initiatedBy.user.id
+- properties.initiatedBy.user.ipAddress
+- properties.initiatedBy.user.userPrincipalName
+- properties.loggedByService
+- properties.operationType
+- properties.result
+- properties.resultReason
+- properties.targetResources{}.displayName
+- properties.targetResources{}.id
+- properties.targetResources{}.modifiedProperties{}.displayName
+- properties.targetResources{}.modifiedProperties{}.newValue
+- properties.targetResources{}.modifiedProperties{}.oldValue
+- properties.userAgent
+- punct
+- resourceId
+- resultSignature
+- source
+- sourcetype
+- splunk_server
+- tenantId
+- time
+- timeendpos
+- timestartpos
example_log: '{"time": "2023-07-26T13:44:59.0372448Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Set domain authentication", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
diff --git a/data_sources/azure_active_directory_sign_in_activity.yml b/data_sources/azure_active_directory_sign_in_activity.yml
index d5ed7fa94d..4b8e5c152f 100644
--- a/data_sources/azure_active_directory_sign_in_activity.yml
+++ b/data_sources/azure_active_directory_sign_in_activity.yml
@@ -6,118 +6,118 @@ author: Patrick Bareiss, Splunk
description: Logs an event when a user attempts to sign into Azure Active Directory,
capturing authentication details and outcomes.
mitre_components:
- - User Account Authentication
- - Logon Session Creation
- - User Account Metadata
+- User Account Authentication
+- Logon Session Creation
+- User Account Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Sign-in activity
supported_TA:
- - name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+- name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
- - _time
- - Level
- - callerIpAddress
- - category
- - correlationId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - durationMs
- - host
- - identity
- - index
- - linecount
- - location
- - operationName
- - operationVersion
- - properties.alternateSignInName
- - properties.appDisplayName
- - properties.appId
- - properties.appServicePrincipalId
- - properties.authenticationDetails{}.RequestSequence
- - properties.authenticationDetails{}.StatusSequence
- - properties.authenticationDetails{}.authenticationMethod
- - properties.authenticationDetails{}.authenticationMethodDetail
- - properties.authenticationDetails{}.authenticationStepDateTime
- - properties.authenticationDetails{}.authenticationStepRequirement
- - properties.authenticationDetails{}.authenticationStepResultDetail
- - properties.authenticationDetails{}.succeeded
- - properties.authenticationProcessingDetails{}.key
- - properties.authenticationProcessingDetails{}.value
- - properties.authenticationProtocol
- - properties.authenticationRequirement
- - properties.authenticationRequirementPolicies{}.detail
- - properties.authenticationRequirementPolicies{}.requirementProvider
- - properties.autonomousSystemNumber
- - properties.clientAppUsed
- - properties.clientCredentialType
- - properties.conditionalAccessStatus
- - properties.correlationId
- - properties.createdDateTime
- - properties.crossTenantAccessType
- - properties.deviceDetail.deviceId
- - properties.deviceDetail.operatingSystem
- - properties.flaggedForReview
- - properties.homeTenantId
- - properties.id
- - properties.incomingTokenType
- - properties.ipAddress
- - properties.isInteractive
- - properties.isTenantRestricted
- - properties.location.city
- - properties.location.countryOrRegion
- - properties.location.geoCoordinates.latitude
- - properties.location.geoCoordinates.longitude
- - properties.location.state
- - properties.originalRequestId
- - properties.originalTransferMethod
- - properties.processingTimeInMilliseconds
- - properties.resourceDisplayName
- - properties.resourceId
- - properties.resourceServicePrincipalId
- - properties.resourceTenantId
- - properties.riskDetail
- - properties.riskLevelAggregated
- - properties.riskLevelDuringSignIn
- - properties.riskState
- - properties.rngcStatus
- - properties.servicePrincipalId
- - properties.signInIdentifier
- - properties.signInTokenProtectionStatus
- - properties.ssoExtensionVersion
- - properties.status.additionalDetails
- - properties.status.errorCode
- - properties.status.failureReason
- - properties.tenantId
- - properties.tokenIssuerName
- - properties.tokenIssuerType
- - properties.uniqueTokenIdentifier
- - properties.userAgent
- - properties.userDisplayName
- - properties.userId
- - properties.userPrincipalName
- - properties.userType
- - punct
- - resourceId
- - resultDescription
- - resultSignature
- - resultType
- - source
- - sourcetype
- - splunk_server
- - tenantId
- - time
- - timeendpos
- - timestartpos
+- _time
+- Level
+- callerIpAddress
+- category
+- correlationId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- durationMs
+- host
+- identity
+- index
+- linecount
+- location
+- operationName
+- operationVersion
+- properties.alternateSignInName
+- properties.appDisplayName
+- properties.appId
+- properties.appServicePrincipalId
+- properties.authenticationDetails{}.RequestSequence
+- properties.authenticationDetails{}.StatusSequence
+- properties.authenticationDetails{}.authenticationMethod
+- properties.authenticationDetails{}.authenticationMethodDetail
+- properties.authenticationDetails{}.authenticationStepDateTime
+- properties.authenticationDetails{}.authenticationStepRequirement
+- properties.authenticationDetails{}.authenticationStepResultDetail
+- properties.authenticationDetails{}.succeeded
+- properties.authenticationProcessingDetails{}.key
+- properties.authenticationProcessingDetails{}.value
+- properties.authenticationProtocol
+- properties.authenticationRequirement
+- properties.authenticationRequirementPolicies{}.detail
+- properties.authenticationRequirementPolicies{}.requirementProvider
+- properties.autonomousSystemNumber
+- properties.clientAppUsed
+- properties.clientCredentialType
+- properties.conditionalAccessStatus
+- properties.correlationId
+- properties.createdDateTime
+- properties.crossTenantAccessType
+- properties.deviceDetail.deviceId
+- properties.deviceDetail.operatingSystem
+- properties.flaggedForReview
+- properties.homeTenantId
+- properties.id
+- properties.incomingTokenType
+- properties.ipAddress
+- properties.isInteractive
+- properties.isTenantRestricted
+- properties.location.city
+- properties.location.countryOrRegion
+- properties.location.geoCoordinates.latitude
+- properties.location.geoCoordinates.longitude
+- properties.location.state
+- properties.originalRequestId
+- properties.originalTransferMethod
+- properties.processingTimeInMilliseconds
+- properties.resourceDisplayName
+- properties.resourceId
+- properties.resourceServicePrincipalId
+- properties.resourceTenantId
+- properties.riskDetail
+- properties.riskLevelAggregated
+- properties.riskLevelDuringSignIn
+- properties.riskState
+- properties.rngcStatus
+- properties.servicePrincipalId
+- properties.signInIdentifier
+- properties.signInTokenProtectionStatus
+- properties.ssoExtensionVersion
+- properties.status.additionalDetails
+- properties.status.errorCode
+- properties.status.failureReason
+- properties.tenantId
+- properties.tokenIssuerName
+- properties.tokenIssuerType
+- properties.uniqueTokenIdentifier
+- properties.userAgent
+- properties.userDisplayName
+- properties.userId
+- properties.userPrincipalName
+- properties.userType
+- punct
+- resourceId
+- resultDescription
+- resultSignature
+- resultType
+- source
+- sourcetype
+- splunk_server
+- tenantId
+- time
+- timeendpos
+- timestartpos
example_log: '{"time": "2023-10-24T20:13:31.4449614Z", "resourceId": "/tenants/887c9144-28b8-431b-885b-764fdeefcf62/providers/Microsoft.aadiam",
"operationName": "Sign-in activity", "operationVersion": "1.0", "category": "SignInLogs",
"tenantId": "887c9144-28b8-431b-885b-764fdeefcf62", "resultType": "50076", "resultSignature":
diff --git a/data_sources/azure_active_directory_update_application.yml b/data_sources/azure_active_directory_update_application.yml
index fe57e659f8..e82edafcca 100644
--- a/data_sources/azure_active_directory_update_application.yml
+++ b/data_sources/azure_active_directory_update_application.yml
@@ -6,68 +6,68 @@ author: Patrick Bareiss, Splunk
description: Logs an event when an application in Azure Active Directory is updated,
such as changes to its settings or permissions.
mitre_components:
- - Service Modification
- - User Account Modification
- - Cloud Service Modification
+- Service Modification
+- User Account Modification
+- Cloud Service Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Update application
supported_TA:
- - name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+- name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
- - _time
- - Level
- - category
- - correlationId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - durationMs
- - host
- - index
- - linecount
- - operationName
- - operationVersion
- - properties.activityDateTime
- - properties.activityDisplayName
- - properties.additionalDetails{}.key
- - properties.additionalDetails{}.value
- - properties.category
- - properties.correlationId
- - properties.id
- - properties.initiatedBy.user.displayName
- - properties.initiatedBy.user.id
- - properties.initiatedBy.user.ipAddress
- - properties.initiatedBy.user.userPrincipalName
- - properties.loggedByService
- - properties.operationType
- - properties.result
- - properties.resultReason
- - properties.targetResources{}.displayName
- - properties.targetResources{}.id
- - properties.targetResources{}.modifiedProperties{}.displayName
- - properties.targetResources{}.modifiedProperties{}.newValue
- - properties.targetResources{}.modifiedProperties{}.oldValue
- - properties.targetResources{}.type
- - properties.userAgent
- - punct
- - resourceId
- - resultSignature
- - source
- - sourcetype
- - splunk_server
- - tenantId
- - time
- - timeendpos
- - timestartpos
+- _time
+- Level
+- category
+- correlationId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- durationMs
+- host
+- index
+- linecount
+- operationName
+- operationVersion
+- properties.activityDateTime
+- properties.activityDisplayName
+- properties.additionalDetails{}.key
+- properties.additionalDetails{}.value
+- properties.category
+- properties.correlationId
+- properties.id
+- properties.initiatedBy.user.displayName
+- properties.initiatedBy.user.id
+- properties.initiatedBy.user.ipAddress
+- properties.initiatedBy.user.userPrincipalName
+- properties.loggedByService
+- properties.operationType
+- properties.result
+- properties.resultReason
+- properties.targetResources{}.displayName
+- properties.targetResources{}.id
+- properties.targetResources{}.modifiedProperties{}.displayName
+- properties.targetResources{}.modifiedProperties{}.newValue
+- properties.targetResources{}.modifiedProperties{}.oldValue
+- properties.targetResources{}.type
+- properties.userAgent
+- punct
+- resourceId
+- resultSignature
+- source
+- sourcetype
+- splunk_server
+- tenantId
+- time
+- timeendpos
+- timestartpos
example_log: '{"time": "2024-01-29T21:31:03.0102031Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam",
"operationName": "Update application", "operationVersion": "1.0", "category": "AuditLogs",
"tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "resultSignature": "None", "durationMs":
diff --git a/data_sources/azure_active_directory_update_authorization_policy.yml b/data_sources/azure_active_directory_update_authorization_policy.yml
index 34e141f92e..54dd3ca2a9 100644
--- a/data_sources/azure_active_directory_update_authorization_policy.yml
+++ b/data_sources/azure_active_directory_update_authorization_policy.yml
@@ -6,69 +6,69 @@ author: Patrick Bareiss, Splunk
description: Logs an event when an authorization policy is updated in Azure Active
Directory.
mitre_components:
- - User Account Modification
- - Group Modification
- - Active Directory Object Modification
+- User Account Modification
+- Group Modification
+- Active Directory Object Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Update authorization policy
supported_TA:
- - name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+- name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
- - _time
- - Level
- - callerIpAddress
- - category
- - correlationId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - durationMs
- - host
- - index
- - linecount
- - operationName
- - operationVersion
- - properties.activityDateTime
- - properties.activityDisplayName
- - properties.additionalDetails{}.key
- - properties.additionalDetails{}.value
- - properties.category
- - properties.correlationId
- - properties.id
- - properties.initiatedBy.user.displayName
- - properties.initiatedBy.user.id
- - properties.initiatedBy.user.ipAddress
- - properties.initiatedBy.user.userPrincipalName
- - properties.loggedByService
- - properties.operationType
- - properties.result
- - properties.resultReason
- - properties.targetResources{}.displayName
- - properties.targetResources{}.id
- - properties.targetResources{}.modifiedProperties{}.displayName
- - properties.targetResources{}.modifiedProperties{}.newValue
- - properties.targetResources{}.modifiedProperties{}.oldValue
- - properties.targetResources{}.type
- - properties.userAgent
- - punct
- - resourceId
- - resultSignature
- - source
- - sourcetype
- - splunk_server
- - tenantId
- - time
- - timeendpos
- - timestartpos
+- _time
+- Level
+- callerIpAddress
+- category
+- correlationId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- durationMs
+- host
+- index
+- linecount
+- operationName
+- operationVersion
+- properties.activityDateTime
+- properties.activityDisplayName
+- properties.additionalDetails{}.key
+- properties.additionalDetails{}.value
+- properties.category
+- properties.correlationId
+- properties.id
+- properties.initiatedBy.user.displayName
+- properties.initiatedBy.user.id
+- properties.initiatedBy.user.ipAddress
+- properties.initiatedBy.user.userPrincipalName
+- properties.loggedByService
+- properties.operationType
+- properties.result
+- properties.resultReason
+- properties.targetResources{}.displayName
+- properties.targetResources{}.id
+- properties.targetResources{}.modifiedProperties{}.displayName
+- properties.targetResources{}.modifiedProperties{}.newValue
+- properties.targetResources{}.modifiedProperties{}.oldValue
+- properties.targetResources{}.type
+- properties.userAgent
+- punct
+- resourceId
+- resultSignature
+- source
+- sourcetype
+- splunk_server
+- tenantId
+- time
+- timeendpos
+- timestartpos
example_log: '{"time": "2023-10-26T19:22:20.2814027Z", "resourceId": "/tenants/5f210575-a69b-41a7-b623-3f6d79ccd432/providers/Microsoft.aadiam",
"operationName": "Update authorization policy", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "5f210575-a69b-41a7-b623-3f6d79ccd432", "resultSignature":
diff --git a/data_sources/azure_active_directory_update_user.yml b/data_sources/azure_active_directory_update_user.yml
index 3bc111e209..26951a9695 100644
--- a/data_sources/azure_active_directory_update_user.yml
+++ b/data_sources/azure_active_directory_update_user.yml
@@ -5,69 +5,69 @@ date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when a user account is updated in Azure Active Directory.
mitre_components:
- - User Account Modification
- - User Account Metadata
+- User Account Modification
+- User Account Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Update user
supported_TA:
- - name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+- name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
- - _time
- - Level
- - callerIpAddress
- - category
- - correlationId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - durationMs
- - host
- - index
- - linecount
- - operationName
- - operationVersion
- - properties.activityDateTime
- - properties.activityDisplayName
- - properties.additionalDetails{}.key
- - properties.additionalDetails{}.value
- - properties.category
- - properties.correlationId
- - properties.id
- - properties.initiatedBy.user.displayName
- - properties.initiatedBy.user.id
- - properties.initiatedBy.user.ipAddress
- - properties.initiatedBy.user.userPrincipalName
- - properties.loggedByService
- - properties.operationType
- - properties.result
- - properties.resultReason
- - properties.targetResources{}.displayName
- - properties.targetResources{}.id
- - properties.targetResources{}.modifiedProperties{}.displayName
- - properties.targetResources{}.modifiedProperties{}.newValue
- - properties.targetResources{}.modifiedProperties{}.oldValue
- - properties.targetResources{}.type
- - properties.targetResources{}.userPrincipalName
- - properties.userAgent
- - punct
- - resourceId
- - resultSignature
- - source
- - sourcetype
- - splunk_server
- - tenantId
- - time
- - timeendpos
- - timestartpos
+- _time
+- Level
+- callerIpAddress
+- category
+- correlationId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- durationMs
+- host
+- index
+- linecount
+- operationName
+- operationVersion
+- properties.activityDateTime
+- properties.activityDisplayName
+- properties.additionalDetails{}.key
+- properties.additionalDetails{}.value
+- properties.category
+- properties.correlationId
+- properties.id
+- properties.initiatedBy.user.displayName
+- properties.initiatedBy.user.id
+- properties.initiatedBy.user.ipAddress
+- properties.initiatedBy.user.userPrincipalName
+- properties.loggedByService
+- properties.operationType
+- properties.result
+- properties.resultReason
+- properties.targetResources{}.displayName
+- properties.targetResources{}.id
+- properties.targetResources{}.modifiedProperties{}.displayName
+- properties.targetResources{}.modifiedProperties{}.newValue
+- properties.targetResources{}.modifiedProperties{}.oldValue
+- properties.targetResources{}.type
+- properties.targetResources{}.userPrincipalName
+- properties.userAgent
+- punct
+- resourceId
+- resultSignature
+- source
+- sourcetype
+- splunk_server
+- tenantId
+- time
+- timeendpos
+- timestartpos
example_log: '{"time": "2023-07-24T14:28:15.2233481Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Update user", "operationVersion": "1.0", "category": "AuditLogs",
"tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs":
diff --git a/data_sources/azure_active_directory_user_registered_security_info.yml b/data_sources/azure_active_directory_user_registered_security_info.yml
index db1c5af928..3a2ba69d86 100644
--- a/data_sources/azure_active_directory_user_registered_security_info.yml
+++ b/data_sources/azure_active_directory_user_registered_security_info.yml
@@ -6,65 +6,65 @@ author: Patrick Bareiss, Splunk
description: Logs an event when a user registers or updates their security information
in Azure Active Directory.
mitre_components:
- - User Account Modification
- - User Account Metadata
+- User Account Modification
+- User Account Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: User registered security info
supported_TA:
- - name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+- name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
- - _time
- - Level
- - callerIpAddress
- - category
- - correlationId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - durationMs
- - host
- - index
- - linecount
- - operationName
- - operationVersion
- - properties.activityDateTime
- - properties.activityDisplayName
- - properties.category
- - properties.correlationId
- - properties.id
- - properties.initiatedBy.user.displayName
- - properties.initiatedBy.user.id
- - properties.initiatedBy.user.ipAddress
- - properties.initiatedBy.user.userPrincipalName
- - properties.loggedByService
- - properties.operationType
- - properties.result
- - properties.resultReason
- - properties.targetResources{}.displayName
- - properties.targetResources{}.id
- - properties.targetResources{}.type
- - properties.targetResources{}.userPrincipalName
- - properties.userAgent
- - punct
- - resourceId
- - resultDescription
- - resultSignature
- - source
- - sourcetype
- - splunk_server
- - tenantId
- - time
- - timeendpos
- - timestartpos
+- _time
+- Level
+- callerIpAddress
+- category
+- correlationId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- durationMs
+- host
+- index
+- linecount
+- operationName
+- operationVersion
+- properties.activityDateTime
+- properties.activityDisplayName
+- properties.category
+- properties.correlationId
+- properties.id
+- properties.initiatedBy.user.displayName
+- properties.initiatedBy.user.id
+- properties.initiatedBy.user.ipAddress
+- properties.initiatedBy.user.userPrincipalName
+- properties.loggedByService
+- properties.operationType
+- properties.result
+- properties.resultReason
+- properties.targetResources{}.displayName
+- properties.targetResources{}.id
+- properties.targetResources{}.type
+- properties.targetResources{}.userPrincipalName
+- properties.userAgent
+- punct
+- resourceId
+- resultDescription
+- resultSignature
+- source
+- sourcetype
+- splunk_server
+- tenantId
+- time
+- timeendpos
+- timestartpos
example_log: '{"time": "2023-01-30T21:11:30.8690619Z", "resourceId": "/tenants/91da745f-8abb-4a7d-ba94-5667c6f9e01a/providers/Microsoft.aadiam",
"operationName": "User registered security info", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "91da745f-8abb-4a7d-ba94-5667c6f9e01a", "resultSignature":
diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml
index d16b39fe67..65f6f7e767 100644
--- a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml
+++ b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml
@@ -5,106 +5,106 @@ date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when an Azure Automation account is created or updated.
mitre_components:
- - Cloud Service Creation
- - Cloud Service Modification
- - Cloud Service Metadata
+- Cloud Service Creation
+- Cloud Service Modification
+- Cloud Service Metadata
source: mscs:azure:audit
sourcetype: mscs:azure:audit
separator: operationName.localizedValue
separator_value: Create or Update an Azure Automation account
supported_TA:
- - name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+- name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
- - _time
- - authorization.action
- - authorization.scope
- - caller
- - channels
- - claims.aio
- - claims.altsecid
- - claims.appid
- - claims.appidacr
- - claims.aud
- - claims.exp
- - claims.groups
- - claims.http://schemas.microsoft.com/claims/authnclassreference
- - claims.http://schemas.microsoft.com/claims/authnmethodsreferences
- - claims.http://schemas.microsoft.com/identity/claims/identityprovider
- - claims.http://schemas.microsoft.com/identity/claims/objectidentifier
- - claims.http://schemas.microsoft.com/identity/claims/scope
- - claims.http://schemas.microsoft.com/identity/claims/tenantid
- - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
- - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
- - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
- - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
- - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
- - claims.iat
- - claims.ipaddr
- - claims.iss
- - claims.name
- - claims.nbf
- - claims.puid
- - claims.rh
- - claims.uti
- - claims.ver
- - claims.wids
- - claims.xms_tcdt
- - correlationId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - eventDataId
- - eventName.localizedValue
- - eventName.value
- - eventSource.localizedValue
- - eventSource.value
- - eventTimestamp
- - host
- - id
- - index
- - level
- - linecount
- - object
- - object_id
- - object_path
- - operationId
- - operationName.localizedValue
- - operationName.value
- - product
- - properties.entity
- - properties.eventCategory
- - properties.hierarchy
- - properties.message
- - punct
- - resourceGroupName
- - resourceProviderName.localizedValue
- - resourceProviderName.value
- - resourceUri
- - source
- - sourcetype
- - splunk_server
- - status
- - status.localizedValue
- - status.value
- - subStatus.value
- - submissionTimestamp
- - subscriptionId
- - timeendpos
- - timestartpos
- - user
- - user_name
- - vendor
- - vendor_product
- - vendor_res_code
+- _time
+- authorization.action
+- authorization.scope
+- caller
+- channels
+- claims.aio
+- claims.altsecid
+- claims.appid
+- claims.appidacr
+- claims.aud
+- claims.exp
+- claims.groups
+- claims.http://schemas.microsoft.com/claims/authnclassreference
+- claims.http://schemas.microsoft.com/claims/authnmethodsreferences
+- claims.http://schemas.microsoft.com/identity/claims/identityprovider
+- claims.http://schemas.microsoft.com/identity/claims/objectidentifier
+- claims.http://schemas.microsoft.com/identity/claims/scope
+- claims.http://schemas.microsoft.com/identity/claims/tenantid
+- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
+- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
+- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
+- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
+- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
+- claims.iat
+- claims.ipaddr
+- claims.iss
+- claims.name
+- claims.nbf
+- claims.puid
+- claims.rh
+- claims.uti
+- claims.ver
+- claims.wids
+- claims.xms_tcdt
+- correlationId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- eventDataId
+- eventName.localizedValue
+- eventName.value
+- eventSource.localizedValue
+- eventSource.value
+- eventTimestamp
+- host
+- id
+- index
+- level
+- linecount
+- object
+- object_id
+- object_path
+- operationId
+- operationName.localizedValue
+- operationName.value
+- product
+- properties.entity
+- properties.eventCategory
+- properties.hierarchy
+- properties.message
+- punct
+- resourceGroupName
+- resourceProviderName.localizedValue
+- resourceProviderName.value
+- resourceUri
+- source
+- sourcetype
+- splunk_server
+- status
+- status.localizedValue
+- status.value
+- subStatus.value
+- submissionTimestamp
+- subscriptionId
+- timeendpos
+- timestartpos
+- user
+- user_name
+- vendor
+- vendor_product
+- vendor_res_code
example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/write",
"scope": "/subscriptions/67165197-75ea-4ca3-96a5-3e23868eacd0/resourcegroups/ResourceGroup1/providers/Microsoft.Automation/automationAccounts/TestAutomationAccount"},
"caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/",
diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml
index 8522e7ab79..f9de2d68b5 100644
--- a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml
+++ b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml
@@ -6,105 +6,105 @@ author: Patrick Bareiss, Splunk
description: Logs an event when a new Azure Automation Runbook is created or an existing
one is updated.
mitre_components:
- - Scheduled Job Modification
- - Scheduled Job Creation
+- Scheduled Job Modification
+- Scheduled Job Creation
source: mscs:azure:audit
sourcetype: mscs:azure:audit
separator: operationName.localizedValue
separator_value: Create or Update an Azure Automation Runbook
supported_TA:
- - name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+- name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
- - _time
- - authorization.action
- - authorization.scope
- - caller
- - channels
- - claims.aio
- - claims.altsecid
- - claims.appid
- - claims.appidacr
- - claims.aud
- - claims.exp
- - claims.groups
- - claims.http://schemas.microsoft.com/claims/authnclassreference
- - claims.http://schemas.microsoft.com/claims/authnmethodsreferences
- - claims.http://schemas.microsoft.com/identity/claims/identityprovider
- - claims.http://schemas.microsoft.com/identity/claims/objectidentifier
- - claims.http://schemas.microsoft.com/identity/claims/scope
- - claims.http://schemas.microsoft.com/identity/claims/tenantid
- - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
- - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
- - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
- - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
- - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
- - claims.iat
- - claims.ipaddr
- - claims.iss
- - claims.name
- - claims.nbf
- - claims.puid
- - claims.rh
- - claims.uti
- - claims.ver
- - claims.wids
- - claims.xms_tcdt
- - correlationId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - eventDataId
- - eventName.localizedValue
- - eventName.value
- - eventSource.localizedValue
- - eventSource.value
- - eventTimestamp
- - host
- - id
- - index
- - level
- - linecount
- - object
- - object_id
- - object_path
- - operationId
- - operationName.localizedValue
- - operationName.value
- - product
- - properties.entity
- - properties.eventCategory
- - properties.hierarchy
- - properties.message
- - punct
- - resourceGroupName
- - resourceProviderName.localizedValue
- - resourceProviderName.value
- - resourceUri
- - source
- - sourcetype
- - splunk_server
- - status
- - status.localizedValue
- - status.value
- - subStatus.value
- - submissionTimestamp
- - subscriptionId
- - timeendpos
- - timestartpos
- - user
- - user_name
- - vendor
- - vendor_product
- - vendor_res_code
+- _time
+- authorization.action
+- authorization.scope
+- caller
+- channels
+- claims.aio
+- claims.altsecid
+- claims.appid
+- claims.appidacr
+- claims.aud
+- claims.exp
+- claims.groups
+- claims.http://schemas.microsoft.com/claims/authnclassreference
+- claims.http://schemas.microsoft.com/claims/authnmethodsreferences
+- claims.http://schemas.microsoft.com/identity/claims/identityprovider
+- claims.http://schemas.microsoft.com/identity/claims/objectidentifier
+- claims.http://schemas.microsoft.com/identity/claims/scope
+- claims.http://schemas.microsoft.com/identity/claims/tenantid
+- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
+- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
+- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
+- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
+- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
+- claims.iat
+- claims.ipaddr
+- claims.iss
+- claims.name
+- claims.nbf
+- claims.puid
+- claims.rh
+- claims.uti
+- claims.ver
+- claims.wids
+- claims.xms_tcdt
+- correlationId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- eventDataId
+- eventName.localizedValue
+- eventName.value
+- eventSource.localizedValue
+- eventSource.value
+- eventTimestamp
+- host
+- id
+- index
+- level
+- linecount
+- object
+- object_id
+- object_path
+- operationId
+- operationName.localizedValue
+- operationName.value
+- product
+- properties.entity
+- properties.eventCategory
+- properties.hierarchy
+- properties.message
+- punct
+- resourceGroupName
+- resourceProviderName.localizedValue
+- resourceProviderName.value
+- resourceUri
+- source
+- sourcetype
+- splunk_server
+- status
+- status.localizedValue
+- status.value
+- subStatus.value
+- submissionTimestamp
+- subscriptionId
+- timeendpos
+- timestartpos
+- user
+- user_name
+- vendor
+- vendor_product
+- vendor_res_code
example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/runbooks/write",
"scope": "/subscriptions/1aee0e3d-b75b-440a-a927-76f0552a14e6/resourceGroups/resourceGroup1/providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/runbooks/SuspiciousRunbook"},
"caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/",
diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml
index eb21ed90a8..6668b0a88d 100644
--- a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml
+++ b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml
@@ -5,115 +5,115 @@ date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when a webhook is created or updated in Azure Automation.
mitre_components:
- - Scheduled Job Modification
- - Cloud Service Modification
- - Scheduled Job Metadata
+- Scheduled Job Modification
+- Cloud Service Modification
+- Scheduled Job Metadata
source: mscs:azure:audit
sourcetype: mscs:azure:audit
separator: operationName.localizedValue
separator_value: Create or Update an Azure Automation webhook
supported_TA:
- - name: Splunk Add-on for Microsoft Cloud Services
- url: https://splunkbase.splunk.com/app/3110
- version: 5.4.1
+- name: Splunk Add-on for Microsoft Cloud Services
+ url: https://splunkbase.splunk.com/app/3110
+ version: 5.4.1
fields:
- - _time
- - authorization.action
- - authorization.scope
- - caller
- - channels
- - claims.aio
- - claims.altsecid
- - claims.appid
- - claims.appidacr
- - claims.aud
- - claims.exp
- - claims.groups
- - claims.http://schemas.microsoft.com/claims/authnclassreference
- - claims.http://schemas.microsoft.com/claims/authnmethodsreferences
- - claims.http://schemas.microsoft.com/identity/claims/identityprovider
- - claims.http://schemas.microsoft.com/identity/claims/objectidentifier
- - claims.http://schemas.microsoft.com/identity/claims/scope
- - claims.http://schemas.microsoft.com/identity/claims/tenantid
- - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
- - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
- - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
- - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
- - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
- - claims.iat
- - claims.ipaddr
- - claims.iss
- - claims.name
- - claims.nbf
- - claims.puid
- - claims.rh
- - claims.uti
- - claims.ver
- - claims.wids
- - claims.xms_tcdt
- - correlationId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - eventDataId
- - eventName.localizedValue
- - eventName.value
- - eventSource.localizedValue
- - eventSource.value
- - eventTimestamp
- - host
- - httpRequest.clientIpAddress
- - httpRequest.clientRequestId
- - httpRequest.method
- - id
- - index
- - level
- - linecount
- - object
- - object_id
- - object_path
- - operationId
- - operationName.localizedValue
- - operationName.value
- - product
- - properties.entity
- - properties.eventCategory
- - properties.hierarchy
- - properties.message
- - properties.serviceRequestId
- - properties.statusCode
- - punct
- - resourceGroupName
- - resourceProviderName.localizedValue
- - resourceProviderName.value
- - resourceUri
- - result
- - result_id
- - source
- - sourcetype
- - splunk_server
- - src
- - status
- - status.localizedValue
- - status.value
- - subStatus.localizedValue
- - subStatus.value
- - submissionTimestamp
- - subscriptionId
- - timeendpos
- - timestartpos
- - user
- - user_name
- - vendor
- - vendor_product
- - vendor_res_code
+- _time
+- authorization.action
+- authorization.scope
+- caller
+- channels
+- claims.aio
+- claims.altsecid
+- claims.appid
+- claims.appidacr
+- claims.aud
+- claims.exp
+- claims.groups
+- claims.http://schemas.microsoft.com/claims/authnclassreference
+- claims.http://schemas.microsoft.com/claims/authnmethodsreferences
+- claims.http://schemas.microsoft.com/identity/claims/identityprovider
+- claims.http://schemas.microsoft.com/identity/claims/objectidentifier
+- claims.http://schemas.microsoft.com/identity/claims/scope
+- claims.http://schemas.microsoft.com/identity/claims/tenantid
+- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
+- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
+- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
+- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
+- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
+- claims.iat
+- claims.ipaddr
+- claims.iss
+- claims.name
+- claims.nbf
+- claims.puid
+- claims.rh
+- claims.uti
+- claims.ver
+- claims.wids
+- claims.xms_tcdt
+- correlationId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- eventDataId
+- eventName.localizedValue
+- eventName.value
+- eventSource.localizedValue
+- eventSource.value
+- eventTimestamp
+- host
+- httpRequest.clientIpAddress
+- httpRequest.clientRequestId
+- httpRequest.method
+- id
+- index
+- level
+- linecount
+- object
+- object_id
+- object_path
+- operationId
+- operationName.localizedValue
+- operationName.value
+- product
+- properties.entity
+- properties.eventCategory
+- properties.hierarchy
+- properties.message
+- properties.serviceRequestId
+- properties.statusCode
+- punct
+- resourceGroupName
+- resourceProviderName.localizedValue
+- resourceProviderName.value
+- resourceUri
+- result
+- result_id
+- source
+- sourcetype
+- splunk_server
+- src
+- status
+- status.localizedValue
+- status.value
+- subStatus.localizedValue
+- subStatus.value
+- submissionTimestamp
+- subscriptionId
+- timeendpos
+- timestartpos
+- user
+- user_name
+- vendor
+- vendor_product
+- vendor_res_code
example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/webhooks/write",
"scope": "/subscriptions/e0c00901-96b2-4151-80f7-746e24c03e98/resourceGroups/resourceGroup1providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/webhooks/MaliciousWebHook"},
"caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/",
diff --git a/data_sources/bro_conn.yml b/data_sources/bro_conn.yml
index 992da75275..1d8e4110c3 100644
--- a/data_sources/bro_conn.yml
+++ b/data_sources/bro_conn.yml
@@ -6,11 +6,10 @@ author: Jacob Delgado, SnapAttack
description: Logs network connection metadata captured by Zeek (formerly Bro), including
details such as source and destination IPs, ports, connection state, and protocol.
mitre_components:
- - Network Connection Creation
- - Network Traffic Flow
- - Response Metadata
- - Application Log Content
+- Network Connection Creation
+- Network Traffic Flow
+- Response Metadata
+- Application Log Content
source: bro:conn:json
sourcetype: bro:conn:json
supported_TA: []
-
diff --git a/data_sources/bro_dns.yml b/data_sources/bro_dns.yml
index 7d878c681b..b4deae7a6c 100644
--- a/data_sources/bro_dns.yml
+++ b/data_sources/bro_dns.yml
@@ -6,11 +6,11 @@ author: Jacob Delgado, SnapAttack
description: Logs DNS queries and responses captured by Zeek (formerly Bro), including
details such as queried domains, resolved IPs, query types, and response codes.
mitre_components:
- - Active DNS
- - Passive DNS
- - Network Traffic Content
- - Network Traffic Flow
- - Response Metadata
+- Active DNS
+- Passive DNS
+- Network Traffic Content
+- Network Traffic Flow
+- Response Metadata
source: bro:dns:json
sourcetype: bro:dns:json
supported_TA: []
diff --git a/data_sources/bro_files.yml b/data_sources/bro_files.yml
index 4cb84af9fa..20121d2067 100644
--- a/data_sources/bro_files.yml
+++ b/data_sources/bro_files.yml
@@ -7,11 +7,11 @@ description: Logs metadata about files transferred over the network captured by
(formerly Bro), including details such as file names, hashes, MIME types, and transfer
protocols.
mitre_components:
- - File Metadata
- - Network Traffic Content
- - Network Traffic Flow
- - Response Metadata
- - Application Log Content
+- File Metadata
+- Network Traffic Content
+- Network Traffic Flow
+- Response Metadata
+- Application Log Content
source: bro:files:json
sourcetype: bro:files:json
supported_TA: []
diff --git a/data_sources/bro_http.yml b/data_sources/bro_http.yml
index 59232b529e..e8e25150dc 100644
--- a/data_sources/bro_http.yml
+++ b/data_sources/bro_http.yml
@@ -6,11 +6,11 @@ author: Patrick Bareiss, Splunk
description: Logs HTTP traffic analyzed by Zeek (formerly Bro), including details
such as request methods, URLs, user agents, response codes, and headers.
mitre_components:
- - Network Traffic Content
- - Network Traffic Flow
- - Response Content
- - Response Metadata
- - Application Log Content
+- Network Traffic Content
+- Network Traffic Flow
+- Response Content
+- Response Metadata
+- Application Log Content
source: bro:http:json
sourcetype: bro:http:json
supported_TA: []
diff --git a/data_sources/bro_loaded_scripts.yml b/data_sources/bro_loaded_scripts.yml
index be17c3a7e1..2b9669bac3 100644
--- a/data_sources/bro_loaded_scripts.yml
+++ b/data_sources/bro_loaded_scripts.yml
@@ -6,10 +6,10 @@ author: Jacob Delgado, SnapAttack
description: Logs details about the scripts loaded by Zeek (formerly Bro) during initialization,
including script names and paths.
mitre_components:
- - Application Log Content
- - Configuration Modification
- - Script Execution
- - OS API Execution
+- Application Log Content
+- Configuration Modification
+- Script Execution
+- OS API Execution
source: bro:loaded_scripts:json
sourcetype: bro:loaded_scripts:json
supported_TA: []
diff --git a/data_sources/bro_ntp.yml b/data_sources/bro_ntp.yml
index b849d5d5db..727dfc5bfa 100644
--- a/data_sources/bro_ntp.yml
+++ b/data_sources/bro_ntp.yml
@@ -6,10 +6,10 @@ author: Jacob Delgado, SnapAttack
description: Logs Network Time Protocol (NTP) activity captured by Zeek (formerly
Bro), including details such as NTP requests, responses, and server metadata.
mitre_components:
- - Network Traffic Flow
- - Network Traffic Content
- - Response Metadata
- - Application Log Content
+- Network Traffic Flow
+- Network Traffic Content
+- Response Metadata
+- Application Log Content
source: bro:ntp:json
sourcetype: bro:ntp:json
supported_TA: []
diff --git a/data_sources/bro_ocsp.yml b/data_sources/bro_ocsp.yml
index 00e8942e83..316e75d352 100644
--- a/data_sources/bro_ocsp.yml
+++ b/data_sources/bro_ocsp.yml
@@ -6,11 +6,11 @@ author: Jacob Delgado, SnapAttack
description: Logs Online Certificate Status Protocol (OCSP) activity captured by Zeek
(formerly Bro), including details such as certificate validation requests and responses.
mitre_components:
- - Certificate Registration
- - Network Traffic Flow
- - Network Traffic Content
- - Response Metadata
- - Application Log Content
+- Certificate Registration
+- Network Traffic Flow
+- Network Traffic Content
+- Response Metadata
+- Application Log Content
source: bro:ocsp:json
sourcetype: bro:ocsp:json
supported_TA: []
diff --git a/data_sources/bro_ssl.yml b/data_sources/bro_ssl.yml
index a2c17d7261..b138786a0f 100644
--- a/data_sources/bro_ssl.yml
+++ b/data_sources/bro_ssl.yml
@@ -6,11 +6,11 @@ author: Jacob Delgado, SnapAttack
description: Logs SSL/TLS handshake and session details captured by Zeek (formerly
Bro), including certificates, cipher suites, and session information.
mitre_components:
- - Certificate Registration
- - Network Traffic Flow
- - Network Traffic Content
- - Response Metadata
- - Application Log Content
+- Certificate Registration
+- Network Traffic Flow
+- Network Traffic Content
+- Response Metadata
+- Application Log Content
source: bro:ssl:json
sourcetype: bro:ssl:json
supported_TA: []
diff --git a/data_sources/bro_weird.yml b/data_sources/bro_weird.yml
index 1fc72ac2de..4d46c68d74 100644
--- a/data_sources/bro_weird.yml
+++ b/data_sources/bro_weird.yml
@@ -6,11 +6,11 @@ author: Jacob Delgado, SnapAttack
description: Logs anomalous or unexpected network behaviors identified by Zeek (formerly
Bro), including protocol violations and unusual traffic patterns.
mitre_components:
- - Network Traffic Flow
- - Network Traffic Content
- - Response Metadata
- - Application Log Content
- - Host Status
+- Network Traffic Flow
+- Network Traffic Content
+- Response Metadata
+- Application Log Content
+- Host Status
source: bro:weird:json
sourcetype: bro:weird:json
supported_TA: []
diff --git a/data_sources/bro_x509.yml b/data_sources/bro_x509.yml
index 3d9d08adf7..3f23109ebd 100644
--- a/data_sources/bro_x509.yml
+++ b/data_sources/bro_x509.yml
@@ -6,11 +6,11 @@ author: Jacob Delgado, SnapAttack
description: Logs details about X.509 certificates observed in network traffic captured
by Zeek (formerly Bro), including certificate fields, validity periods, and issuers.
mitre_components:
- - Certificate Registration
- - Network Traffic Content
- - Response Metadata
- - Application Log Content
- - Host Status
+- Certificate Registration
+- Network Traffic Content
+- Response Metadata
+- Application Log Content
+- Host Status
source: bro:x509:json
sourcetype: bro:x509:json
supported_TA: []
diff --git a/data_sources/circleci.yml b/data_sources/circleci.yml
index b07ad95c84..dc231daca7 100644
--- a/data_sources/circleci.yml
+++ b/data_sources/circleci.yml
@@ -6,70 +6,70 @@ author: Patrick Bareiss, Splunk
description: Logs activities related to CI/CD pipelines executed in CircleCI, including
job execution, workflow progress, and configuration changes.
mitre_components:
- - Scheduled Job Execution
- - Scheduled Job Metadata
- - Application Log Content
- - Configuration Modification
- - Host Status
+- Scheduled Job Execution
+- Scheduled Job Metadata
+- Application Log Content
+- Configuration Modification
+- Host Status
source: circleci
sourcetype: circleci
supported_TA:
- - name: App for CircleCI
- url: https://splunkbase.splunk.com/app/5162
- version: 0.1.1
+- name: App for CircleCI
+ url: https://splunkbase.splunk.com/app/5162
+ version: 0.1.1
fields:
- - _time
- - author_name
- - avatar_url
- - branch
- - build_num
- - build_time_millis
- - build_url
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - eventtype
- - fail_reason
- - host
- - index
- - job_name
- - job_time
- - linecount
- - owners{}
- - project_slug
- - punct
- - queued_time
- - reponame
- - source
- - sourcetype
- - splunk_server
- - start_time
- - status
- - stop_time
- - tag
- - tag::eventtype
- - timedout
- - timeendpos
- - timestartpos
- - username
- - vcs.commit_time
- - vcs.committer_name
- - vcs.revision
- - vcs.subject
- - vcs.tag
- - vcs.type
- - vcs.url
- - workflows.job_id
- - workflows.job_name
- - workflows.upstream_job_ids{}
- - workflows.workflow_id
- - workflows.workflow_name
- - workflows.workspace_id
+- _time
+- author_name
+- avatar_url
+- branch
+- build_num
+- build_time_millis
+- build_url
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- eventtype
+- fail_reason
+- host
+- index
+- job_name
+- job_time
+- linecount
+- owners{}
+- project_slug
+- punct
+- queued_time
+- reponame
+- source
+- sourcetype
+- splunk_server
+- start_time
+- status
+- stop_time
+- tag
+- tag::eventtype
+- timedout
+- timeendpos
+- timestartpos
+- username
+- vcs.commit_time
+- vcs.committer_name
+- vcs.revision
+- vcs.subject
+- vcs.tag
+- vcs.type
+- vcs.url
+- workflows.job_id
+- workflows.job_name
+- workflows.upstream_job_ids{}
+- workflows.workflow_id
+- workflows.workflow_name
+- workflows.workspace_id
example_log: '{"job_time": "2021-09-02T08:13:34.273Z", "stop_time": "2021-09-02T08:13:34.273Z",
"start_time": "2021-09-02T08:10:15.829Z", "queued_time": "2021-09-02T08:10:12.764Z",
"job_name": "Unknown", "reponame": "devsecops_poc", "build_num": 94, "build_url":
diff --git a/data_sources/crowdstrike_processrollup2.yml b/data_sources/crowdstrike_processrollup2.yml
index d160cf8620..a038a6273f 100644
--- a/data_sources/crowdstrike_processrollup2.yml
+++ b/data_sources/crowdstrike_processrollup2.yml
@@ -7,109 +7,109 @@ description: Logs process-related activities captured by CrowdStrike, including
creation, termination, and metadata such as hashes, parent processes, and command-line
arguments.
mitre_components:
- - Process Creation
- - Process Termination
- - Process Metadata
- - Command Execution
- - OS API Execution
+- Process Creation
+- Process Termination
+- Process Metadata
+- Command Execution
+- OS API Execution
source: crowdstrike
sourcetype: crowdstrike:events:sensor
separator: event_simpleName
separator_value: ProcessRollup2
supported_TA:
- - name: Splunk Add-on for CrowdStrike FDR
- url: https://splunkbase.splunk.com/app/5579
- version: 2.0.3
+- name: Splunk Add-on for CrowdStrike FDR
+ url: https://splunkbase.splunk.com/app/5579
+ version: 2.0.3
fields:
- - AuthenticationId
- - AuthenticationId_meaning
- - AuthenticodeHashData
- - CommandLine
- - ConfigBuild
- - ConfigStateHash
- - EffectiveTransmissionClass
- - Entitlements
- - EventOrigin
- - ImageFileName
- - ImageSubsystem
- - ImageSubsystem_meaning
- - IntegrityLevel
- - IntegrityLevel_meaning
- - MD5HashData
- - ParentAuthenticationId
- - ParentBaseFileName
- - ParentProcessId
- - ProcessCreateFlags
- - ProcessEndTime
- - ProcessParameterFlags
- - ProcessParameterFlags_meaning
- - ProcessStartTime
- - ProcessSxsFlags
- - ProcessSxsFlags_meaning
- - RawProcessId
- - SHA1HashData
- - SHA256HashData
- - SessionId
- - SignInfoFlags
- - SignInfoFlags_meaning
- - SourceProcessId
- - SourceThreadId
- - Tags
- - TargetProcessId
- - TokenType
- - TokenType_meaning
- - UserSid
- - WindowFlags
- - WindowFlags_meaning
- - action
- - aid
- - aid_city
- - aid_computer_name
- - aid_continent
- - aid_country
- - aid_machine_domain
- - aid_os_version
- - aid_ou
- - aid_site_name
- - aid_system_product_name
- - aip
- - cid
- - dest
- - event_ingest_time
- - event_platform
- - event_simpleName
- - eventtype
- - host_res_aid
- - id
- - os
- - parent_process_exec
- - parent_process_id
- - parent_process_name
- - process
- - process_exec
- - process_hash
- - process_id
- - process_integrity_level
- - process_name
- - process_path
- - resolve_dest
- - resolve_process_integrity_level
- - tag
- - timestamp
- - user
- - user_id
- - vendor_product
+- AuthenticationId
+- AuthenticationId_meaning
+- AuthenticodeHashData
+- CommandLine
+- ConfigBuild
+- ConfigStateHash
+- EffectiveTransmissionClass
+- Entitlements
+- EventOrigin
+- ImageFileName
+- ImageSubsystem
+- ImageSubsystem_meaning
+- IntegrityLevel
+- IntegrityLevel_meaning
+- MD5HashData
+- ParentAuthenticationId
+- ParentBaseFileName
+- ParentProcessId
+- ProcessCreateFlags
+- ProcessEndTime
+- ProcessParameterFlags
+- ProcessParameterFlags_meaning
+- ProcessStartTime
+- ProcessSxsFlags
+- ProcessSxsFlags_meaning
+- RawProcessId
+- SHA1HashData
+- SHA256HashData
+- SessionId
+- SignInfoFlags
+- SignInfoFlags_meaning
+- SourceProcessId
+- SourceThreadId
+- Tags
+- TargetProcessId
+- TokenType
+- TokenType_meaning
+- UserSid
+- WindowFlags
+- WindowFlags_meaning
+- action
+- aid
+- aid_city
+- aid_computer_name
+- aid_continent
+- aid_country
+- aid_machine_domain
+- aid_os_version
+- aid_ou
+- aid_site_name
+- aid_system_product_name
+- aip
+- cid
+- dest
+- event_ingest_time
+- event_platform
+- event_simpleName
+- eventtype
+- host_res_aid
+- id
+- os
+- parent_process_exec
+- parent_process_id
+- parent_process_name
+- process
+- process_exec
+- process_hash
+- process_id
+- process_integrity_level
+- process_name
+- process_path
+- resolve_dest
+- resolve_process_integrity_level
+- tag
+- timestamp
+- user
+- user_id
+- vendor_product
field_mappings:
- - data_model: cim
- data_set: Endpoint.Processes
- mapping:
- CommandLine: Processes.process
- ImageFileName: Processes.process_path
- ParentBaseFileName: Processes.parent_process_name
- ParentProcessId: Processes.parent_process_id
- RawProcessId: Processes.process_id
- SHA256HashData: Processes.process_hash
- UserSid: Processes.user
+- data_model: cim
+ data_set: Endpoint.Processes
+ mapping:
+ CommandLine: Processes.process
+ ImageFileName: Processes.process_path
+ ParentBaseFileName: Processes.parent_process_name
+ ParentProcessId: Processes.parent_process_id
+ RawProcessId: Processes.process_id
+ SHA256HashData: Processes.process_hash
+ UserSid: Processes.user
example_log: '{"LinkName":"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start
Menu\\Programs\\Windows PowerShell\\Windows PowerShell.lnk","ProcessCreateFlags":"67634196","IntegrityLevel":"12288","ParentProcessId":"5459598860","SourceProcessId":"5459598860","aip":"3.126.231.40","SHA1HashData":"0000000000000000000000000000000000000000","UserSid":"S-1-5-21-586445407-708991241-1829972403-500","event_platform":"Win","TokenType":"1","ProcessEndTime":"","AuthenticodeHashData":"3b98faafc17b47beb9027c437fceeafdf0624a1c","ParentBaseFileName":"explorer.exe","EventOrigin":"1","ImageSubsystem":"3","id":"e2210781-0e8f-47d2-bf6a-56d2c59f38ee","EffectiveTransmissionClass":"3","SessionId":"2","ShowWindowFlags":"1","Tags":"27,
40, 151, 874, 924, 12094627905582, 12094627906234, 211106232533012, 212205744161605,
diff --git a/data_sources/crushftp.yml b/data_sources/crushftp.yml
index 67968d73ef..597fda30f8 100644
--- a/data_sources/crushftp.yml
+++ b/data_sources/crushftp.yml
@@ -6,17 +6,17 @@ author: Patrick Bareiss, Splunk
description: Logs activities related to file transfers and user interactions in CrushFTP,
including file uploads, downloads, user authentication, and session details.
mitre_components:
- - File Access
- - File Metadata
- - User Account Authentication
- - Logon Session Metadata
- - Network Traffic Content
+- File Access
+- File Metadata
+- User Account Authentication
+- Logon Session Metadata
+- Network Traffic Content
source: crushftp
sourcetype: crushftp:sessionlogs
supported_TA: []
fields:
- - _time
- - _raw
+- _time
+- _raw
example_log: 'SESSION|05/14/2024 17:36:21.859|[HTTPS:169_52326_sMa:anonymous:10.0.1.30]
READ: *POST /WebInterface/function/?c2f=CmF1&command=zip&path=%3CINCLUDE%3Eusers/MainUsers/groups.XML%3C/INCLUDE%3E&names=/a
HTTP/1.1*'
diff --git a/data_sources/g_suite_drive.yml b/data_sources/g_suite_drive.yml
index 0d56a7944d..dac656446b 100644
--- a/data_sources/g_suite_drive.yml
+++ b/data_sources/g_suite_drive.yml
@@ -6,49 +6,49 @@ author: Patrick Bareiss, Splunk
description: Logs activities related to Google Drive in G Suite, including file creation,
modification, sharing, and access details.
mitre_components:
- - File Access
- - File Creation
- - File Modification
- - Cloud Storage Access
- - Cloud Storage Metadata
+- File Access
+- File Creation
+- File Modification
+- Cloud Storage Access
+- Cloud Storage Metadata
source: http:gsuite
sourcetype: gsuite:drive:json
supported_TA:
- - name: Splunk Add-on for Google Workspace
- url: https://splunkbase.splunk.com/app/5556
- version: 3.0.2
+- name: Splunk Add-on for Google Workspace
+ url: https://splunkbase.splunk.com/app/5556
+ version: 3.0.2
fields:
- - _time
- - email
- - host
- - index
- - ip_address
- - linecount
- - name
- - parameters.actor_is_collaborator_account
- - parameters.billable
- - parameters.doc_id
- - parameters.doc_title
- - parameters.doc_type
- - parameters.is_encrypted
- - parameters.new_value{}
- - parameters.old_value{}
- - parameters.old_visibility
- - parameters.originating_app_id
- - parameters.owner
- - parameters.owner_is_shared_drive
- - parameters.owner_is_team_drive
- - parameters.primary_event
- - parameters.target_user
- - parameters.visibility
- - parameters.visibility_change
- - punct
- - source
- - sourcetype
- - splunk_server
- - timestamp
- - type
- - unique_id
+- _time
+- email
+- host
+- index
+- ip_address
+- linecount
+- name
+- parameters.actor_is_collaborator_account
+- parameters.billable
+- parameters.doc_id
+- parameters.doc_title
+- parameters.doc_type
+- parameters.is_encrypted
+- parameters.new_value{}
+- parameters.old_value{}
+- parameters.old_visibility
+- parameters.originating_app_id
+- parameters.owner
+- parameters.owner_is_shared_drive
+- parameters.owner_is_team_drive
+- parameters.primary_event
+- parameters.target_user
+- parameters.visibility
+- parameters.visibility_change
+- punct
+- source
+- sourcetype
+- splunk_server
+- timestamp
+- type
+- unique_id
example_log: '{"type": "acl_change", "name": "change_user_access", "parameters": {"primary_event":
true, "billable": true, "visibility_change": "none", "target_user": "alberto@internal_test_email.com",
"old_value": ["none"], "new_value": ["can_edit"], "old_visibility": "private", "doc_id":
diff --git a/data_sources/g_suite_gmail.yml b/data_sources/g_suite_gmail.yml
index c89e7087fb..1d698151df 100644
--- a/data_sources/g_suite_gmail.yml
+++ b/data_sources/g_suite_gmail.yml
@@ -6,87 +6,87 @@ author: Patrick Bareiss, Splunk
description: Logs Gmail activities in G Suite, including email sending, receiving,
and access details, as well as potential security-related events.
mitre_components:
- - Application Log Content
- - User Account Metadata
- - Email Metadata
- - Cloud Service Metadata
+- Application Log Content
+- User Account Metadata
+- Email Metadata
+- Cloud Service Metadata
source: http:gsuite
sourcetype: gsuite:gmail:bigquery
supported_TA:
- - name: Splunk Add-on for Google Workspace
- url: https://splunkbase.splunk.com/app/5556
- version: 3.0.2
+- name: Splunk Add-on for Google Workspace
+ url: https://splunkbase.splunk.com/app/5556
+ version: 3.0.2
fields:
- - _time
- - action_type
- - attachment{}.file_extension_type
- - attachment{}.malware_family
- - attachment{}.sha256
- - connection_info.authenticated_domain{}.name
- - connection_info.authenticated_domain{}.type
- - connection_info.client_host_zone
- - connection_info.client_ip
- - connection_info.dkim_pass
- - connection_info.dmarc_pass
- - connection_info.dmarc_published_domain
- - connection_info.ip_geo_city
- - connection_info.ip_geo_country
- - connection_info.is_internal
- - connection_info.is_intra_domain
- - connection_info.smtp_in_connect_ip
- - connection_info.smtp_out_connect_ip
- - connection_info.smtp_out_remote_host
- - connection_info.smtp_reply_code
- - connection_info.smtp_response_reason
- - connection_info.smtp_tls_cipher
- - connection_info.smtp_tls_state
- - connection_info.smtp_tls_version
- - connection_info.smtp_user_agent_ip
- - connection_info.spf_pass
- - connection_info.tls_required_but_unavailable
- - description
- - destination{}.address
- - destination{}.rcpt_response
- - destination{}.selector
- - destination{}.service
- - destination{}.smime_decryption_success
- - destination{}.smime_extraction_success
- - destination{}.smime_parsing_success
- - destination{}.smime_signature_verification_success
- - eventtype
- - flattened_destinations
- - flattened_triggered_rule_info
- - host
- - index
- - is_policy_check_for_sender
- - is_spam
- - linecount
- - message_set{}.type
- - num_message_attachments
- - payload_size
- - punct
- - rfc2822_message_id
- - smime_content_type
- - smime_encrypt_message
- - smime_extraction_success
- - smime_packaging_success
- - smime_sign_message
- - smtp_relay_error
- - source
- - source.address
- - source.from_header_address
- - source.from_header_displayname
- - source.selector
- - source.service
- - sourcetype
- - spam_info
- - splunk_server
- - structured_policy_log_info
- - subject
- - tag
- - tag::eventtype
- - timestamp
- - upload_error_category
+- _time
+- action_type
+- attachment{}.file_extension_type
+- attachment{}.malware_family
+- attachment{}.sha256
+- connection_info.authenticated_domain{}.name
+- connection_info.authenticated_domain{}.type
+- connection_info.client_host_zone
+- connection_info.client_ip
+- connection_info.dkim_pass
+- connection_info.dmarc_pass
+- connection_info.dmarc_published_domain
+- connection_info.ip_geo_city
+- connection_info.ip_geo_country
+- connection_info.is_internal
+- connection_info.is_intra_domain
+- connection_info.smtp_in_connect_ip
+- connection_info.smtp_out_connect_ip
+- connection_info.smtp_out_remote_host
+- connection_info.smtp_reply_code
+- connection_info.smtp_response_reason
+- connection_info.smtp_tls_cipher
+- connection_info.smtp_tls_state
+- connection_info.smtp_tls_version
+- connection_info.smtp_user_agent_ip
+- connection_info.spf_pass
+- connection_info.tls_required_but_unavailable
+- description
+- destination{}.address
+- destination{}.rcpt_response
+- destination{}.selector
+- destination{}.service
+- destination{}.smime_decryption_success
+- destination{}.smime_extraction_success
+- destination{}.smime_parsing_success
+- destination{}.smime_signature_verification_success
+- eventtype
+- flattened_destinations
+- flattened_triggered_rule_info
+- host
+- index
+- is_policy_check_for_sender
+- is_spam
+- linecount
+- message_set{}.type
+- num_message_attachments
+- payload_size
+- punct
+- rfc2822_message_id
+- smime_content_type
+- smime_encrypt_message
+- smime_extraction_success
+- smime_packaging_success
+- smime_sign_message
+- smtp_relay_error
+- source
+- source.address
+- source.from_header_address
+- source.from_header_displayname
+- source.selector
+- source.service
+- sourcetype
+- spam_info
+- splunk_server
+- structured_policy_log_info
+- subject
+- tag
+- tag::eventtype
+- timestamp
+- upload_error_category
example_log: '{"action_type": 10, "rfc2822_message_id": "",
"subject": "New Order DHL0000001 - Dummy email for Detection Development", "payload_size":
6733, "source": {"address": "john@external_test_email.com", "service": "gmail-for-work",
diff --git a/data_sources/github.yml b/data_sources/github.yml
index 32ebea53e7..eaeabb40ed 100644
--- a/data_sources/github.yml
+++ b/data_sources/github.yml
@@ -6,207 +6,207 @@ author: Patrick Bareiss, Splunk
description: Logs activities on GitHub repositories, including push events, pull requests,
issue creation, and user authentication events.
mitre_components:
- - User Account Authentication
- - Configuration Modification
- - Application Log Content
- - User Account Metadata
- - Scheduled Job Metadata
+- User Account Authentication
+- Configuration Modification
+- Application Log Content
+- User Account Metadata
+- Scheduled Job Metadata
source: github
sourcetype: aws:firehose:json
supported_TA:
- - name: Splunk Add-on for Github
- url: https://splunkbase.splunk.com/app/6254
- version: 3.1.0
+- name: Splunk Add-on for Github
+ url: https://splunkbase.splunk.com/app/6254
+ version: 3.1.0
fields:
- - _time
- - action
- - host
- - index
- - linecount
- - meta
- - punct
- - source
- - sourcetype
- - splunk_server
- - timestamp
- - workflow_run.actor.avatar_url
- - workflow_run.actor.events_url
- - workflow_run.actor.followers_url
- - workflow_run.actor.following_url
- - workflow_run.actor.gists_url
- - workflow_run.actor.gravatar_id
- - workflow_run.actor.html_url
- - workflow_run.actor.id
- - workflow_run.actor.login
- - workflow_run.actor.node_id
- - workflow_run.actor.organizations_url
- - workflow_run.actor.received_events_url
- - workflow_run.actor.repos_url
- - workflow_run.actor.site_admin
- - workflow_run.actor.starred_url
- - workflow_run.actor.subscriptions_url
- - workflow_run.actor.type
- - workflow_run.actor.url
- - workflow_run.artifacts_url
- - workflow_run.cancel_url
- - workflow_run.check_suite_id
- - workflow_run.check_suite_node_id
- - workflow_run.check_suite_url
- - workflow_run.conclusion
- - workflow_run.created_at
- - workflow_run.event
- - workflow_run.head_branch
- - workflow_run.head_commit.author.email
- - workflow_run.head_commit.author.name
- - workflow_run.head_commit.committer.email
- - workflow_run.head_commit.committer.name
- - workflow_run.head_commit.id
- - workflow_run.head_commit.message
- - workflow_run.head_commit.timestamp
- - workflow_run.head_commit.tree_id
- - workflow_run.head_repository.collaborators_url
- - workflow_run.head_repository.description
- - workflow_run.head_repository.fork
- - workflow_run.head_repository.forks_url
- - workflow_run.head_repository.full_name
- - workflow_run.head_repository.hooks_url
- - workflow_run.head_repository.html_url
- - workflow_run.head_repository.id
- - workflow_run.head_repository.keys_url
- - workflow_run.head_repository.name
- - workflow_run.head_repository.node_id
- - workflow_run.head_repository.owner.avatar_url
- - workflow_run.head_repository.owner.events_url
- - workflow_run.head_repository.owner.followers_url
- - workflow_run.head_repository.owner.following_url
- - workflow_run.head_repository.owner.gists_url
- - workflow_run.head_repository.owner.gravatar_id
- - workflow_run.head_repository.owner.html_url
- - workflow_run.head_repository.owner.id
- - workflow_run.head_repository.owner.login
- - workflow_run.head_repository.owner.node_id
- - workflow_run.head_repository.owner.organizations_url
- - workflow_run.head_repository.owner.received_events_url
- - workflow_run.head_repository.owner.repos_url
- - workflow_run.head_repository.owner.site_admin
- - workflow_run.head_repository.owner.starred_url
- - workflow_run.head_repository.owner.subscriptions_url
- - workflow_run.head_repository.owner.type
- - workflow_run.head_repository.owner.url
- - workflow_run.head_repository.private
- - workflow_run.head_repository.teams_url
- - workflow_run.head_repository.url
- - workflow_run.head_sha
- - workflow_run.html_url
- - workflow_run.id
- - workflow_run.jobs_url
- - workflow_run.logs_url
- - workflow_run.name
- - workflow_run.node_id
- - workflow_run.previous_attempt_url
- - workflow_run.pull_requests{}.base.ref
- - workflow_run.pull_requests{}.base.repo.id
- - workflow_run.pull_requests{}.base.repo.name
- - workflow_run.pull_requests{}.base.repo.url
- - workflow_run.pull_requests{}.base.sha
- - workflow_run.pull_requests{}.head.ref
- - workflow_run.pull_requests{}.head.repo.id
- - workflow_run.pull_requests{}.head.repo.name
- - workflow_run.pull_requests{}.head.repo.url
- - workflow_run.pull_requests{}.head.sha
- - workflow_run.pull_requests{}.id
- - workflow_run.pull_requests{}.number
- - workflow_run.pull_requests{}.url
- - workflow_run.repository.archive_url
- - workflow_run.repository.assignees_url
- - workflow_run.repository.blobs_url
- - workflow_run.repository.branches_url
- - workflow_run.repository.collaborators_url
- - workflow_run.repository.comments_url
- - workflow_run.repository.commits_url
- - workflow_run.repository.compare_url
- - workflow_run.repository.contents_url
- - workflow_run.repository.contributors_url
- - workflow_run.repository.deployments_url
- - workflow_run.repository.description
- - workflow_run.repository.downloads_url
- - workflow_run.repository.events_url
- - workflow_run.repository.fork
- - workflow_run.repository.forks_url
- - workflow_run.repository.full_name
- - workflow_run.repository.git_commits_url
- - workflow_run.repository.git_refs_url
- - workflow_run.repository.git_tags_url
- - workflow_run.repository.hooks_url
- - workflow_run.repository.html_url
- - workflow_run.repository.id
- - workflow_run.repository.issue_comment_url
- - workflow_run.repository.issue_events_url
- - workflow_run.repository.issues_url
- - workflow_run.repository.keys_url
- - workflow_run.repository.labels_url
- - workflow_run.repository.languages_url
- - workflow_run.repository.merges_url
- - workflow_run.repository.milestones_url
- - workflow_run.repository.name
- - workflow_run.repository.node_id
- - workflow_run.repository.notifications_url
- - workflow_run.repository.owner.avatar_url
- - workflow_run.repository.owner.events_url
- - workflow_run.repository.owner.followers_url
- - workflow_run.repository.owner.following_url
- - workflow_run.repository.owner.gists_url
- - workflow_run.repository.owner.gravatar_id
- - workflow_run.repository.owner.html_url
- - workflow_run.repository.owner.id
- - workflow_run.repository.owner.login
- - workflow_run.repository.owner.node_id
- - workflow_run.repository.owner.organizations_url
- - workflow_run.repository.owner.received_events_url
- - workflow_run.repository.owner.repos_url
- - workflow_run.repository.owner.site_admin
- - workflow_run.repository.owner.starred_url
- - workflow_run.repository.owner.subscriptions_url
- - workflow_run.repository.owner.type
- - workflow_run.repository.owner.url
- - workflow_run.repository.private
- - workflow_run.repository.pulls_url
- - workflow_run.repository.releases_url
- - workflow_run.repository.stargazers_url
- - workflow_run.repository.statuses_url
- - workflow_run.repository.subscribers_url
- - workflow_run.repository.subscription_url
- - workflow_run.repository.tags_url
- - workflow_run.repository.teams_url
- - workflow_run.repository.trees_url
- - workflow_run.repository.url
- - workflow_run.rerun_url
- - workflow_run.run_attempt
- - workflow_run.run_number
- - workflow_run.run_started_at
- - workflow_run.status
- - workflow_run.triggering_actor.avatar_url
- - workflow_run.triggering_actor.events_url
- - workflow_run.triggering_actor.followers_url
- - workflow_run.triggering_actor.following_url
- - workflow_run.triggering_actor.gists_url
- - workflow_run.triggering_actor.gravatar_id
- - workflow_run.triggering_actor.html_url
- - workflow_run.triggering_actor.id
- - workflow_run.triggering_actor.login
- - workflow_run.triggering_actor.node_id
- - workflow_run.triggering_actor.organizations_url
- - workflow_run.triggering_actor.received_events_url
- - workflow_run.triggering_actor.repos_url
- - workflow_run.triggering_actor.site_admin
- - workflow_run.triggering_actor.starred_url
- - workflow_run.triggering_actor.subscriptions_url
- - workflow_run.triggering_actor.type
- - workflow_run.triggering_actor.url
- - workflow_run.updated_at
- - workflow_run.url
- - workflow_run.workflow_id
- - workflow_run.workflow_url
+- _time
+- action
+- host
+- index
+- linecount
+- meta
+- punct
+- source
+- sourcetype
+- splunk_server
+- timestamp
+- workflow_run.actor.avatar_url
+- workflow_run.actor.events_url
+- workflow_run.actor.followers_url
+- workflow_run.actor.following_url
+- workflow_run.actor.gists_url
+- workflow_run.actor.gravatar_id
+- workflow_run.actor.html_url
+- workflow_run.actor.id
+- workflow_run.actor.login
+- workflow_run.actor.node_id
+- workflow_run.actor.organizations_url
+- workflow_run.actor.received_events_url
+- workflow_run.actor.repos_url
+- workflow_run.actor.site_admin
+- workflow_run.actor.starred_url
+- workflow_run.actor.subscriptions_url
+- workflow_run.actor.type
+- workflow_run.actor.url
+- workflow_run.artifacts_url
+- workflow_run.cancel_url
+- workflow_run.check_suite_id
+- workflow_run.check_suite_node_id
+- workflow_run.check_suite_url
+- workflow_run.conclusion
+- workflow_run.created_at
+- workflow_run.event
+- workflow_run.head_branch
+- workflow_run.head_commit.author.email
+- workflow_run.head_commit.author.name
+- workflow_run.head_commit.committer.email
+- workflow_run.head_commit.committer.name
+- workflow_run.head_commit.id
+- workflow_run.head_commit.message
+- workflow_run.head_commit.timestamp
+- workflow_run.head_commit.tree_id
+- workflow_run.head_repository.collaborators_url
+- workflow_run.head_repository.description
+- workflow_run.head_repository.fork
+- workflow_run.head_repository.forks_url
+- workflow_run.head_repository.full_name
+- workflow_run.head_repository.hooks_url
+- workflow_run.head_repository.html_url
+- workflow_run.head_repository.id
+- workflow_run.head_repository.keys_url
+- workflow_run.head_repository.name
+- workflow_run.head_repository.node_id
+- workflow_run.head_repository.owner.avatar_url
+- workflow_run.head_repository.owner.events_url
+- workflow_run.head_repository.owner.followers_url
+- workflow_run.head_repository.owner.following_url
+- workflow_run.head_repository.owner.gists_url
+- workflow_run.head_repository.owner.gravatar_id
+- workflow_run.head_repository.owner.html_url
+- workflow_run.head_repository.owner.id
+- workflow_run.head_repository.owner.login
+- workflow_run.head_repository.owner.node_id
+- workflow_run.head_repository.owner.organizations_url
+- workflow_run.head_repository.owner.received_events_url
+- workflow_run.head_repository.owner.repos_url
+- workflow_run.head_repository.owner.site_admin
+- workflow_run.head_repository.owner.starred_url
+- workflow_run.head_repository.owner.subscriptions_url
+- workflow_run.head_repository.owner.type
+- workflow_run.head_repository.owner.url
+- workflow_run.head_repository.private
+- workflow_run.head_repository.teams_url
+- workflow_run.head_repository.url
+- workflow_run.head_sha
+- workflow_run.html_url
+- workflow_run.id
+- workflow_run.jobs_url
+- workflow_run.logs_url
+- workflow_run.name
+- workflow_run.node_id
+- workflow_run.previous_attempt_url
+- workflow_run.pull_requests{}.base.ref
+- workflow_run.pull_requests{}.base.repo.id
+- workflow_run.pull_requests{}.base.repo.name
+- workflow_run.pull_requests{}.base.repo.url
+- workflow_run.pull_requests{}.base.sha
+- workflow_run.pull_requests{}.head.ref
+- workflow_run.pull_requests{}.head.repo.id
+- workflow_run.pull_requests{}.head.repo.name
+- workflow_run.pull_requests{}.head.repo.url
+- workflow_run.pull_requests{}.head.sha
+- workflow_run.pull_requests{}.id
+- workflow_run.pull_requests{}.number
+- workflow_run.pull_requests{}.url
+- workflow_run.repository.archive_url
+- workflow_run.repository.assignees_url
+- workflow_run.repository.blobs_url
+- workflow_run.repository.branches_url
+- workflow_run.repository.collaborators_url
+- workflow_run.repository.comments_url
+- workflow_run.repository.commits_url
+- workflow_run.repository.compare_url
+- workflow_run.repository.contents_url
+- workflow_run.repository.contributors_url
+- workflow_run.repository.deployments_url
+- workflow_run.repository.description
+- workflow_run.repository.downloads_url
+- workflow_run.repository.events_url
+- workflow_run.repository.fork
+- workflow_run.repository.forks_url
+- workflow_run.repository.full_name
+- workflow_run.repository.git_commits_url
+- workflow_run.repository.git_refs_url
+- workflow_run.repository.git_tags_url
+- workflow_run.repository.hooks_url
+- workflow_run.repository.html_url
+- workflow_run.repository.id
+- workflow_run.repository.issue_comment_url
+- workflow_run.repository.issue_events_url
+- workflow_run.repository.issues_url
+- workflow_run.repository.keys_url
+- workflow_run.repository.labels_url
+- workflow_run.repository.languages_url
+- workflow_run.repository.merges_url
+- workflow_run.repository.milestones_url
+- workflow_run.repository.name
+- workflow_run.repository.node_id
+- workflow_run.repository.notifications_url
+- workflow_run.repository.owner.avatar_url
+- workflow_run.repository.owner.events_url
+- workflow_run.repository.owner.followers_url
+- workflow_run.repository.owner.following_url
+- workflow_run.repository.owner.gists_url
+- workflow_run.repository.owner.gravatar_id
+- workflow_run.repository.owner.html_url
+- workflow_run.repository.owner.id
+- workflow_run.repository.owner.login
+- workflow_run.repository.owner.node_id
+- workflow_run.repository.owner.organizations_url
+- workflow_run.repository.owner.received_events_url
+- workflow_run.repository.owner.repos_url
+- workflow_run.repository.owner.site_admin
+- workflow_run.repository.owner.starred_url
+- workflow_run.repository.owner.subscriptions_url
+- workflow_run.repository.owner.type
+- workflow_run.repository.owner.url
+- workflow_run.repository.private
+- workflow_run.repository.pulls_url
+- workflow_run.repository.releases_url
+- workflow_run.repository.stargazers_url
+- workflow_run.repository.statuses_url
+- workflow_run.repository.subscribers_url
+- workflow_run.repository.subscription_url
+- workflow_run.repository.tags_url
+- workflow_run.repository.teams_url
+- workflow_run.repository.trees_url
+- workflow_run.repository.url
+- workflow_run.rerun_url
+- workflow_run.run_attempt
+- workflow_run.run_number
+- workflow_run.run_started_at
+- workflow_run.status
+- workflow_run.triggering_actor.avatar_url
+- workflow_run.triggering_actor.events_url
+- workflow_run.triggering_actor.followers_url
+- workflow_run.triggering_actor.following_url
+- workflow_run.triggering_actor.gists_url
+- workflow_run.triggering_actor.gravatar_id
+- workflow_run.triggering_actor.html_url
+- workflow_run.triggering_actor.id
+- workflow_run.triggering_actor.login
+- workflow_run.triggering_actor.node_id
+- workflow_run.triggering_actor.organizations_url
+- workflow_run.triggering_actor.received_events_url
+- workflow_run.triggering_actor.repos_url
+- workflow_run.triggering_actor.site_admin
+- workflow_run.triggering_actor.starred_url
+- workflow_run.triggering_actor.subscriptions_url
+- workflow_run.triggering_actor.type
+- workflow_run.triggering_actor.url
+- workflow_run.updated_at
+- workflow_run.url
+- workflow_run.workflow_id
+- workflow_run.workflow_url
example_log: '{"action":"requested","workflow_run":{"id":2088708615,"name":"auto-update","node_id":"WFR_kwLOCa00Ec58fyoH","head_branch":"mac_os_detections","head_sha":"4049334910ea3d52a917ca35aed66d11c80ed966","run_number":9504,"event":"push","status":"queued","conclusion":null,"workflow_id":4692335,"check_suite_id":5918781611,"check_suite_node_id":"CS_kwDOCa00Ec8AAAABYMlwqw","url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615","html_url":"https://github.com/splunk/security_content/actions/runs/2088708615","pull_requests":[{"url":"https://api.github.com/repos/splunk/security_content/pulls/2131","id":893091277,"number":2131,"head":{"ref":"mac_os_detections","sha":"4049334910ea3d52a917ca35aed66d11c80ed966","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}},"base":{"ref":"develop","sha":"a7d3d1dc57f9bf36fe22e470bcf518fcc2c89283","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}}}],"created_at":"2022-04-04T08:43:15Z","updated_at":"2022-04-04T08:43:15Z","actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"run_attempt":1,"run_started_at":"2022-04-04T08:43:15Z","triggering_actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"jobs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/jobs","logs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/logs","check_suite_url":"https://api.github.com/repos/splunk/security_content/check-suites/5918781611","artifacts_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/artifacts","cancel_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/cancel","rerun_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/rerun","previous_attempt_url":null,"workflow_url":"https://api.github.com/repos/splunk/security_content/actions/workflows/4692335","head_commit":{"id":"4049334910ea3d52a917ca35aed66d11c80ed966","tree_id":"df4ddc1359be3b19f093b7a27dbf5708187743a0","message":"small
change","timestamp":"2022-04-04T08:43:01Z","author":{"name":"jsmith","email":"jsmith@evilcorp.com"},"committer":{"name":"jsmith","email":"jsmith@evilcorp.com"}},"repository":{"id":162346001,"node_id":"MDEwOlJlcG9zaXRvcnkxNjIzNDYwMDE=","name":"security_content","full_name":"splunk/security_content","private":false,"owner":{"login":"splunk","id":651467,"node_id":"MDEyOk9yZ2FuaXphdGlvbjY1MTQ2Nw==","avatar_url":"https://avatars.githubusercontent.com/u/651467?v=4","gravatar_id":"","url":"https://api.github.com/users/splunk","html_url":"https://github.com/splunk","followers_url":"https://api.github.com/users/splunk/followers","following_url":"https://api.github.com/users/splunk/following{/other_user}","gists_url":"https://api.github.com/users/splunk/gists{/gist_id}","starred_url":"https://api.github.com/users/splunk/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/splunk/subscriptions","organizations_url":"https://api.github.com/users/splunk/orgs","repos_url":"https://api.github.com/users/splunk/repos","events_url":"https://api.github.com/users/splunk/events{/privacy}","received_events_url":"https://api.github.com/users/splunk/received_events","type":"Organization","site_admin":false},"html_url":"https://github.com/splunk/security_content","description":"Splunk
Security Content","fork":false,"url":"https://api.github.com/repos/splunk/security_content","forks_url":"https://api.github.com/repos/splunk/security_content/forks","keys_url":"https://api.github.com/repos/splunk/security_content/keys{/key_id}","collaborators_url":"https://api.github.com/repos/splunk/security_content/collaborators{/collaborator}","teams_url":"https://api.github.com/repos/splunk/security_content/teams","hooks_url":"https://api.github.com/repos/splunk/security_content/hooks","issue_events_url":"https://api.github.com/repos/splunk/security_content/issues/events{/number}","events_url":"https://api.github.com/repos/splunk/security_content/events","assignees_url":"https://api.github.com/repos/splunk/security_content/assignees{/user}","branches_url":"https://api.github.com/repos/splunk/security_content/branches{/branch}","tags_url":"https://api.github.com/repos/splunk/security_content/tags","blobs_url":"https://api.github.com/repos/splunk/security_content/git/blobs{/sha}","git_tags_url":"https://api.github.com/repos/splunk/security_content/git/tags{/sha}","git_refs_url":"https://api.github.com/repos/splunk/security_content/git/refs{/sha}","trees_url":"https://api.github.com/repos/splunk/security_content/git/trees{/sha}","statuses_url":"https://api.github.com/repos/splunk/security_content/statuses/{sha}","languages_url":"https://api.github.com/repos/splunk/security_content/languages","stargazers_url":"https://api.github.com/repos/splunk/security_content/stargazers","contributors_url":"https://api.github.com/repos/splunk/security_content/contributors","subscribers_url":"https://api.github.com/repos/splunk/security_content/subscribers","subscription_url":"https://api.github.com/repos/splunk/security_content/subscription","commits_url":"https://api.github.com/repos/splunk/security_content/commits{/sha}","git_commits_url":"https://api.github.com/repos/splunk/security_content/git/commits{/sha}","comments_url":"https://api.github.com/repos/splunk/security_content/comments{/number}","issue_comment_url":"https://api.github.com/repos/splunk/security_content/issues/comments{/number}","contents_url":"https://api.github.com/repos/splunk/security_content/contents/{+path}","compare_url":"https://api.github.com/repos/splunk/security_content/compare/{base}...{head}","merges_url":"https://api.github.com/repos/splunk/security_content/merges","archive_url":"https://api.github.com/repos/splunk/security_content/{archive_format}{/ref}","downloads_url":"https://api.github.com/repos/splunk/security_content/downloads","issues_url":"https://api.github.com/repos/splunk/security_content/issues{/number}","pulls_url":"https://api.github.com/repos/splunk/security_content/pulls{/number}","milestones_url":"https://api.github.com/repos/splunk/security_content/milestones{/number}","notifications_url":"https://api.github.com/repos/splunk/security_content/notifications{?since,all,participating}","labels_url":"https://api.github.com/repos/splunk/security_content/labels{/name}","releases_url":"https://api.github.com/repos/splunk/security_content/releases{/id}","deployments_url":"https://api.github.com/repos/splunk/security_content/deployments"},"head_repository":{"id":162346001,"node_id":"MDEwOlJlcG9zaXRvcnkxNjIzNDYwMDE=","name":"security_content","full_name":"splunk/security_content","private":false,"owner":{"login":"splunk","id":651467,"node_id":"MDEyOk9yZ2FuaXphdGlvbjY1MTQ2Nw==","avatar_url":"https://avatars.githubusercontent.com/u/651467?v=4","gravatar_id":"","url":"https://api.github.com/users/splunk","html_url":"https://github.com/splunk","followers_url":"https://api.github.com/users/splunk/followers","following_url":"https://api.github.com/users/splunk/following{/other_user}","gists_url":"https://api.github.com/users/splunk/gists{/gist_id}","starred_url":"https://api.github.com/users/splunk/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/splunk/subscriptions","organizations_url":"https://api.github.com/users/splunk/orgs","repos_url":"https://api.github.com/users/splunk/repos","events_url":"https://api.github.com/users/splunk/events{/privacy}","received_events_url":"https://api.github.com/users/splunk/received_events","type":"Organization","site_admin":false},"html_url":"https://github.com/splunk/security_content","description":"Splunk
diff --git a/data_sources/google_workspace_login_failure.yml b/data_sources/google_workspace_login_failure.yml
index f853aa35f3..702959eef7 100644
--- a/data_sources/google_workspace_login_failure.yml
+++ b/data_sources/google_workspace_login_failure.yml
@@ -6,54 +6,54 @@ author: Patrick Bareiss, Splunk
description: Logs failed login attempts to Google Workspace accounts, including details
about the user, IP address, and reason for failure.
mitre_components:
- - User Account Authentication
- - Logon Session Metadata
- - User Account Metadata
- - Application Log Content
+- User Account Authentication
+- Logon Session Metadata
+- User Account Metadata
+- Application Log Content
source: gws:reports:admin
sourcetype: gws:reports:admin
separator: event.name
separator_value: login_failure
supported_TA:
- - name: Splunk Add-on for Google Workspace
- url: https://splunkbase.splunk.com/app/5556
- version: 3.0.2
+- name: Splunk Add-on for Google Workspace
+ url: https://splunkbase.splunk.com/app/5556
+ version: 3.0.2
fields:
- - _time
- - actor.email
- - actor.profileId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - etag
- - event.name
- - event.parameters{}.multiValue{}
- - event.parameters{}.name
- - event.parameters{}.value
- - event.type
- - eventtype
- - host
- - id.applicationName
- - id.customerId
- - id.time
- - id.uniqueQualifier
- - index
- - ipAddress
- - kind
- - linecount
- - punct
- - source
- - sourcetype
- - splunk_server
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
+- _time
+- actor.email
+- actor.profileId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- etag
+- event.name
+- event.parameters{}.multiValue{}
+- event.parameters{}.name
+- event.parameters{}.value
+- event.type
+- eventtype
+- host
+- id.applicationName
+- id.customerId
+- id.time
+- id.uniqueQualifier
+- index
+- ipAddress
+- kind
+- linecount
+- punct
+- source
+- sourcetype
+- splunk_server
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
example_log: '{"kind": "admin#reports#activity", "id": {"time": "2022-10-12T01:05:35.119Z",
"uniqueQualifier": "720229394436", "applicationName": "login", "customerId": "C046r85ir"},
"etag": "\"JCPRxFaiNR1s5TJ6ecIH8OpGdY4efiOYXbIB65itOzY/_lixtTooT11WXorGf6w6ElN0m0g\"",
diff --git a/data_sources/google_workspace_login_success.yml b/data_sources/google_workspace_login_success.yml
index 4f0d7d8265..3ad47e3299 100644
--- a/data_sources/google_workspace_login_success.yml
+++ b/data_sources/google_workspace_login_success.yml
@@ -6,52 +6,52 @@ author: Patrick Bareiss, Splunk
description: Logs successful login attempts to Google Workspace accounts, including
details about the user, IP address, and session metadata.
mitre_components:
- - User Account Authentication
- - Logon Session Creation
- - User Account Metadata
- - Logon Session Metadata
+- User Account Authentication
+- Logon Session Creation
+- User Account Metadata
+- Logon Session Metadata
source: gws:reports:admin
sourcetype: gws:reports:admin
separator: event.name
separator_value: login_success
supported_TA:
- - name: Splunk Add-on for Google Workspace
- url: https://splunkbase.splunk.com/app/5556
- version: 3.0.2
+- name: Splunk Add-on for Google Workspace
+ url: https://splunkbase.splunk.com/app/5556
+ version: 3.0.2
fields:
- - _time
- - actor.email
- - actor.profileId
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - etag
- - event.name
- - event.parameters{}.boolValue
- - event.parameters{}.multiValue{}
- - event.parameters{}.name
- - event.parameters{}.value
- - event.type
- - host
- - id.applicationName
- - id.customerId
- - id.time
- - id.uniqueQualifier
- - index
- - ipAddress
- - kind
- - linecount
- - punct
- - source
- - sourcetype
- - splunk_server
- - timeendpos
- - timestartpos
+- _time
+- actor.email
+- actor.profileId
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- etag
+- event.name
+- event.parameters{}.boolValue
+- event.parameters{}.multiValue{}
+- event.parameters{}.name
+- event.parameters{}.value
+- event.type
+- host
+- id.applicationName
+- id.customerId
+- id.time
+- id.uniqueQualifier
+- index
+- ipAddress
+- kind
+- linecount
+- punct
+- source
+- sourcetype
+- splunk_server
+- timeendpos
+- timestartpos
example_log: '{"kind": "admin#reports#activity", "id": {"time": "2022-10-13T20:57:35.833Z",
"uniqueQualifier": "437744618349", "applicationName": "login", "customerId": "C046r85ir"},
"etag": "\"JCPRxFaiNR1s5TJ6ecIH8OpGdY4efiOYXbIB65itOzY/OgAbD-Tz8hSD1vUJWw7NLiJ5SF4\"",
diff --git a/data_sources/ivanti_vtm_audit.yml b/data_sources/ivanti_vtm_audit.yml
index 389bf9b8d9..31e1bdc95e 100644
--- a/data_sources/ivanti_vtm_audit.yml
+++ b/data_sources/ivanti_vtm_audit.yml
@@ -6,22 +6,22 @@ author: Michael Haag, Splunk
description: Logs administrative and operational activities in Ivanti Virtual Traffic
Manager (VTM), including configuration changes, user actions, and system events.
mitre_components:
- - Configuration Modification
- - Application Log Content
- - User Account Metadata
- - Host Status
- - Service Modification
+- Configuration Modification
+- Application Log Content
+- User Account Metadata
+- Host Status
+- Service Modification
source: ivanti_vtm
sourcetype: ivanti_vtm_audit
supported_TA: []
fields:
- - _time
- - IP
- - MODUSER
- - OPERATION
- - MODGROUP
- - AUTH
- - USER
- - GROUP
+- _time
+- IP
+- MODUSER
+- OPERATION
+- MODGROUP
+- AUTH
+- USER
+- GROUP
example_log: '[19/Aug/2024:19:41:22 +0000] USER=!!ABSENT!! GROUP=!!ABSENT!! AUTH=!!ABSENT!!
IP=!!ABSENT!! OPERATION=adduser MODUSER=newadmin MODGROUP=admin'
diff --git a/data_sources/kubernetes_audit.yml b/data_sources/kubernetes_audit.yml
index 89588cee18..7553357ea4 100644
--- a/data_sources/kubernetes_audit.yml
+++ b/data_sources/kubernetes_audit.yml
@@ -6,62 +6,62 @@ author: Patrick Bareiss, Splunk
description: Logs activities within a Kubernetes cluster, including API server requests,
resource access, configuration changes, and user authentication events.
mitre_components:
- - Pod Metadata
- - Pod Modification
- - Cluster Metadata
- - User Account Authentication
- - Configuration Modification
- - Application Log Content
+- Pod Metadata
+- Pod Modification
+- Cluster Metadata
+- User Account Authentication
+- Configuration Modification
+- Application Log Content
source: kubernetes
sourcetype: _json
supported_TA: []
fields:
- - _time
- - annotations.authorization.k8s.io/decision
- - annotations.authorization.k8s.io/reason
- - apiVersion
- - auditID
- - eventtype
- - host
- - index
- - kind
- - level
- - linecount
- - objectRef.apiGroup
- - objectRef.apiVersion
- - objectRef.namespace
- - objectRef.resource
- - punct
- - requestReceivedTimestamp
- - requestURI
- - responseObject.apiVersion
- - responseObject.code
- - responseObject.details.group
- - responseObject.details.kind
- - responseObject.kind
- - responseObject.message
- - responseObject.reason
- - responseObject.status
- - responseStatus.code
- - responseStatus.details.group
- - responseStatus.details.kind
- - responseStatus.message
- - responseStatus.reason
- - responseStatus.status
- - source
- - sourceIPs{}
- - sourcetype
- - splunk_server
- - stage
- - stageTimestamp
- - tag
- - tag::eventtype
- - timestamp
- - user.groups{}
- - user.uid
- - user.username
- - userAgent
- - verb
+- _time
+- annotations.authorization.k8s.io/decision
+- annotations.authorization.k8s.io/reason
+- apiVersion
+- auditID
+- eventtype
+- host
+- index
+- kind
+- level
+- linecount
+- objectRef.apiGroup
+- objectRef.apiVersion
+- objectRef.namespace
+- objectRef.resource
+- punct
+- requestReceivedTimestamp
+- requestURI
+- responseObject.apiVersion
+- responseObject.code
+- responseObject.details.group
+- responseObject.details.kind
+- responseObject.kind
+- responseObject.message
+- responseObject.reason
+- responseObject.status
+- responseStatus.code
+- responseStatus.details.group
+- responseStatus.details.kind
+- responseStatus.message
+- responseStatus.reason
+- responseStatus.status
+- source
+- sourceIPs{}
+- sourcetype
+- splunk_server
+- stage
+- stageTimestamp
+- tag
+- tag::eventtype
+- timestamp
+- user.groups{}
+- user.uid
+- user.username
+- userAgent
+- verb
example_log: '{"kind":"Event","apiVersion":"audit.k8s.io/v1","level":"RequestResponse","auditID":"582c31ab-4906-49bb-9ff9-872f980ccb84","stage":"ResponseComplete","requestURI":"/apis/batch/v1/namespaces/test2/jobs?fieldManager=kubectl-create\u0026fieldValidation=Strict","verb":"create","user":{"username":"k8s-test-user","uid":"aws-iam-authenticator:591511147606:AROAYTOGP2RLFHNBOTP5J","groups":["system:authenticated"]},"sourceIPs":["176.95.188.101"],"userAgent":"kubectl/v1.27.2
(darwin/arm64) kubernetes/7f6f68f","objectRef":{"resource":"jobs","namespace":"test2","apiGroup":"batch","apiVersion":"v1"},"responseStatus":{"metadata":{},"status":"Failure","message":"jobs.batch
is forbidden: User \"k8s-test-user\" cannot create resource \"jobs\" in API group
diff --git a/data_sources/kubernetes_falco.yml b/data_sources/kubernetes_falco.yml
index cff1b27f1c..f5f7cf1762 100644
--- a/data_sources/kubernetes_falco.yml
+++ b/data_sources/kubernetes_falco.yml
@@ -6,50 +6,50 @@ author: Patrick Bareiss, Splunk
description: Logs suspicious or anomalous activities within a Kubernetes environment
detected by Falco, including system calls, file access, and network activity.
mitre_components:
- - File Access
- - Network Traffic Content
- - Process Creation
- - Process Modification
- - Application Log Content
- - Host Status
+- File Access
+- Network Traffic Content
+- Process Creation
+- Process Modification
+- Application Log Content
+- Host Status
source: kubernetes
sourcetype: kube:container:falco
supported_TA: []
fields:
- - _time
- - command
- - container_id
- - container_image
- - container_image_tag
- - container_name
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - evt_type
- - exe_flags
- - host
- - index
- - k8s_ns
- - k8s_pod_name
- - linecount
- - parent
- - proc_exepath
- - process
- - punct
- - source
- - sourcetype
- - splunk_server
- - terminal
- - timeendpos
- - timestartpos
- - user
- - user_loginuid
- - user_uid
+- _time
+- command
+- container_id
+- container_image
+- container_image_tag
+- container_name
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- evt_type
+- exe_flags
+- host
+- index
+- k8s_ns
+- k8s_pod_name
+- linecount
+- parent
+- proc_exepath
+- process
+- punct
+- source
+- sourcetype
+- splunk_server
+- terminal
+- timeendpos
+- timestartpos
+- user
+- user_loginuid
+- user_uid
example_log: '12:18:18.691725165: Notice A shell was spawned in a container with an
attached terminal (evt_type=execve user=root user_uid=0 user_loginuid=-1 process=bash
proc_exepath=/usr/lib/splunk-otel-collector/agent-bundle/bin/bash parent=runc command=bash
diff --git a/data_sources/linux_auditd_add_user.yml b/data_sources/linux_auditd_add_user.yml
index da361ede71..4fce4de435 100644
--- a/data_sources/linux_auditd_add_user.yml
+++ b/data_sources/linux_auditd_add_user.yml
@@ -7,38 +7,38 @@ description: Logs activities related to the addition of a new user account on a
system, including details about the username, UID, and the process initiating the
action.
mitre_components:
- - User Account Creation
- - User Account Metadata
- - OS API Execution
- - Application Log Content
+- User Account Creation
+- User Account Metadata
+- OS API Execution
+- Application Log Content
source: /var/log/audit/audit.log
sourcetype: linux:audit
separator: type
separator_value: ADD_USER
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
- - name: Splunk Add-on for Unix and Linux
- url: https://splunkbase.splunk.com/app/833
- version: 9.2.0
+- name: Splunk Add-on for Unix and Linux
+ url: https://splunkbase.splunk.com/app/833
+ version: 9.2.0
fields:
- - msg
- - type
- - pid
- - uid
- - auid
- - ses
- - subj
- - msg
- - op
- - id
- - exe
- - hostname
- - addr
- - terminal
- - res
- - UID
- - AUID
- - ID
-example_log: "type=ADD_USER msg=audit(1722950859.266:6994): pid=1788 uid=0 auid=1000
- ses=1 subj=unconfined msg='op=adding user id=1002 exe=\"/usr/sbin/useradd\" hostname=ar-linux1
- addr=? terminal=pts/1 res=success'UID=\"root\" AUID=\"ubuntu\" ID=\"unknown(1002)\""
+- msg
+- type
+- pid
+- uid
+- auid
+- ses
+- subj
+- msg
+- op
+- id
+- exe
+- hostname
+- addr
+- terminal
+- res
+- UID
+- AUID
+- ID
+example_log: 'type=ADD_USER msg=audit(1722950859.266:6994): pid=1788 uid=0 auid=1000
+ ses=1 subj=unconfined msg=''op=adding user id=1002 exe="/usr/sbin/useradd" hostname=ar-linux1
+ addr=? terminal=pts/1 res=success''UID="root" AUID="ubuntu" ID="unknown(1002)"'
diff --git a/data_sources/linux_auditd_execve.yml b/data_sources/linux_auditd_execve.yml
index 72433806de..c9f6bac6aa 100644
--- a/data_sources/linux_auditd_execve.yml
+++ b/data_sources/linux_auditd_execve.yml
@@ -6,24 +6,24 @@ author: Teoderick Contreras, Splunk
description: Logs the execution of processes on a Linux system, including details
about the executed command, arguments, and the initiating process.
mitre_components:
- - Command Execution
- - Process Creation
- - Process Metadata
- - OS API Execution
- - Application Log Content
+- Command Execution
+- Process Creation
+- Process Metadata
+- OS API Execution
+- Application Log Content
source: /var/log/audit/audit.log
sourcetype: linux:audit
separator: type
separator_value: EXECVE
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
- - name: Splunk Add-on for Unix and Linux
- url: https://splunkbase.splunk.com/app/833
- version: 9.2.0
+- name: Splunk Add-on for Unix and Linux
+ url: https://splunkbase.splunk.com/app/833
+ version: 9.2.0
fields:
- - msg
- - type
- - msg
- - argc
+- msg
+- type
+- msg
+- argc
example_log: 'type=EXECVE msg=audit(1723044684.257:15795): argc=3 a0="sudo" a1="LD_PRELOAD=./myfopen.so"
a2="./prog"'
diff --git a/data_sources/linux_auditd_path.yml b/data_sources/linux_auditd_path.yml
index d612530b4e..27ecc36cab 100644
--- a/data_sources/linux_auditd_path.yml
+++ b/data_sources/linux_auditd_path.yml
@@ -6,39 +6,39 @@ author: Teoderick Contreras, Splunk
description: Logs file system access events on a Linux system, including details about
file paths, permissions, and associated processes.
mitre_components:
- - File Access
- - File Metadata
- - Process Metadata
- - OS API Execution
- - Application Log Content
+- File Access
+- File Metadata
+- Process Metadata
+- OS API Execution
+- Application Log Content
source: /var/log/audit/audit.log
sourcetype: linux:audit
separator: type
separator_value: PATH
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
- - name: Splunk Add-on for Unix and Linux
- url: https://splunkbase.splunk.com/app/833
- version: 9.2.0
+- name: Splunk Add-on for Unix and Linux
+ url: https://splunkbase.splunk.com/app/833
+ version: 9.2.0
fields:
- - msg
- - type
- - item
- - name
- - inode
- - dev
- - mode
- - ouid
- - ogid
- - rdev
- - nametype
- - cap_fp
- - cap_fi
- - cap_fe
- - cap_fver
- - cap_frootid
- - OUID
- - OGID
+- msg
+- type
+- item
+- name
+- inode
+- dev
+- mode
+- ouid
+- ogid
+- rdev
+- nametype
+- cap_fp
+- cap_fi
+- cap_fe
+- cap_fver
+- cap_frootid
+- OUID
+- OGID
example_log: 'type=PATH msg=audit(1723043687.149:14898): item=1 name="/etc/ssh/ssh_config~"
inode=1292 dev=103:01 mode=0100644 ouid=0 ogid=0 rdev=00:00 nametype=DELETE cap_fp=0
cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0 OUID="root" OGID="root"'
diff --git a/data_sources/linux_auditd_proctitle.yml b/data_sources/linux_auditd_proctitle.yml
index fbd067aed5..bd4b0ce319 100644
--- a/data_sources/linux_auditd_proctitle.yml
+++ b/data_sources/linux_auditd_proctitle.yml
@@ -6,21 +6,21 @@ author: Teoderick Contreras, Splunk
description: Logs the full command-line arguments of a process execution on a Linux
system, providing visibility into the executed command and its parameters.
mitre_components:
- - Command Execution
- - Process Metadata
- - OS API Execution
- - Application Log Content
+- Command Execution
+- Process Metadata
+- OS API Execution
+- Application Log Content
separator: type
separator_value: PROCTITLE
source: /var/log/audit/audit.log
sourcetype: linux:audit
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
- - name: Splunk Add-on for Unix and Linux
- url: https://splunkbase.splunk.com/app/833
- version: 9.2.0
+- name: Splunk Add-on for Unix and Linux
+ url: https://splunkbase.splunk.com/app/833
+ version: 9.2.0
fields:
- - proctitle
- - msg
- - type
+- proctitle
+- msg
+- type
example_log: 'type=PROCTITLE msg=audit(1722944427.844:4146): proctitle=63686D6F640037373700312E7368'
diff --git a/data_sources/linux_auditd_service_stop.yml b/data_sources/linux_auditd_service_stop.yml
index 8b1c94b0f2..e44ecf9e3e 100644
--- a/data_sources/linux_auditd_service_stop.yml
+++ b/data_sources/linux_auditd_service_stop.yml
@@ -7,36 +7,36 @@ description: Logs events related to the stoppage of a service on a Linux system,
details about the service name, the process initiating the stop, and associated
timestamps.
mitre_components:
- - Service Modification
- - Service Metadata
- - OS API Execution
- - Application Log Content
+- Service Modification
+- Service Metadata
+- OS API Execution
+- Application Log Content
separator: type
separator_value: SERVICE_STOP
source: /var/log/audit/audit.log
sourcetype: linux:audit
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
- - name: Splunk Add-on for Unix and Linux
- url: https://splunkbase.splunk.com/app/833
- version: 9.2.0
+- name: Splunk Add-on for Unix and Linux
+ url: https://splunkbase.splunk.com/app/833
+ version: 9.2.0
fields:
- - msg
- - type
- - pid
- - uid
- - auid
- - ses
- - subj
- - msg
- - comm
- - exe
- - hostname
- - addr
- - terminal
- - res
- - UID
- - AUID
-example_log: "type=SERVICE_STOP msg=audit(1722957155.494:4802): pid=1 uid=0 auid=4294967295
- ses=4294967295 subj=unconfined msg='unit=atd comm=\"systemd\" exe=\"/usr/lib/systemd/systemd\"\
- \ hostname=? addr=? terminal=? res=success'UID=\"root\" AUID=\"unset\""
+- msg
+- type
+- pid
+- uid
+- auid
+- ses
+- subj
+- msg
+- comm
+- exe
+- hostname
+- addr
+- terminal
+- res
+- UID
+- AUID
+example_log: 'type=SERVICE_STOP msg=audit(1722957155.494:4802): pid=1 uid=0 auid=4294967295
+ ses=4294967295 subj=unconfined msg=''unit=atd comm="systemd" exe="/usr/lib/systemd/systemd"
+ hostname=? addr=? terminal=? res=success''UID="root" AUID="unset"'
diff --git a/data_sources/linux_auditd_syscall.yml b/data_sources/linux_auditd_syscall.yml
index c753a66b54..dcc8e48779 100644
--- a/data_sources/linux_auditd_syscall.yml
+++ b/data_sources/linux_auditd_syscall.yml
@@ -6,59 +6,59 @@ author: Teoderick Contreras, Splunk
description: Logs system calls made by processes on a Linux system, including details
about the syscall number, arguments, return values, and associated process metadata.
mitre_components:
- - OS API Execution
- - Process Metadata
- - Application Log Content
- - Host Status
+- OS API Execution
+- Process Metadata
+- Application Log Content
+- Host Status
source: /var/log/audit/audit.log
sourcetype: linux:audit
separator: type
separator_value: syscall
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
- - name: Splunk Add-on for Unix and Linux
- url: https://splunkbase.splunk.com/app/833
- version: 9.2.0
+- name: Splunk Add-on for Unix and Linux
+ url: https://splunkbase.splunk.com/app/833
+ version: 9.2.0
fields:
- - msg
- - type
- - msg
- - arch
- - syscall
- - success
- - exit
- - a1
- - a2
- - a3
- - items
- - ppid
- - pid
- - auid
- - uid
- - gid
- - euid
- - suid
- - fsuid
- - egid
- - sgid
- - fsgid
- - tty
- - ses
- - comm
- - exe
- - subj
- - key
- - ARCH
- - SYSCALL
- - AUID
- - UID
- - GID
- - EUID
- - SUID
- - FSUID
- - EGID
- - SGID
- - FSGID
+- msg
+- type
+- msg
+- arch
+- syscall
+- success
+- exit
+- a1
+- a2
+- a3
+- items
+- ppid
+- pid
+- auid
+- uid
+- gid
+- euid
+- suid
+- fsuid
+- egid
+- sgid
+- fsgid
+- tty
+- ses
+- comm
+- exe
+- subj
+- key
+- ARCH
+- SYSCALL
+- AUID
+- UID
+- GID
+- EUID
+- SUID
+- FSUID
+- EGID
+- SGID
+- FSGID
example_log: 'type=SYSCALL msg=audit(1723035666.627:3663): arch=c000003e syscall=59
success=yes exit=0 a0=556a6d697a58 a1=556a6d68ad00 a2=556a6d69c980 a3=0 items=2
ppid=1300 pid=1301 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0
diff --git a/data_sources/linux_secure.yml b/data_sources/linux_secure.yml
index e6f8b78160..77d0e1f105 100644
--- a/data_sources/linux_secure.yml
+++ b/data_sources/linux_secure.yml
@@ -6,49 +6,49 @@ author: Patrick Bareiss, Splunk
description: Logs authentication and authorization events on a Linux system, including
login attempts, SSH connections, and privilege escalation activities.
mitre_components:
- - User Account Authentication
- - Logon Session Creation
- - Logon Session Metadata
- - User Account Metadata
- - Application Log Content
+- User Account Authentication
+- Logon Session Creation
+- Logon Session Metadata
+- User Account Metadata
+- Application Log Content
source: /var/log/secure
sourcetype: linux_secure
supported_TA: []
fields:
- - _time
- - action
- - app
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - eventtype
- - host
- - index
- - linecount
- - pid
- - process
- - punct
- - source
- - sourcetype
- - splunk_server
- - src
- - src_port
- - sshd_protocol
- - tag
- - tag::action
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - user_name
- - vendor_action
- - vendor_product
+- _time
+- action
+- app
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- eventtype
+- host
+- index
+- linecount
+- pid
+- process
+- punct
+- source
+- sourcetype
+- splunk_server
+- src
+- src_port
+- sshd_protocol
+- tag
+- tag::action
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- user_name
+- vendor_action
+- vendor_product
example_log: 'May 27 09:28:36 ip-172-31-24-46 sshd[5617]: Accepted password for mikael
from 84.202.159.161 port 63487 ssh2'
diff --git a/data_sources/ms365_defender_incident_alerts.yml b/data_sources/ms365_defender_incident_alerts.yml
index 80e582df46..4f6665ecbc 100644
--- a/data_sources/ms365_defender_incident_alerts.yml
+++ b/data_sources/ms365_defender_incident_alerts.yml
@@ -6,236 +6,185 @@ author: Bhavin Patel, Splunk
description: Logs security incidents and correlated alerts in Microsoft 365 Defender,
including details about affected assets, threat types, and remediation steps.
mitre_components:
- - Host Status
- - User Account Metadata
- - Application Log Content
- - Malware Metadata
- - Active Directory Object Access
+- Host Status
+- User Account Metadata
+- Application Log Content
+- Malware Metadata
+- Active Directory Object Access
source: ms365_defender_incident_alerts
sourcetype: ms365:defender:incident:alerts
supported_TA:
- - name: Splunk Add-on for Microsoft Security
- url: https://splunkbase.splunk.com/app/6207
- version: 2.4.1
+- name: Splunk Add-on for Microsoft Security
+ url: https://splunkbase.splunk.com/app/6207
+ version: 2.4.1
fields:
- - actorName
- - alertId
- - app
- - assignedTo
- - body
- - category
- - classification
- - creationTime
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - description
- - dest
- - detectionSource
- - detectorId
- - determination
- - devices{}.aadDeviceId
- - devices{}.defenderAvStatus
- - devices{}.deviceDnsName
- - devices{}.firstSeen
- - devices{}.healthStatus
- - devices{}.loggedOnUsers{}.accountName
- - devices{}.loggedOnUsers{}.domainName
- - devices{}.mdatpDeviceId
- - devices{}.onboardingStatus
- - devices{}.osBuild
- - devices{}.osPlatform
- - devices{}.osProcessor
- - devices{}.rbacGroupName
- - devices{}.riskScore
- - devices{}.version
- - devices{}.vmMetadata
- - devices{}.vmMetadata.cloudProvider
- - devices{}.vmMetadata.resourceId
- - devices{}.vmMetadata.subscriptionId
- - devices{}.vmMetadata.vmId
- - entities{}.aadUserId
- - entities{}.accountName
- - entities{}.applicationId
- - entities{}.applicationName
- - entities{}.detectionStatus
- - entities{}.deviceId
- - entities{}.domainName
- - entities{}.entityType
- - entities{}.evidenceCreationTime
- - entities{}.fileName
- - entities{}.filePath
- - entities{}.ipAddress
- - entities{}.parentProcessCreationTime
- - entities{}.parentProcessFileName
- - entities{}.parentProcessFilePath
- - entities{}.parentProcessId
- - entities{}.processCommandLine
- - entities{}.processCreationTime
- - entities{}.processId
- - entities{}.remediationStatus
- - entities{}.remediationStatusDetails
- - entities{}.sha1
- - entities{}.sha256
- - entities{}.userPrincipalName
- - entities{}.userSid
- - entities{}.verdict
- - eventtype
- - firstActivity
- - host
- - id
- - incidentId
- - index
- - investigationId
- - investigationState
- - lastActivity
- - lastUpdatedTime
- - linecount
- - mitreTechniques{}
- - mitre_technique_id
- - providerAlertId
- - resolvedTime
- - serviceSource
- - severity
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - splunk_server_group
- - src
- - status
- - subject
- - tag
- - tag::app
- - tag::eventtype
- - threatFamilyName
- - timeendpos
- - timestartpos
- - title
- - type
- - user
- - user_name
- - _bkt
- - _cd
- - _eventtype_color
- - _indextime
- - _raw
- - _serial
- - _si
- - _sourcetype
- - _subsecond
- - _time
-example_log: |-
- {
- "alertId": "da638001130101730338_582949328",
- "providerAlertId": "da638001130101730338_582949328",
- "incidentId": 486,
- "serviceSource": "MicrosoftDefenderForEndpoint",
- "creationTime": "2022-09-30T05:36:50.1732198Z",
- "lastUpdatedTime": "2022-11-19T01:35:42.7033333Z",
- "resolvedTime": "2022-10-01T01:36:00.5066667Z",
- "firstActivity": "2022-09-30T05:06:43.8196597Z",
- "lastActivity": "2022-09-30T05:06:43.8196597Z",
- "title": "Suspicious URL clicked",
- "description": "A user opened a potentially malicious URL. This alert was triggered based on a Microsoft Defender for Office 365 alert.",
- "category": "InitialAccess",
- "status": "Resolved",
- "severity": "High",
- "investigationId": null,
- "investigationState": "UnsupportedAlertType",
- "classification": "TruePositive",
- "determination": "SecurityTesting",
- "detectionSource": "MTP",
- "detectorId": "359b36eb-337c-4f1c-b280-8c5e08f9c4a0",
- "assignedTo": "msftadmin@metal.m365dpoc.com",
- "actorName": null,
- "threatFamilyName": null,
- "mitreTechniques": [
- "T1566.002"
- ],
- "devices": [
- {
- "mdatpDeviceId": "c7e147cb0eb3534a4dcea5acb8e61c933713b145",
- "aadDeviceId": null,
- "deviceDnsName": "metal-win10v.metal.m365dpoc.com",
- "osPlatform": "Windows10",
- "version": "1809",
- "osProcessor": "x64",
- "osBuild": 17763,
- "healthStatus": "Active",
- "riskScore": "High",
- "rbacGroupName": "Full Auto Clients",
- "firstSeen": "2022-08-08T08:51:02.455Z",
- "tags": [
- "Full auto"
- ],
- "defenderAvStatus": "Updated",
- "onboardingStatus": "Onboarded",
- "vmMetadata": {
- "vmId": "17881b39-b03f-4a2c-9b56-078be1330bd0",
- "cloudProvider": "Unknown",
- "resourceId": "/subscriptions/29e73d07-8740-4164-a257-592a19a7b77c/resourceGroups/MSDXV2/providers/Microsoft.Compute/virtualMachines/MSDXV2-Win10V",
- "subscriptionId": "29e73d07-8740-4164-a257-592a19a7b77c"
- },
- "loggedOnUsers": [
- {
- "accountName": "hetfield",
- "domainName": "MSDXV2"
- }
- ]
- }
- ],
- "entities": [
- {
- "entityType": "Process",
- "evidenceCreationTime": "2022-09-30T05:36:50.2133333Z",
- "verdict": "Suspicious",
- "remediationStatus": "None",
- "sha1": "6cbce4a295c163791b60fc23d285e6d84f28ee4c",
- "sha256": "de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c",
- "fileName": "powershell.exe",
- "filePath": "",
- "processId": 7068,
- "processCommandLine": "powershell.exe -command \" $Process = New-Object System.Diagnostics.Process; $Process.StartInfo.FileName = 'https://nam12.safelinks.protection.outlook.com/?url=http%3A%2F%2Fgcajebahdi.corporatelogon.xyz%2Fab%2Fjnkmbkkdnlgedc&data=05%7C01%7Chetfield%40metal.m365dpoc.com%7Cca409616a82145bd6a5f08daa2a10255%7C1a49212958c8401191cd245285f5345c%7C0%7C0%7C638001109710345383%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=FyEjRS5qOd2SkJELlueibuxLFMYNjL7fz8EbuOAvFwg%3D&reserved=0'; $Process.StartInfo.UseShellExecute = $true; $Process.Start() | Out-Null; \" ",
- "processCreationTime": "2022-09-30T05:06:43.3390523Z",
- "parentProcessId": 7116,
- "parentProcessCreationTime": "2022-09-30T05:06:43.3100364Z",
- "accountName": "hetfield",
- "userSid": "S-1-5-21-2300221942-1987151257-321556088-1104"
- },
- {
- "entityType": "File",
- "evidenceCreationTime": "2022-09-30T05:36:50.2133333Z",
- "verdict": "Suspicious",
- "remediationStatus": "None",
- "sha1": "6cbce4a295c163791b60fc23d285e6d84f28ee4c",
- "sha256": "de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c",
- "fileName": "powershell.exe",
- "filePath": ""
- },
- {
- "entityType": "User",
- "evidenceCreationTime": "2022-09-30T05:36:50.2133333Z",
- "verdict": "Suspicious",
- "remediationStatus": "None",
- "accountName": "hetfield",
- "domainName": "metal.m365dpoc",
- "userSid": "S-1-5-21-2300221942-1987151257-321556088-1104",
- "aadUserId": "e848b07a-87af-4448-9979-09f0b809c8d4",
- "userPrincipalName": "daftpunk"
- },
- {
- "entityType": "Url",
- "evidenceCreationTime": "2022-09-30T05:36:50.2133333Z",
- "verdict": "Suspicious",
- "remediationStatus": "None",
- "url": "http://gcajebahdi.corporatelogon.xyz/ab/jnkmbkkdnlgedc"
- }
- ]
- }
+- actorName
+- alertId
+- app
+- assignedTo
+- body
+- category
+- classification
+- creationTime
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- description
+- dest
+- detectionSource
+- detectorId
+- determination
+- devices{}.aadDeviceId
+- devices{}.defenderAvStatus
+- devices{}.deviceDnsName
+- devices{}.firstSeen
+- devices{}.healthStatus
+- devices{}.loggedOnUsers{}.accountName
+- devices{}.loggedOnUsers{}.domainName
+- devices{}.mdatpDeviceId
+- devices{}.onboardingStatus
+- devices{}.osBuild
+- devices{}.osPlatform
+- devices{}.osProcessor
+- devices{}.rbacGroupName
+- devices{}.riskScore
+- devices{}.version
+- devices{}.vmMetadata
+- devices{}.vmMetadata.cloudProvider
+- devices{}.vmMetadata.resourceId
+- devices{}.vmMetadata.subscriptionId
+- devices{}.vmMetadata.vmId
+- entities{}.aadUserId
+- entities{}.accountName
+- entities{}.applicationId
+- entities{}.applicationName
+- entities{}.detectionStatus
+- entities{}.deviceId
+- entities{}.domainName
+- entities{}.entityType
+- entities{}.evidenceCreationTime
+- entities{}.fileName
+- entities{}.filePath
+- entities{}.ipAddress
+- entities{}.parentProcessCreationTime
+- entities{}.parentProcessFileName
+- entities{}.parentProcessFilePath
+- entities{}.parentProcessId
+- entities{}.processCommandLine
+- entities{}.processCreationTime
+- entities{}.processId
+- entities{}.remediationStatus
+- entities{}.remediationStatusDetails
+- entities{}.sha1
+- entities{}.sha256
+- entities{}.userPrincipalName
+- entities{}.userSid
+- entities{}.verdict
+- eventtype
+- firstActivity
+- host
+- id
+- incidentId
+- index
+- investigationId
+- investigationState
+- lastActivity
+- lastUpdatedTime
+- linecount
+- mitreTechniques{}
+- mitre_technique_id
+- providerAlertId
+- resolvedTime
+- serviceSource
+- severity
+- signature
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- splunk_server_group
+- src
+- status
+- subject
+- tag
+- tag::app
+- tag::eventtype
+- threatFamilyName
+- timeendpos
+- timestartpos
+- title
+- type
+- user
+- user_name
+- _bkt
+- _cd
+- _eventtype_color
+- _indextime
+- _raw
+- _serial
+- _si
+- _sourcetype
+- _subsecond
+- _time
+example_log: "{\n \"alertId\": \"da638001130101730338_582949328\",\n \"providerAlertId\"\
+ : \"da638001130101730338_582949328\",\n \"incidentId\": 486,\n \"serviceSource\"\
+ : \"MicrosoftDefenderForEndpoint\",\n \"creationTime\": \"2022-09-30T05:36:50.1732198Z\"\
+ ,\n \"lastUpdatedTime\": \"2022-11-19T01:35:42.7033333Z\",\n \"resolvedTime\"\
+ : \"2022-10-01T01:36:00.5066667Z\",\n \"firstActivity\": \"2022-09-30T05:06:43.8196597Z\"\
+ ,\n \"lastActivity\": \"2022-09-30T05:06:43.8196597Z\",\n \"title\": \"Suspicious\
+ \ URL clicked\",\n \"description\": \"A user opened a potentially malicious URL.\
+ \ This alert was triggered based on a Microsoft Defender for Office 365 alert.\"\
+ ,\n \"category\": \"InitialAccess\",\n \"status\": \"Resolved\",\n \"severity\"\
+ : \"High\",\n \"investigationId\": null,\n \"investigationState\": \"UnsupportedAlertType\"\
+ ,\n \"classification\": \"TruePositive\",\n \"determination\": \"SecurityTesting\"\
+ ,\n \"detectionSource\": \"MTP\",\n \"detectorId\": \"359b36eb-337c-4f1c-b280-8c5e08f9c4a0\"\
+ ,\n \"assignedTo\": \"msftadmin@metal.m365dpoc.com\",\n \"actorName\": null,\n\
+ \ \"threatFamilyName\": null,\n \"mitreTechniques\": [\n \"T1566.002\"\n ],\n\
+ \ \"devices\": [\n {\n \"mdatpDeviceId\": \"c7e147cb0eb3534a4dcea5acb8e61c933713b145\"\
+ ,\n \"aadDeviceId\": null,\n \"deviceDnsName\": \"metal-win10v.metal.m365dpoc.com\"\
+ ,\n \"osPlatform\": \"Windows10\",\n \"version\": \"1809\",\n \"\
+ osProcessor\": \"x64\",\n \"osBuild\": 17763,\n \"healthStatus\": \"Active\"\
+ ,\n \"riskScore\": \"High\",\n \"rbacGroupName\": \"Full Auto Clients\"\
+ ,\n \"firstSeen\": \"2022-08-08T08:51:02.455Z\",\n \"tags\": [\n \
+ \ \"Full auto\"\n ],\n \"defenderAvStatus\": \"Updated\",\n \"\
+ onboardingStatus\": \"Onboarded\",\n \"vmMetadata\": {\n \"vmId\": \"\
+ 17881b39-b03f-4a2c-9b56-078be1330bd0\",\n \"cloudProvider\": \"Unknown\"\
+ ,\n \"resourceId\": \"/subscriptions/29e73d07-8740-4164-a257-592a19a7b77c/resourceGroups/MSDXV2/providers/Microsoft.Compute/virtualMachines/MSDXV2-Win10V\"\
+ ,\n \"subscriptionId\": \"29e73d07-8740-4164-a257-592a19a7b77c\"\n },\n\
+ \ \"loggedOnUsers\": [\n {\n \"accountName\": \"hetfield\"\
+ ,\n \"domainName\": \"MSDXV2\"\n }\n ]\n }\n ],\n \"entities\"\
+ : [\n {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\":\
+ \ \"2022-09-30T05:36:50.2133333Z\",\n \"verdict\": \"Suspicious\",\n \"\
+ remediationStatus\": \"None\",\n \"sha1\": \"6cbce4a295c163791b60fc23d285e6d84f28ee4c\"\
+ ,\n \"sha256\": \"de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c\"\
+ ,\n \"fileName\": \"powershell.exe\",\n \"filePath\": \"\",\n \"\
+ processId\": 7068,\n \"processCommandLine\": \"powershell.exe -command \\\"\
+ \ $Process = New-Object\
+ \ System.Diagnostics.Process; \
+ \ $Process.StartInfo.FileName = 'https://nam12.safelinks.protection.outlook.com/?url=http%3A%2F%2Fgcajebahdi.corporatelogon.xyz%2Fab%2Fjnkmbkkdnlgedc&data=05%7C01%7Chetfield%40metal.m365dpoc.com%7Cca409616a82145bd6a5f08daa2a10255%7C1a49212958c8401191cd245285f5345c%7C0%7C0%7C638001109710345383%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=FyEjRS5qOd2SkJELlueibuxLFMYNjL7fz8EbuOAvFwg%3D&reserved=0';\
+ \ $Process.StartInfo.UseShellExecute\
+ \ = $true; $Process.Start()\
+ \ | Out-Null; \\\" \
+ \ \",\n \"processCreationTime\"\
+ : \"2022-09-30T05:06:43.3390523Z\",\n \"parentProcessId\": 7116,\n \"\
+ parentProcessCreationTime\": \"2022-09-30T05:06:43.3100364Z\",\n \"accountName\"\
+ : \"hetfield\",\n \"userSid\": \"S-1-5-21-2300221942-1987151257-321556088-1104\"\
+ \n },\n {\n \"entityType\": \"File\",\n \"evidenceCreationTime\"\
+ : \"2022-09-30T05:36:50.2133333Z\",\n \"verdict\": \"Suspicious\",\n \"\
+ remediationStatus\": \"None\",\n \"sha1\": \"6cbce4a295c163791b60fc23d285e6d84f28ee4c\"\
+ ,\n \"sha256\": \"de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c\"\
+ ,\n \"fileName\": \"powershell.exe\",\n \"filePath\": \"\"\n },\n \
+ \ {\n \"entityType\": \"User\",\n \"evidenceCreationTime\": \"2022-09-30T05:36:50.2133333Z\"\
+ ,\n \"verdict\": \"Suspicious\",\n \"remediationStatus\": \"None\",\n\
+ \ \"accountName\": \"hetfield\",\n \"domainName\": \"metal.m365dpoc\"\
+ ,\n \"userSid\": \"S-1-5-21-2300221942-1987151257-321556088-1104\",\n \
+ \ \"aadUserId\": \"e848b07a-87af-4448-9979-09f0b809c8d4\",\n \"userPrincipalName\"\
+ : \"daftpunk\"\n },\n {\n \"entityType\": \"Url\",\n \"evidenceCreationTime\"\
+ : \"2022-09-30T05:36:50.2133333Z\",\n \"verdict\": \"Suspicious\",\n \"\
+ remediationStatus\": \"None\",\n \"url\": \"http://gcajebahdi.corporatelogon.xyz/ab/jnkmbkkdnlgedc\"\
+ \n }\n ]\n}"
diff --git a/data_sources/ms_defender_atp_alerts.yml b/data_sources/ms_defender_atp_alerts.yml
index f1f68b0b7e..f7429f3de6 100644
--- a/data_sources/ms_defender_atp_alerts.yml
+++ b/data_sources/ms_defender_atp_alerts.yml
@@ -6,424 +6,274 @@ author: Bryan Pluta, Bhavin Patel, Splunk
description: Logs security alerts generated by Microsoft Defender for Endpoint, including
information about detected threats, impacted devices, and recommended actions.
mitre_components:
- - Host Status
- - Malware Metadata
- - Process Metadata
- - User Account Metadata
- - Application Log Content
+- Host Status
+- Malware Metadata
+- Process Metadata
+- User Account Metadata
+- Application Log Content
source: ms_defender_atp_alerts
sourcetype: ms:defender:atp:alerts
supported_TA:
- - name: Splunk Add-on for Microsoft Security
- url: https://splunkbase.splunk.com/app/6207
- version: 2.4.1
+- name: Splunk Add-on for Microsoft Security
+ url: https://splunkbase.splunk.com/app/6207
+ version: 2.4.1
fields:
- - column
- - accountName
- - action
- - activity
- - activityType
- - actor
- - actorName
- - alertId
- - app
- - assignedTo
- - body
- - category
- - classification
- - creationTime
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - description
- - dest
- - detectionSource
- - detectorId
- - determination
- - devices{}.aadDeviceId
- - devices{}.defenderAvStatus
- - devices{}.deviceDnsName
- - devices{}.firstSeen
- - devices{}.healthStatus
- - devices{}.loggedOnUsers{}.accountName
- - devices{}.loggedOnUsers{}.domainName
- - devices{}.mdatpDeviceId
- - devices{}.onboardingStatus
- - devices{}.osBuild
- - devices{}.osPlatform
- - devices{}.osProcessor
- - devices{}.rbacGroupName
- - devices{}.riskScore
- - devices{}.version
- - devices{}.vmMetadata
- - devices{}.vmMetadata.cloudProvider
- - devices{}.vmMetadata.resourceId
- - devices{}.vmMetadata.subscriptionId
- - devices{}.vmMetadata.vmId
- - entities{}.aadUserId
- - entities{}.accountName
- - entities{}.applicationId
- - entities{}.applicationName
- - entities{}.detectionStatus
- - entities{}.deviceId
- - entities{}.domainName
- - entities{}.entityType
- - entities{}.evidenceCreationTime
- - entities{}.fileName
- - entities{}.filePath
- - entities{}.ipAddress
- - entities{}.parentProcessCreationTime
- - entities{}.parentProcessFileName
- - entities{}.parentProcessFilePath
- - entities{}.parentProcessId
- - entities{}.processCommandLine
- - entities{}.processCreationTime
- - entities{}.processId
- - entities{}.remediationStatus
- - entities{}.remediationStatusDetails
- - entities{}.sha1
- - entities{}.sha256
- - entities{}.userPrincipalName
- - entities{}.userSid
- - entities{}.verdict
- - eventtype
- - firstActivity
- - host
- - id
- - incidentId
- - index
- - investigationId
- - investigationState
- - lastActivity
- - lastUpdatedTime
- - linecount
- - mitreTechniques{}
- - mitre_technique_id
- - providerAlertId
- - resolvedTime
- - serviceSource
- - severity
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - splunk_server_group
- - src
- - status
- - subject
- - tag
- - tag::app
- - tag::eventtype
- - threatFamilyName
- - timeendpos
- - timestartpos
- - title
- - type
- - user
- - user_name
- - _time
-example_log: |-
- {
- "id": "da47dc5671-e560-4229-984b-457564996b31_1",
- "incidentId": 989,
- "investigationId": null,
- "assignedTo": null,
- "severity": "High",
- "status": "New",
- "classification": null,
- "determination": null,
- "investigationState": "UnsupportedAlertType",
- "detectionSource": "WindowsDefenderAtp",
- "detectorId": "9c3a70ec-e18a-4f92-865a-530f73130b7c",
- "category": "LateralMovement",
- "threatFamilyName": null,
- "title": "Ongoing hands-on-keyboard attack via Impacket toolkit",
- "description": "Suspicious execution of a command via Impacket was observed on this device. This tool connects to other hosts to explore network shares and execute commands. Attackers might be attempting to move laterally across the network using this tool. This usage of Impacket has often been observed in hands-on-keyboard attacks, where ransomware and other payloads are installed on target devices.",
- "alertCreationTime": "2023-01-24T05:33:37.3245808Z",
- "firstEventTime": "2023-01-24T05:31:07.5276179Z",
- "lastEventTime": "2023-01-24T13:02:50.7831636Z",
- "lastUpdateTime": "2023-01-24T13:07:13.3233333Z",
- "resolvedTime": null,
- "machineId": "302293d9f276eae65553e5042156bce93cbc7148",
- "computerDnsName": "diytestmachine",
- "rbacGroupName": "UnassignedGroup",
- "aadTenantId": "1a492129-58c8-4011-91cd-245285f5345c",
- "threatName": null,
- "mitreTechniques": [
- "T1021.002",
- "T1047",
- "T1059.003"
- ],
- "relatedUser": {
- "userName": "User1",
- "domainName": "DIYTESTMACHINE"
- },
- "loggedOnUsers": [
- {
- "accountName": "administrator1",
- "domainName": "DIYTESTMACHINE"
- }
- ],
- "comments": [],
- "evidence": [
- {
- "entityType": "Process",
- "evidenceCreationTime": "2023-01-24T05:45:51.6833333Z",
- "sha1": "3ea7cc066317ac45f963c2227c4c7c50aa16eb7c",
- "sha256": "2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3",
- "fileName": "WmiPrvSE.exe",
- "filePath": "C:\\Windows\\System32\\wbem",
- "processId": 4476,
- "processCommandLine": "wmiprvse.exe -secured -Embedding",
- "processCreationTime": "2023-01-24T05:43:32.4631151Z",
- "parentProcessId": 896,
- "parentProcessCreationTime": "2023-01-24T04:44:17.1940386Z",
- "parentProcessFileName": "svchost.exe",
- "parentProcessFilePath": "C:\\Windows\\System32",
- "ipAddress": null,
- "url": null,
- "registryKey": null,
- "registryHive": null,
- "registryValueType": null,
- "registryValue": null,
- "registryValueName": null,
- "accountName": "NETWORK SERVICE",
- "domainName": "NT AUTHORITY",
- "userSid": "S-1-5-20",
- "aadUserId": null,
- "userPrincipalName": null,
- "detectionStatus": "Detected"
- },
- {
- "entityType": "User",
- "evidenceCreationTime": "2023-01-24T05:33:37.4166667Z",
- "sha1": null,
- "sha256": null,
- "fileName": null,
- "filePath": null,
- "processId": null,
- "processCommandLine": null,
- "processCreationTime": null,
- "parentProcessId": null,
- "parentProcessCreationTime": null,
- "parentProcessFileName": null,
- "parentProcessFilePath": null,
- "ipAddress": null,
- "url": null,
- "registryKey": null,
- "registryHive": null,
- "registryValueType": null,
- "registryValue": null,
- "registryValueName": null,
- "accountName": "User1",
- "domainName": "DIYTESTMACHINE",
- "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002",
- "aadUserId": null,
- "userPrincipalName": null,
- "detectionStatus": null
- },
- {
- "entityType": "Process",
- "evidenceCreationTime": "2023-01-24T05:33:37.4166667Z",
- "sha1": "3ea7cc066317ac45f963c2227c4c7c50aa16eb7c",
- "sha256": "2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3",
- "fileName": "WmiPrvSE.exe",
- "filePath": "C:\\Windows\\System32\\wbem",
- "processId": 7824,
- "processCommandLine": "wmiprvse.exe -secured -Embedding",
- "processCreationTime": "2023-01-24T05:30:50.8649791Z",
- "parentProcessId": 896,
- "parentProcessCreationTime": "2023-01-24T04:44:17.1940386Z",
- "parentProcessFileName": "svchost.exe",
- "parentProcessFilePath": "C:\\Windows\\System32",
- "ipAddress": null,
- "url": null,
- "registryKey": null,
- "registryHive": null,
- "registryValueType": null,
- "registryValue": null,
- "registryValueName": null,
- "accountName": "NETWORK SERVICE",
- "domainName": "NT AUTHORITY",
- "userSid": "S-1-5-20",
- "aadUserId": null,
- "userPrincipalName": null,
- "detectionStatus": "Detected"
- },
- {
- "entityType": "Process",
- "evidenceCreationTime": "2023-01-24T13:07:13.2233333Z",
- "sha1": "f1efb0fddc156e4c61c5f78a54700e4e7984d55d",
- "sha256": "b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450",
- "fileName": "cmd.exe",
- "filePath": "C:\\Windows\\System32",
- "processId": 5500,
- "processCommandLine": "cmd.exe /Q /c powershell -NoProfile -ExecutionPolicy Bypass -File \"C:\\Users\\administrator1\\Desktop\\SharedFolder\\payload.ps1\" 1> \\\\127.0.0.1\\SharedFolder\\__1674565222.7012053 2>&1",
- "processCreationTime": "2023-01-24T13:02:50.4661885Z",
- "parentProcessId": 756,
- "parentProcessCreationTime": "2023-01-24T13:00:35.0107475Z",
- "parentProcessFileName": "WmiPrvSE.exe",
- "parentProcessFilePath": "C:\\Windows\\System32\\wbem",
- "ipAddress": null,
- "url": null,
- "registryKey": null,
- "registryHive": null,
- "registryValueType": null,
- "registryValue": null,
- "registryValueName": null,
- "accountName": "User1",
- "domainName": "DIYTESTMACHINE",
- "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002",
- "aadUserId": null,
- "userPrincipalName": null,
- "detectionStatus": "Detected"
- },
- {
- "entityType": "Process",
- "evidenceCreationTime": "2023-01-24T05:33:37.4166667Z",
- "sha1": "f1efb0fddc156e4c61c5f78a54700e4e7984d55d",
- "sha256": "b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450",
- "fileName": "cmd.exe",
- "filePath": "C:\\Windows\\System32",
- "processId": 8964,
- "processCommandLine": "cmd.exe /Q /c powershell -NoProfile -ExecutionPolicy Bypass -File \"C:\\Users\\administrator1\\Desktop\\SharedFolder\\payload.ps1\" 1> \\\\127.0.0.1\\SharedFolder\\__1674538248.357367 2>&1",
- "processCreationTime": "2023-01-24T05:31:04.0743902Z",
- "parentProcessId": 7824,
- "parentProcessCreationTime": "2023-01-24T05:30:50.8649791Z",
- "parentProcessFileName": "WmiPrvSE.exe",
- "parentProcessFilePath": "C:\\Windows\\System32\\wbem",
- "ipAddress": null,
- "url": null,
- "registryKey": null,
- "registryHive": null,
- "registryValueType": null,
- "registryValue": null,
- "registryValueName": null,
- "accountName": "User1",
- "domainName": "DIYTESTMACHINE",
- "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002",
- "aadUserId": null,
- "userPrincipalName": null,
- "detectionStatus": "Detected"
- },
- {
- "entityType": "Process",
- "evidenceCreationTime": "2023-01-24T05:39:47.1733333Z",
- "sha1": "f1efb0fddc156e4c61c5f78a54700e4e7984d55d",
- "sha256": "b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450",
- "fileName": "cmd.exe",
- "filePath": "C:\\Windows\\System32",
- "processId": 884,
- "processCommandLine": "cmd.exe /Q /c powershell -NoProfile -ExecutionPolicy Bypass -File \"C:\\Users\\administrator1\\Desktop\\SharedFolder\\payload.ps1\" 1> \\\\127.0.0.1\\SharedFolder\\__1674538583.8648584 2>&1",
- "processCreationTime": "2023-01-24T05:36:38.826505Z",
- "parentProcessId": 7736,
- "parentProcessCreationTime": "2023-01-24T05:36:26.0524655Z",
- "parentProcessFileName": "WmiPrvSE.exe",
- "parentProcessFilePath": "C:\\Windows\\System32\\wbem",
- "ipAddress": null,
- "url": null,
- "registryKey": null,
- "registryHive": null,
- "registryValueType": null,
- "registryValue": null,
- "registryValueName": null,
- "accountName": "User1",
- "domainName": "DIYTESTMACHINE",
- "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002",
- "aadUserId": null,
- "userPrincipalName": null,
- "detectionStatus": "Detected"
- },
- {
- "entityType": "Process",
- "evidenceCreationTime": "2023-01-24T13:07:13.2233333Z",
- "sha1": "3ea7cc066317ac45f963c2227c4c7c50aa16eb7c",
- "sha256": "2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3",
- "fileName": "WmiPrvSE.exe",
- "filePath": "C:\\Windows\\System32\\wbem",
- "processId": 756,
- "processCommandLine": "wmiprvse.exe -secured -Embedding",
- "processCreationTime": "2023-01-24T13:00:35.0107475Z",
- "parentProcessId": 908,
- "parentProcessCreationTime": "2023-01-24T08:20:44.6877667Z",
- "parentProcessFileName": "svchost.exe",
- "parentProcessFilePath": "C:\\Windows\\System32",
- "ipAddress": null,
- "url": null,
- "registryKey": null,
- "registryHive": null,
- "registryValueType": null,
- "registryValue": null,
- "registryValueName": null,
- "accountName": "NETWORK SERVICE",
- "domainName": "NT AUTHORITY",
- "userSid": "S-1-5-20",
- "aadUserId": null,
- "userPrincipalName": null,
- "detectionStatus": "Detected"
- },
- {
- "entityType": "Process",
- "evidenceCreationTime": "2023-01-24T05:45:51.6833333Z",
- "sha1": "f1efb0fddc156e4c61c5f78a54700e4e7984d55d",
- "sha256": "b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450",
- "fileName": "cmd.exe",
- "filePath": "C:\\Windows\\System32",
- "processId": 1140,
- "processCommandLine": "cmd.exe /Q /c powershell -NoProfile -ExecutionPolicy Bypass -File \"C:\\Users\\administrator1\\Desktop\\SharedFolder\\payload.ps1\" 1> \\\\127.0.0.1\\SharedFolder\\__1674538878.1586335 2>&1",
- "processCreationTime": "2023-01-24T05:43:49.9375398Z",
- "parentProcessId": 4476,
- "parentProcessCreationTime": "2023-01-24T05:43:32.4631151Z",
- "parentProcessFileName": "WmiPrvSE.exe",
- "parentProcessFilePath": "C:\\Windows\\System32\\wbem",
- "ipAddress": null,
- "url": null,
- "registryKey": null,
- "registryHive": null,
- "registryValueType": null,
- "registryValue": null,
- "registryValueName": null,
- "accountName": "User1",
- "domainName": "DIYTESTMACHINE",
- "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002",
- "aadUserId": null,
- "userPrincipalName": null,
- "detectionStatus": "Detected"
- },
- {
- "entityType": "Process",
- "evidenceCreationTime": "2023-01-24T05:39:47.1733333Z",
- "sha1": "3ea7cc066317ac45f963c2227c4c7c50aa16eb7c",
- "sha256": "2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3",
- "fileName": "WmiPrvSE.exe",
- "filePath": "C:\\Windows\\System32\\wbem",
- "processId": 7736,
- "processCommandLine": "wmiprvse.exe -secured -Embedding",
- "processCreationTime": "2023-01-24T05:36:26.0524655Z",
- "parentProcessId": 896,
- "parentProcessCreationTime": "2023-01-24T04:44:17.1940386Z",
- "parentProcessFileName": "svchost.exe",
- "parentProcessFilePath": "C:\\Windows\\System32",
- "ipAddress": null,
- "url": null,
- "registryKey": null,
- "registryHive": null,
- "registryValueType": null,
- "registryValue": null,
- "registryValueName": null,
- "accountName": "NETWORK SERVICE",
- "domainName": "NT AUTHORITY",
- "userSid": "S-1-5-20",
- "aadUserId": null,
- "userPrincipalName": null,
- "detectionStatus": "Detected"
- }
- ],
- "domains": []
- }
+- column
+- accountName
+- action
+- activity
+- activityType
+- actor
+- actorName
+- alertId
+- app
+- assignedTo
+- body
+- category
+- classification
+- creationTime
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- description
+- dest
+- detectionSource
+- detectorId
+- determination
+- devices{}.aadDeviceId
+- devices{}.defenderAvStatus
+- devices{}.deviceDnsName
+- devices{}.firstSeen
+- devices{}.healthStatus
+- devices{}.loggedOnUsers{}.accountName
+- devices{}.loggedOnUsers{}.domainName
+- devices{}.mdatpDeviceId
+- devices{}.onboardingStatus
+- devices{}.osBuild
+- devices{}.osPlatform
+- devices{}.osProcessor
+- devices{}.rbacGroupName
+- devices{}.riskScore
+- devices{}.version
+- devices{}.vmMetadata
+- devices{}.vmMetadata.cloudProvider
+- devices{}.vmMetadata.resourceId
+- devices{}.vmMetadata.subscriptionId
+- devices{}.vmMetadata.vmId
+- entities{}.aadUserId
+- entities{}.accountName
+- entities{}.applicationId
+- entities{}.applicationName
+- entities{}.detectionStatus
+- entities{}.deviceId
+- entities{}.domainName
+- entities{}.entityType
+- entities{}.evidenceCreationTime
+- entities{}.fileName
+- entities{}.filePath
+- entities{}.ipAddress
+- entities{}.parentProcessCreationTime
+- entities{}.parentProcessFileName
+- entities{}.parentProcessFilePath
+- entities{}.parentProcessId
+- entities{}.processCommandLine
+- entities{}.processCreationTime
+- entities{}.processId
+- entities{}.remediationStatus
+- entities{}.remediationStatusDetails
+- entities{}.sha1
+- entities{}.sha256
+- entities{}.userPrincipalName
+- entities{}.userSid
+- entities{}.verdict
+- eventtype
+- firstActivity
+- host
+- id
+- incidentId
+- index
+- investigationId
+- investigationState
+- lastActivity
+- lastUpdatedTime
+- linecount
+- mitreTechniques{}
+- mitre_technique_id
+- providerAlertId
+- resolvedTime
+- serviceSource
+- severity
+- signature
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- splunk_server_group
+- src
+- status
+- subject
+- tag
+- tag::app
+- tag::eventtype
+- threatFamilyName
+- timeendpos
+- timestartpos
+- title
+- type
+- user
+- user_name
+- _time
+example_log: "{\n\"id\": \"da47dc5671-e560-4229-984b-457564996b31_1\",\n\"incidentId\"\
+ : 989,\n\"investigationId\": null,\n\"assignedTo\": null,\n\"severity\": \"High\"\
+ ,\n\"status\": \"New\",\n\"classification\": null,\n\"determination\": null,\n\"\
+ investigationState\": \"UnsupportedAlertType\",\n\"detectionSource\": \"WindowsDefenderAtp\"\
+ ,\n\"detectorId\": \"9c3a70ec-e18a-4f92-865a-530f73130b7c\",\n\"category\": \"LateralMovement\"\
+ ,\n\"threatFamilyName\": null,\n\"title\": \"Ongoing hands-on-keyboard attack via\
+ \ Impacket toolkit\",\n\"description\": \"Suspicious execution of a command via\
+ \ Impacket was observed on this device. This tool connects to other hosts to explore\
+ \ network shares and execute commands. Attackers might be attempting to move laterally\
+ \ across the network using this tool. This usage of Impacket has often been observed\
+ \ in hands-on-keyboard attacks, where ransomware and other payloads are installed\
+ \ on target devices.\",\n\"alertCreationTime\": \"2023-01-24T05:33:37.3245808Z\"\
+ ,\n\"firstEventTime\": \"2023-01-24T05:31:07.5276179Z\",\n\"lastEventTime\": \"\
+ 2023-01-24T13:02:50.7831636Z\",\n\"lastUpdateTime\": \"2023-01-24T13:07:13.3233333Z\"\
+ ,\n\"resolvedTime\": null,\n\"machineId\": \"302293d9f276eae65553e5042156bce93cbc7148\"\
+ ,\n\"computerDnsName\": \"diytestmachine\",\n\"rbacGroupName\": \"UnassignedGroup\"\
+ ,\n\"aadTenantId\": \"1a492129-58c8-4011-91cd-245285f5345c\",\n\"threatName\": null,\n\
+ \"mitreTechniques\": [\n \"T1021.002\",\n \"T1047\",\n \"T1059.003\"\n],\n\"\
+ relatedUser\": {\n \"userName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\"\
+ \n},\n\"loggedOnUsers\": [\n {\n \"accountName\": \"administrator1\",\n \"\
+ domainName\": \"DIYTESTMACHINE\"\n }\n],\n\"comments\": [],\n\"evidence\": [\n\
+ \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:45:51.6833333Z\"\
+ ,\n \"sha1\": \"3ea7cc066317ac45f963c2227c4c7c50aa16eb7c\",\n \"sha256\":\
+ \ \"2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3\",\n \"\
+ fileName\": \"WmiPrvSE.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\\\\\
+ wbem\",\n \"processId\": 4476,\n \"processCommandLine\": \"wmiprvse.exe -secured\
+ \ -Embedding\",\n \"processCreationTime\": \"2023-01-24T05:43:32.4631151Z\",\n\
+ \ \"parentProcessId\": 896,\n \"parentProcessCreationTime\": \"2023-01-24T04:44:17.1940386Z\"\
+ ,\n \"parentProcessFileName\": \"svchost.exe\",\n \"parentProcessFilePath\"\
+ : \"C:\\\\Windows\\\\System32\",\n \"ipAddress\": null,\n \"url\": null,\n\
+ \ \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\
+ : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\
+ accountName\": \"NETWORK SERVICE\",\n \"domainName\": \"NT AUTHORITY\",\n \
+ \ \"userSid\": \"S-1-5-20\",\n \"aadUserId\": null,\n \"userPrincipalName\"\
+ : null,\n \"detectionStatus\": \"Detected\"\n },\n {\n \"entityType\": \"\
+ User\",\n \"evidenceCreationTime\": \"2023-01-24T05:33:37.4166667Z\",\n \"\
+ sha1\": null,\n \"sha256\": null,\n \"fileName\": null,\n \"filePath\"\
+ : null,\n \"processId\": null,\n \"processCommandLine\": null,\n \"processCreationTime\"\
+ : null,\n \"parentProcessId\": null,\n \"parentProcessCreationTime\": null,\n\
+ \ \"parentProcessFileName\": null,\n \"parentProcessFilePath\": null,\n \
+ \ \"ipAddress\": null,\n \"url\": null,\n \"registryKey\": null,\n \"\
+ registryHive\": null,\n \"registryValueType\": null,\n \"registryValue\":\
+ \ null,\n \"registryValueName\": null,\n \"accountName\": \"User1\",\n \
+ \ \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\": \"S-1-5-21-4215714199-1288013905-3478400915-1002\"\
+ ,\n \"aadUserId\": null,\n \"userPrincipalName\": null,\n \"detectionStatus\"\
+ : null\n },\n {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\"\
+ : \"2023-01-24T05:33:37.4166667Z\",\n \"sha1\": \"3ea7cc066317ac45f963c2227c4c7c50aa16eb7c\"\
+ ,\n \"sha256\": \"2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3\"\
+ ,\n \"fileName\": \"WmiPrvSE.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\\\
+ \\wbem\",\n \"processId\": 7824,\n \"processCommandLine\": \"wmiprvse.exe\
+ \ -secured -Embedding\",\n \"processCreationTime\": \"2023-01-24T05:30:50.8649791Z\"\
+ ,\n \"parentProcessId\": 896,\n \"parentProcessCreationTime\": \"2023-01-24T04:44:17.1940386Z\"\
+ ,\n \"parentProcessFileName\": \"svchost.exe\",\n \"parentProcessFilePath\"\
+ : \"C:\\\\Windows\\\\System32\",\n \"ipAddress\": null,\n \"url\": null,\n\
+ \ \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\
+ : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\
+ accountName\": \"NETWORK SERVICE\",\n \"domainName\": \"NT AUTHORITY\",\n \
+ \ \"userSid\": \"S-1-5-20\",\n \"aadUserId\": null,\n \"userPrincipalName\"\
+ : null,\n \"detectionStatus\": \"Detected\"\n },\n {\n \"entityType\": \"\
+ Process\",\n \"evidenceCreationTime\": \"2023-01-24T13:07:13.2233333Z\",\n \
+ \ \"sha1\": \"f1efb0fddc156e4c61c5f78a54700e4e7984d55d\",\n \"sha256\": \"b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450\"\
+ ,\n \"fileName\": \"cmd.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\"\
+ ,\n \"processId\": 5500,\n \"processCommandLine\": \"cmd.exe /Q /c powershell\
+ \ -NoProfile -ExecutionPolicy Bypass -File \\\"C:\\\\Users\\\\administrator1\\\\\
+ Desktop\\\\SharedFolder\\\\payload.ps1\\\" 1> \\\\\\\\127.0.0.1\\\\SharedFolder\\\
+ \\__1674565222.7012053 2>&1\",\n \"processCreationTime\": \"2023-01-24T13:02:50.4661885Z\"\
+ ,\n \"parentProcessId\": 756,\n \"parentProcessCreationTime\": \"2023-01-24T13:00:35.0107475Z\"\
+ ,\n \"parentProcessFileName\": \"WmiPrvSE.exe\",\n \"parentProcessFilePath\"\
+ : \"C:\\\\Windows\\\\System32\\\\wbem\",\n \"ipAddress\": null,\n \"url\"\
+ : null,\n \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\
+ : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\
+ accountName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\"\
+ : \"S-1-5-21-4215714199-1288013905-3478400915-1002\",\n \"aadUserId\": null,\n\
+ \ \"userPrincipalName\": null,\n \"detectionStatus\": \"Detected\"\n },\n\
+ \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:33:37.4166667Z\"\
+ ,\n \"sha1\": \"f1efb0fddc156e4c61c5f78a54700e4e7984d55d\",\n \"sha256\":\
+ \ \"b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450\",\n \"\
+ fileName\": \"cmd.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\",\n \
+ \ \"processId\": 8964,\n \"processCommandLine\": \"cmd.exe /Q /c powershell -NoProfile\
+ \ -ExecutionPolicy Bypass -File \\\"C:\\\\Users\\\\administrator1\\\\Desktop\\\\\
+ SharedFolder\\\\payload.ps1\\\" 1> \\\\\\\\127.0.0.1\\\\SharedFolder\\\\__1674538248.357367\
+ \ 2>&1\",\n \"processCreationTime\": \"2023-01-24T05:31:04.0743902Z\",\n \"\
+ parentProcessId\": 7824,\n \"parentProcessCreationTime\": \"2023-01-24T05:30:50.8649791Z\"\
+ ,\n \"parentProcessFileName\": \"WmiPrvSE.exe\",\n \"parentProcessFilePath\"\
+ : \"C:\\\\Windows\\\\System32\\\\wbem\",\n \"ipAddress\": null,\n \"url\"\
+ : null,\n \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\
+ : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\
+ accountName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\"\
+ : \"S-1-5-21-4215714199-1288013905-3478400915-1002\",\n \"aadUserId\": null,\n\
+ \ \"userPrincipalName\": null,\n \"detectionStatus\": \"Detected\"\n },\n\
+ \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:39:47.1733333Z\"\
+ ,\n \"sha1\": \"f1efb0fddc156e4c61c5f78a54700e4e7984d55d\",\n \"sha256\":\
+ \ \"b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450\",\n \"\
+ fileName\": \"cmd.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\",\n \
+ \ \"processId\": 884,\n \"processCommandLine\": \"cmd.exe /Q /c powershell -NoProfile\
+ \ -ExecutionPolicy Bypass -File \\\"C:\\\\Users\\\\administrator1\\\\Desktop\\\\\
+ SharedFolder\\\\payload.ps1\\\" 1> \\\\\\\\127.0.0.1\\\\SharedFolder\\\\__1674538583.8648584\
+ \ 2>&1\",\n \"processCreationTime\": \"2023-01-24T05:36:38.826505Z\",\n \"\
+ parentProcessId\": 7736,\n \"parentProcessCreationTime\": \"2023-01-24T05:36:26.0524655Z\"\
+ ,\n \"parentProcessFileName\": \"WmiPrvSE.exe\",\n \"parentProcessFilePath\"\
+ : \"C:\\\\Windows\\\\System32\\\\wbem\",\n \"ipAddress\": null,\n \"url\"\
+ : null,\n \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\
+ : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\
+ accountName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\"\
+ : \"S-1-5-21-4215714199-1288013905-3478400915-1002\",\n \"aadUserId\": null,\n\
+ \ \"userPrincipalName\": null,\n \"detectionStatus\": \"Detected\"\n },\n\
+ \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T13:07:13.2233333Z\"\
+ ,\n \"sha1\": \"3ea7cc066317ac45f963c2227c4c7c50aa16eb7c\",\n \"sha256\":\
+ \ \"2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3\",\n \"\
+ fileName\": \"WmiPrvSE.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\\\\\
+ wbem\",\n \"processId\": 756,\n \"processCommandLine\": \"wmiprvse.exe -secured\
+ \ -Embedding\",\n \"processCreationTime\": \"2023-01-24T13:00:35.0107475Z\",\n\
+ \ \"parentProcessId\": 908,\n \"parentProcessCreationTime\": \"2023-01-24T08:20:44.6877667Z\"\
+ ,\n \"parentProcessFileName\": \"svchost.exe\",\n \"parentProcessFilePath\"\
+ : \"C:\\\\Windows\\\\System32\",\n \"ipAddress\": null,\n \"url\": null,\n\
+ \ \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\
+ : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\
+ accountName\": \"NETWORK SERVICE\",\n \"domainName\": \"NT AUTHORITY\",\n \
+ \ \"userSid\": \"S-1-5-20\",\n \"aadUserId\": null,\n \"userPrincipalName\"\
+ : null,\n \"detectionStatus\": \"Detected\"\n },\n {\n \"entityType\": \"\
+ Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:45:51.6833333Z\",\n \
+ \ \"sha1\": \"f1efb0fddc156e4c61c5f78a54700e4e7984d55d\",\n \"sha256\": \"b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450\"\
+ ,\n \"fileName\": \"cmd.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\"\
+ ,\n \"processId\": 1140,\n \"processCommandLine\": \"cmd.exe /Q /c powershell\
+ \ -NoProfile -ExecutionPolicy Bypass -File \\\"C:\\\\Users\\\\administrator1\\\\\
+ Desktop\\\\SharedFolder\\\\payload.ps1\\\" 1> \\\\\\\\127.0.0.1\\\\SharedFolder\\\
+ \\__1674538878.1586335 2>&1\",\n \"processCreationTime\": \"2023-01-24T05:43:49.9375398Z\"\
+ ,\n \"parentProcessId\": 4476,\n \"parentProcessCreationTime\": \"2023-01-24T05:43:32.4631151Z\"\
+ ,\n \"parentProcessFileName\": \"WmiPrvSE.exe\",\n \"parentProcessFilePath\"\
+ : \"C:\\\\Windows\\\\System32\\\\wbem\",\n \"ipAddress\": null,\n \"url\"\
+ : null,\n \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\
+ : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\
+ accountName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\"\
+ : \"S-1-5-21-4215714199-1288013905-3478400915-1002\",\n \"aadUserId\": null,\n\
+ \ \"userPrincipalName\": null,\n \"detectionStatus\": \"Detected\"\n },\n\
+ \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:39:47.1733333Z\"\
+ ,\n \"sha1\": \"3ea7cc066317ac45f963c2227c4c7c50aa16eb7c\",\n \"sha256\":\
+ \ \"2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3\",\n \"\
+ fileName\": \"WmiPrvSE.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\\\\\
+ wbem\",\n \"processId\": 7736,\n \"processCommandLine\": \"wmiprvse.exe -secured\
+ \ -Embedding\",\n \"processCreationTime\": \"2023-01-24T05:36:26.0524655Z\",\n\
+ \ \"parentProcessId\": 896,\n \"parentProcessCreationTime\": \"2023-01-24T04:44:17.1940386Z\"\
+ ,\n \"parentProcessFileName\": \"svchost.exe\",\n \"parentProcessFilePath\"\
+ : \"C:\\\\Windows\\\\System32\",\n \"ipAddress\": null,\n \"url\": null,\n\
+ \ \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\
+ : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\
+ accountName\": \"NETWORK SERVICE\",\n \"domainName\": \"NT AUTHORITY\",\n \
+ \ \"userSid\": \"S-1-5-20\",\n \"aadUserId\": null,\n \"userPrincipalName\"\
+ : null,\n \"detectionStatus\": \"Detected\"\n }\n],\n\"domains\": []\n}"
diff --git a/data_sources/nginx_access.yml b/data_sources/nginx_access.yml
index e24bb4163c..c7b491e28c 100644
--- a/data_sources/nginx_access.yml
+++ b/data_sources/nginx_access.yml
@@ -6,74 +6,74 @@ author: Patrick Bareiss, Splunk
description: Logs HTTP/S access events on an Nginx server, including details such
as client IP, request method, URI, response status, and user agent.
mitre_components:
- - Network Traffic Content
- - Network Traffic Flow
- - Response Metadata
- - Application Log Content
- - User Account Metadata
+- Network Traffic Content
+- Network Traffic Flow
+- Response Metadata
+- Application Log Content
+- User Account Metadata
source: /var/log/nginx/access.log
sourcetype: nginx:plus:kv
supported_TA: []
fields:
- - _time
- - action
- - app
- - bytes
- - bytes_in
- - bytes_out
- - category
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_ip
- - dest_port
- - eventtype
- - host
- - http_content_type
- - http_method
- - http_referer
- - http_user_agent
- - http_user_agent_length
- - http_x_forwarded_for
- - http_x_header
- - https
- - index
- - linecount
- - nginx_version
- - product
- - protocol
- - punct
- - request_time
- - response_time
- - server
- - site
- - source
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - status
- - status_description
- - status_type
- - tag
- - tag::eventtype
- - time_local
- - timeendpos
- - timestartpos
- - uri_path
- - url
- - url_domain
- - url_length
- - vendor
- - vendor_product
- - version
- - web_server
+- _time
+- action
+- app
+- bytes
+- bytes_in
+- bytes_out
+- category
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_ip
+- dest_port
+- eventtype
+- host
+- http_content_type
+- http_method
+- http_referer
+- http_user_agent
+- http_user_agent_length
+- http_x_forwarded_for
+- http_x_header
+- https
+- index
+- linecount
+- nginx_version
+- product
+- protocol
+- punct
+- request_time
+- response_time
+- server
+- site
+- source
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- status
+- status_description
+- status_type
+- tag
+- tag::eventtype
+- time_local
+- timeendpos
+- timestartpos
+- uri_path
+- url
+- url_domain
+- url_length
+- vendor
+- vendor_product
+- version
+- web_server
example_log: site="www.example.com" server="www.example.com" dest_port="443" dest_ip="192.0.2.1"
src="198.51.100.1" src_ip="198.51.100.1" user="-" time_local="22/Feb/2024:13:00:00
-0500" protocol="HTTP/1.1" status="200" bytes_out="1073741000" bytes_in="234" http_referer="-"
diff --git a/data_sources/o365.yml b/data_sources/o365.yml
index 3bda514d41..36c3c9bc2a 100644
--- a/data_sources/o365.yml
+++ b/data_sources/o365.yml
@@ -6,15 +6,15 @@ author: Patrick Bareiss, Splunk
description: Logs management activities in Microsoft 365, including administrative
actions, user activities, and configuration changes across various services.
mitre_components:
- - User Account Metadata
- - Cloud Service Modification
- - Application Log Content
- - Configuration Modification
- - Active Directory Object Modification
+- User Account Metadata
+- Cloud Service Modification
+- Application Log Content
+- Configuration Modification
+- Active Directory Object Modification
source: o365
sourcetype: o365:management:activity
separator: Operation
supported_TA:
- - name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+- name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
diff --git a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml
index a6e90c409a..d97086d833 100644
--- a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml
+++ b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml
@@ -6,88 +6,88 @@ author: Patrick Bareiss, Splunk
description: Logs the assignment of an application role grant to a user in Microsoft
365, including details about the role, user, and application involved.
mitre_components:
- - User Account Modification
- - Group Modification
- - Cloud Service Modification
- - Cloud Service Metadata
+- User Account Modification
+- Group Modification
+- Cloud Service Modification
+- Cloud Service Metadata
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Add app role assignment grant to user.
supported_TA:
- - name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+- name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
- - _time
- - ActorContextId
- - ActorIpAddress
- - Actor{}.ID
- - Actor{}.Type
- - AzureActiveDirectoryEventType
- - ClientIP
- - CreationTime
- - ExtendedProperties{}.Name
- - ExtendedProperties{}.Value
- - Id
- - InterSystemsId
- - IntraSystemId
- - ModifiedProperties{}.Name
- - ModifiedProperties{}.NewValue
- - ModifiedProperties{}.OldValue
- - ObjectId
- - Operation
- - OrganizationId
- - RecordType
- - ResultStatus
- - SupportTicketId
- - TargetContextId
- - Target{}.ID
- - Target{}.Type
- - UserId
- - UserKey
- - UserType
- - Version
- - Workload
- - additionalDetails
- - app
- - authentication_service
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_name
- - dvc
- - event_type
- - extendedAuditEventCategory
- - extended_properties
- - host
- - index
- - linecount
- - object
- - punct
- - record_type
- - signature
- - source
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - src_user
- - status
- - timeendpos
- - timestartpos
- - user
- - user_id
- - user_type
- - vendor_account
- - vendor_product
+- _time
+- ActorContextId
+- ActorIpAddress
+- Actor{}.ID
+- Actor{}.Type
+- AzureActiveDirectoryEventType
+- ClientIP
+- CreationTime
+- ExtendedProperties{}.Name
+- ExtendedProperties{}.Value
+- Id
+- InterSystemsId
+- IntraSystemId
+- ModifiedProperties{}.Name
+- ModifiedProperties{}.NewValue
+- ModifiedProperties{}.OldValue
+- ObjectId
+- Operation
+- OrganizationId
+- RecordType
+- ResultStatus
+- SupportTicketId
+- TargetContextId
+- Target{}.ID
+- Target{}.Type
+- UserId
+- UserKey
+- UserType
+- Version
+- Workload
+- additionalDetails
+- app
+- authentication_service
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_name
+- dvc
+- event_type
+- extendedAuditEventCategory
+- extended_properties
+- host
+- index
+- linecount
+- object
+- punct
+- record_type
+- signature
+- source
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- src_user
+- status
+- timeendpos
+- timestartpos
+- user
+- user_id
+- user_type
+- vendor_account
+- vendor_product
example_log: '{"Actor": [{"ID": "rodsoto@rodsoto.onmicrosoft.com", "Type": 5}, {"ID":
"10037FFEA938FB92", "Type": 3}, {"ID": "74658136-14ec-4630-ad9b-26e160ff0fc6", "Type":
2}, {"ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484", "Type": 2}, {"ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
diff --git a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml
index 720652a539..250a21a230 100644
--- a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml
+++ b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml
@@ -7,87 +7,87 @@ description: Logs the assignment of an application role to a service principal i
Microsoft 365, including details about the role, service principal, and application
involved.
mitre_components:
- - Cloud Service Modification
- - Cloud Service Metadata
- - User Account Metadata
- - Group Modification
+- Cloud Service Modification
+- Cloud Service Metadata
+- User Account Metadata
+- Group Modification
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Add app role assignment to service principal.
supported_TA:
- - name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+- name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
- - _time
- - ActorContextId
- - Actor{}.ID
- - Actor{}.Type
- - AzureActiveDirectoryEventType
- - CreationTime
- - ExtendedProperties{}.Name
- - ExtendedProperties{}.Value
- - Id
- - InterSystemsId
- - IntraSystemId
- - ModifiedProperties{}.Name
- - ModifiedProperties{}.NewValue
- - ModifiedProperties{}.OldValue
- - ObjectId
- - Operation
- - OrganizationId
- - RecordType
- - ResultStatus
- - SupportTicketId
- - TargetContextId
- - Target{}.ID
- - Target{}.Type
- - UserId
- - UserKey
- - UserType
- - Version
- - Workload
- - additionalDetails
- - app
- - authentication_service
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_name
- - dvc
- - event_type
- - eventtype
- - extendedAuditEventCategory
- - host
- - index
- - linecount
- - object
- - punct
- - record_type
- - signature
- - source
- - sourcetype
- - splunk_server
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - user_agent
- - user_agent_change
- - user_id
- - user_type
- - vendor_account
- - vendor_product
+- _time
+- ActorContextId
+- Actor{}.ID
+- Actor{}.Type
+- AzureActiveDirectoryEventType
+- CreationTime
+- ExtendedProperties{}.Name
+- ExtendedProperties{}.Value
+- Id
+- InterSystemsId
+- IntraSystemId
+- ModifiedProperties{}.Name
+- ModifiedProperties{}.NewValue
+- ModifiedProperties{}.OldValue
+- ObjectId
+- Operation
+- OrganizationId
+- RecordType
+- ResultStatus
+- SupportTicketId
+- TargetContextId
+- Target{}.ID
+- Target{}.Type
+- UserId
+- UserKey
+- UserType
+- Version
+- Workload
+- additionalDetails
+- app
+- authentication_service
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_name
+- dvc
+- event_type
+- eventtype
+- extendedAuditEventCategory
+- host
+- index
+- linecount
+- object
+- punct
+- record_type
+- signature
+- source
+- sourcetype
+- splunk_server
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- user_agent
+- user_agent_change
+- user_id
+- user_type
+- vendor_account
+- vendor_product
example_log: '{"CreationTime": "2024-02-08T21:49:53", "Id": "a6bee61d-8b3f-42e1-b4fa-778fb05c43ac",
"Operation": "Add app role assignment to service principal.", "OrganizationId":
"75243ab2-44f8-435c-a7a6-b479385df6d4", "RecordType": 8, "ResultStatus": "Success",
diff --git a/data_sources/o365_add_mailboxpermission.yml b/data_sources/o365_add_mailboxpermission.yml
index 09a36817fe..191c1d0e6b 100644
--- a/data_sources/o365_add_mailboxpermission.yml
+++ b/data_sources/o365_add_mailboxpermission.yml
@@ -7,79 +7,79 @@ description: Logs the addition of mailbox permissions in Microsoft 365, includin
details about the mailbox, granted permissions, and the user or administrator performing
the action.
mitre_components:
- - User Account Modification
- - User Account Metadata
- - Active Directory Object Modification
- - Application Log Content
+- User Account Modification
+- User Account Metadata
+- Active Directory Object Modification
+- Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Add-MailboxPermission
supported_TA:
- - name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+- name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
- - _time
- - AccessRights
- - AppId
- - ClientAppId
- - ClientIP
- - CreationTime
- - ExternalAccess
- - Id
- - Identity
- - InheritanceType
- - ObjectId
- - Operation
- - OrganizationId
- - OrganizationName
- - OriginatingServer
- - Parameters{}.Name
- - Parameters{}.Value
- - RecordType
- - ResultStatus
- - SessionId
- - User
- - UserId
- - UserKey
- - UserType
- - Version
- - Workload
- - app
- - authentication_service
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_name
- - dvc
- - host
- - index
- - linecount
- - object
- - punct
- - record_type
- - signature
- - source
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - status
- - timeendpos
- - timestartpos
- - user
- - user_id
- - user_type
- - vendor_account
- - vendor_product
+- _time
+- AccessRights
+- AppId
+- ClientAppId
+- ClientIP
+- CreationTime
+- ExternalAccess
+- Id
+- Identity
+- InheritanceType
+- ObjectId
+- Operation
+- OrganizationId
+- OrganizationName
+- OriginatingServer
+- Parameters{}.Name
+- Parameters{}.Value
+- RecordType
+- ResultStatus
+- SessionId
+- User
+- UserId
+- UserKey
+- UserType
+- Version
+- Workload
+- app
+- authentication_service
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_name
+- dvc
+- host
+- index
+- linecount
+- object
+- punct
+- record_type
+- signature
+- source
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- status
+- timeendpos
+- timestartpos
+- user
+- user_id
+- user_type
+- vendor_account
+- vendor_product
example_log: '{"AppId": "", "ClientAppId": "", "ClientIP": "18.159.234.121:30395",
"CreationTime": "2020-12-15T10:18:53", "ExternalAccess": false, "Id": "bb6e31a3-e98f-493d-bbff-08d8a0e2d2b0",
"ObjectId": "jhernan", "Operation": "Add-MailboxPermission", "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
diff --git a/data_sources/o365_add_member_to_role_.yml b/data_sources/o365_add_member_to_role_.yml
index 7a6ea65406..29145e6d5b 100644
--- a/data_sources/o365_add_member_to_role_.yml
+++ b/data_sources/o365_add_member_to_role_.yml
@@ -6,90 +6,90 @@ author: Patrick Bareiss, Splunk
description: Logs the addition of a member to a role in Microsoft 365, including details
about the role, the added member, and the user or administrator performing the action.
mitre_components:
- - Group Modification
- - Group Metadata
- - User Account Metadata
- - Cloud Service Modification
+- Group Modification
+- Group Metadata
+- User Account Metadata
+- Cloud Service Modification
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Add member to role.
supported_TA:
- - name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+- name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
- - _time
- - ActorContextId
- - Actor{}.ID
- - Actor{}.Type
- - AzureActiveDirectoryEventType
- - CreationTime
- - ExtendedProperties{}.Name
- - ExtendedProperties{}.Value
- - Id
- - InterSystemsId
- - IntraSystemId
- - ModifiedProperties{}.Name
- - ModifiedProperties{}.NewValue
- - ModifiedProperties{}.OldValue
- - ObjectId
- - Operation
- - OrganizationId
- - RecordType
- - ResultStatus
- - SupportTicketId
- - TargetContextId
- - Target{}.ID
- - Target{}.Type
- - UserId
- - UserKey
- - UserType
- - Version
- - Workload
- - action
- - additionalDetails
- - app
- - authentication_service
- - change_type
- - command
- - dataset_name
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_name
- - dvc
- - event_type
- - eventtype
- - extendedAuditEventCategory
- - host
- - index
- - linecount
- - object
- - object_attrs
- - object_category
- - punct
- - record_type
- - signature
- - source
- - sourcetype
- - splunk_server
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - user_id
- - user_type
- - vendor_account
- - vendor_product
+- _time
+- ActorContextId
+- Actor{}.ID
+- Actor{}.Type
+- AzureActiveDirectoryEventType
+- CreationTime
+- ExtendedProperties{}.Name
+- ExtendedProperties{}.Value
+- Id
+- InterSystemsId
+- IntraSystemId
+- ModifiedProperties{}.Name
+- ModifiedProperties{}.NewValue
+- ModifiedProperties{}.OldValue
+- ObjectId
+- Operation
+- OrganizationId
+- RecordType
+- ResultStatus
+- SupportTicketId
+- TargetContextId
+- Target{}.ID
+- Target{}.Type
+- UserId
+- UserKey
+- UserType
+- Version
+- Workload
+- action
+- additionalDetails
+- app
+- authentication_service
+- change_type
+- command
+- dataset_name
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_name
+- dvc
+- event_type
+- eventtype
+- extendedAuditEventCategory
+- host
+- index
+- linecount
+- object
+- object_attrs
+- object_category
+- punct
+- record_type
+- signature
+- source
+- sourcetype
+- splunk_server
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- user_id
+- user_type
+- vendor_account
+- vendor_product
example_log: '{"CreationTime": "2023-10-20T16:50:46", "Id": "30a8b107-b190-406c-9b80-c3f5c3a29129",
"Operation": "Add member to role.", "OrganizationId": "d8211c86-3244-409b-8c4f-ae27ed34b4a5",
"RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com",
diff --git a/data_sources/o365_add_owner_to_application_.yml b/data_sources/o365_add_owner_to_application_.yml
index 5c3b3c7f4b..dd7f2632d4 100644
--- a/data_sources/o365_add_owner_to_application_.yml
+++ b/data_sources/o365_add_owner_to_application_.yml
@@ -7,92 +7,92 @@ description: Logs the addition of an owner to an application in Microsoft 365, i
details about the application, the new owner, and the user or administrator performing
the action.
mitre_components:
- - User Account Modification
- - Group Modification
- - Cloud Service Modification
- - Cloud Service Metadata
+- User Account Modification
+- Group Modification
+- Cloud Service Modification
+- Cloud Service Metadata
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Add owner to application.
supported_TA:
- - name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+- name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
- - _time
- - ActorContextId
- - Actor{}.ID
- - Actor{}.Type
- - AzureActiveDirectoryEventType
- - CreationTime
- - ExtendedProperties{}.Name
- - ExtendedProperties{}.Value
- - Id
- - InterSystemsId
- - IntraSystemId
- - ModifiedProperties{}.Name
- - ModifiedProperties{}.NewValue
- - ModifiedProperties{}.OldValue
- - ObjectId
- - Operation
- - OrganizationId
- - RecordType
- - ResultStatus
- - SupportTicketId
- - TargetContextId
- - Target{}.ID
- - Target{}.Type
- - UserId
- - UserKey
- - UserType
- - Version
- - Workload
- - action
- - additionalDetails
- - app
- - authentication_service
- - change_type
- - command
- - dataset_name
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_name
- - dvc
- - event_type
- - eventtype
- - extendedAuditEventCategory
- - host
- - index
- - linecount
- - object
- - object_attrs
- - object_category
- - punct
- - record_type
- - signature
- - source
- - sourcetype
- - splunk_server
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - user_agent
- - user_agent_change
- - user_id
- - user_type
- - vendor_account
- - vendor_product
+- _time
+- ActorContextId
+- Actor{}.ID
+- Actor{}.Type
+- AzureActiveDirectoryEventType
+- CreationTime
+- ExtendedProperties{}.Name
+- ExtendedProperties{}.Value
+- Id
+- InterSystemsId
+- IntraSystemId
+- ModifiedProperties{}.Name
+- ModifiedProperties{}.NewValue
+- ModifiedProperties{}.OldValue
+- ObjectId
+- Operation
+- OrganizationId
+- RecordType
+- ResultStatus
+- SupportTicketId
+- TargetContextId
+- Target{}.ID
+- Target{}.Type
+- UserId
+- UserKey
+- UserType
+- Version
+- Workload
+- action
+- additionalDetails
+- app
+- authentication_service
+- change_type
+- command
+- dataset_name
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_name
+- dvc
+- event_type
+- eventtype
+- extendedAuditEventCategory
+- host
+- index
+- linecount
+- object
+- object_attrs
+- object_category
+- punct
+- record_type
+- signature
+- source
+- sourcetype
+- splunk_server
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- user_agent
+- user_agent_change
+- user_id
+- user_type
+- vendor_account
+- vendor_product
example_log: '{"CreationTime": "2023-09-07T13:42:04", "Id": "6e2c723b-8f6e-47f4-8c60-fa23ef3fccee",
"Operation": "Add owner to application.", "OrganizationId": "48203edf-5d2c-45f2-8123-a368cc8b0e51",
"RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@contoso.onmicrosoft.com",
diff --git a/data_sources/o365_add_service_principal_.yml b/data_sources/o365_add_service_principal_.yml
index 806ce7eda5..8f4af7e270 100644
--- a/data_sources/o365_add_service_principal_.yml
+++ b/data_sources/o365_add_service_principal_.yml
@@ -6,92 +6,92 @@ author: Patrick Bareiss, Splunk
description: Logs the addition of a new service principal in Microsoft 365, including
details about the associated application and the action initiator.
mitre_components:
- - Cloud Service Creation
- - Cloud Service Metadata
- - User Account Metadata
- - Active Directory Object Creation
+- Cloud Service Creation
+- Cloud Service Metadata
+- User Account Metadata
+- Active Directory Object Creation
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Add service principal.
supported_TA:
- - name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+- name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
- - _time
- - ActorContextId
- - Actor{}.ID
- - Actor{}.Type
- - AzureActiveDirectoryEventType
- - CreationTime
- - ExtendedProperties{}.Name
- - ExtendedProperties{}.Value
- - Id
- - InterSystemsId
- - IntraSystemId
- - ModifiedProperties{}.Name
- - ModifiedProperties{}.NewValue
- - ModifiedProperties{}.OldValue
- - ObjectId
- - Operation
- - OrganizationId
- - RecordType
- - ResultStatus
- - SupportTicketId
- - TargetContextId
- - Target{}.ID
- - Target{}.Type
- - UserId
- - UserKey
- - UserType
- - Version
- - Workload
- - action
- - additionalDetails
- - app
- - authentication_service
- - change_type
- - command
- - dataset_name
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_name
- - dvc
- - event_type
- - eventtype
- - extendedAuditEventCategory
- - host
- - index
- - linecount
- - object_attrs
- - object_category
- - punct
- - record_type
- - signature
- - source
- - sourcetype
- - splunk_server
- - src_user
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - user_agent
- - user_agent_change
- - user_id
- - user_type
- - vendor_account
- - vendor_product
+- _time
+- ActorContextId
+- Actor{}.ID
+- Actor{}.Type
+- AzureActiveDirectoryEventType
+- CreationTime
+- ExtendedProperties{}.Name
+- ExtendedProperties{}.Value
+- Id
+- InterSystemsId
+- IntraSystemId
+- ModifiedProperties{}.Name
+- ModifiedProperties{}.NewValue
+- ModifiedProperties{}.OldValue
+- ObjectId
+- Operation
+- OrganizationId
+- RecordType
+- ResultStatus
+- SupportTicketId
+- TargetContextId
+- Target{}.ID
+- Target{}.Type
+- UserId
+- UserKey
+- UserType
+- Version
+- Workload
+- action
+- additionalDetails
+- app
+- authentication_service
+- change_type
+- command
+- dataset_name
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_name
+- dvc
+- event_type
+- eventtype
+- extendedAuditEventCategory
+- host
+- index
+- linecount
+- object_attrs
+- object_category
+- punct
+- record_type
+- signature
+- source
+- sourcetype
+- splunk_server
+- src_user
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- user_agent
+- user_agent_change
+- user_id
+- user_type
+- vendor_account
+- vendor_product
example_log: '{"CreationTime": "2024-02-07T22:31:14", "Id": "f624ed92-b4a2-4d42-aa8b-20a261d06b7f",
"Operation": "Add service principal.", "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com",
diff --git a/data_sources/o365_change_user_license_.yml b/data_sources/o365_change_user_license_.yml
index cec6ea1cc1..d26262857c 100644
--- a/data_sources/o365_change_user_license_.yml
+++ b/data_sources/o365_change_user_license_.yml
@@ -6,88 +6,88 @@ author: Patrick Bareiss, Splunk
description: Logs changes to user licenses in Microsoft 365, including additions,
removals, or updates to service plans associated with a user account.
mitre_components:
- - User Account Modification
- - User Account Metadata
- - Cloud Service Modification
- - Configuration Modification
+- User Account Modification
+- User Account Metadata
+- Cloud Service Modification
+- Configuration Modification
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Change user license.
supported_TA:
- - name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+- name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
- - _time
- - ActorContextId
- - Actor{}.ID
- - Actor{}.Type
- - AzureActiveDirectoryEventType
- - CreationTime
- - ExtendedProperties{}.Name
- - ExtendedProperties{}.Value
- - Id
- - InterSystemsId
- - IntraSystemId
- - ObjectId
- - Operation
- - OrganizationId
- - RecordType
- - ResultStatus
- - SupportTicketId
- - TargetContextId
- - Target{}.ID
- - Target{}.Type
- - UserId
- - UserKey
- - UserType
- - Version
- - Workload
- - action
- - additionalDetails
- - app
- - authentication_service
- - change_type
- - command
- - dataset_name
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_name
- - dvc
- - event_type
- - eventtype
- - extendedAuditEventCategory
- - host
- - index
- - linecount
- - object
- - object_attrs
- - object_category
- - punct
- - record_type
- - signature
- - source
- - sourcetype
- - splunk_server
- - src_user
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - user_id
- - user_type
- - vendor_account
- - vendor_product
+- _time
+- ActorContextId
+- Actor{}.ID
+- Actor{}.Type
+- AzureActiveDirectoryEventType
+- CreationTime
+- ExtendedProperties{}.Name
+- ExtendedProperties{}.Value
+- Id
+- InterSystemsId
+- IntraSystemId
+- ObjectId
+- Operation
+- OrganizationId
+- RecordType
+- ResultStatus
+- SupportTicketId
+- TargetContextId
+- Target{}.ID
+- Target{}.Type
+- UserId
+- UserKey
+- UserType
+- Version
+- Workload
+- action
+- additionalDetails
+- app
+- authentication_service
+- change_type
+- command
+- dataset_name
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_name
+- dvc
+- event_type
+- eventtype
+- extendedAuditEventCategory
+- host
+- index
+- linecount
+- object
+- object_attrs
+- object_category
+- punct
+- record_type
+- signature
+- source
+- sourcetype
+- splunk_server
+- src_user
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- user_id
+- user_type
+- vendor_account
+- vendor_product
example_log: '{"CreationTime": "2023-09-11T15:55:46", "Id": "1e39f32d-081d-4494-994a-533b57f91df7",
"Operation": "Change user license.", "OrganizationId": "bbad9541-eb53-4533-bcef-2b76182c3b75",
"RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com",
diff --git a/data_sources/o365_consent_to_application_.yml b/data_sources/o365_consent_to_application_.yml
index 9a8aacafcd..5698a08a0d 100644
--- a/data_sources/o365_consent_to_application_.yml
+++ b/data_sources/o365_consent_to_application_.yml
@@ -7,84 +7,84 @@ description: Logs user or administrator consent to an application's permissions
Microsoft 365, including details about the application, granted permissions, and
the consenting user or process.
mitre_components:
- - User Account Modification
- - Cloud Service Modification
- - Cloud Service Metadata
- - Configuration Modification
+- User Account Modification
+- Cloud Service Modification
+- Cloud Service Metadata
+- Configuration Modification
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Consent to application.
supported_TA:
- - name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+- name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
- - _time
- - ActorContextId
- - Actor{}.ID
- - Actor{}.Type
- - AzureActiveDirectoryEventType
- - CreationTime
- - ExtendedProperties{}.Name
- - ExtendedProperties{}.Value
- - Id
- - InterSystemsId
- - IntraSystemId
- - ModifiedProperties{}.Name
- - ModifiedProperties{}.NewValue
- - ModifiedProperties{}.OldValue
- - ObjectId
- - Operation
- - OrganizationId
- - RecordType
- - ResultStatus
- - SupportTicketId
- - TargetContextId
- - Target{}.ID
- - Target{}.Type
- - UserId
- - UserKey
- - UserType
- - Version
- - Workload
- - additionalDetails
- - app
- - authentication_service
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_name
- - dvc
- - event_type
- - extendedAuditEventCategory
- - host
- - index
- - linecount
- - object
- - punct
- - record_type
- - signature
- - source
- - sourcetype
- - splunk_server
- - status
- - timeendpos
- - timestartpos
- - user
- - user_agent
- - user_agent_change
- - user_id
- - user_type
- - vendor_account
- - vendor_product
+- _time
+- ActorContextId
+- Actor{}.ID
+- Actor{}.Type
+- AzureActiveDirectoryEventType
+- CreationTime
+- ExtendedProperties{}.Name
+- ExtendedProperties{}.Value
+- Id
+- InterSystemsId
+- IntraSystemId
+- ModifiedProperties{}.Name
+- ModifiedProperties{}.NewValue
+- ModifiedProperties{}.OldValue
+- ObjectId
+- Operation
+- OrganizationId
+- RecordType
+- ResultStatus
+- SupportTicketId
+- TargetContextId
+- Target{}.ID
+- Target{}.Type
+- UserId
+- UserKey
+- UserType
+- Version
+- Workload
+- additionalDetails
+- app
+- authentication_service
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_name
+- dvc
+- event_type
+- extendedAuditEventCategory
+- host
+- index
+- linecount
+- object
+- punct
+- record_type
+- signature
+- source
+- sourcetype
+- splunk_server
+- status
+- timeendpos
+- timestartpos
+- user
+- user_agent
+- user_agent_change
+- user_id
+- user_type
+- vendor_account
+- vendor_product
example_log: '{"CreationTime": "2023-09-05T21:05:31", "Id": "5822e126-1fbc-4269-9ad6-4c1879cdbcf3",
"Operation": "Consent to application.", "OrganizationId": "9c00a473-1b2c-4bc2-9215-84df3f57aee5",
"RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@contoso.onmicrosoft.com",
diff --git a/data_sources/o365_disable_strong_authentication_.yml b/data_sources/o365_disable_strong_authentication_.yml
index bd40f2eca5..8682551f6c 100644
--- a/data_sources/o365_disable_strong_authentication_.yml
+++ b/data_sources/o365_disable_strong_authentication_.yml
@@ -7,85 +7,85 @@ description: Logs the disabling of strong authentication (e.g., multi-factor aut
for a user or group in Microsoft 365, including details about the affected accounts
and the action initiator.
mitre_components:
- - User Account Modification
- - Group Modification
- - Configuration Modification
- - Application Log Content
+- User Account Modification
+- Group Modification
+- Configuration Modification
+- Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Disable Strong Authentication.
supported_TA:
- - name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+- name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
- - _time
- - ActorContextId
- - ActorIpAddress
- - Actor{}.ID
- - Actor{}.Type
- - AzureActiveDirectoryEventType
- - ClientIP
- - CreationTime
- - ExtendedProperties{}.Name
- - ExtendedProperties{}.Value
- - Id
- - InterSystemsId
- - IntraSystemId
- - ModifiedProperties{}.Name
- - ModifiedProperties{}.NewValue
- - ModifiedProperties{}.OldValue
- - ObjectId
- - Operation
- - OrganizationId
- - RecordType
- - ResultStatus
- - SupportTicketId
- - TargetContextId
- - Target{}.ID
- - Target{}.Type
- - UserId
- - UserKey
- - UserType
- - Version
- - Workload
- - additionalDetails
- - app
- - authentication_service
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_name
- - dvc
- - event_type
- - extendedAuditEventCategory
- - extended_properties
- - host
- - index
- - linecount
- - object
- - punct
- - record_type
- - signature
- - source
- - sourcetype
- - splunk_server
- - status
- - timeendpos
- - timestartpos
- - user
- - user_id
- - user_type
- - vendor_account
- - vendor_product
+- _time
+- ActorContextId
+- ActorIpAddress
+- Actor{}.ID
+- Actor{}.Type
+- AzureActiveDirectoryEventType
+- ClientIP
+- CreationTime
+- ExtendedProperties{}.Name
+- ExtendedProperties{}.Value
+- Id
+- InterSystemsId
+- IntraSystemId
+- ModifiedProperties{}.Name
+- ModifiedProperties{}.NewValue
+- ModifiedProperties{}.OldValue
+- ObjectId
+- Operation
+- OrganizationId
+- RecordType
+- ResultStatus
+- SupportTicketId
+- TargetContextId
+- Target{}.ID
+- Target{}.Type
+- UserId
+- UserKey
+- UserType
+- Version
+- Workload
+- additionalDetails
+- app
+- authentication_service
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_name
+- dvc
+- event_type
+- extendedAuditEventCategory
+- extended_properties
+- host
+- index
+- linecount
+- object
+- punct
+- record_type
+- signature
+- source
+- sourcetype
+- splunk_server
+- status
+- timeendpos
+- timestartpos
+- user
+- user_id
+- user_type
+- vendor_account
+- vendor_product
example_log: '{"Actor": [{"ID": "rodsoto@rodsoto.onmicrosoft.com", "Type": 5}, {"ID":
"10037FFEA938FB92", "Type": 3}, {"ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2}, {"ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484", "Type": 2}, {"ID": "User",
diff --git a/data_sources/o365_mailitemsaccessed.yml b/data_sources/o365_mailitemsaccessed.yml
index 49429c5898..e1c6afc695 100644
--- a/data_sources/o365_mailitemsaccessed.yml
+++ b/data_sources/o365_mailitemsaccessed.yml
@@ -6,81 +6,81 @@ author: Patrick Bareiss, Splunk
description: Logs access to mailbox items in Microsoft 365, including details about
the user accessing the items, the accessed content, and the method of access.
mitre_components:
- - File Access
- - User Account Metadata
- - Application Log Content
- - Active Directory Object Access
+- File Access
+- User Account Metadata
+- Application Log Content
+- Active Directory Object Access
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: MailItemsAccessed
supported_TA:
- - name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+- name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
- - _time
- - AppId
- - ClientAppId
- - ClientIPAddress
- - ClientInfoString
- - CreationTime
- - ExternalAccess
- - Folders{}.FolderItems{}.InternetMessageId
- - Folders{}.FolderItems{}.SizeInBytes
- - Folders{}.Id
- - Folders{}.Path
- - Id
- - InternalLogonType
- - IsThrottled
- - LogonType
- - LogonUserSid
- - MailAccessType
- - MailboxGuid
- - MailboxOwnerSid
- - MailboxOwnerUPN
- - Operation
- - OperationCount
- - OperationProperties{}.Name
- - OperationProperties{}.Value
- - OrganizationId
- - OrganizationName
- - OriginatingServer
- - RecordType
- - ResultStatus
- - UserId
- - UserKey
- - UserType
- - Version
- - Workload
- - app
- - authentication_service
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dvc
- - host
- - index
- - linecount
- - punct
- - signature
- - source
- - sourcetype
- - splunk_server
- - status
- - timeendpos
- - timestartpos
- - user
- - user_id
- - user_type
- - vendor_account
- - vendor_product
+- _time
+- AppId
+- ClientAppId
+- ClientIPAddress
+- ClientInfoString
+- CreationTime
+- ExternalAccess
+- Folders{}.FolderItems{}.InternetMessageId
+- Folders{}.FolderItems{}.SizeInBytes
+- Folders{}.Id
+- Folders{}.Path
+- Id
+- InternalLogonType
+- IsThrottled
+- LogonType
+- LogonUserSid
+- MailAccessType
+- MailboxGuid
+- MailboxOwnerSid
+- MailboxOwnerUPN
+- Operation
+- OperationCount
+- OperationProperties{}.Name
+- OperationProperties{}.Value
+- OrganizationId
+- OrganizationName
+- OriginatingServer
+- RecordType
+- ResultStatus
+- UserId
+- UserKey
+- UserType
+- Version
+- Workload
+- app
+- authentication_service
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dvc
+- host
+- index
+- linecount
+- punct
+- signature
+- source
+- sourcetype
+- splunk_server
+- status
+- timeendpos
+- timestartpos
+- user
+- user_id
+- user_type
+- vendor_account
+- vendor_product
example_log: '{"CreationTime": "2024-02-01T16:07:34", "Id": "9cef02e9-4bfa-4c73-be7d-9dad68b9cea8",
"Operation": "MailItemsAccessed", "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"RecordType": 50, "ResultStatus": "Succeeded", "UserKey": "100320030DF47B14", "UserType":
diff --git a/data_sources/o365_modifyfolderpermissions.yml b/data_sources/o365_modifyfolderpermissions.yml
index aca4f79957..77b5ee58cf 100644
--- a/data_sources/o365_modifyfolderpermissions.yml
+++ b/data_sources/o365_modifyfolderpermissions.yml
@@ -6,99 +6,99 @@ author: Patrick Bareiss, Splunk
description: Logs modifications to folder permissions in Microsoft 365, including
updates to access levels, user assignments, and sharing settings.
mitre_components:
- - User Account Modification
- - File Access
- - Active Directory Object Modification
- - Application Log Content
+- User Account Modification
+- File Access
+- Active Directory Object Modification
+- Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: ModifyFolderPermissions
supported_TA:
- - name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+- name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
- - _time
- - AppId
- - ClientIP
- - ClientIPAddress
- - ClientInfoString
- - CreationTime
- - ExternalAccess
- - Id
- - InternalLogonType
- - Item.Id
- - Item.ParentFolder.Id
- - Item.ParentFolder.MemberRights
- - Item.ParentFolder.MemberSid
- - Item.ParentFolder.MemberUpn
- - Item.ParentFolder.Name
- - Item.ParentFolder.Path
- - LogonType
- - LogonUserSid
- - MailboxGuid
- - MailboxOwnerSid
- - MailboxOwnerUPN
- - Operation
- - OrganizationId
- - OrganizationName
- - OriginatingServer
- - RecordType
- - ResultStatus
- - SessionId
- - UserId
- - UserKey
- - UserType
- - Version
- - Workload
- - action
- - app
- - authentication_service
- - change_type
- - client_info_str
- - command
- - dataset_name
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_name
- - dvc
- - eventtype
- - host
- - index
- - linecount
- - object
- - object_attrs
- - object_category
- - object_id
- - punct
- - record_type
- - result
- - signature
- - source
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - status
- - tag
- - tag::eventtype
- - tenant_id
- - timeendpos
- - timestartpos
- - user
- - user_agent
- - user_id
- - user_type
- - vendor_account
- - vendor_product
+- _time
+- AppId
+- ClientIP
+- ClientIPAddress
+- ClientInfoString
+- CreationTime
+- ExternalAccess
+- Id
+- InternalLogonType
+- Item.Id
+- Item.ParentFolder.Id
+- Item.ParentFolder.MemberRights
+- Item.ParentFolder.MemberSid
+- Item.ParentFolder.MemberUpn
+- Item.ParentFolder.Name
+- Item.ParentFolder.Path
+- LogonType
+- LogonUserSid
+- MailboxGuid
+- MailboxOwnerSid
+- MailboxOwnerUPN
+- Operation
+- OrganizationId
+- OrganizationName
+- OriginatingServer
+- RecordType
+- ResultStatus
+- SessionId
+- UserId
+- UserKey
+- UserType
+- Version
+- Workload
+- action
+- app
+- authentication_service
+- change_type
+- client_info_str
+- command
+- dataset_name
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_name
+- dvc
+- eventtype
+- host
+- index
+- linecount
+- object
+- object_attrs
+- object_category
+- object_id
+- punct
+- record_type
+- result
+- signature
+- source
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- status
+- tag
+- tag::eventtype
+- tenant_id
+- timeendpos
+- timestartpos
+- user
+- user_agent
+- user_id
+- user_type
+- vendor_account
+- vendor_product
example_log: '{"CreationTime": "2023-09-07T18:19:07", "Id": "ff065c17-e638-4013-20ab-08dbafceeca1",
"Operation": "ModifyFolderPermissions", "OrganizationId": "e17879dd-24ec-44a6-be92-9dcbf6969220",
"RecordType": 2, "ResultStatus": "Succeeded", "UserKey": "10032002CC029AE9", "UserType":
diff --git a/data_sources/o365_set_company_information_.yml b/data_sources/o365_set_company_information_.yml
index e3da9d7ddd..7348172690 100644
--- a/data_sources/o365_set_company_information_.yml
+++ b/data_sources/o365_set_company_information_.yml
@@ -6,93 +6,93 @@ author: Patrick Bareiss, Splunk
description: Logs updates to organizational settings and company information in Microsoft
365, including changes to contact details, branding, and configuration policies.
mitre_components:
- - Cloud Service Modification
- - Configuration Modification
- - Cloud Service Metadata
- - Application Log Content
+- Cloud Service Modification
+- Configuration Modification
+- Cloud Service Metadata
+- Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Set Company Information.
supported_TA:
- - name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+- name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
- - _time
- - ActorContextId
- - ActorIpAddress
- - Actor{}.ID
- - Actor{}.Type
- - AzureActiveDirectoryEventType
- - ClientIP
- - CreationTime
- - ExtendedProperties{}.Name
- - ExtendedProperties{}.Value
- - Id
- - InterSystemsId
- - IntraSystemId
- - ModifiedProperties{}.Name
- - ModifiedProperties{}.NewValue
- - ModifiedProperties{}.OldValue
- - ObjectId
- - Operation
- - OrganizationId
- - RecordType
- - ResultStatus
- - SupportTicketId
- - TargetContextId
- - Target{}.ID
- - Target{}.Type
- - UserId
- - UserKey
- - UserType
- - Version
- - Workload
- - action
- - additionalDetails
- - app
- - authentication_service
- - change_type
- - command
- - dataset_name
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_name
- - dvc
- - event_type
- - eventtype
- - extendedAuditEventCategory
- - extended_properties
- - host
- - index
- - linecount
- - object
- - object_attrs
- - object_category
- - punct
- - record_type
- - signature
- - source
- - sourcetype
- - splunk_server
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - user_id
- - user_type
- - vendor_account
- - vendor_product
+- _time
+- ActorContextId
+- ActorIpAddress
+- Actor{}.ID
+- Actor{}.Type
+- AzureActiveDirectoryEventType
+- ClientIP
+- CreationTime
+- ExtendedProperties{}.Name
+- ExtendedProperties{}.Value
+- Id
+- InterSystemsId
+- IntraSystemId
+- ModifiedProperties{}.Name
+- ModifiedProperties{}.NewValue
+- ModifiedProperties{}.OldValue
+- ObjectId
+- Operation
+- OrganizationId
+- RecordType
+- ResultStatus
+- SupportTicketId
+- TargetContextId
+- Target{}.ID
+- Target{}.Type
+- UserId
+- UserKey
+- UserType
+- Version
+- Workload
+- action
+- additionalDetails
+- app
+- authentication_service
+- change_type
+- command
+- dataset_name
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_name
+- dvc
+- event_type
+- eventtype
+- extendedAuditEventCategory
+- extended_properties
+- host
+- index
+- linecount
+- object
+- object_attrs
+- object_category
+- punct
+- record_type
+- signature
+- source
+- sourcetype
+- splunk_server
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- user_id
+- user_type
+- vendor_account
+- vendor_product
example_log: '{"Actor": [{"ID": "bpatel@rodsoto.onmicrosoft.com", "Type": 5}, {"ID":
"100320010208B5DC", "Type": 3}, {"ID": "User_425b75db-38be-4c7b-a474-5f0709247370",
"Type": 2}, {"ID": "425b75db-38be-4c7b-a474-5f0709247370", "Type": 2}, {"ID": "User",
diff --git a/data_sources/o365_set_mailbox.yml b/data_sources/o365_set_mailbox.yml
index 9da03f53f4..2cf75ed058 100644
--- a/data_sources/o365_set_mailbox.yml
+++ b/data_sources/o365_set_mailbox.yml
@@ -6,89 +6,89 @@ author: Patrick Bareiss, Splunk
description: Logs changes to mailbox properties in Microsoft 365, including updates
to permissions, storage quotas, and configuration settings.
mitre_components:
- - User Account Modification
- - Active Directory Object Modification
- - User Account Metadata
- - Application Log Content
+- User Account Modification
+- Active Directory Object Modification
+- User Account Metadata
+- Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Set-Mailbox
supported_TA:
- - name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+- name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
- - _time
- - AppId
- - ClientAppId
- - ClientIP
- - CreationTime
- - ExternalAccess
- - Id
- - Identity
- - ObjectId
- - Operation
- - OrganizationId
- - OrganizationName
- - OriginatingServer
- - Parameters{}.Name
- - Parameters{}.Value
- - Params
- - RecordType
- - ResultStatus
- - SessionId
- - UserId
- - UserKey
- - UserType
- - Version
- - Workload
- - action
- - app
- - authentication_service
- - change_type
- - command
- - dataset_name
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_name
- - dvc
- - eventtype
- - host
- - index
- - linecount
- - object
- - object_attrs
- - object_category
- - object_id
- - punct
- - record_type
- - result
- - signature
- - source
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - src_user
- - src_user_type
- - status
- - tag
- - tag::eventtype
- - tenant_id
- - timeendpos
- - timestartpos
- - user
- - user_id
- - vendor_account
- - vendor_product
+- _time
+- AppId
+- ClientAppId
+- ClientIP
+- CreationTime
+- ExternalAccess
+- Id
+- Identity
+- ObjectId
+- Operation
+- OrganizationId
+- OrganizationName
+- OriginatingServer
+- Parameters{}.Name
+- Parameters{}.Value
+- Params
+- RecordType
+- ResultStatus
+- SessionId
+- UserId
+- UserKey
+- UserType
+- Version
+- Workload
+- action
+- app
+- authentication_service
+- change_type
+- command
+- dataset_name
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_name
+- dvc
+- eventtype
+- host
+- index
+- linecount
+- object
+- object_attrs
+- object_category
+- object_id
+- punct
+- record_type
+- result
+- signature
+- source
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- src_user
+- src_user_type
+- status
+- tag
+- tag::eventtype
+- tenant_id
+- timeendpos
+- timestartpos
+- user
+- user_id
+- vendor_account
+- vendor_product
example_log: '{"AppId": "", "ClientAppId": "", "ClientIP": "18.192.200.190:52816",
"CreationTime": "2020-12-16T12:32:28", "ExternalAccess": false, "Id": "a6a52406-0912-448d-36eb-08d8a1bea6be",
"ObjectId": "bpatel", "Operation": "Set-Mailbox", "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
diff --git a/data_sources/o365_update_application_.yml b/data_sources/o365_update_application_.yml
index 2b04a3230b..4e9728c9e5 100644
--- a/data_sources/o365_update_application_.yml
+++ b/data_sources/o365_update_application_.yml
@@ -6,92 +6,92 @@ author: Patrick Bareiss, Splunk
description: Logs updates made to applications in Microsoft 365, including changes
to configurations, permissions, and role assignments.
mitre_components:
- - Cloud Service Modification
- - Configuration Modification
- - Cloud Service Metadata
- - Application Log Content
+- Cloud Service Modification
+- Configuration Modification
+- Cloud Service Metadata
+- Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Update application.
supported_TA:
- - name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+- name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
- - _time
- - ActorContextId
- - Actor{}.ID
- - Actor{}.Type
- - AzureActiveDirectoryEventType
- - CreationTime
- - ExtendedProperties{}.Name
- - ExtendedProperties{}.Value
- - Id
- - InterSystemsId
- - IntraSystemId
- - ModifiedProperties{}.Name
- - ModifiedProperties{}.NewValue
- - ModifiedProperties{}.OldValue
- - ObjectId
- - Operation
- - OrganizationId
- - RecordType
- - ResultStatus
- - SupportTicketId
- - TargetContextId
- - Target{}.ID
- - Target{}.Type
- - UserId
- - UserKey
- - UserType
- - Version
- - Workload
- - action
- - additionalDetails
- - app
- - authentication_service
- - change_type
- - command
- - dataset_name
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_name
- - dvc
- - event_type
- - eventtype
- - extendedAuditEventCategory
- - host
- - index
- - linecount
- - object
- - object_attrs
- - object_category
- - punct
- - record_type
- - signature
- - source
- - sourcetype
- - splunk_server
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - user_agent
- - user_agent_change
- - user_id
- - user_type
- - vendor_account
- - vendor_product
+- _time
+- ActorContextId
+- Actor{}.ID
+- Actor{}.Type
+- AzureActiveDirectoryEventType
+- CreationTime
+- ExtendedProperties{}.Name
+- ExtendedProperties{}.Value
+- Id
+- InterSystemsId
+- IntraSystemId
+- ModifiedProperties{}.Name
+- ModifiedProperties{}.NewValue
+- ModifiedProperties{}.OldValue
+- ObjectId
+- Operation
+- OrganizationId
+- RecordType
+- ResultStatus
+- SupportTicketId
+- TargetContextId
+- Target{}.ID
+- Target{}.Type
+- UserId
+- UserKey
+- UserType
+- Version
+- Workload
+- action
+- additionalDetails
+- app
+- authentication_service
+- change_type
+- command
+- dataset_name
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_name
+- dvc
+- event_type
+- eventtype
+- extendedAuditEventCategory
+- host
+- index
+- linecount
+- object
+- object_attrs
+- object_category
+- punct
+- record_type
+- signature
+- source
+- sourcetype
+- splunk_server
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- user_agent
+- user_agent_change
+- user_id
+- user_type
+- vendor_account
+- vendor_product
example_log: '{"CreationTime": "2023-09-01T17:16:20", "Id": "c428c85c-4fa0-4e97-9033-6a76d9dee45d",
"Operation": "Update application.", "OrganizationId": "58aee3b9-7433-46a0-b54e-2429487992a0",
"RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@contoso.onmicrosoft.com",
diff --git a/data_sources/o365_update_authorization_policy_.yml b/data_sources/o365_update_authorization_policy_.yml
index 90825eca41..1c0d97242a 100644
--- a/data_sources/o365_update_authorization_policy_.yml
+++ b/data_sources/o365_update_authorization_policy_.yml
@@ -6,84 +6,84 @@ author: Patrick Bareiss, Splunk
description: Logs changes to authorization policies in Microsoft 365, including updates
to access controls, permissions, and security settings.
mitre_components:
- - Cloud Service Modification
- - Configuration Modification
- - User Account Metadata
- - Application Log Content
+- Cloud Service Modification
+- Configuration Modification
+- User Account Metadata
+- Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Update authorization policy.
supported_TA:
- - name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+- name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
- - _time
- - ActorContextId
- - Actor{}.ID
- - Actor{}.Type
- - AzureActiveDirectoryEventType
- - CreationTime
- - ExtendedProperties{}.Name
- - ExtendedProperties{}.Value
- - Id
- - InterSystemsId
- - IntraSystemId
- - ModifiedProperties{}.Name
- - ModifiedProperties{}.NewValue
- - ModifiedProperties{}.OldValue
- - ObjectId
- - Operation
- - OrganizationId
- - RecordType
- - ResultStatus
- - SupportTicketId
- - TargetContextId
- - Target{}.ID
- - Target{}.Type
- - UserId
- - UserKey
- - UserType
- - Version
- - Workload
- - additionalDetails
- - app
- - authentication_service
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_name
- - dvc
- - event_type
- - extendedAuditEventCategory
- - host
- - index
- - linecount
- - object
- - punct
- - record_type
- - signature
- - source
- - sourcetype
- - splunk_server
- - status
- - timeendpos
- - timestartpos
- - user
- - user_agent
- - user_agent_change
- - user_id
- - user_type
- - vendor_account
- - vendor_product
+- _time
+- ActorContextId
+- Actor{}.ID
+- Actor{}.Type
+- AzureActiveDirectoryEventType
+- CreationTime
+- ExtendedProperties{}.Name
+- ExtendedProperties{}.Value
+- Id
+- InterSystemsId
+- IntraSystemId
+- ModifiedProperties{}.Name
+- ModifiedProperties{}.NewValue
+- ModifiedProperties{}.OldValue
+- ObjectId
+- Operation
+- OrganizationId
+- RecordType
+- ResultStatus
+- SupportTicketId
+- TargetContextId
+- Target{}.ID
+- Target{}.Type
+- UserId
+- UserKey
+- UserType
+- Version
+- Workload
+- additionalDetails
+- app
+- authentication_service
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_name
+- dvc
+- event_type
+- extendedAuditEventCategory
+- host
+- index
+- linecount
+- object
+- punct
+- record_type
+- signature
+- source
+- sourcetype
+- splunk_server
+- status
+- timeendpos
+- timestartpos
+- user
+- user_agent
+- user_agent_change
+- user_id
+- user_type
+- vendor_account
+- vendor_product
example_log: '{"CreationTime": "2023-10-26T19:22:20", "Id": "83774e72-313f-4d1f-8609-7d0c7bb3b4ff",
"Operation": "Update authorization policy.", "OrganizationId": "a417c578-c7ee-480d-a225-d48057e74df5",
"RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com",
diff --git a/data_sources/o365_update_user_.yml b/data_sources/o365_update_user_.yml
index f733a674a4..c9d47f5456 100644
--- a/data_sources/o365_update_user_.yml
+++ b/data_sources/o365_update_user_.yml
@@ -6,91 +6,91 @@ author: Patrick Bareiss, Splunk
description: Logs updates to user account properties in Microsoft 365, including changes
to roles, permissions, and profile information.
mitre_components:
- - User Account Modification
- - User Account Metadata
- - Active Directory Object Modification
- - Application Log Content
+- User Account Modification
+- User Account Metadata
+- Active Directory Object Modification
+- Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: Update user.
supported_TA:
- - name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+- name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
- - _time
- - ActorContextId
- - Actor{}.ID
- - Actor{}.Type
- - AzureActiveDirectoryEventType
- - CreationTime
- - ExtendedProperties{}.Name
- - ExtendedProperties{}.Value
- - Id
- - InterSystemsId
- - IntraSystemId
- - ModifiedProperties{}.Name
- - ModifiedProperties{}.NewValue
- - ModifiedProperties{}.OldValue
- - ObjectId
- - Operation
- - OrganizationId
- - RecordType
- - ResultStatus
- - SupportTicketId
- - TargetContextId
- - Target{}.ID
- - Target{}.Type
- - UserId
- - UserKey
- - UserType
- - Version
- - Workload
- - action
- - additionalDetails
- - app
- - authentication_service
- - change_type
- - command
- - dataset_name
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_name
- - dvc
- - event_type
- - eventtype
- - extendedAuditEventCategory
- - host
- - index
- - linecount
- - object
- - object_attrs
- - object_category
- - punct
- - record_type
- - signature
- - source
- - sourcetype
- - splunk_server
- - src_user
- - status
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - user_id
- - user_type
- - vendor_account
- - vendor_product
+- _time
+- ActorContextId
+- Actor{}.ID
+- Actor{}.Type
+- AzureActiveDirectoryEventType
+- CreationTime
+- ExtendedProperties{}.Name
+- ExtendedProperties{}.Value
+- Id
+- InterSystemsId
+- IntraSystemId
+- ModifiedProperties{}.Name
+- ModifiedProperties{}.NewValue
+- ModifiedProperties{}.OldValue
+- ObjectId
+- Operation
+- OrganizationId
+- RecordType
+- ResultStatus
+- SupportTicketId
+- TargetContextId
+- Target{}.ID
+- Target{}.Type
+- UserId
+- UserKey
+- UserType
+- Version
+- Workload
+- action
+- additionalDetails
+- app
+- authentication_service
+- change_type
+- command
+- dataset_name
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_name
+- dvc
+- event_type
+- eventtype
+- extendedAuditEventCategory
+- host
+- index
+- linecount
+- object
+- object_attrs
+- object_category
+- punct
+- record_type
+- signature
+- source
+- sourcetype
+- splunk_server
+- src_user
+- status
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- user_id
+- user_type
+- vendor_account
+- vendor_product
example_log: '{"CreationTime": "2023-10-20T19:32:59", "Id": "d06df1c6-b3f2-4595-90b9-99b8f91811c3",
"Operation": "Update user.", "OrganizationId": "99825d50-9544-4061-8e46-68923805cbf2",
"RecordType": 8, "ResultStatus": "Success", "UserKey": "10032002CC029AE9@splunkresearch1.onmicrosoft.com",
diff --git a/data_sources/o365_userloggedin.yml b/data_sources/o365_userloggedin.yml
index f9169deaee..4e5fbdcea2 100644
--- a/data_sources/o365_userloggedin.yml
+++ b/data_sources/o365_userloggedin.yml
@@ -6,91 +6,91 @@ author: Patrick Bareiss, Splunk
description: Logs successful login events by users in Microsoft 365, including details
about the user account, IP address, and session metadata.
mitre_components:
- - User Account Authentication
- - Logon Session Creation
- - User Account Metadata
- - Logon Session Metadata
+- User Account Authentication
+- Logon Session Creation
+- User Account Metadata
+- Logon Session Metadata
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: UserLoggedIn
supported_TA:
- - name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+- name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
- - _time
- - ActorContextId
- - ActorIpAddress
- - Actor{}.ID
- - Actor{}.Type
- - ApplicationId
- - AzureActiveDirectoryEventType
- - BrowserType
- - ClientIP
- - CreationTime
- - DeviceProperties{}.Name
- - DeviceProperties{}.Value
- - ErrorNumber
- - ExtendedProperties{}.Name
- - ExtendedProperties{}.Value
- - Id
- - InterSystemsId
- - IntraSystemId
- - OS
- - ObjectId
- - Operation
- - OrganizationId
- - RecordType
- - RequestType
- - ResultStatus
- - ResultStatusDetail
- - SessionId
- - SupportTicketId
- - TargetContextId
- - Target{}.ID
- - Target{}.Type
- - UserAgent
- - UserId
- - UserKey
- - UserType
- - Version
- - Workload
- - app
- - authentication_service
- - command
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_name
- - dvc
- - event_type
- - host
- - index
- - linecount
- - object
- - punct
- - record_type
- - signature
- - source
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - status
- - timeendpos
- - timestartpos
- - user
- - user_agent
- - user_type
- - vendor_account
- - vendor_product
+- _time
+- ActorContextId
+- ActorIpAddress
+- Actor{}.ID
+- Actor{}.Type
+- ApplicationId
+- AzureActiveDirectoryEventType
+- BrowserType
+- ClientIP
+- CreationTime
+- DeviceProperties{}.Name
+- DeviceProperties{}.Value
+- ErrorNumber
+- ExtendedProperties{}.Name
+- ExtendedProperties{}.Value
+- Id
+- InterSystemsId
+- IntraSystemId
+- OS
+- ObjectId
+- Operation
+- OrganizationId
+- RecordType
+- RequestType
+- ResultStatus
+- ResultStatusDetail
+- SessionId
+- SupportTicketId
+- TargetContextId
+- Target{}.ID
+- Target{}.Type
+- UserAgent
+- UserId
+- UserKey
+- UserType
+- Version
+- Workload
+- app
+- authentication_service
+- command
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_name
+- dvc
+- event_type
+- host
+- index
+- linecount
+- object
+- punct
+- record_type
+- signature
+- source
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- status
+- timeendpos
+- timestartpos
+- user
+- user_agent
+- user_type
+- vendor_account
+- vendor_product
example_log: '{"CreationTime": "2023-12-04T20:42:05", "Id": "52d72a62-132b-487b-bb7f-c4c119f90700",
"Operation": "UserLoggedIn", "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"RecordType": 15, "ResultStatus": "Success", "UserKey": "2d2f9e2c-8350-4d98-852e-3f06daaf7185",
diff --git a/data_sources/o365_userloginfailed.yml b/data_sources/o365_userloginfailed.yml
index 8f3df80a3f..1a571c469a 100644
--- a/data_sources/o365_userloginfailed.yml
+++ b/data_sources/o365_userloginfailed.yml
@@ -6,100 +6,100 @@ author: Patrick Bareiss, Splunk
description: Logs failed login attempts by users in Microsoft 365, including details
about the user account, IP address, and reason for failure.
mitre_components:
- - User Account Authentication
- - Logon Session Metadata
- - User Account Metadata
- - Application Log Content
+- User Account Authentication
+- Logon Session Metadata
+- User Account Metadata
+- Application Log Content
source: o365
sourcetype: o365:management:activity
separator: Operation
separator_value: UserLoginFailed
supported_TA:
- - name: Splunk Add-on for Microsoft Office 365
- url: https://splunkbase.splunk.com/app/4055
- version: 4.7.0
+- name: Splunk Add-on for Microsoft Office 365
+ url: https://splunkbase.splunk.com/app/4055
+ version: 4.7.0
fields:
- - _time
- - ActorContextId
- - ActorIpAddress
- - Actor{}.ID
- - Actor{}.Type
- - ApplicationId
- - AzureActiveDirectoryEventType
- - BrowserType
- - ClientIP
- - CreationTime
- - DeviceProperties{}.Name
- - DeviceProperties{}.Value
- - ErrorNumber
- - ExtendedProperties{}.Name
- - ExtendedProperties{}.Value
- - Id
- - InterSystemsId
- - IntraSystemId
- - IsCompliantAndManaged
- - LogonError
- - OS
- - ObjectId
- - Operation
- - OrganizationId
- - RecordType
- - RequestType
- - ResultStatus
- - ResultStatusDetail
- - SupportTicketId
- - TargetContextId
- - Target{}.ID
- - Target{}.Type
- - UserAgent
- - UserAuthenticationMethod
- - UserId
- - UserKey
- - UserType
- - Version
- - Workload
- - action
- - app
- - authentication_method
- - authentication_service
- - command
- - dataset_name
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_name
- - dvc
- - event_type
- - eventtype
- - host
- - index
- - linecount
- - object
- - punct
- - reason
- - record_type
- - result
- - signature
- - source
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - status
- - tag
- - tag::action
- - tag::eventtype
- - user
- - user_agent
- - user_type
- - vendor_account
- - vendor_product
+- _time
+- ActorContextId
+- ActorIpAddress
+- Actor{}.ID
+- Actor{}.Type
+- ApplicationId
+- AzureActiveDirectoryEventType
+- BrowserType
+- ClientIP
+- CreationTime
+- DeviceProperties{}.Name
+- DeviceProperties{}.Value
+- ErrorNumber
+- ExtendedProperties{}.Name
+- ExtendedProperties{}.Value
+- Id
+- InterSystemsId
+- IntraSystemId
+- IsCompliantAndManaged
+- LogonError
+- OS
+- ObjectId
+- Operation
+- OrganizationId
+- RecordType
+- RequestType
+- ResultStatus
+- ResultStatusDetail
+- SupportTicketId
+- TargetContextId
+- Target{}.ID
+- Target{}.Type
+- UserAgent
+- UserAuthenticationMethod
+- UserId
+- UserKey
+- UserType
+- Version
+- Workload
+- action
+- app
+- authentication_method
+- authentication_service
+- command
+- dataset_name
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_name
+- dvc
+- event_type
+- eventtype
+- host
+- index
+- linecount
+- object
+- punct
+- reason
+- record_type
+- result
+- signature
+- source
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- status
+- tag
+- tag::action
+- tag::eventtype
+- user
+- user_agent
+- user_type
+- vendor_account
+- vendor_product
example_log: '{"CreationTime": "2023-10-10T17:08:65", "Id": "4593aac8-855f-4341-9d2a-4289146eb800",
"Operation": "UserLoginFailed", "OrganizationId": "d541aae6-6b73-4a7c-aaf0-a4de30c872bc",
"RecordType": 15, "ResultStatus": "Failed", "UserKey": "57e4bd36-9722-4a4a-9729-7203d8e00b72",
diff --git a/data_sources/okta.yml b/data_sources/okta.yml
index 4c4de15b28..3d83e462b9 100644
--- a/data_sources/okta.yml
+++ b/data_sources/okta.yml
@@ -6,14 +6,14 @@ author: Patrick Bareiss, Splunk
description: Logs authentication and administrative activities captured by Okta, including
user login attempts, session management, and configuration changes.
mitre_components:
- - User Account Authentication
- - Logon Session Creation
- - User Account Metadata
- - Configuration Modification
- - Application Log Content
+- User Account Authentication
+- Logon Session Creation
+- User Account Metadata
+- Configuration Modification
+- Application Log Content
source: Okta
sourcetype: OktaIM2:log
supported_TA:
- - name: Splunk Add-on for Okta Identity Cloud
- url: https://splunkbase.splunk.com/app/6553
- version: 3.0.0
+- name: Splunk Add-on for Okta Identity Cloud
+ url: https://splunkbase.splunk.com/app/6553
+ version: 3.0.0
diff --git a/data_sources/osquery.yml b/data_sources/osquery.yml
index b2b1828e0f..b14df40563 100644
--- a/data_sources/osquery.yml
+++ b/data_sources/osquery.yml
@@ -6,68 +6,68 @@ author: Patrick Bareiss, Splunk
description: Logs system queries performed using osquery, including details about
processes, file access, network activity, and system configurations.
mitre_components:
- - Process Metadata
- - File Access
- - Network Traffic Content
- - Host Status
- - Application Log Content
+- Process Metadata
+- File Access
+- Network Traffic Content
+- Host Status
+- Application Log Content
source: osquery
sourcetype: osquery:results
supported_TA: []
fields:
- - _time
- - calendarTime
- - columns.cdhash
- - columns.child_pid
- - columns.cmdline
- - columns.cmdline_count
- - columns.cwd
- - columns.egid
- - columns.env
- - columns.env_count
- - columns.euid
- - columns.event_type
- - columns.exit_code
- - columns.gid
- - columns.global_seq_num
- - columns.original_parent
- - columns.parent
- - columns.path
- - columns.pid
- - columns.platform_binary
- - columns.seq_num
- - columns.signing_id
- - columns.team_id
- - columns.time
- - columns.uid
- - columns.username
- - columns.version
- - counter
- - dest
- - epoch
- - eventtype
- - host
- - hostIdentifier
- - index
- - linecount
- - name
- - numerics
- - parent_process_id
- - process_current_directory
- - process_id
- - process_path
- - punct
- - source
- - sourcetype
- - splunk_server
- - src
- - subject
- - tag
- - tag::eventtype
- - timestamp
- - unixTime
- - user_id
- - vendor_product
+- _time
+- calendarTime
+- columns.cdhash
+- columns.child_pid
+- columns.cmdline
+- columns.cmdline_count
+- columns.cwd
+- columns.egid
+- columns.env
+- columns.env_count
+- columns.euid
+- columns.event_type
+- columns.exit_code
+- columns.gid
+- columns.global_seq_num
+- columns.original_parent
+- columns.parent
+- columns.path
+- columns.pid
+- columns.platform_binary
+- columns.seq_num
+- columns.signing_id
+- columns.team_id
+- columns.time
+- columns.uid
+- columns.username
+- columns.version
+- counter
+- dest
+- epoch
+- eventtype
+- host
+- hostIdentifier
+- index
+- linecount
+- name
+- numerics
+- parent_process_id
+- process_current_directory
+- process_id
+- process_path
+- punct
+- source
+- sourcetype
+- splunk_server
+- src
+- subject
+- tag
+- tag::eventtype
+- timestamp
+- unixTime
+- user_id
+- vendor_product
example_log: '{"name":"es_process_events","hostIdentifier":"HackBook.local","calendarTime":"Tue
Mar 29 13:03:51 2022 UTC","unixTime":1648559031,"epoch":0,"counter":82,"numerics":false,"columns":{"cdhash":"f63c5fbfcf1484b20aa4407a26e087fe3fe28146","child_pid":"","cmdline":"plutil
--help ","cmdline_count":"2","cwd":"/Users/patrick","egid":"20","env":"TERM_SESSION_ID=w0t1p0:93AA9D79-7028-49F1-A93D-4EAEFB7BA6E3
diff --git a/data_sources/palo_alto_network_threat.yml b/data_sources/palo_alto_network_threat.yml
index 48d799c14e..10e7c74e79 100644
--- a/data_sources/palo_alto_network_threat.yml
+++ b/data_sources/palo_alto_network_threat.yml
@@ -6,40 +6,39 @@ author: Patrick Bareiss, Splunk
description: Logs detected threats identified by Palo Alto Networks devices, including
details about malware, intrusion attempts, and malicious network activity.
mitre_components:
- - Malware Metadata
- - Network Traffic Content
- - Network Traffic Flow
- - Application Log Content
- - Host Status
+- Malware Metadata
+- Network Traffic Content
+- Network Traffic Flow
+- Application Log Content
+- Host Status
source: pan:threat
sourcetype: pan:threat
supported_TA:
- - name: Palo Alto Networks Add-on
- url: https://splunkbase.splunk.com/app/2757
- version: 8.1.3
+- name: Palo Alto Networks Add-on
+ url: https://splunkbase.splunk.com/app/2757
+ version: 8.1.3
fields:
- - _time
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - host
- - index
- - linecount
- - punct
- - source
- - sourcetype
- - splunk_server
- - timeendpos
- - timestartpos
+- _time
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- host
+- index
+- linecount
+- punct
+- source
+- sourcetype
+- splunk_server
+- timeendpos
+- timestartpos
example_log: May 10 11:08:39 sjc.example.com 1,2022/05/10 11:08:38,013201004583,THREAT,url,2305,2022/05/10
11:08:38,2.18.4.7,1.2.3.4,2.18.4.7,1.2.3.4,service-globalprotect,,,web-browsing,vsys1,UNTRUST,UNTRUST,ethernet1/20,loopback.1,Zero,2022/05/10
11:08:38,1535535,1,32880,443,32880,20077,0x1403000,tcp,allow,"sr.example.com/mgmt/tm/util/bash",(9999),allow-URL,informational,client-to-server,7081856864553612091,0xa000000000000000,United
States,United States,0,,0,,,1,"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.36
- (KHTML, like Gecko) Chrome/36.0.1944.0
- Safari/537.36",,,,,,,0,177,204,178,382,,sjc1-fw-01,,,,post,0,,0,,N/A,unknown,AppThreat-0-0,0x0,0,4294967295,,"
+ (KHTML, like Gecko) Chrome/36.0.1944.0 Safari/537.36",,,,,,,0,177,204,178,382,,sjc1-fw-01,,,,post,0,,0,,N/A,unknown,AppThreat-0-0,0x0,0,4294967295,,"
allow-URL,computer-and-internet-info,low-risk",5283cb95-6902-41db-96c6-ef807361eba5,0,
diff --git a/data_sources/palo_alto_network_traffic.yml b/data_sources/palo_alto_network_traffic.yml
index c4673e3fe7..09515ca80d 100644
--- a/data_sources/palo_alto_network_traffic.yml
+++ b/data_sources/palo_alto_network_traffic.yml
@@ -6,39 +6,37 @@ author: Patrick Bareiss, Splunk
description: Logs network traffic events captured by Palo Alto Networks devices, including
details about sessions, protocols, and source and destination IPs.
mitre_components:
- - Network Traffic Content
- - Network Traffic Flow
- - Network Connection Creation
- - Response Metadata
- - Application Log Content
+- Network Traffic Content
+- Network Traffic Flow
+- Network Connection Creation
+- Response Metadata
+- Application Log Content
source: screenconnect_palo_traffic
sourcetype: pan:traffic
supported_TA:
- - name: Palo Alto Networks Add-on
- url: https://splunkbase.splunk.com/app/2757
- version: 8.1.3
+- name: Palo Alto Networks Add-on
+ url: https://splunkbase.splunk.com/app/2757
+ version: 8.1.3
fields:
- - _time
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - host
- - index
- - linecount
- - punct
- - source
- - sourcetype
- - splunk_server
- - timeendpos
- - timestartpos
+- _time
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- host
+- index
+- linecount
+- punct
+- source
+- sourcetype
+- splunk_server
+- timeendpos
+- timestartpos
example_log: 577 <14>1 2024-02-22T12:33:50-05:00 PALO220.ATTACK_RANGE.LAN - - - -
- 1,2024/02/22 12:33:50,012801036556,TRAFFIC,end,2305,2024/02/22
- 12:33:50,192.168.1.205,147.28.146.44,201.17.96.104,147.28.146.44,No_Vuln_Filtering_OUT,,,screenconnect,vsys1,Trust,Untrust,ethernet1/2,ethernet1/1,splunk_range,2024/02/22
+ 1,2024/02/22 12:33:50,012801036556,TRAFFIC,end,2305,2024/02/22 12:33:50,192.168.1.205,147.28.146.44,201.17.96.104,147.28.146.44,No_Vuln_Filtering_OUT,,,screenconnect,vsys1,Trust,Untrust,ethernet1/2,ethernet1/1,splunk_range,2024/02/22
12:33:50,14740,1,50624,443,11024,443,0x40005e,tcp,allow,7419,6609,810,25,2024/02/22
- 12:32:29,65,any,0,376156893,0x0,192.168.0.0-192.168.255.255,United
- States,0,14,11,tcp-fin,0,0,0,0,,PALO220,from-policy,,,0,,0,,N/A,0,0,0,0,0862e58b-4a54-436b-b3ac-ea3eccf8403b,0,0,,,,,,,
+ 12:32:29,65,any,0,376156893,0x0,192.168.0.0-192.168.255.255,United States,0,14,11,tcp-fin,0,0,0,0,,PALO220,from-policy,,,0,,0,,N/A,0,0,0,0,0862e58b-4a54-436b-b3ac-ea3eccf8403b,0,0,,,,,,,
diff --git a/data_sources/pingid.yml b/data_sources/pingid.yml
index 5b7648219f..bde7518b61 100644
--- a/data_sources/pingid.yml
+++ b/data_sources/pingid.yml
@@ -6,41 +6,41 @@ author: Patrick Bareiss, Splunk
description: Logs authentication and multi-factor authentication (MFA) events managed
by PingID, including user logins, device enrollments, and MFA challenges.
mitre_components:
- - User Account Authentication
- - Logon Session Metadata
- - User Account Metadata
- - Application Log Content
- - Host Status
+- User Account Authentication
+- Logon Session Metadata
+- User Account Metadata
+- Application Log Content
+- Host Status
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
supported_TA: []
fields:
- - _time
- - actors{}.name
- - actors{}.type
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - extracted_source
- - host
- - id
- - index
- - linecount
- - punct
- - recorded
- - resources{}.ipaddress
- - resources{}.websession
- - result.message
- - result.status
- - source
- - sourcetype
- - splunk_server
- - timeendpos
- - timestartpos
+- _time
+- actors{}.name
+- actors{}.type
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- extracted_source
+- host
+- id
+- index
+- linecount
+- punct
+- recorded
+- resources{}.ipaddress
+- resources{}.websession
+- result.message
+- result.status
+- source
+- sourcetype
+- splunk_server
+- timeendpos
+- timestartpos
example_log: '{"source":"PINGID","id":"b2eb1fef-651b-11ee-b38b-0ac7a554ed19","recorded":"2023-10-05T14:10:53.538Z","actors":[{"type":"user","name":"victim_user"}],"resources":[{"ipaddress":"174.235.80.142","websession":"webs_ijkF-T_bAC_G3w2TfvdpAEQeC545KFlqVFOsolCXdjo"}],"result":{"status":"SUCCESS","message":"Device
Paired SMS \"Mobile 1\""}}'
diff --git a/data_sources/powershell_installed_iis_modules.yml b/data_sources/powershell_installed_iis_modules.yml
index 3e466057a5..ddb49cbdf7 100644
--- a/data_sources/powershell_installed_iis_modules.yml
+++ b/data_sources/powershell_installed_iis_modules.yml
@@ -6,22 +6,22 @@ author: Patrick Bareiss, Splunk
description: Logs the list of installed IIS modules retrieved using PowerShell, including
details about their names and statuses.
mitre_components:
- - Service Metadata
- - Configuration Modification
- - OS API Execution
- - Application Log Content
+- Service Metadata
+- Configuration Modification
+- OS API Execution
+- Application Log Content
source: powershell://AppCmdModules
sourcetype: Pwsh:InstalledIISModules
supported_TA: []
fields:
- - _time
- - Schema
- - host
- - index
- - linecount
- - punct
- - source
- - sourcetype
- - splunk_server
- - timestamp
+- _time
+- Schema
+- host
+- index
+- linecount
+- punct
+- source
+- sourcetype
+- splunk_server
+- timestamp
example_log: Schema="Microsoft.IIs.PowerShell.Framework.ConfigurationElementSchema"
diff --git a/data_sources/powershell_script_block_logging_4104.yml b/data_sources/powershell_script_block_logging_4104.yml
index 67794c1e47..99f3ace10f 100644
--- a/data_sources/powershell_script_block_logging_4104.yml
+++ b/data_sources/powershell_script_block_logging_4104.yml
@@ -6,92 +6,91 @@ author: Patrick Bareiss, Splunk
description: Logs detailed content of PowerShell script blocks as they are executed,
including the full command text and context for the execution.
mitre_components:
- - Script Execution
- - Command Execution
- - Process Metadata
- - OS API Execution
- - Application Log Content
+- Script Execution
+- Command Execution
+- Process Metadata
+- OS API Execution
+- Application Log Content
source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
sourcetype: xmlwineventlog
separator: EventID
separator_value: 4104
supported_TA:
- - name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+- name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
- - _time
- - ActivityID
- - Channel
- - Computer
- - EventCode
- - EventData_Xml
- - EventID
- - EventRecordID
- - Guid
- - Keywords
- - Level
- - MessageNumber
- - MessageTotal
- - Name
- - Opcode
- - Path
- - ProcessID
- - RecordNumber
- - ScriptBlockId
- - ScriptBlockText
- - SystemTime
- - System_Props_Xml
- - Task
- - ThreadID
- - UserID
- - Version
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dvc
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - punct
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user_id
- - vendor_product
+- _time
+- ActivityID
+- Channel
+- Computer
+- EventCode
+- EventData_Xml
+- EventID
+- EventRecordID
+- Guid
+- Keywords
+- Level
+- MessageNumber
+- MessageTotal
+- Name
+- Opcode
+- Path
+- ProcessID
+- RecordNumber
+- ScriptBlockId
+- ScriptBlockText
+- SystemTime
+- System_Props_Xml
+- Task
+- ThreadID
+- UserID
+- Version
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dvc
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- punct
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user_id
+- vendor_product
field_mappings:
- - data_model: cim
- data_set: Endpoint.Processes
- mapping:
- Computer: Processes.dest
- Path: Processes.process_path
- ScriptBlockId: Processes.process_id
- ScriptBlockText: Processes.process
- UserID: Processes.user_id
- - data_model: ocsf
- mapping:
- Computer: device.hostname
- Path: process.file.path
- ScriptBlockId: process.uid
- ScriptBlockText: process.cmd_line
- UserID: actor.user.uid
+- data_model: cim
+ data_set: Endpoint.Processes
+ mapping:
+ Computer: Processes.dest
+ Path: Processes.process_path
+ ScriptBlockId: Processes.process_id
+ ScriptBlockText: Processes.process
+ UserID: Processes.user_id
+- data_model: ocsf
+ mapping:
+ Computer: device.hostname
+ Path: process.file.path
+ ScriptBlockId: process.uid
+ ScriptBlockText: process.cmd_line
+ UserID: actor.user.uid
example_log: 4104152150x04104152150x0112748Microsoft-Windows-PowerShell/Operationalwin-dc-mhaag-attack-range-270.attackrange.local154100x8000000000000000154100x80000000000000004522Microsoft-Windows-Sysmon/Operationalwin-dc-6764986.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-6764986.attackrange.local-2020-10-08
11:03:46.615{96128EA2-F212-5F7E-E400-000000007F01}2296C:\Windows\System32\cmd.exeMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{96128EA2-F211-5F7E-DF00-000000007F01}4624C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"powershell.exe" -noninteractive -encodedcommand
- WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADAAMwAuADAAMAAyACIAIAAtAEMAbwBuAGYAaQByAG0AOgAkAGYAYQBsAHMAZQAgAC0AVABpAG0AZQBvAHUAdABTAGUAYwBvAG4AZABzACAAMwAwADAAIAAtAEUAeABlAGMAdQB0AGkAbwBuAEwAbwBnAFAAYQB0AGgAIABDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAYQB0AGMAXwBlAHgAZQBjAHUAdABpAG8AbgAuAGMAcwB2AA==
+ Name='ParentCommandLine'>"powershell.exe" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADAAMwAuADAAMAAyACIAIAAtAEMAbwBuAGYAaQByAG0AOgAkAGYAYQBsAHMAZQAgAC0AVABpAG0AZQBvAHUAdABTAGUAYwBvAG4AZABzACAAMwAwADAAIAAtAEUAeABlAGMAdQB0AGkAbwBuAEwAbwBnAFAAYQB0AGgAIABDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAYQB0AGMAXwBlAHgAZQBjAHUAdABpAG8AbgAuAGMAcwB2AA==
diff --git a/data_sources/sysmon_eventid_10.yml b/data_sources/sysmon_eventid_10.yml
index 6197a6a241..844e023f1a 100644
--- a/data_sources/sysmon_eventid_10.yml
+++ b/data_sources/sysmon_eventid_10.yml
@@ -6,104 +6,102 @@ author: Patrick Bareiss, Splunk
description: Logs events where one process accesses another process, typically for
memory reads or injections, including details about the source and target processes.
mitre_components:
- - Process Access
- - Process Metadata
- - Application Log Content
- - OS API Execution
+- Process Access
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
separator_value: 10
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- - name: Splunk Add-on for Sysmon
- url: https://splunkbase.splunk.com/app/5709
- version: 4.0.2
+- name: Splunk Add-on for Sysmon
+ url: https://splunkbase.splunk.com/app/5709
+ version: 4.0.2
fields:
- - _time
- - CallTrace
- - Channel
- - Computer
- - EventChannel
- - EventCode
- - EventData_Xml
- - EventDescription
- - EventID
- - EventRecordID
- - GrantedAccess
- - Guid
- - Keywords
- - Level
- - Name
- - Opcode
- - ProcessID
- - RecordID
- - RecordNumber
- - RuleName
- - SecurityID
- - SourceImage
- - SourceProcessGUID
- - SourceProcessId
- - SourceThreadId
- - SystemTime
- - System_Props_Xml
- - TargetImage
- - TargetProcessGUID
- - TargetProcessId
- - Task
- - ThreadID
- - TimeCreated
- - UserID
- - UtcTime
- - Version
- - action
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - dvc_nt_host
- - event_id
- - eventtype
- - granted_access
- - host
- - id
- - index
- - linecount
- - os
- - parent_process_exec
- - parent_process_guid
- - parent_process_id
- - parent_process_name
- - parent_process_path
- - process_exec
- - process_guid
- - process_id
- - process_name
- - process_path
- - punct
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user_id
- - vendor_product
+- _time
+- CallTrace
+- Channel
+- Computer
+- EventChannel
+- EventCode
+- EventData_Xml
+- EventDescription
+- EventID
+- EventRecordID
+- GrantedAccess
+- Guid
+- Keywords
+- Level
+- Name
+- Opcode
+- ProcessID
+- RecordID
+- RecordNumber
+- RuleName
+- SecurityID
+- SourceImage
+- SourceProcessGUID
+- SourceProcessId
+- SourceThreadId
+- SystemTime
+- System_Props_Xml
+- TargetImage
+- TargetProcessGUID
+- TargetProcessId
+- Task
+- ThreadID
+- TimeCreated
+- UserID
+- UtcTime
+- Version
+- action
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- dvc_nt_host
+- event_id
+- eventtype
+- granted_access
+- host
+- id
+- index
+- linecount
+- os
+- parent_process_exec
+- parent_process_guid
+- parent_process_id
+- parent_process_name
+- parent_process_path
+- process_exec
+- process_guid
+- process_id
+- process_name
+- process_path
+- punct
+- signature
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user_id
+- vendor_product
example_log: 10341000x800000000000000010341000x8000000000000000150624412Microsoft-Windows-Sysmon/Operationalwin-dc-128.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-128.attackrange.local-2022-02-01
21:01:44.670{3BF36828-9F6D-61F9-390A-02000000CF01}1272956C:\Tools\Rubeus.exe11241100x800000000000000011241100x80000000000000007712490Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-84.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-84.attackrange.localDownloads2023-02-08 13:01:11.053{0F9A6540-A70E-63E2-3091-00000000BD02}9332C:\Users\Administrator\Downloads\mimikatz_trunk\x64\mimikatz.exe9332C:\Users\Administrator\Downloads\mimikatz_trunk\x64\mimikatz.exeC:\Users\Administrator\Downloads\mimikatz_trunk\x64\CURRENT_USER_My_4_atomic@art2.local.pfx2023-02-08 13:01:11.053
diff --git a/data_sources/sysmon_eventid_12.yml b/data_sources/sysmon_eventid_12.yml
index 57e13fb712..b1fe5f0b54 100644
--- a/data_sources/sysmon_eventid_12.yml
+++ b/data_sources/sysmon_eventid_12.yml
@@ -6,102 +6,99 @@ author: Patrick Bareiss, Splunk
description: Logs the creation of a new registry key, including details about the
key name, registry path, and associated process metadata.
mitre_components:
- - Windows Registry Key Creation
- - Process Metadata
- - Application Log Content
- - OS API Execution
+- Windows Registry Key Creation
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
separator_value: 12
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- - name: Splunk Add-on for Sysmon
- url: https://splunkbase.splunk.com/app/5709
- version: 4.0.2
+- name: Splunk Add-on for Sysmon
+ url: https://splunkbase.splunk.com/app/5709
+ version: 4.0.2
fields:
- - _time
- - Channel
- - Computer
- - EventChannel
- - EventCode
- - EventData_Xml
- - EventDescription
- - EventID
- - EventRecordID
- - EventType
- - Guid
- - Image
- - Keywords
- - Level
- - Name
- - Opcode
- - ProcessGuid
- - ProcessID
- - ProcessId
- - RecordID
- - RecordNumber
- - RuleName
- - SecurityID
- - SystemTime
- - System_Props_Xml
- - TargetObject
- - Task
- - ThreadID
- - TimeCreated
- - UserID
- - UtcTime
- - Version
- - action
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - object_category
- - object_path
- - process_exec
- - process_guid
- - process_id
- - process_name
- - process_path
- - punct
- - registry_hive
- - registry_key_name
- - registry_path
- - severity_id
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - status
- - tag
- - tag::eventtype
- - tag::object_category
- - timeendpos
- - timestartpos
- - user_id
- - vendor_product
+- _time
+- Channel
+- Computer
+- EventChannel
+- EventCode
+- EventData_Xml
+- EventDescription
+- EventID
+- EventRecordID
+- EventType
+- Guid
+- Image
+- Keywords
+- Level
+- Name
+- Opcode
+- ProcessGuid
+- ProcessID
+- ProcessId
+- RecordID
+- RecordNumber
+- RuleName
+- SecurityID
+- SystemTime
+- System_Props_Xml
+- TargetObject
+- Task
+- ThreadID
+- TimeCreated
+- UserID
+- UtcTime
+- Version
+- action
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- object_category
+- object_path
+- process_exec
+- process_guid
+- process_id
+- process_name
+- process_path
+- punct
+- registry_hive
+- registry_key_name
+- registry_path
+- severity_id
+- signature
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- status
+- tag
+- tag::eventtype
+- tag::object_category
+- timeendpos
+- timestartpos
+- user_id
+- vendor_product
example_log: 12241200x800000000000000012241200x80000000000000001055579Microsoft-Windows-Sysmon/Operationalwin-dc-890.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-890.attackrange.local-DeleteKey2021-07-12 08:10:32.592{466BC892-F8F2-60EB-107E-00000000CF01}10188C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10188C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-2333072374-3391925831-3197092227-1112_Classes\exefile\shell\runas\command
diff --git a/data_sources/sysmon_eventid_13.yml b/data_sources/sysmon_eventid_13.yml
index d533ac7a5c..e586cf23e2 100644
--- a/data_sources/sysmon_eventid_13.yml
+++ b/data_sources/sysmon_eventid_13.yml
@@ -6,116 +6,114 @@ author: Patrick Bareiss, Splunk
description: Logs changes to a registry key, including details about the modified
key, value, and associated process.
mitre_components:
- - Windows Registry Key Modification
- - Process Metadata
- - Application Log Content
- - OS API Execution
+- Windows Registry Key Modification
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
separator_value: 13
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- - name: Splunk Add-on for Sysmon
- url: https://splunkbase.splunk.com/app/5709
- version: 4.0.2
+- name: Splunk Add-on for Sysmon
+ url: https://splunkbase.splunk.com/app/5709
+ version: 4.0.2
fields:
- - _time
- - Channel
- - Computer
- - Details
- - EventChannel
- - EventCode
- - EventData_Xml
- - EventDescription
- - EventID
- - EventRecordID
- - EventType
- - Guid
- - Image
- - Keywords
- - Level
- - Name
- - Opcode
- - ProcessGuid
- - ProcessID
- - ProcessId
- - RecordID
- - RecordNumber
- - RegistryValueData
- - RegistryValueType
- - RuleName
- - SecurityID
- - SystemTime
- - System_Props_Xml
- - TargetObject
- - Task
- - ThreadID
- - TimeCreated
- - UserID
- - UtcTime
- - Version
- - action
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - object_category
- - object_path
- - process_exec
- - process_guid
- - process_id
- - process_name
- - process_path
- - punct
- - registry_hive
- - registry_key_name
- - registry_path
- - registry_value_data
- - registry_value_name
- - registry_value_type
- - severity_id
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - status
- - tag
- - tag::eventtype
- - tag::object_category
- - timeendpos
- - timestartpos
- - user_id
- - vendor_product
+- _time
+- Channel
+- Computer
+- Details
+- EventChannel
+- EventCode
+- EventData_Xml
+- EventDescription
+- EventID
+- EventRecordID
+- EventType
+- Guid
+- Image
+- Keywords
+- Level
+- Name
+- Opcode
+- ProcessGuid
+- ProcessID
+- ProcessId
+- RecordID
+- RecordNumber
+- RegistryValueData
+- RegistryValueType
+- RuleName
+- SecurityID
+- SystemTime
+- System_Props_Xml
+- TargetObject
+- Task
+- ThreadID
+- TimeCreated
+- UserID
+- UtcTime
+- Version
+- action
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- object_category
+- object_path
+- process_exec
+- process_guid
+- process_id
+- process_name
+- process_path
+- punct
+- registry_hive
+- registry_key_name
+- registry_path
+- registry_value_data
+- registry_value_name
+- registry_value_type
+- severity_id
+- signature
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- status
+- tag
+- tag::eventtype
+- tag::object_category
+- timeendpos
+- timestartpos
+- user_id
+- vendor_product
field_mappings:
- - data_model: cim
- data_set: Endpoint.Registry
- mapping:
- Computer: Registry.dest
- ProcessGuid: Registry.process_guid
- ProcessId: Registry.process_id
- TargetObject: Registry.registry_path
- Details: Registry.registry_value_data
+- data_model: cim
+ data_set: Endpoint.Registry
+ mapping:
+ Computer: Registry.dest
+ ProcessGuid: Registry.process_guid
+ ProcessId: Registry.process_id
+ TargetObject: Registry.registry_path
+ Details: Registry.registry_value_data
example_log: 13241300x800000000000000013241300x8000000000000000810987Microsoft-Windows-Sysmon/Operationalwin-host-623.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-host-623.attackrange.local-SetValue2021-07-12 08:11:04.547{0C1E0330-048F-60E8-0B00-00000000D001}628C:\Windows\system32\lsass.exe15241500x800000000000000015241500x8000000000000000667860Microsoft-Windows-Sysmon/Operationalproject-mumbai-hostMicrosoft-Windows-Sysmon/Operationalproject-mumbai-host-2021-04-28
20:11:34.709{ED2ECF8A-C154-6089-F967-00000000BB01}7000C:\Users\DefaultAccount\AppData\Roaming\Telegram
Desktop\Telegram.exeC:\Users\DefaultAccount\Downloads\Telegram
Desktop\Good(NLA).txt:Zone.Identifier2021-04-28
- 20:11:33.238MD5=C785C55D5FA3443A11B8417209C4B524,SHA256=D07777E0DC36EBECCE3FA9644F0F44DC4A0B7EDE0CBC1F5D33E8D6CB07AF5B5C,IMPHASH=00000000000000000000000000000000MD5=C785C55D5FA3443A11B8417209C4B524,SHA256=D07777E0DC36EBECCE3FA9644F0F44DC4A0B7EDE0CBC1F5D33E8D6CB07AF5B5C,IMPHASH=00000000000000000000000000000000[ZoneTransfer] ZoneId=3
diff --git a/data_sources/sysmon_eventid_17.yml b/data_sources/sysmon_eventid_17.yml
index 17f9cba91f..b871828540 100644
--- a/data_sources/sysmon_eventid_17.yml
+++ b/data_sources/sysmon_eventid_17.yml
@@ -5,92 +5,90 @@ date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Sysmon EventID 17 logs details about the detection of a named pipe.
mitre_components:
- - Named Pipe Metadata
+- Named Pipe Metadata
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
separator_value: 17
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- - name: Splunk Add-on for Sysmon
- url: https://splunkbase.splunk.com/app/5709
- version: 4.0.2
+- name: Splunk Add-on for Sysmon
+ url: https://splunkbase.splunk.com/app/5709
+ version: 4.0.2
fields:
- - _time
- - Channel
- - Computer
- - EventChannel
- - EventCode
- - EventData_Xml
- - EventDescription
- - EventID
- - EventRecordID
- - EventType
- - Guid
- - Image
- - Keywords
- - Level
- - Name
- - Opcode
- - PipeName
- - ProcessGuid
- - ProcessID
- - ProcessId
- - RecordID
- - RecordNumber
- - RuleName
- - SecurityID
- - SystemTime
- - System_Props_Xml
- - Task
- - ThreadID
- - TimeCreated
- - UserID
- - UtcTime
- - Version
- - action
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - os
- - pipe_name
- - process_exec
- - process_guid
- - process_id
- - process_name
- - process_path
- - punct
- - severity_id
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user_id
- - vendor_product
+- _time
+- Channel
+- Computer
+- EventChannel
+- EventCode
+- EventData_Xml
+- EventDescription
+- EventID
+- EventRecordID
+- EventType
+- Guid
+- Image
+- Keywords
+- Level
+- Name
+- Opcode
+- PipeName
+- ProcessGuid
+- ProcessID
+- ProcessId
+- RecordID
+- RecordNumber
+- RuleName
+- SecurityID
+- SystemTime
+- System_Props_Xml
+- Task
+- ThreadID
+- TimeCreated
+- UserID
+- UtcTime
+- Version
+- action
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- os
+- pipe_name
+- process_exec
+- process_guid
+- process_id
+- process_name
+- process_path
+- punct
+- severity_id
+- signature
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user_id
+- vendor_product
example_log: 17141700x800000000000000017141700x8000000000000000162168Microsoft-Windows-Sysmon/Operationalwin-dc-982.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-982.attackrange.local-CreatePipe2021-04-19 21:00:18.288{761B69BB-EF62-607D-B211-00000000BA01}6960\MSSE-1516-server18141800x800000000000000018141800x8000000000000000162173Microsoft-Windows-Sysmon/Operationalwin-dc-982.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-982.attackrange.local-ConnectPipe2021-04-19 21:00:19.312{761B69BB-EF62-607D-B211-00000000BA01}6960\MSSE-1516-server20342000x800000000000000020342000x80000000000000006249Microsoft-Windows-Sysmon/Operationalwin-dc-935.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-935.attackrange.local-WmiConsumerEvent2020-12-08 13:54:48.514DeletedATTACKRANGE\Administrator "AtomicRedTeam-WMIPersistence-Example"21342100x800000000000000021342100x8000000000000000151644Microsoft-Windows-Sysmon/Operationalwin-host-14.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-host-14.attackrange.local-WmiBindingEvent2021-06-16 21:46:50.222ModifiedWIN-HOST-14\Administrator "CommandLineEventConsumer.Name=\"Evil
diff --git a/data_sources/sysmon_eventid_22.yml b/data_sources/sysmon_eventid_22.yml
index a40a8dc863..c8c1f78cdd 100644
--- a/data_sources/sysmon_eventid_22.yml
+++ b/data_sources/sysmon_eventid_22.yml
@@ -6,94 +6,92 @@ author: Patrick Bareiss, Splunk
description: Logs DNS query events, including details about the queried domain, source
IP, query type, and response data.
mitre_components:
- - Passive DNS
- - Active DNS
- - Network Traffic Content
- - Network Traffic Flow
- - Application Log Content
+- Passive DNS
+- Active DNS
+- Network Traffic Content
+- Network Traffic Flow
+- Application Log Content
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
separator_value: 22
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- - name: Splunk Add-on for Sysmon
- url: https://splunkbase.splunk.com/app/5709
- version: 4.0.2
+- name: Splunk Add-on for Sysmon
+ url: https://splunkbase.splunk.com/app/5709
+ version: 4.0.2
fields:
- - _time
- - Channel
- - Computer
- - EventChannel
- - EventCode
- - EventData_Xml
- - EventDescription
- - EventID
- - EventRecordID
- - Guid
- - Image
- - Keywords
- - Level
- - Name
- - Opcode
- - ProcessGuid
- - ProcessID
- - ProcessId
- - QueryName
- - QueryResults
- - QueryStatus
- - RecordID
- - RecordNumber
- - RuleName
- - SecurityID
- - SystemTime
- - System_Props_Xml
- - Task
- - ThreadID
- - TimeCreated
- - UserID
- - UtcTime
- - Version
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - process_exec
- - process_guid
- - process_name
- - punct
- - query
- - query_count
- - reply_code_id
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - src
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user_id
- - vendor_product
+- _time
+- Channel
+- Computer
+- EventChannel
+- EventCode
+- EventData_Xml
+- EventDescription
+- EventID
+- EventRecordID
+- Guid
+- Image
+- Keywords
+- Level
+- Name
+- Opcode
+- ProcessGuid
+- ProcessID
+- ProcessId
+- QueryName
+- QueryResults
+- QueryStatus
+- RecordID
+- RecordNumber
+- RuleName
+- SecurityID
+- SystemTime
+- System_Props_Xml
+- Task
+- ThreadID
+- TimeCreated
+- UserID
+- UtcTime
+- Version
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- process_exec
+- process_guid
+- process_name
+- punct
+- query
+- query_count
+- reply_code_id
+- signature
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- src
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user_id
+- vendor_product
example_log: 22542200x800000000000000022542200x8000000000000000113892Microsoft-Windows-Sysmon/Operationalwin-dc-299.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-299.attackrange.local-2021-03-24
12:25:12.840{3CFDEE80-2F7D-605B-F50A-00000000AE01}717250.220.65.3.spam.dnsbl.sorbs.net23542300x800000000000000023542300x8000000000000000281771Microsoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-865.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-865.attackrange.local-2023-02-01
10:57:09.814{F522A29C-446D-63DA-9F01-00000000BB02}2428ATTACKRANGE\Administrator354300x8000000000000000354300x8000000000000000156837Microsoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-403.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-403.attackrange.local-2022-09-15
12:56:19.679{6820D070-1F1B-6323-E113-000000007402}5728C:\Temp\agent_tesla-deob.exe534500x8000000000000000534500x800000000000000039965Microsoft-Windows-Sysmon/Operationalwin-dc-654.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-654.attackrange.local-2021-03-16
14:01:44.004{26337912-BA32-6050-3506-00000000AE01}8672C:\Users\Public\steam.exe
diff --git a/data_sources/sysmon_eventid_6.yml b/data_sources/sysmon_eventid_6.yml
index d019cb51cf..c9d0d5d247 100644
--- a/data_sources/sysmon_eventid_6.yml
+++ b/data_sources/sysmon_eventid_6.yml
@@ -6,97 +6,94 @@ author: Patrick Bareiss, Splunk
description: Logs the loading of a driver into the kernel or user mode, including
details about the driver name, file path, and associated process metadata.
mitre_components:
- - Driver Load
- - Process Metadata
- - Application Log Content
- - OS API Execution
+- Driver Load
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
separator_value: 6
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- - name: Splunk Add-on for Sysmon
- url: https://splunkbase.splunk.com/app/5709
- version: 4.0.2
+- name: Splunk Add-on for Sysmon
+ url: https://splunkbase.splunk.com/app/5709
+ version: 4.0.2
fields:
- - _time
- - Channel
- - Computer
- - EventChannel
- - EventCode
- - EventData_Xml
- - EventDescription
- - EventID
- - EventRecordID
- - Guid
- - Hashes
- - ImageLoaded
- - Keywords
- - Level
- - MD5
- - Name
- - Opcode
- - ProcessID
- - RecordID
- - RecordNumber
- - RuleName
- - SHA256
- - SecurityID
- - Signature
- - SignatureStatus
- - Signed
- - SystemTime
- - System_Props_Xml
- - Task
- - ThreadID
- - TimeCreated
- - UserID
- - UtcTime
- - Version
- - action
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - os
- - process_hash
- - process_path
- - punct
- - service_signature_exists
- - service_signature_verified
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user_id
- - vendor_product
+- _time
+- Channel
+- Computer
+- EventChannel
+- EventCode
+- EventData_Xml
+- EventDescription
+- EventID
+- EventRecordID
+- Guid
+- Hashes
+- ImageLoaded
+- Keywords
+- Level
+- MD5
+- Name
+- Opcode
+- ProcessID
+- RecordID
+- RecordNumber
+- RuleName
+- SHA256
+- SecurityID
+- Signature
+- SignatureStatus
+- Signed
+- SystemTime
+- System_Props_Xml
+- Task
+- ThreadID
+- TimeCreated
+- UserID
+- UtcTime
+- Version
+- action
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- os
+- process_hash
+- process_path
+- punct
+- service_signature_exists
+- service_signature_verified
+- signature
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user_id
+- vendor_product
example_log: 644600x8000000000000000644600x800000000000000015708989Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-702.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-702.attackrange.local-2022-04-04
- 17:37:04.640C:\Program
- Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\npf.sysC:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\npf.sysMD5=DE7FCC77F4A503AF4CA6A47D49B3713D,SHA256=4BFAA99393F635CD05D91A64DE73EDB5639412C129E049F0FE34F88517A10FC6trueRiverbed Technology, Inc.Valid
diff --git a/data_sources/sysmon_eventid_7.yml b/data_sources/sysmon_eventid_7.yml
index 23a3dcf3a1..8c5dcd335e 100644
--- a/data_sources/sysmon_eventid_7.yml
+++ b/data_sources/sysmon_eventid_7.yml
@@ -6,120 +6,117 @@ author: Patrick Bareiss, Splunk
description: Logs the loading of an image (module) into a process, including details
about the image name, file path, and hash information.
mitre_components:
- - Module Load
- - Process Metadata
- - File Metadata
- - Application Log Content
- - OS API Execution
+- Module Load
+- Process Metadata
+- File Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
separator_value: 7
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- - name: Splunk Add-on for Sysmon
- url: https://splunkbase.splunk.com/app/5709
- version: 4.0.2
+- name: Splunk Add-on for Sysmon
+ url: https://splunkbase.splunk.com/app/5709
+ version: 4.0.2
fields:
- - _time
- - Channel
- - Company
- - Computer
- - Description
- - EventChannel
- - EventCode
- - EventData_Xml
- - EventDescription
- - EventID
- - EventRecordID
- - FileVersion
- - Guid
- - Hashes
- - IMPHASH
- - Image
- - ImageLoaded
- - Keywords
- - Level
- - MD5
- - Name
- - Opcode
- - OriginalFileName
- - ProcessGuid
- - ProcessID
- - ProcessId
- - Product
- - RecordID
- - RecordNumber
- - RuleName
- - SHA256
- - SecurityID
- - Signature
- - SignatureStatus
- - Signed
- - SystemTime
- - System_Props_Xml
- - Task
- - ThreadID
- - TimeCreated
- - User
- - UserID
- - UtcTime
- - Version
- - action
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - os
- - parent_process_exec
- - parent_process_guid
- - parent_process_id
- - parent_process_name
- - parent_process_path
- - process_exec
- - process_hash
- - process_name
- - process_path
- - punct
- - service_dll_signature_exists
- - service_dll_signature_verified
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - tag
- - tag::action
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - user_id
- - vendor_product
+- _time
+- Channel
+- Company
+- Computer
+- Description
+- EventChannel
+- EventCode
+- EventData_Xml
+- EventDescription
+- EventID
+- EventRecordID
+- FileVersion
+- Guid
+- Hashes
+- IMPHASH
+- Image
+- ImageLoaded
+- Keywords
+- Level
+- MD5
+- Name
+- Opcode
+- OriginalFileName
+- ProcessGuid
+- ProcessID
+- ProcessId
+- Product
+- RecordID
+- RecordNumber
+- RuleName
+- SHA256
+- SecurityID
+- Signature
+- SignatureStatus
+- Signed
+- SystemTime
+- System_Props_Xml
+- Task
+- ThreadID
+- TimeCreated
+- User
+- UserID
+- UtcTime
+- Version
+- action
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- os
+- parent_process_exec
+- parent_process_guid
+- parent_process_id
+- parent_process_name
+- parent_process_path
+- process_exec
+- process_hash
+- process_name
+- process_path
+- punct
+- service_dll_signature_exists
+- service_dll_signature_verified
+- signature
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- tag
+- tag::action
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- user_id
+- vendor_product
example_log: 734700x8000000000000000734700x800000000000000045273Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.localMicrosoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-2023-09-12
08:06:31.433{8814F3F5-1C07-6500-9600-000000000E03}4440C:\Users\Administrator\AppData\Local\Temp\server.exeC:\Users\Administrator\AppData\Local\Temp\server.exe-----MD5=696CBE2CB6F7FAC5ED6262BCA51238BB,SHA256=43005D86607DC94C7D378AA1B8844947BAA03860652F2F2340266061AF12E524,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744--MD5=696CBE2CB6F7FAC5ED6262BCA51238BB,SHA256=43005D86607DC94C7D378AA1B8844947BAA03860652F2F2340266061AF12E524,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744false-UnavailableATTACKRANGE\Administrator
diff --git a/data_sources/sysmon_eventid_8.yml b/data_sources/sysmon_eventid_8.yml
index 086d972abf..bb8b3a983b 100644
--- a/data_sources/sysmon_eventid_8.yml
+++ b/data_sources/sysmon_eventid_8.yml
@@ -6,106 +6,104 @@ author: Patrick Bareiss, Splunk
description: Logs the creation of a new thread in a process, including details about
the thread ID, start address, and source process.
mitre_components:
- - Process Modification
- - Process Metadata
- - Application Log Content
- - OS API Execution
+- Process Modification
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
separator_value: 8
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- - name: Splunk Add-on for Sysmon
- url: https://splunkbase.splunk.com/app/5709
- version: 4.0.2
+- name: Splunk Add-on for Sysmon
+ url: https://splunkbase.splunk.com/app/5709
+ version: 4.0.2
fields:
- - _time
- - Channel
- - Computer
- - EventChannel
- - EventCode
- - EventData_Xml
- - EventDescription
- - EventID
- - EventRecordID
- - Guid
- - Keywords
- - Level
- - Name
- - NewThreadId
- - Opcode
- - ProcessID
- - RecordID
- - RecordNumber
- - RuleName
- - SecurityID
- - SourceImage
- - SourceProcessGuid
- - SourceProcessId
- - StartAddress
- - StartFunction
- - StartModule
- - SystemTime
- - System_Props_Xml
- - TargetImage
- - TargetProcessGuid
- - TargetProcessId
- - Task
- - ThreadID
- - TimeCreated
- - UserID
- - UtcTime
- - Version
- - action
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - os
- - parent_process_exec
- - parent_process_guid
- - parent_process_id
- - parent_process_name
- - parent_process_path
- - process_exec
- - process_guid
- - process_id
- - process_name
- - process_path
- - punct
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - src_address
- - src_function
- - src_module
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user_id
- - vendor_product
+- _time
+- Channel
+- Computer
+- EventChannel
+- EventCode
+- EventData_Xml
+- EventDescription
+- EventID
+- EventRecordID
+- Guid
+- Keywords
+- Level
+- Name
+- NewThreadId
+- Opcode
+- ProcessID
+- RecordID
+- RecordNumber
+- RuleName
+- SecurityID
+- SourceImage
+- SourceProcessGuid
+- SourceProcessId
+- StartAddress
+- StartFunction
+- StartModule
+- SystemTime
+- System_Props_Xml
+- TargetImage
+- TargetProcessGuid
+- TargetProcessId
+- Task
+- ThreadID
+- TimeCreated
+- UserID
+- UtcTime
+- Version
+- action
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- os
+- parent_process_exec
+- parent_process_guid
+- parent_process_id
+- parent_process_name
+- parent_process_path
+- process_exec
+- process_guid
+- process_id
+- process_name
+- process_path
+- punct
+- signature
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- src_address
+- src_function
+- src_module
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user_id
+- vendor_product
example_log: 824800x8000000000000000824800x8000000000000000362233Microsoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-487.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-487.attackrange.local-2022-10-27
13:59:12.427{3381F800-8EB0-635A-1306-000000008A02}4864C:\Windows\SysWOW64\wermgr.exe924900x8000000000000000924900x8000000000000000190607Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-478.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-478.attackrange.local-2022-02-25
12:25:33.359{414E8EDF-CABB-6218-F103-000000003702}6068C:\Temp\c.exe\Device\HarddiskVolume1
diff --git a/data_sources/sysmon_for_linux_eventid_1.yml b/data_sources/sysmon_for_linux_eventid_1.yml
index 5850fd83d6..e8c72edc4e 100644
--- a/data_sources/sysmon_for_linux_eventid_1.yml
+++ b/data_sources/sysmon_for_linux_eventid_1.yml
@@ -6,113 +6,111 @@ author: Patrick Bareiss, Splunk
description: Logs process creation events on Linux systems, including details about
the process name, process ID, command line arguments, and parent process ID.
mitre_components:
- - Process Creation
- - Command Execution
- - Process Metadata
- - OS API Execution
- - Application Log Content
+- Process Creation
+- Command Execution
+- Process Metadata
+- OS API Execution
+- Application Log Content
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon:linux
separator: EventID
separator_value: 1
supported_TA:
- - name: Splunk Add-on for Sysmon for Linux
- url: https://splunkbase.splunk.com/app/6652
- version: 1.0.0
+- name: Splunk Add-on for Sysmon for Linux
+ url: https://splunkbase.splunk.com/app/6652
+ version: 1.0.0
fields:
- - _time
- - Channel
- - CommandLine
- - Company
- - Computer
- - CurrentDirectory
- - Description
- - EventChannel
- - EventCode
- - EventData_Xml
- - EventDescription
- - EventID
- - EventRecordID
- - FileVersion
- - Guid
- - Hashes
- - Image
- - IntegrityLevel
- - Keywords
- - Level
- - LogonGuid
- - LogonId
- - Name
- - Opcode
- - OriginalFileName
- - ParentCommandLine
- - ParentImage
- - ParentProcessGuid
- - ParentProcessId
- - ParentUser
- - ProcessGuid
- - ProcessID
- - ProcessId
- - Product
- - RecordID
- - RuleName
- - SystemTime
- - System_Props_Xml
- - Task
- - TerminalSessionId
- - ThreadID
- - User
- - UserId
- - UtcTime
- - Version
- - action
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - eventtype
- - host
- - index
- - linecount
- - original_file_name
- - os
- - parent_process
- - parent_process_exec
- - parent_process_guid
- - parent_process_id
- - parent_process_name
- - parent_process_path
- - process
- - process_current_directory
- - process_exec
- - process_guid
- - process_hash
- - process_id
- - process_integrity_level
- - process_name
- - process_path
- - punct
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - vendor_product
-example_log: 154100x8000000000000000154100x80000000000000001926574Linux-Sysmon/Operationalar-linuxLinux-Sysmon/Operationalar-linux-2022-08-09
10:42:47.757{ec23eae3-3a27-62f2-085e-16549b550000}10268/usr/bin/sudo-11241100x800000000000000011241100x8000000000000000792913Linux-Sysmon/Operationalsysmonlinux-tcontreras-attack-range-4134Linux-Sysmon/Operationalsysmonlinux-tcontreras-attack-range-4134-2021-12-20
16:07:17.929{ec2c97d1-6aa9-61c0-3038-618238560000}5256/opt/splunkforwarder/bin/splunkd4688201331200x80200000000000004688201331200x8020000000000000362027Securityar-win-2.attackrange.localSecurityar-win-2.attackrange.localNT AUTHORITY\SYSTEMAR-WIN-2$ATTACKRANGE0x3e70xa44C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe228202000x80000000000000228202000x800000000000001001307Applicationwin-dc-exch01.attackrange.localc:\temp\msf.dllAMD64C1000000
+ ProcessID='0' ThreadID='0'/>Applicationwin-dc-exch01.attackrange.localc:\temp\msf.dllAMD64C1000000
diff --git a/data_sources/windows_event_log_application_3000.yml b/data_sources/windows_event_log_application_3000.yml
index f7588b104a..a3dcec0bda 100644
--- a/data_sources/windows_event_log_application_3000.yml
+++ b/data_sources/windows_event_log_application_3000.yml
@@ -6,70 +6,68 @@ author: Patrick Bareiss, Splunk
description: Logs the termination of a process, including details about the process,
its termination code, and timestamp.
mitre_components:
- - Process Termination
- - Process Metadata
- - Application Log Content
- - OS API Execution
+- Process Termination
+- Process Metadata
+- Application Log Content
+- OS API Execution
source: XmlWinEventLog:Application
sourcetype: XmlWinEventLog
separator: EventCode
separator_value: 3000
supported_TA:
- - name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+- name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
- - _time
- - Channel
- - Computer
- - Error_Code
- - EventCode
- - EventData_Xml
- - EventRecordID
- - EventSourceName
- - Guid
- - Keywords
- - Level
- - Name
- - Opcode
- - ProcessID
- - Qualifiers
- - RecordNumber
- - SystemTime
- - System_Props_Xml
- - Task
- - ThreadID
- - UserID
- - Version
- - dest
- - dvc
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - param1
- - param2
- - param3
- - punct
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - tag
- - tag::eventtype
- - timestamp
- - user_id
- - vendor_product
+- _time
+- Channel
+- Computer
+- Error_Code
+- EventCode
+- EventData_Xml
+- EventRecordID
+- EventSourceName
+- Guid
+- Keywords
+- Level
+- Name
+- Opcode
+- ProcessID
+- Qualifiers
+- RecordNumber
+- SystemTime
+- System_Props_Xml
+- Task
+- ThreadID
+- UserID
+- Version
+- dest
+- dvc
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- param1
+- param2
+- param3
+- punct
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- tag
+- tag::eventtype
+- timestamp
+- user_id
+- vendor_product
example_log: 300004000x80000000000000300004000x8000000000000021334Applicationwin-host-mhaag-attack-range-117Applicationwin-host-mhaag-attack-range-117C:\Windows\System32\klist.exe001d8c3afcf370d13
diff --git a/data_sources/windows_event_log_capi2_70.yml b/data_sources/windows_event_log_capi2_70.yml
index 1ace202695..cc9a329fac 100644
--- a/data_sources/windows_event_log_capi2_70.yml
+++ b/data_sources/windows_event_log_capi2_70.yml
@@ -6,73 +6,71 @@ author: Patrick Bareiss, Splunk
description: This event log records events related to cryptographic operations, including
the deletion and export of certificates.
mitre_components:
- - Certificate Registration
- - Process Metadata
- - Application Log Content
- - OS API Execution
- - Host Status
+- Certificate Registration
+- Process Metadata
+- Application Log Content
+- OS API Execution
+- Host Status
source: XmlWinEventLog:Microsoft-Windows-CAPI2/Operational
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 70
supported_TA:
- - name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+- name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
- - _time
- - Channel
- - Computer
- - EventCode
- - EventID
- - EventRecordID
- - Guid
- - Keywords
- - Level
- - Name
- - Opcode
- - ProcessID
- - RecordNumber
- - SystemTime
- - System_Props_Xml
- - Task
- - ThreadID
- - UserData_Xml
- - UserID
- - Version
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dvc
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - punct
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user_id
- - vendor_product
+- _time
+- Channel
+- Computer
+- EventCode
+- EventID
+- EventRecordID
+- Guid
+- Keywords
+- Level
+- Name
+- Opcode
+- ProcessID
+- RecordNumber
+- SystemTime
+- System_Props_Xml
+- Task
+- ThreadID
+- UserData_Xml
+- UserID
+- Version
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dvc
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- punct
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user_id
+- vendor_product
example_log: 70047000x400000000000008070047000x4000000000000080308332Microsoft-Windows-CAPI2/Operationalwin-dc-mhaag-attack-range-84.attackrange.localMicrosoft-Windows-CAPI2/Operationalwin-dc-mhaag-attack-range-84.attackrange.local81028020x400000000000004081028020x40000000000000402400597Microsoft-Windows-CAPI2/Operationalmswin-server.attackrange.localMicrosoft-Windows-CAPI2/Operationalmswin-server.attackrange.local{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}WTD_UI_NONEWTD_STATEACTION_VERIFY2021-01-07T23:21:42.655Z2021-01-07T23:21:42.655ZThe digital signature of the object did not verify.100704000x8000000000000000100704000x80000000000000002Microsoft-Windows-CertificateServicesClient-Lifecycle-System/OperationalDESKTOP-92OQLA1112103000x8000000000000000112103000x80000000000000002975Microsoft-Windows-Windows Defender/Operationalresearchvmhaa112204000x8000000000000000112204000x80000000000000003701Microsoft-Windows-Windows Defender/Operationalresearchvmhaa500704000x8000000000000000500704000x80000000000000003726Microsoft-Windows-Windows Defender/OperationalresearchvmhaaMicrosoft Defender
diff --git a/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml b/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml
index 66a21053dc..c0b00aad8d 100644
--- a/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml
+++ b/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml
@@ -6,47 +6,47 @@ author: Michael Haag, Splunk
description: Logs an event when a Remote Desktop Protocol (RDP) client successfully
connects to a remote host.
mitre_components:
- - Network Connection Creation
- - Logon Session Creation
+- Network Connection Creation
+- Logon Session Creation
source: WinEventLog:Microsoft-Windows-TerminalServices-RDPClient/Operational
sourcetype: WinEventLog
separator: EventCode
supported_TA: []
fields:
- - _time
- - Channel
- - Computer
- - EventCode
- - EventData
- - EventID
- - EventRecordID
- - EventType
- - Keywords
- - Level
- - Message
- - Opcode
- - ProcessID
- - RecordNumber
- - Security_ID
- - Src
- - Src_Host
- - Src_NT_Domain
- - Src_User
- - System_TimeCreated
- - Task
- - ThreadID
- - Type
- - User
- - UserID
- - Version
- - dest
- - dvc
- - event_id
- - host
- - source
- - sourcetype
- - tag
- - user
+- _time
+- Channel
+- Computer
+- EventCode
+- EventData
+- EventID
+- EventRecordID
+- EventType
+- Keywords
+- Level
+- Message
+- Opcode
+- ProcessID
+- RecordNumber
+- Security_ID
+- Src
+- Src_Host
+- Src_NT_Domain
+- Src_User
+- System_TimeCreated
+- Task
+- ThreadID
+- Type
+- User
+- UserID
+- Version
+- dest
+- dvc
+- event_id
+- host
+- source
+- sourcetype
+- tag
+- user
example_log: 11/21/2024 06:09:16 PM LogName=Microsoft-Windows-TerminalServices-RDPClient/Operational
EventCode=1024 EventType=4 ComputerName=ar-win-5.attackrange.local User=NOT_TRANSLATED
Sid=S-1-5-21-1731938146-2314223186-1848411941-500 SidType=0 SourceName=Microsoft-Windows-TerminalServices-ClientActiveXCore
diff --git a/data_sources/windows_event_log_printservice_316.yml b/data_sources/windows_event_log_printservice_316.yml
index 74eecb2f6a..a13491e365 100644
--- a/data_sources/windows_event_log_printservice_316.yml
+++ b/data_sources/windows_event_log_printservice_316.yml
@@ -5,59 +5,59 @@ date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when printer drivers are installed or updated on the system.
mitre_components:
- - Driver Load
- - Driver Metadata
+- Driver Load
+- Driver Metadata
source: WinEventLog:Microsoft-Windows-PrintService/Admin
sourcetype: WinEventLog
separator: EventCode
separator_value: 316
supported_TA:
- - name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+- name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
- - _time
- - ComputerName
- - EventCode
- - EventType
- - Keywords
- - LogName
- - Message
- - OpCode
- - RecordNumber
- - Sid
- - SidType
- - SourceName
- - TaskCategory
- - Type
- - User
- - category
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dvc
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - punct
- - severity
- - severity_id
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - vendor_product
+- _time
+- ComputerName
+- EventCode
+- EventType
+- Keywords
+- LogName
+- Message
+- OpCode
+- RecordNumber
+- Sid
+- SidType
+- SourceName
+- TaskCategory
+- Type
+- User
+- category
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dvc
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- punct
+- severity
+- severity_id
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- vendor_product
example_log: 07/01/2021 04:20:47 PM
diff --git a/data_sources/windows_event_log_printservice_808.yml b/data_sources/windows_event_log_printservice_808.yml
index 3f73b548be..2f1c1363e4 100644
--- a/data_sources/windows_event_log_printservice_808.yml
+++ b/data_sources/windows_event_log_printservice_808.yml
@@ -6,63 +6,63 @@ author: Patrick Bareiss, Splunk
description: Logs an event when the print spooler service fails to load a printer
plug-in module.
mitre_components:
- - Module Load
- - Application Log Content
- - Service Metadata
+- Module Load
+- Application Log Content
+- Service Metadata
source: WinEventLog:Microsoft-Windows-PrintService/Admin
sourcetype: WinEventLog
separator: EventCode
separator_value: 808
supported_TA:
- - name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+- name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
- - _time
- - ComputerName
- - EventCode
- - EventType
- - Keywords
- - LogName
- - Message
- - OpCode
- - RecordNumber
- - Sid
- - SidType
- - SourceName
- - TaskCategory
- - Type
- - User
- - category
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dvc
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - name
- - punct
- - severity
- - severity_id
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - subject
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - vendor_product
+- _time
+- ComputerName
+- EventCode
+- EventType
+- Keywords
+- LogName
+- Message
+- OpCode
+- RecordNumber
+- Sid
+- SidType
+- SourceName
+- TaskCategory
+- Type
+- User
+- category
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dvc
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- name
+- punct
+- severity
+- severity_id
+- signature
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- subject
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- vendor_product
example_log: 07/01/2021 04:20:47 PM
diff --git a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml
index 00eb66eec2..17e1e81b90 100644
--- a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml
+++ b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml
@@ -5,63 +5,60 @@ date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when a Remote Desktop Service session is initialized.
mitre_components:
- - Network Connection Creation
- - Logon Session Creation
- - Logon Session Metadata
-source:
- WinEventLog:Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational
+- Network Connection Creation
+- Logon Session Creation
+- Logon Session Metadata
+source: WinEventLog:Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational
sourcetype: wineventlog
separator: EventCode
separator_value: 1149
supported_TA:
- - name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+- name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
- - _time
- - ActivityID
- - Channel
- - Computer
- - EventCode
- - EventID
- - EventRecordID
- - Guid
- - Keywords
- - Level
- - Name
- - Opcode
- - ProcessID
- - RecordNumber
- - SystemTime
- - System_Props_Xml
- - Task
- - ThreadID
- - UserData_Xml
- - UserID
- - Version
- - dvc
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - punct
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - tag
- - tag::eventtype
- - timestamp
- - user_id
- - vendor_product
+- _time
+- ActivityID
+- Channel
+- Computer
+- EventCode
+- EventID
+- EventRecordID
+- Guid
+- Keywords
+- Level
+- Name
+- Opcode
+- ProcessID
+- RecordNumber
+- SystemTime
+- System_Props_Xml
+- Task
+- ThreadID
+- UserData_Xml
+- UserID
+- Version
+- dvc
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- punct
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- tag
+- tag::eventtype
+- timestamp
+- user_id
+- vendor_product
example_log: 114904000x1000000000000000114904000x10000000000000002064Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operationalar-win-1.attackrange.localAdministratorATTACKRANGE10.0.1.14
+ UserID='S-1-5-20'/>AdministratorATTACKRANGE10.0.1.14
diff --git a/data_sources/windows_event_log_security_1100.yml b/data_sources/windows_event_log_security_1100.yml
index 3c118a5dfc..f926bde8c2 100644
--- a/data_sources/windows_event_log_security_1100.yml
+++ b/data_sources/windows_event_log_security_1100.yml
@@ -5,82 +5,80 @@ date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when the event logging service has shut down.
mitre_components:
- - Host Status
- - System Configuration Changes
+- Host Status
+- System Configuration Changes
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 1100
supported_TA:
- - name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+- name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
- - _time
- - Channel
- - Computer
- - Error_Code
- - EventCode
- - EventID
- - EventRecordID
- - Guid
- - Keywords
- - Level
- - Name
- - Opcode
- - ProcessID
- - RecordNumber
- - SystemTime
- - System_Props_Xml
- - Task
- - ThreadID
- - UserData_Xml
- - Version
- - action
- - app
- - change_type
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - name
- - object_attrs
- - object_category
- - product
- - punct
- - service
- - service_name
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - status
- - subject
- - ta_windows_action
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - vendor
- - vendor_product
+- _time
+- Channel
+- Computer
+- Error_Code
+- EventCode
+- EventID
+- EventRecordID
+- Guid
+- Keywords
+- Level
+- Name
+- Opcode
+- ProcessID
+- RecordNumber
+- SystemTime
+- System_Props_Xml
+- Task
+- ThreadID
+- UserData_Xml
+- Version
+- action
+- app
+- change_type
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- name
+- object_attrs
+- object_category
+- product
+- punct
+- service
+- service_name
+- signature
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- status
+- subject
+- ta_windows_action
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- vendor
+- vendor_product
example_log: 11000410300x402000000000000011000410300x4020000000000000140874Securityar-win-2Securityar-win-2
diff --git a/data_sources/windows_event_log_security_1102.yml b/data_sources/windows_event_log_security_1102.yml
index 3e46c4323f..d66920335f 100644
--- a/data_sources/windows_event_log_security_1102.yml
+++ b/data_sources/windows_event_log_security_1102.yml
@@ -5,88 +5,86 @@ date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when the audit log is cleared.
mitre_components:
- - User Account Modification
- - Logon Session Metadata
- - File Deletion
+- User Account Modification
+- Logon Session Metadata
+- File Deletion
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 1102
supported_TA:
- - name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+- name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
- - _time
- - Caller_User_Name
- - Channel
- - Computer
- - Error_Code
- - EventCode
- - EventID
- - EventRecordID
- - Guid
- - Keywords
- - Level
- - LogFileCleared_Xml
- - Name
- - Opcode
- - ProcessID
- - RecordNumber
- - SubjectDomainName
- - SubjectLogonId
- - SubjectUserName
- - SubjectUserSid
- - SystemTime
- - System_Props_Xml
- - Task
- - ThreadID
- - UserData_Xml
- - Version
- - action
- - app
- - change_type
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - name
- - object_attrs
- - object_category
- - product
- - punct
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - src_user
- - status
- - subject
- - ta_windows_action
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - vendor
- - vendor_product
+- _time
+- Caller_User_Name
+- Channel
+- Computer
+- Error_Code
+- EventCode
+- EventID
+- EventRecordID
+- Guid
+- Keywords
+- Level
+- LogFileCleared_Xml
+- Name
+- Opcode
+- ProcessID
+- RecordNumber
+- SubjectDomainName
+- SubjectLogonId
+- SubjectUserName
+- SubjectUserSid
+- SystemTime
+- System_Props_Xml
+- Task
+- ThreadID
+- UserData_Xml
+- Version
+- action
+- app
+- change_type
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- name
+- object_attrs
+- object_category
+- product
+- punct
+- signature
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- src_user
+- status
+- subject
+- ta_windows_action
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- vendor
+- vendor_product
example_log: 11020410400x402000000000000011020410400x40200000000000001826166Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localATTACKRANGE\AdministratorAdministratorATTACKRANGE0x34a3a27
diff --git a/data_sources/windows_event_log_security_4624.yml b/data_sources/windows_event_log_security_4624.yml
index 62d69f0c10..823b6f2dee 100644
--- a/data_sources/windows_event_log_security_4624.yml
+++ b/data_sources/windows_event_log_security_4624.yml
@@ -5,125 +5,124 @@ date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when an account successfully logs on to a system.
mitre_components:
- - Logon Session Creation
- - User Account Authentication
- - Logon Session Metadata
+- Logon Session Creation
+- User Account Authentication
+- Logon Session Metadata
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 4624
supported_TA:
- - name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+- name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
- - _time
- - ActivityID
- - AuthenticationPackageName
- - Caller_Domain
- - Caller_User_Name
- - Channel
- - Computer
- - ElevatedToken
- - Error_Code
- - EventCode
- - EventData_Xml
- - EventID
- - EventRecordID
- - Guid
- - ImpersonationLevel
- - IpAddress
- - IpPort
- - KeyLength
- - Keywords
- - Level
- - LmPackageName
- - LogonGuid
- - LogonProcessName
- - LogonType
- - Logon_ID
- - Logon_Type
- - Name
- - Opcode
- - ProcessID
- - ProcessId
- - ProcessName
- - RecordNumber
- - RestrictedAdminMode
- - Source_Port
- - Source_Workstation
- - SubjectDomainName
- - SubjectLogonId
- - SubjectUserName
- - SubjectUserSid
- - SystemTime
- - System_Props_Xml
- - TargetDomainName
- - TargetLinkedLogonId
- - TargetLogonId
- - TargetOutboundDomainName
- - TargetOutboundUserName
- - TargetUserName
- - TargetUserSid
- - Target_Domain
- - Target_User_Name
- - Task
- - ThreadID
- - TransmittedServices
- - Version
- - VirtualAccount
- - WorkstationName
- - action
- - app
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_nt_domain
- - dvc
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - name
- - process
- - process_id
- - process_name
- - process_path
- - product
- - punct
- - session_id
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - src_ip
- - src_port
- - status
- - subject
- - ta_windows_action
- - tag
- - tag::action
- - tag::app
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - user_group
- - vendor
- - vendor_product
+- _time
+- ActivityID
+- AuthenticationPackageName
+- Caller_Domain
+- Caller_User_Name
+- Channel
+- Computer
+- ElevatedToken
+- Error_Code
+- EventCode
+- EventData_Xml
+- EventID
+- EventRecordID
+- Guid
+- ImpersonationLevel
+- IpAddress
+- IpPort
+- KeyLength
+- Keywords
+- Level
+- LmPackageName
+- LogonGuid
+- LogonProcessName
+- LogonType
+- Logon_ID
+- Logon_Type
+- Name
+- Opcode
+- ProcessID
+- ProcessId
+- ProcessName
+- RecordNumber
+- RestrictedAdminMode
+- Source_Port
+- Source_Workstation
+- SubjectDomainName
+- SubjectLogonId
+- SubjectUserName
+- SubjectUserSid
+- SystemTime
+- System_Props_Xml
+- TargetDomainName
+- TargetLinkedLogonId
+- TargetLogonId
+- TargetOutboundDomainName
+- TargetOutboundUserName
+- TargetUserName
+- TargetUserSid
+- Target_Domain
+- Target_User_Name
+- Task
+- ThreadID
+- TransmittedServices
+- Version
+- VirtualAccount
+- WorkstationName
+- action
+- app
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_nt_domain
+- dvc
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- name
+- process
+- process_id
+- process_name
+- process_path
+- product
+- punct
+- session_id
+- signature
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- src_ip
+- src_port
+- status
+- subject
+- ta_windows_action
+- tag
+- tag::action
+- tag::app
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- user_group
+- vendor
+- vendor_product
example_log: 4624201254400x80200000000000004624201254400x8020000000000000371886Securityar-win-7.attackrange.local4625001254400x80100000000000004625001254400x8010000000000000367348Securityar-win-8.attackrange.local4627001255400x80200000000000004627001255400x8020000000000000186260Securityar-win-dc.attackrange.local4648001254400x80200000000000004648001254400x8020000000000000336567Securitywin-host-mvelazco-02713-447.attackrange.local4662001408000x80100000000000004662001408000x801000000000000021623198276Securityattack_range_dc4663101280000x80200000000000004663101280000x802000000000000010525869Securityar-win-2.attackrange.localSecurityar-win-2.attackrange.localAR-WIN-2\AdministratorAdministratorAR-WIN-20x6cfe7SecurityFileC:\Program
diff --git a/data_sources/windows_event_log_security_4672.yml b/data_sources/windows_event_log_security_4672.yml
index 9c507ba8bc..b56a07aae1 100644
--- a/data_sources/windows_event_log_security_4672.yml
+++ b/data_sources/windows_event_log_security_4672.yml
@@ -6,89 +6,88 @@ author: Patrick Bareiss, Splunk
description: Logs an event when a user with administrative privileges logs on to a
system.
mitre_components:
- - Logon Session Creation
- - User Account Authentication
+- Logon Session Creation
+- User Account Authentication
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 4672
supported_TA:
- - name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+- name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
- - _time
- - ActivityID
- - Caller_Domain
- - Caller_User_Name
- - Channel
- - Computer
- - Error_Code
- - EventCode
- - EventData_Xml
- - EventID
- - EventRecordID
- - Guid
- - Keywords
- - Level
- - Logon_ID
- - Name
- - Opcode
- - PrivilegeList
- - ProcessID
- - RecordNumber
- - SubjectDomainName
- - SubjectLogonId
- - SubjectUserName
- - SubjectUserSid
- - SystemTime
- - System_Props_Xml
- - Task
- - ThreadID
- - Version
- - action
- - app
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - name
- - product
- - punct
- - session_id
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - src_nt_domain
- - src_user
- - status
- - subject
- - ta_windows_action
- - tag
- - tag::action
- - tag::eventtype
- - timeendpos
- - timestartpos
- - vendor
- - vendor_product
+- _time
+- ActivityID
+- Caller_Domain
+- Caller_User_Name
+- Channel
+- Computer
+- Error_Code
+- EventCode
+- EventData_Xml
+- EventID
+- EventRecordID
+- Guid
+- Keywords
+- Level
+- Logon_ID
+- Name
+- Opcode
+- PrivilegeList
+- ProcessID
+- RecordNumber
+- SubjectDomainName
+- SubjectLogonId
+- SubjectUserName
+- SubjectUserSid
+- SystemTime
+- System_Props_Xml
+- Task
+- ThreadID
+- Version
+- action
+- app
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- name
+- product
+- punct
+- session_id
+- signature
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- src_nt_domain
+- src_user
+- status
+- subject
+- ta_windows_action
+- tag
+- tag::action
+- tag::eventtype
+- timeendpos
+- timestartpos
+- vendor
+- vendor_product
example_log: 4672001254800x80200000000000004672001254800x8020000000000000148946Securityar-win-6.attackrange.local4688201331200x80200000000000004688201331200x8020000000000000432820Securityar-win-1Securityar-win-1NT AUTHORITY\SYSTEMAR-WIN-1$WORKGROUP0x3e70xf84C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe4703001331700x80200000000000004703001331700x8020000000000000328761Securitywin-host-ctus-attack-range-115Securitywin-host-ctus-attack-range-115WIN-HOST-CTUS-A\AdministratorAdministratorWIN-HOST-CTUS-A0x288b91WIN-HOST-CTUS-A\AdministratorAdministrator4719001356800x80200000000000004719001356800x8020000000000000353597Securityar-win-dc.attackrange.local4724001382400x80200000000000004724001382400x8020000000000000276779Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localTRUMAN_CLEMENTSATTACKRANGEATTACKRANGE\TRUMAN_CLEMENTSATTACKRANGE\AdministratorAdministratorATTACKRANGE4725001382400x80200000000000004725001382400x8020000000000000278771Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localWILFORD_SUTTONATTACKRANGEATTACKRANGE\WILFORD_SUTTONATTACKRANGE\AdministratorAdministratorATTACKRANGE4726001382400x80200000000000004726001382400x8020000000000000279283Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localLYNN_WOLFATTACKRANGES-1-5-21-2851375338-1978525053-2422663219-2445ATTACKRANGE\AdministratorAdministratorATTACKRANGE4738001382400x80200000000000004738001382400x80200000000000006389713Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.local-unprivATTACKRANGES-1-5-21-945660386-2529346225-2932127451-1112S-1-5-21-945660386-2529346225-2932127451-500AdministratorATTACKRANGE4739001356900x80200000000000004739001356900x8020000000000000394176Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localLockout PolicyATTACKRANGEATTACKRANGE\NT AUTHORITY\SYSTEMAR-WIN-DC$ATTACKRANGE4741001382500x80200000000000004741001382500x8020000000000000143475Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localAR-WIN-2$ATTACKRANGEATTACKRANGE\AR-WIN-2$ATTACKRANGE\AdministratorAdministratorATTACKRANGE4742001382500x80200000000000004742001382500x8020000000000000901860Securitywin-dc-root-04195-428.attackrange.localSecuritywin-dc-root-04195-428.attackrange.local-WIN-HOST-ROOT-0$ATTACKRANGES-1-5-21-199921393-3534762603-6736986-1111S-1-5-21-199921393-3534762603-6736986-500Administrator4768001433900x80100000000000004768001433900x8010000000000000391562Securitywin-dc-mvelazco-02713-392.attackrange.localSecuritywin-dc-mvelazco-02713-392.attackrange.localRXETPKZHattackrange.localNULL SIDkrbtgt/attackrange.localNULL SID0x408100104769001433700x80200000000000004769001433700x8020000000000000148521Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localAR-WIN-2$@ATTACKRANGE.LOCALATTACKRANGE.LOCALAR-WIN-2$ATTACKRANGE\AR-WIN-2$0x408100000x174771001433900x80100000000000004771001433900x8010000000000000391511Securitywin-dc-mvelazco-02713-392.attackrange.localSecuritywin-dc-mvelazco-02713-392.attackrange.localALLISON_WATERSATTACKRANGE\ALLISON_WATERSkrbtgt/attackrange.local0x408100100x182::ffff:10.0.1.154776001433600x80100000000000004776001433600x8010000000000000391615Securitywin-dc-mvelazco-02713-392.attackrange.localSecuritywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0KSYLEFUAWIN-HOST-MVELAZ0xc0000064
diff --git a/data_sources/windows_event_log_security_4781.yml b/data_sources/windows_event_log_security_4781.yml
index eee4c4c3f3..2e6adff3c4 100644
--- a/data_sources/windows_event_log_security_4781.yml
+++ b/data_sources/windows_event_log_security_4781.yml
@@ -6,107 +6,106 @@ author: Patrick Bareiss, Splunk
description: Logs changes made to the name of a computer account, including the old
and new names and the user performing the action.
mitre_components:
- - User Account Modification
- - User Account Metadata
- - Active Directory Object Modification
- - Application Log Content
+- User Account Modification
+- User Account Metadata
+- Active Directory Object Modification
+- Application Log Content
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 4781
supported_TA:
- - name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+- name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
- - _time
- - ActivityID
- - Caller_Domain
- - Caller_User_Name
- - CategoryString
- - Channel
- - Computer
- - Error_Code
- - EventCode
- - EventData_Xml
- - EventID
- - EventRecordID
- - Guid
- - Keywords
- - Level
- - Logon_ID
- - Name
- - NewTargetUserName
- - OldTargetUserName
- - Opcode
- - PrivilegeList
- - ProcessID
- - RecordNumber
- - SubjectDomainName
- - SubjectLogonId
- - SubjectUserName
- - SubjectUserSid
- - SystemTime
- - System_Props_Xml
- - TargetDomainName
- - TargetSid
- - Target_Domain
- - Task
- - ThreadID
- - Version
- - action
- - app
- - change_type
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dest_nt_domain
- - dvc
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - name
- - object
- - object_attrs
- - object_category
- - object_id
- - product
- - punct
- - result
- - session_id
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - src_nt_domain
- - src_user
- - src_user_name
- - status
- - subject
- - ta_windows_action
- - ta_windows_security_CategoryString
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user
- - user_name
- - vendor
- - vendor_product
+- _time
+- ActivityID
+- Caller_Domain
+- Caller_User_Name
+- CategoryString
+- Channel
+- Computer
+- Error_Code
+- EventCode
+- EventData_Xml
+- EventID
+- EventRecordID
+- Guid
+- Keywords
+- Level
+- Logon_ID
+- Name
+- NewTargetUserName
+- OldTargetUserName
+- Opcode
+- PrivilegeList
+- ProcessID
+- RecordNumber
+- SubjectDomainName
+- SubjectLogonId
+- SubjectUserName
+- SubjectUserSid
+- SystemTime
+- System_Props_Xml
+- TargetDomainName
+- TargetSid
+- Target_Domain
+- Task
+- ThreadID
+- Version
+- action
+- app
+- change_type
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dest_nt_domain
+- dvc
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- name
+- object
+- object_attrs
+- object_category
+- object_id
+- product
+- punct
+- result
+- session_id
+- signature
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- src_nt_domain
+- src_user
+- src_user_name
+- status
+- subject
+- ta_windows_action
+- ta_windows_security_CategoryString
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user
+- user_name
+- vendor
+- vendor_product
example_log: 4781001382400x80200000000000004781001382400x8020000000000000148763Securityar-win-dc.attackrange.local4794001382400x80200000000000004794001382400x8020000000000000821077Securitywin-dc-root-17044-552.attackrange.local4798001382400x80200000000000004798001382400x8020000000000000386860Securityar-win-2.attackrange.local4876001280500x80200000000000004876001280500x802000000000000015379961Securitywin-dc-mhaag-attack-range-84.attackrange.local4886001280500x80200000000000004886001280500x802000000000000015379925Securitywin-dc-mhaag-attack-range-84.attackrange.local4887001280500x80200000000000004887001280500x80200000000000001830974609Securitycert_authority.attack_range.local5136001408100x80200000000000005136001408100x80200000000000001997365Securitywin-dc-mvelazco-02713-392.attackrange.local{73C96723-504B-4F15-830A-F4DDB1C48F2E}-ATTACKRANGE\AdministratorAdministratorATTACKRANGE0x95675attackrange.local%%14676CN=DANNIE_CERVANTES,OU=ServiceAccounts,OU=OGC,OU=Stage,DC=attackrange,DC=localattackrange.local%%14676CN=DANNIE_CERVANTES,OU=ServiceAccounts,OU=OGC,OU=Stage,DC=attackrange,DC=local{15AFB68A-679C-4F5B-AC18-4D988B3B3E44}userservicePrincipalName2.5.5.12adm/srv1.attackrange.local%%14674
diff --git a/data_sources/windows_event_log_security_5137.yml b/data_sources/windows_event_log_security_5137.yml
index 9dc78ab362..b7da687fc2 100644
--- a/data_sources/windows_event_log_security_5137.yml
+++ b/data_sources/windows_event_log_security_5137.yml
@@ -6,102 +6,99 @@ author: Patrick Bareiss, Splunk
description: Logs the creation of a new Active Directory object, including details
about the object name, type, and the user performing the action.
mitre_components:
- - Active Directory Object Creation
- - Active Directory Object Modification
- - User Account Metadata
- - Application Log Content
+- Active Directory Object Creation
+- Active Directory Object Modification
+- User Account Metadata
+- Application Log Content
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 5137
supported_TA:
- - name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+- name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
- - _time
- - AppCorrelationID
- - Caller_Domain
- - Caller_User_Name
- - Channel
- - Computer
- - DSName
- - DSType
- - Error_Code
- - EventCode
- - EventData_Xml
- - EventID
- - EventRecordID
- - Guid
- - Keywords
- - Level
- - Logon_ID
- - Name
- - ObjectClass
- - ObjectDN
- - ObjectGUID
- - OpCorrelationID
- - Opcode
- - ProcessID
- - RecordNumber
- - SubjectDomainName
- - SubjectLogonId
- - SubjectUserName
- - SubjectUserSid
- - SystemTime
- - System_Props_Xml
- - Task
- - ThreadID
- - Version
- - action
- - app
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - name
- - product
- - punct
- - session_id
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - src_nt_domain
- - src_user
- - status
- - subject
- - ta_windows_action
- - tag
- - tag::action
- - tag::eventtype
- - timeendpos
- - timestartpos
- - vendor
- - vendor_product
+- _time
+- AppCorrelationID
+- Caller_Domain
+- Caller_User_Name
+- Channel
+- Computer
+- DSName
+- DSType
+- Error_Code
+- EventCode
+- EventData_Xml
+- EventID
+- EventRecordID
+- Guid
+- Keywords
+- Level
+- Logon_ID
+- Name
+- ObjectClass
+- ObjectDN
+- ObjectGUID
+- OpCorrelationID
+- Opcode
+- ProcessID
+- RecordNumber
+- SubjectDomainName
+- SubjectLogonId
+- SubjectUserName
+- SubjectUserSid
+- SystemTime
+- System_Props_Xml
+- Task
+- ThreadID
+- Version
+- action
+- app
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- name
+- product
+- punct
+- session_id
+- signature
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- src_nt_domain
+- src_user
+- status
+- subject
+- ta_windows_action
+- tag
+- tag::action
+- tag::eventtype
+- timeendpos
+- timestartpos
+- vendor
+- vendor_product
example_log: 5137001408100x80200000000000005137001408100x8020000000000000170140Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.local{681cac8c-b5a4-48fd-be93-4339996bd94d}-ATTACKRANGE\AdministratorAdministratorATTACKRANGE0x8561aattackrange.local%%14676CN={2C4C7CD3-7AA5-4E84-89B5-CE9FC75611D4},CN=Policies,CN=System,DC=attackrange,DC=localattackrange.local%%14676CN={2C4C7CD3-7AA5-4E84-89B5-CE9FC75611D4},CN=Policies,CN=System,DC=attackrange,DC=local{3e7ae4de-29a6-41c1-b27c-bf9548b0444c}groupPolicyContainer
diff --git a/data_sources/windows_event_log_security_5140.yml b/data_sources/windows_event_log_security_5140.yml
index 4fb8bf8cc6..537ad5db65 100644
--- a/data_sources/windows_event_log_security_5140.yml
+++ b/data_sources/windows_event_log_security_5140.yml
@@ -6,119 +6,117 @@ author: Patrick Bareiss, Splunk
description: Logs access to a network share, including details about the user, share
path, and the access type.
mitre_components:
- - Network Share Access
- - File Access
- - User Account Metadata
- - Application Log Content
+- Network Share Access
+- File Access
+- User Account Metadata
+- Application Log Content
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 5140
supported_TA:
- - name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+- name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
- - _time
- - AccessList
- - AccessMask
- - Caller_Domain
- - Caller_User_Name
- - Channel
- - Computer
- - Error_Code
- - EventCode
- - EventData_Xml
- - EventID
- - EventRecordID
- - Guid
- - IpAddress
- - IpPort
- - Keywords
- - Level
- - Logon_ID
- - Name
- - ObjectType
- - Opcode
- - ProcessID
- - RecordNumber
- - ShareName
- - Source_Port
- - Source_Workstation
- - SubjectDomainName
- - SubjectLogonId
- - SubjectUserName
- - SubjectUserSid
- - SystemTime
- - System_Props_Xml
- - Task
- - ThreadID
- - Version
- - action
- - app
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - dvc_nt_host
- - event_id
- - eventtype
- - file_name
- - host
- - id
- - index
- - linecount
- - name
- - product
- - punct
- - session_id
- - signature
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - src
- - src_ip
- - src_nt_domain
- - src_nt_host
- - src_port
- - src_user
- - status
- - subject
- - ta_windows_action
- - tag
- - tag::action
- - tag::eventtype
- - timeendpos
- - timestartpos
- - vendor
- - vendor_product
+- _time
+- AccessList
+- AccessMask
+- Caller_Domain
+- Caller_User_Name
+- Channel
+- Computer
+- Error_Code
+- EventCode
+- EventData_Xml
+- EventID
+- EventRecordID
+- Guid
+- IpAddress
+- IpPort
+- Keywords
+- Level
+- Logon_ID
+- Name
+- ObjectType
+- Opcode
+- ProcessID
+- RecordNumber
+- ShareName
+- Source_Port
+- Source_Workstation
+- SubjectDomainName
+- SubjectLogonId
+- SubjectUserName
+- SubjectUserSid
+- SystemTime
+- System_Props_Xml
+- Task
+- ThreadID
+- Version
+- action
+- app
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- dvc_nt_host
+- event_id
+- eventtype
+- file_name
+- host
+- id
+- index
+- linecount
+- name
+- product
+- punct
+- session_id
+- signature
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- src
+- src_ip
+- src_nt_domain
+- src_nt_host
+- src_port
+- src_user
+- status
+- subject
+- ta_windows_action
+- tag
+- tag::action
+- tag::eventtype
+- timeendpos
+- timestartpos
+- vendor
+- vendor_product
field_mappings:
- - data_model: ocsf
- mapping:
- AccessList: access_list
- AccessMask: access_mask
- AccessReason: access_result
- ShareLocalPath: file
- ObjectType: file.type
- IpAddress: src_endpoint.ip
- IpPort: src_endpoint.port
- SubjectDomainName: actor.user.domain
- SubjectUserName: actor.user.name
- SubjectLogonId: actor.session.uid
- SubjectUserSid: actor.user.uid
+- data_model: ocsf
+ mapping:
+ AccessList: access_list
+ AccessMask: access_mask
+ AccessReason: access_result
+ ShareLocalPath: file
+ ObjectType: file.type
+ IpAddress: src_endpoint.ip
+ IpPort: src_endpoint.port
+ SubjectDomainName: actor.user.domain
+ SubjectUserName: actor.user.name
+ SubjectLogonId: actor.session.uid
+ SubjectUserSid: actor.user.uid
example_log: 5140101280800x80200000000000005140101280800x8020000000000000138541Securityar-win-66.attackrange.localSecurityar-win-66.attackrange.localATTACKRANGE\ELMER_SALASELMER_SALASATTACKRANGE0x2f259bFile10.0.1.16498645141001408100x80200000000000005141001408100x8020000000000000670908Securitywin-dc-range-02713-392.attackrange.local5145001281100x80200000000000005145001281100x80200000000000002018939Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localANONYMOUS LOGONANONYMOUS
LOGONATTACKRANGE0x13ef1bFile10.0.1.1550160703604000x8080000000000000703604000x8080000000000000168530Systemar-win-dc.attackrange.localsppsvcstopped7300700070007300760063002F0031000000
+ ProcessID='588' ThreadID='2272'/>Systemar-win-dc.attackrange.localsppsvcstopped7300700070007300760063002F0031000000
diff --git a/data_sources/windows_event_log_system_7040.yml b/data_sources/windows_event_log_system_7040.yml
index 3a5f943ee0..0f26b121a0 100644
--- a/data_sources/windows_event_log_system_7040.yml
+++ b/data_sources/windows_event_log_system_7040.yml
@@ -6,86 +6,84 @@ author: Patrick Bareiss, Splunk
description: Logs changes to the start type of a Windows service, including details
about the service name, old start type, and new start type.
mitre_components:
- - Service Modification
- - Service Metadata
- - OS API Execution
- - Application Log Content
+- Service Modification
+- Service Metadata
+- OS API Execution
+- Application Log Content
source: XmlWinEventLog:System
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 7040
supported_TA:
- - name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+- name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
- - _time
- - Channel
- - Computer
- - Error_Code
- - EventCode
- - EventData_Xml
- - EventRecordID
- - EventSourceName
- - Guid
- - Keywords
- - Level
- - Name
- - Opcode
- - ProcessID
- - Qualifiers
- - RecordNumber
- - ServiceName
- - SystemTime
- - System_Props_Xml
- - Task
- - ThreadID
- - UserID
- - Version
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - param1
- - param2
- - param3
- - param4
- - product
- - punct
- - service
- - service_name
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - start_mode
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user_id
- - vendor
- - vendor_product
+- _time
+- Channel
+- Computer
+- Error_Code
+- EventCode
+- EventData_Xml
+- EventRecordID
+- EventSourceName
+- Guid
+- Keywords
+- Level
+- Name
+- Opcode
+- ProcessID
+- Qualifiers
+- RecordNumber
+- ServiceName
+- SystemTime
+- System_Props_Xml
+- Task
+- ThreadID
+- UserID
+- Version
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- param1
+- param2
+- param3
+- param4
+- product
+- punct
+- service
+- service_name
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- start_mode
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user_id
+- vendor
+- vendor_product
example_log: 704004000x8080000000000000704004000x8080000000000000168231Systemar-win-dc.attackrange.localSystemar-win-dc.attackrange.localPrint Spoolerdemand startdisabledSpooler
diff --git a/data_sources/windows_event_log_system_7045.yml b/data_sources/windows_event_log_system_7045.yml
index a3f5ce006a..87c78b1a51 100644
--- a/data_sources/windows_event_log_system_7045.yml
+++ b/data_sources/windows_event_log_system_7045.yml
@@ -6,86 +6,84 @@ author: Patrick Bareiss, Splunk
description: Logs the successful installation of a new Windows service, including
details about the service name, executable path, and service type.
mitre_components:
- - Service Creation
- - Service Metadata
- - OS API Execution
- - Process Metadata
+- Service Creation
+- Service Metadata
+- OS API Execution
+- Process Metadata
source: XmlWinEventLog:System
sourcetype: xmlwineventlog
separator: EventCode
separator_value: 7045
supported_TA:
- - name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+- name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
- - _time
- - AccountName
- - Channel
- - Computer
- - Error_Code
- - EventCode
- - EventData_Xml
- - EventRecordID
- - EventSourceName
- - Guid
- - ImagePath
- - Keywords
- - Level
- - Name
- - Opcode
- - ProcessID
- - Qualifiers
- - RecordNumber
- - ServiceName
- - ServiceType
- - StartType
- - SystemTime
- - System_Props_Xml
- - Task
- - ThreadID
- - UserID
- - Version
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - product
- - punct
- - service
- - service_name
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - start_mode
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user_id
- - vendor
- - vendor_product
+- _time
+- AccountName
+- Channel
+- Computer
+- Error_Code
+- EventCode
+- EventData_Xml
+- EventRecordID
+- EventSourceName
+- Guid
+- ImagePath
+- Keywords
+- Level
+- Name
+- Opcode
+- ProcessID
+- Qualifiers
+- RecordNumber
+- ServiceName
+- ServiceType
+- StartType
+- SystemTime
+- System_Props_Xml
+- Task
+- ThreadID
+- UserID
+- Version
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- product
+- punct
+- service
+- service_name
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- start_mode
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user_id
+- vendor
+- vendor_product
example_log: 704504000x8080000000000000704504000x8080000000000000168145Systemar-win-dc.attackrange.localSystemar-win-dc.attackrange.localKrbSCMpowershell.exe -WindowStyle
Hiddenestno'
diff --git a/data_sources/windows_event_log_taskscheduler_200.yml b/data_sources/windows_event_log_taskscheduler_200.yml
index 4a29c55df5..2348f6b3f8 100644
--- a/data_sources/windows_event_log_taskscheduler_200.yml
+++ b/data_sources/windows_event_log_taskscheduler_200.yml
@@ -6,80 +6,79 @@ author: Patrick Bareiss, Splunk
description: Logs the successful registration of a new scheduled task in Windows Task
Scheduler, including task details and configurations.
mitre_components:
- - Scheduled Job Creation
- - Scheduled Job Metadata
- - Service Creation
- - OS API Execution
+- Scheduled Job Creation
+- Scheduled Job Metadata
+- Service Creation
+- OS API Execution
source: WinEventLog:Microsoft-Windows-TaskScheduler/Operational
sourcetype: wineventlog
separator: EventCode
separator_value: 200
supported_TA:
- - name: Splunk Add-on for Microsoft Windows
- url: https://splunkbase.splunk.com/app/742
- version: 9.0.1
+- name: Splunk Add-on for Microsoft Windows
+ url: https://splunkbase.splunk.com/app/742
+ version: 9.0.1
fields:
- - _time
- - ActionName
- - ActivityID
- - Channel
- - Computer
- - EnginePID
- - Error_Code
- - EventCode
- - EventData_Xml
- - EventID
- - EventRecordID
- - Guid
- - Keywords
- - Level
- - Name
- - Opcode
- - ProcessID
- - RecordNumber
- - SystemTime
- - System_Props_Xml
- - Task
- - TaskInstanceId
- - TaskName
- - ThreadID
- - UserID
- - Version
- - app
- - date_hour
- - date_mday
- - date_minute
- - date_month
- - date_second
- - date_wday
- - date_year
- - date_zone
- - dest
- - dvc
- - dvc_nt_host
- - event_id
- - eventtype
- - host
- - id
- - index
- - linecount
- - product
- - punct
- - signature_id
- - source
- - sourcetype
- - splunk_server
- - ta_windows_action
- - tag
- - tag::eventtype
- - timeendpos
- - timestartpos
- - user_id
- - vendor
- - vendor_product
+- _time
+- ActionName
+- ActivityID
+- Channel
+- Computer
+- EnginePID
+- Error_Code
+- EventCode
+- EventData_Xml
+- EventID
+- EventRecordID
+- Guid
+- Keywords
+- Level
+- Name
+- Opcode
+- ProcessID
+- RecordNumber
+- SystemTime
+- System_Props_Xml
+- Task
+- TaskInstanceId
+- TaskName
+- ThreadID
+- UserID
+- Version
+- app
+- date_hour
+- date_mday
+- date_minute
+- date_month
+- date_second
+- date_wday
+- date_year
+- date_zone
+- dest
+- dvc
+- dvc_nt_host
+- event_id
+- eventtype
+- host
+- id
+- index
+- linecount
+- product
+- punct
+- signature_id
+- source
+- sourcetype
+- splunk_server
+- ta_windows_action
+- tag
+- tag::eventtype
+- timeendpos
+- timestartpos
+- user_id
+- vendor
+- vendor_product
example_log: 2001420010x80000000000000002001420010x80000000000000004323Microsoft-Windows-TaskScheduler/Operationalar-win-dc.attackrange.local
Date: Tue, 28 Jan 2025 10:42:10 -0800
Subject: [PATCH 04/67] adding a mapping yaml
---
deprecated_detection_mapping.yml | 1260 ++++++++++++++++++++++++++++++
1 file changed, 1260 insertions(+)
create mode 100644 deprecated_detection_mapping.yml
diff --git a/deprecated_detection_mapping.yml b/deprecated_detection_mapping.yml
new file mode 100644
index 0000000000..ca0e64dcb3
--- /dev/null
+++ b/deprecated_detection_mapping.yml
@@ -0,0 +1,1260 @@
+- deprecated_name: ASL AWS Excessive Security Scanning
+ deprecated_id: ff2bfdbc-65b7-4434-8f08-d55761d1d446
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: AWS Cloud Provisioning From Previously Unseen Region
+ deprecated_id: 7971d3df-da82-4648-a6e5-b5637bea5253
+ replacement_name: Cloud Provisioning Activity From Previously Unseen Region
+ replacement_id: 5aba1860-9617-4af9-b19d-aecac16fe4f2
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: First time seen command line argument
+ deprecated_id: a1b6e73f-98d5-470f-99ac-77aacd578473
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Windows connhost exe started forcefully
+ deprecated_id: c114aaca-68ee-41c2-ad8c-32bf21db8769
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Detect Mimikatz Using Loaded Images
+ deprecated_id: 29e307ba-40af-4ab2-91b2-3c6b392bbba0
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Kubernetes Azure detect sensitive role access
+ deprecated_id: f27349e5-1641-4f6a-9e68-30402be0ad4c
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Web Fraud - Anomalous User Clickspeed
+ deprecated_id: 31337bbb-bc22-4752-b599-ef192df2dc7a
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: EC2 Instance Started With Previously Unseen Instance Type
+ deprecated_id: 65541c80-03c7-4e05-83c8-1dcd57a2e1ad
+ replacement_name: Cloud Compute Instance Created With Previously Unseen Instance
+ Type
+ replacement_id: c6ddbf53-9715-49f3-bb4c-fb2e8a309cda
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: EC2 Instance Started With Previously Unseen AMI
+ deprecated_id: 347ec301-601b-48b9-81aa-9ddf9c829dd3
+ replacement_name: Cloud Compute Instance Created With Previously Unseen Image
+ replacement_id: bc24922d-987c-4645-b288-f8c73ec194c4
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Domain Group Discovery With Net
+ deprecated_id: f2f14ac7-fa81-471a-80d5-7eb65c3c7349
+ replacement_name: Windows Group Discovery Via Net
+ replacement_id: c5c8e0f3-147a-43da-bf04-4cfaec27dc44
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Kubernetes AWS detect sensitive role access
+ deprecated_id: b6013a7b-85e0-4a45-b051-10b252d69569
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Winword Spawning Windows Script Host
+ deprecated_id: 637e1b5c-9be1-11eb-9c32-acde48001122
+ replacement_name: Windows Office Product Spawned Uncommon Process
+ replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: 'The following analytics was deprecated in favour of a more generic approach.
+ Where instead of creating specific analytic for every potentially suspicious child
+ of an office product. We group them by threat level.
+
+ This would ease management and false positives tuning.'
+- deprecated_name: Winword Spawning PowerShell
+ deprecated_id: b2c950b8-9be2-11eb-8658-acde48001122
+ replacement_name: Windows Office Product Spawned Uncommon Process
+ replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Attempted Credential Dump From Registry via Reg exe
+ deprecated_id: e9fb4a59-c5fb-440a-9f24-191fbc6b2911
+ replacement_name: Windows Sensitive Registry Hive Dump Via CommandLine
+ replacement_id: 8bbb7d58-b360-11eb-ba21-acde48001122
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: This analytic had some overlap with another one, hence the deprecation.
+ It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry
+ Hive Dump Via CommandLine
+- deprecated_name: Detect processes used for System Network Configuration Discovery
+ deprecated_id: a51bfe1a-94f0-48cc-b1e4-16ae10145893
+ replacement_name: Potential System Network Configuration Discovery Activity
+ replacement_id: 3f0b95e3-3195-46ac-bea3-84fb59e7fac5
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Execution of File With Spaces Before Extension
+ deprecated_id: ab0353e6-a956-420b-b724-a8b4846d5d5a
+ replacement_name: Execution of File with Multiple Extensions
+ replacement_id: b06a555e-dce0-417d-a2eb-28a5d8d66ef7
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Updated to a new detection name
+- deprecated_name: EC2 Instance Started In Previously Unseen Region
+ deprecated_id: ada0f478-84a8-4641-a3f3-d82362d6fd75
+ replacement_name: Cloud Compute Instance Created In Previously Unused Region
+ replacement_id: fa4089e2-50e3-40f7-8469-d2cc1564ca59
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Office Document Spawned Child Process To Download
+ deprecated_id: 6fed27d2-9ec7-11eb-8fe4-aa665a019aa3
+ replacement_name: Windows Office Product Spawned Child Process For Download
+ replacement_id: f02b64b8-cbea-4f75-bf77-7a05111566b1
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Detect new API calls from user roles
+ deprecated_id: 22773e84-bac0-4595-b086-20d3f335b4f1
+ replacement_name: Cloud API Calls From Previously Unseen User Roles
+ replacement_id: 2181ad1f-1e73-4d0c-9780-e8880482a08f
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Cmdline Tool Not Executed In CMD Shell
+ deprecated_id: 6c3f7dd8-153c-11ec-ac2d-acde48001122
+ replacement_name: Windows Cmdline Tool Execution From Non-Shell Process
+ replacement_id: 2afa393f-b88d-41b7-9793-623c93a2dfde
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Linux Auditd Find Private Keys
+ deprecated_id: 80bb9988-190b-4ee0-a3c3-509545a8f678
+ replacement_name: Linux Auditd Private Keys and Certificate Enumeration
+ replacement_id: 892eb674-3344-4143-8e52-4775b1daf3f1
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Detect AWS API Activities From Unapproved Accounts
+ deprecated_id: ada0f478-84a8-4641-a3f1-d82362d4bd55
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Monitor DNS For Brand Abuse
+ deprecated_id: 24dd17b1-e2fb-4c31-878c-d4f746595bfa
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Kubernetes GCP detect sensitive object access
+ deprecated_id: bdb6d596-86a0-4aba-8369-418ae8b9963a
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Kubernetes Azure scan fingerprint
+ deprecated_id: c5e5bd5c-1013-4841-8b23-e7b3253c840a
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: ASL AWS Password Policy Changes
+ deprecated_id: 5ade5937-11a2-4363-ba6b-39a3ee8d5b1a
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: O365 Suspicious Admin Email Forwarding
+ deprecated_id: 7f398cfb-918d-41f4-8db8-2e2474e02c28
+ replacement_name: O365 Mailbox Email Forwarding Enabled
+ replacement_id: 0b6bc75c-05d1-4101-9fc3-97e706168f24
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: AWS Cloud Provisioning From Previously Unseen City
+ deprecated_id: 344a1778-0b25-490c-adb1-de8beddf59cd
+ replacement_name: Cloud Provisioning Activity From Previously Unseen City
+ replacement_id: e7ecc5e0-88df-48b9-91af-51104c68f02f
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Kubernetes AWS detect service accounts forbidden failure access
+ deprecated_id: a6959c57-fa8f-4277-bb86-7c32fba579d5
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Osquery pack - ColdRoot detection
+ deprecated_id: a6fffe5e-05c3-4c04-badc-887607fbb8dc
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Windows Modify Registry Reg Restore
+ deprecated_id: d0072bd2-6d73-4c1b-bc77-ded6d2da3a4e
+ replacement_name: Windows Registry Entries Restored Via Reg
+ replacement_id: a17af481-e2ad-494c-9da6-afb4d243a019
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Kubernetes GCP detect most active service accounts by pod
+ deprecated_id: 7f5c2779-88a0-4824-9caa-0f606c8f260f
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Scheduled tasks used in BadRabbit ransomware
+ deprecated_id: 1297fb80-f42a-4b4a-9c8b-78c066437cf6
+ replacement_name: Scheduled Task Deleted Or Created via CMD
+ replacement_id: d5af132c-7c17-439c-9d31-13d55340f36c
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Updated to a new detection name
+- deprecated_name: Suspicious Rundll32 Rename
+ deprecated_id: 7360137f-abad-473e-8189-acbdaa34d114
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Remote System Discovery with Net
+ deprecated_id: 9df16706-04a2-41e2-bbfe-9b38b34409d3
+ replacement_name: Windows Network Share Interaction With Net
+ replacement_id: 4dc3951f-b3f8-4f46-b412-76a483f72277
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: "This analytic was focusing on 2 separate and unrelated type of threats\
+ \ or actions. It was split into other analytics, namely:\r\n\r\nWindows Network\
+ \ Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277\r\nWindows\
+ \ Sensitive Group Discovery With Net / a23a0e20-0b1b-4a07-82e5-ec5f70811e7a"
+- deprecated_name: Remote System Discovery with Net
+ deprecated_id: 9df16706-04a2-41e2-bbfe-9b38b34409d3
+ replacement_name: Windows Sensitive Group Discovery With Net
+ replacement_id: a23a0e20-0b1b-4a07-82e5-ec5f70811e7a
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: DNS Query Requests Resolved by Unauthorized DNS Servers
+ deprecated_id: 1a67f15a-f4ff-4170-84e9-08cf6f75d6f6
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Suspicious Changes to File Associations
+ deprecated_id: 1b989a0e-0129-4446-a695-f193a5b746fc
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: GCP Detect high risk permissions by resource and account
+ deprecated_id: 2e70ef35-2187-431f-aedc-4503dc9b06ba
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Office Product Writing cab or inf
+ deprecated_id: f48cd1d4-125a-11ec-a447-acde48001122
+ replacement_name: Windows Office Product Dropped Cab or Inf File
+ replacement_id: dbdd251e-dd45-4ec9-a555-f5e151391746
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Identify New User Accounts
+ deprecated_id: 475b9e27-17e4-46e2-b7e2-648221be3b89
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Office Product Spawn CMD Process
+ deprecated_id: b8b19420-e892-11eb-9244-acde48001122
+ replacement_name: Windows Office Product Spawned Uncommon Process
+ replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Windows DLL Search Order Hijacking Hunt
+ deprecated_id: 79c7d0fc-60c7-41be-a616-ccda752efe89
+ replacement_name: Windows DLL Search Order Hijacking Hunt with Sysmon
+ replacement_id: 79c7d1fc-64c7-91be-a616-ccda752efe81
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: ASL AWS CreateAccessKey
+ deprecated_id: ccb3e4af-23d6-407f-9842-a26212816c9e
+ replacement_name: ASL AWS Create Access Key
+ replacement_id: 81a9f2fe-1697-473c-af1d-086b0d8b63c8
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Okta ThreatInsight Login Failure with High Unknown users
+ deprecated_id: 632663b0-4562-4aad-abe9-9f621a049738
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Detect Spike in Security Group Activity
+ deprecated_id: ada0f478-84a8-4641-a3f1-e32372d4bd53
+ replacement_name: Abnormally High Number Of Cloud Security Group API Calls
+ replacement_id: d4dfb7f3-7a37-498a-b5df-f19334e871af
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Office Product Spawning BITSAdmin
+ deprecated_id: e8c591f4-a6d7-11eb-8cf7-acde48001122
+ replacement_name: Windows Office Product Spawned Uncommon Process
+ replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Create local admin accounts using net exe
+ deprecated_id: b89919ed-fe5f-492c-b139-151bb162040e
+ replacement_name: Windows Create Local Administrator Account Via Net
+ replacement_id: 2c568c34-bb57-4b43-9d75-19c605b98e70
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Abnormally High AWS Instances Terminated by User - MLTK
+ deprecated_id: 1c02b86a-cd85-473e-a50b-014a9ac8fe3e
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Windows Office Product Spawning MSDT
+ deprecated_id: 127eba64-c981-40bf-8589-1830638864a7
+ replacement_name: Windows Office Product Spawned MSDT
+ replacement_id: a3148fad-3734-4b7f-9a71-62f08d39fab1
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Detect Spike in AWS API Activity
+ deprecated_id: ada0f478-84a8-4641-a3f1-d32362d4bd55
+ replacement_name: ''
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Office Product Spawning Windows Script Host
+ deprecated_id: b3628a5b-8d02-42fa-a891-eebf2351cbe1
+ replacement_name: Windows Office Product Spawned Uncommon Process
+ replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Prohibited Software On Endpoint
+ deprecated_id: a51bfe1a-94f0-48cc-b4e4-b6ae50145893
+ replacement_name: Attacker Tools On Endpoint
+ replacement_id: a51bfe1a-94f0-48cc-b4e4-16a110145893
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: AWS Cloud Provisioning From Previously Unseen Country
+ deprecated_id: ceb8d3d8-06cb-49eb-beaf-829526e33ff0
+ replacement_name: Cloud Provisioning Activity From Previously Unseen Country
+ replacement_id: 94994255-3acf-4213-9b3f-0494df03bb31
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Detect Critical Alerts from Security Tools
+ deprecated_id: 483e8a68-f2f7-45be-8fc9-bf725f0e22fd
+ replacement_name: Microsoft Defender ATP Alerts
+ replacement_id: 38f034ed-1598-46c8-95e8-14edf05fdf5d
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: As discussed internally, this analytic was too generic for an analyst to
+ do anything with it. It was deprecated in favor of the more specific approach
+ provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender
+ Incident Alerts. Going forward analytics from leveraging alerts from vendors will
+ have their specific analytics.
+- deprecated_name: Detect Critical Alerts from Security Tools
+ deprecated_id: 483e8a68-f2f7-45be-8fc9-bf725f0e22fd
+ replacement_name: Microsoft Defender Incident Alerts
+ replacement_id: 13435b55-afd8-46d4-9045-7d5457f430a5
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Excel Spawning PowerShell
+ deprecated_id: 42d40a22-9be3-11eb-8f08-acde48001122
+ replacement_name: Windows Office Product Spawned Uncommon Process
+ replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Office Application Spawn rundll32 process
+ deprecated_id: 958751e4-9c5f-11eb-b103-acde48001122
+ replacement_name: Windows Office Product Spawned Uncommon Process
+ replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Excessive Usage Of Net App
+ deprecated_id: 45e52536-ae42-11eb-b5c6-acde48001122
+ replacement_name: Windows Excessive Usage Of Net App
+ replacement_id: 355ba810-0a20-4215-8485-9ce3f87f2e38
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Elevated Group Discovery With Net
+ deprecated_id: a23a0e20-0b1b-4a07-82e5-ec5f70811e7a
+ replacement_name: Windows Sensitive Group Discovery With Net
+ replacement_id: d9eb7cda-5622-4722-bc88-7f2442f4b5af
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Local Account Discovery with Net
+ deprecated_id: 5d0d4830-0133-11ec-bae3-acde48001122
+ replacement_name: Windows User Discovery Via Net
+ replacement_id: 7742987e-88c1-476b-a626-a869e088ab72
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Windows Command Shell Fetch Env Variables
+ deprecated_id: 048839e4-1eaa-43ff-8a22-86d17f6fcc13
+ replacement_name: Windows List ENV Variables Via SET Command From Uncommon Parent
+ replacement_id: aec157f4-8783-4584-aca6-754c4dc7fba9
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Suspicious Email - UBA Anomaly
+ deprecated_id: 56e877a6-1455-4479-ad16-0550dc1e33f8
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Detect web traffic to dynamic domain providers
+ deprecated_id: 134da869-e264-4a8f-8d7e-fcd01c18f301
+ replacement_name: Detect hosts connecting to dynamic domain providers
+ replacement_id: a1e761ac-1344-4dbd-88b2-3f34c912d359
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Updated to use a different log source
+- deprecated_name: Okta Failed SSO Attempts
+ deprecated_id: 371a6545-2618-4032-ad84-93386b8698c5
+ replacement_name: Okta Unauthorized Access to Application
+ replacement_id: 5f661629-9750-4cb9-897c-1f05d6db8727
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Kubernetes AWS detect RBAC authorization by account
+ deprecated_id: de7264ed-3ed9-4fef-bb01-6eefc87cefe8
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Kubernetes Azure detect service accounts forbidden failure access
+ deprecated_id: 019690d7-420f-4da0-b320-f27b09961514
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Remote Registry Key modifications
+ deprecated_id: c9f4b923-f8af-4155-b697-1354f5dcbc5e
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: O365 Suspicious User Email Forwarding
+ deprecated_id: f8dfe015-dbb3-4569-ba75-b13787e06aa4
+ replacement_name: O365 Mailbox Email Forwarding Enabled
+ replacement_id: 0b6bc75c-05d1-4101-9fc3-97e706168f24
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Office Product Spawning MSHTA
+ deprecated_id: 6078fa20-a6d2-11eb-b662-acde48001122
+ replacement_name: Windows Office Product Spawned Uncommon Process
+ replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Kubernetes AWS detect most active service accounts by pod
+ deprecated_id: 5b30b25d-7d32-42d8-95ca-64dfcd9076e6
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Correlation by Repository and Risk
+ deprecated_id: 8da9fdd9-6a1b-4ae0-8a34-8c25e6be9687
+ replacement_name: Risk Rule for Dev Sec Ops by Repository
+ replacement_id: 161bc0ca-4651-4c13-9c27-27770660cf67
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the datamodel
+- deprecated_name: Kubernetes Azure detect RBAC authorization by account
+ deprecated_id: 47af7d20-0607-4079-97d7-7a29af58b54e
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Clients Connecting to Multiple DNS Servers
+ deprecated_id: 74ec6f18-604b-4202-a567-86b2066be3ce
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Excessive Service Stop Attempt
+ deprecated_id: ae8d3f4a-acd7-11eb-8846-acde48001122
+ replacement_name: Windows Excessive Service Stop Attempt
+ replacement_id: 8f3a614f-6b98-4f7d-82dd-d0df38452a8b
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Multiple Okta Users With Invalid Credentials From The Same IP
+ deprecated_id: 19cba45f-cad3-4032-8911-0c09e0444552
+ replacement_name: Okta Multiple Users Failing To Authenticate From Ip
+ replacement_id: de365ffa-42f5-46b5-b43f-fa72290b8218
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Suspicious writes to System Volume Information
+ deprecated_id: cd6297cd-2bdd-4aa1-84aa-5d2f84228fac
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Detect new user AWS Console Login
+ deprecated_id: ada0f478-84a8-4641-a3f3-d82362dffd75
+ replacement_name: Detect AWS Console Login by New User
+ replacement_id: bc91a8cd-35e7-4bb2-6140-e756cc46fd71
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Domain Account Discovery With Net App
+ deprecated_id: 98f6a534-04c2-11ec-96b2-acde48001122
+ replacement_name: Windows User Discovery Via Net
+ replacement_id: 5d0d4830-0133-11ec-bae3-acde48001122
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: 'This analytic was a TTP that looked only for commands that tries to query
+ info about the users via net user /do. This had a couple of issues, such as triggering
+ on creation of users via the /add flag etc..
+
+ It was deprecated in favor of a more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122'
+- deprecated_name: Detection of DNS Tunnels
+ deprecated_id: 104658f4-afdc-499f-9719-17a43f9826f4
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Detect DNS requests to Phishing Sites leveraging EvilGinx2
+ deprecated_id: 24dd17b1-e2fb-4c31-878c-d4f226595bfa
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Office Document Creating Schedule Task
+ deprecated_id: cc8b7b74-9d0f-11eb-8342-acde48001122
+ replacement_name: Windows Office Product Loading Taskschd DLL
+ replacement_id: d7297cfa-1f04-4714-bfbe-3679e0666959
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Okta Account Locked Out
+ deprecated_id: d650c0ae-bdc5-400e-9f0f-f7aa0a010ef1
+ replacement_name: Okta Multiple Accounts Locked Out
+ replacement_id: a511426e-184f-4de6-8711-cfd2af29d1e1
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Unsuccessful Netbackup backups
+ deprecated_id: a34aae96-ccf8-4aaa-952c-3ea21444444f
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Detect Mimikatz Via PowerShell And EventCode 4703
+ deprecated_id: 98917be2-bfc8-475a-8618-a9bb06575188
+ replacement_name: Detect Mimikatz With PowerShell Script Block Logging
+ replacement_id: 8148c29c-c952-11eb-9255-acde48001122
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Updated to a new detection name
+- deprecated_name: Winword Spawning Cmd
+ deprecated_id: 6fcbaedc-a37b-11eb-956b-acde48001122
+ replacement_name: Windows Office Product Spawned Uncommon Process
+ replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: GCP Kubernetes cluster scan detection
+ deprecated_id: db5957ec-0144-4c56-b512-9dccbe7a2d26
+ replacement_name: Kubernetes Scanning by Unauthenticated IP Address
+ replacement_id: f9cadf4e-df22-4f4e-a08f-9d3344c2165d
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Kubernetes GCP detect suspicious kubectl calls
+ deprecated_id: a5bed417-070a-41f2-a1e4-82b6aa281557
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: gcp detect oauth token abuse
+ deprecated_id: a7e9f7bb-8901-4ad0-8d88-0a4ab07b1972
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Correlation by User and Risk
+ deprecated_id: 610e12dc-b6fa-4541-825e-4a0b3b6f6773
+ replacement_name: Risk Rule for Dev Sec Ops by Repository
+ replacement_id: 161bc0ca-4651-4c13-9c27-27770660cf67
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the datamodel
+- deprecated_name: Processes created by netsh
+ deprecated_id: b89919ed-fe5f-492c-b139-95dbb162041e
+ replacement_name: Processes launching netsh
+ replacement_id: b89919ed-fe5f-492c-b139-95dbb162040e
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Updated to a new detection name
+- deprecated_name: Office Product Spawning Wmic
+ deprecated_id: ffc236d6-a6c9-11eb-95f1-acde48001122
+ replacement_name: Windows Office Product Spawned Uncommon Process
+ replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Extraction of Registry Hives
+ deprecated_id: 8bbb7d58-b360-11eb-ba21-acde48001122
+ replacement_name: Windows Sensitive Registry Hive Dump Via CommandLine
+ replacement_id: 5aaff29d-0cce-405b-9ee8-5d06b49d045e
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Attempt To Stop Security Service
+ deprecated_id: c8e349c6-b97c-486e-8949-bd7bcd1f3910
+ replacement_name: Windows Attempt To Stop Security Service
+ replacement_id: 9ed27cea-4e27-4eff-b2c6-aac9e78a7517
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Windows MSIExec With Network Connections
+ deprecated_id: 827409a1-5393-4d8d-8da4-bbb297c262a7
+ replacement_name: Windows HTTP Network Communication From MSIExec
+ replacement_id: b0fd38c7-f71a-43a2-870e-f3ca06bcdd99
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Windows Query Registry Reg Save
+ deprecated_id: cbee60c1-b776-456f-83c2-faa56bdbe6c6
+ replacement_name: Windows Registry Entries Exported Via Reg
+ replacement_id: 466379bc-0f47-476c-8202-16ef38112e0d
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Cloud Network Access Control List Deleted
+ deprecated_id: 021abc51-1862-41dd-ad43-43c739c0a983
+ replacement_name: AWS Network Access Control List Deleted
+ replacement_id: ada0f478-84a8-4641-a3f1-d82362d6fd75
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: O365 Suspicious Rights Delegation
+ deprecated_id: b25d2973-303e-47c8-bacd-52b61604c6a7
+ replacement_name: O365 Elevated Mailbox Permission Assigned
+ replacement_id: 2246c142-a678-45f8-8546-aaed7e0efd30
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Abnormally High AWS Instances Launched by User - MLTK
+ deprecated_id: dec41ad5-d579-42cb-b4c6-f5dbb778bbe5
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Reg exe used to hide files directories via registry keys
+ deprecated_id: 61a7d1e6-f5d4-41d9-a9be-39a1ffe69459
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Detect Long DNS TXT Record Response
+ deprecated_id: 05437c07-62f5-452e-afdc-04dd44815bb9
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Password Policy Discovery with Net
+ deprecated_id: 09336538-065a-11ec-8665-acde48001122
+ replacement_name: Windows Password Policy Discovery with Net
+ replacement_id: e52f7865-be78-46bf-b7ed-150fbe447613
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: AWS Cloud Provisioning From Previously Unseen IP Address
+ deprecated_id: 42e15012-ac14-4801-94f4-f1acbe64880b
+ replacement_name: Cloud Provisioning Activity From Previously Unseen IP Address
+ replacement_id: f86a8ec9-b042-45eb-92f4-e9ed1d781078
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Network Connection Discovery With Net
+ deprecated_id: 640337e5-6e41-4b7f-af06-9d9eab5e1e2d
+ replacement_name: Windows Network Connection Discovery Via Net
+ replacement_id: 86a5b949-679b-4197-8d4c-9c180a818c45
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Kubernetes Azure detect suspicious kubectl calls
+ deprecated_id: 4b6d1ba8-0000-4cec-87e6-6cbbd71651b5
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Kubernetes GCP detect sensitive role access
+ deprecated_id: a46923f6-36b9-4806-a681-31f314907c30
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Detect Webshell Exploit Behavior
+ deprecated_id: 22597426-6dbd-49bd-bcdc-4ec19857192f
+ replacement_name: Windows Suspicious Child Process Spawned From WebServer
+ replacement_id: 2d4470ef-7158-4b47-b68b-1f7f16382156
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: DNS record changed
+ deprecated_id: 44d3a43e-dcd5-49f7-8356-5209bb369065
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Unsigned Image Loaded by LSASS
+ deprecated_id: 56ef054c-76ef-45f9-af4a-a634695dcd65
+ replacement_name: ''
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Detect USB device insertion
+ deprecated_id: 104658f4-afdc-499f-9719-17a43f9826f5
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Windows Network Share Interaction With Net
+ deprecated_id: 4dc3951f-b3f8-4f46-b412-76a483f72277
+ replacement_name: Windows Network Share Interaction Via Net
+ replacement_id: e51fbdb0-0be0-474f-92ea-d289f71a695e
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Account Discovery With Net App
+ deprecated_id: 339805ce-ac30-11eb-b87d-acde48001122
+ replacement_name: Windows Excessive Usage Of Net App
+ replacement_id: 45e52536-ae42-11eb-b5c6-acde48001122
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: This analytic was a TTP that focused on unrelated things and called account
+ discovery. Since there were other detection that overlapped with it. I choose
+ to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122
+ / Windows Excessive Usage Of Net App.
+- deprecated_name: Change Default File Association
+ deprecated_id: 462d17d8-1f71-11ec-ad07-acde48001122
+ replacement_name: Windows New Default File Association Value Set
+ replacement_id: 7d1f031f-f1c9-43be-8b0b-c4e3e8a8928a
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Windows Lateral Tool Transfer RemCom
+ deprecated_id: e373a840-5bdc-47ef-b2fd-9cc7aaf387f0
+ replacement_name: Windows Service Execution RemCom
+ replacement_id: 7e3d68db-ea4d-419b-adbd-e14a525ecf09
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Updated to a new detection name
+- deprecated_name: Office Document Executing Macro Code
+ deprecated_id: b12c89bc-9d06-11eb-a592-acde48001122
+ replacement_name: Windows Office Product Loading VBE7 DLL
+ replacement_id: 7cfec906-2697-43f7-898b-83634a051d9a
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Okta Account Lockout Events
+ deprecated_id: 62b70968-a0a5-4724-8ac4-67871e6f544d
+ replacement_name: Okta Multiple Accounts Locked Out
+ replacement_id: a511426e-184f-4de6-8711-cfd2af29d1e1
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Abnormally High AWS Instances Launched by User
+ deprecated_id: 2a9b80d3-6340-4345-b5ad-290bf5d0dac4
+ replacement_name: Abnormally High Number Of Cloud Instances Launched
+ replacement_id: f2361e9f-3928-496c-a556-120cd4223a65
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: EC2 Instance Modified With Previously Unseen User
+ deprecated_id: 56f91724-cf3f-4666-84e1-e3712fb41e76
+ replacement_name: Cloud API Calls From Previously Unseen User Roles
+ replacement_id: 2181ad1f-1e73-4d0c-9780-e8880482a08f
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Windows Valid Account With Never Expires Password
+ deprecated_id: 73a931db-1830-48b3-8296-cd9cfa09c3c8
+ replacement_name: Windows Set Account Password Policy To Unlimited Via Net
+ replacement_id: 11f93009-8083-43fd-82a7-821fcbdc8342
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Windows hosts file modification
+ deprecated_id: 06a6fc63-a72d-41dc-8736-7e3dd9612116
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: MSHTML Module Load in Office Product
+ deprecated_id: 5f1c168e-118b-11ec-84ff-acde48001122
+ replacement_name: Windows Office Product Loaded MSHTML Module
+ replacement_id: 4cc015c9-687c-40d2-adcc-46350f66e10c
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Abnormally High AWS Instances Terminated by User
+ deprecated_id: 8d301246-fccf-45e2-a8e7-3655fd14379c
+ replacement_name: Abnormally High Number Of Cloud Instances Destroyed
+ replacement_id: ef629fc9-1583-4590-b62a-f2247fbf7bbf
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Web Fraud - Account Harvesting
+ deprecated_id: bf1d7b5c-df2f-4249-a401-c09fdc221ddf
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Office Spawning Control
+ deprecated_id: 053e027c-10c7-11ec-8437-acde48001122
+ replacement_name: Windows Office Product Spawned Control
+ replacement_id: 081c485d-ac8d-4bee-ad4c-525772fead4d
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Detect Activity Related to Pass the Hash Attacks
+ deprecated_id: f5939373-8054-40ad-8c64-cec478a22a4b
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Deleting Of Net Users
+ deprecated_id: 1c8c6f66-acce-11eb-aafb-acde48001122
+ replacement_name: Windows User Deletion Via Net
+ replacement_id: b0b6fd2c-8953-4d1b-8f7b-56075ea6ab3e
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Suspicious File Write
+ deprecated_id: 57f76b8a-32f0-42ed-b358-d9fa3ca7bac8
+ replacement_name: ''
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: AWS EKS Kubernetes cluster sensitive object access
+ deprecated_id: 7f227943-2196-4d4d-8d6a-ac8cb308e61c
+ replacement_name: Kubernetes Abuse of Secret by Unusual Location
+ replacement_id: 40a064c1-4ec1-4381-9e35-61192ba8ef82
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Spectre and Meltdown Vulnerable Systems
+ deprecated_id: 354be8e0-32cd-4da0-8c47-796de13b60ea
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: EC2 Instance Started With Previously Unseen User
+ deprecated_id: 22773e84-bac0-4595-b086-20d3f735b4f1
+ replacement_name: Cloud Compute Instance Created By Previously Unseen User
+ replacement_id: 37a0ec8d-827e-4d6d-8025-cedf31f3a149
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Office Product Spawning CertUtil
+ deprecated_id: 6925fe72-a6d5-11eb-9e17-acde48001122
+ replacement_name: Windows Office Product Spawned Uncommon Process
+ replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Kubernetes GCP detect RBAC authorizations by account
+ deprecated_id: 99487de3-7192-4b41-939d-fbe9acfb1340
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Office Application Drop Executable
+ deprecated_id: 73ce70c4-146d-11ec-9184-acde48001122
+ replacement_name: Windows Office Product Dropped Uncommon File
+ replacement_id: 7ac0fced-9eae-4381-a748-90dcd1aa9393
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Kubernetes Azure active service accounts by pod namespace
+ deprecated_id: 55a2264a-b7f0-45e5-addd-1e5ab3415c72
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Kubernetes Azure pod scan fingerprint
+ deprecated_id: 86aad3e0-732f-4f66-bbbc-70df448e461d
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Detect Spike in Network ACL Activity
+ deprecated_id: ada0f478-84a8-4641-a1f1-e32372d4bd53
+ replacement_name: Abnormally High Number Of Cloud Infrastructure API Calls
+ replacement_id: 0840ddf1-8c89-46ff-b730-c8d6722478c0
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Suspicious Powershell Command-Line Arguments
+ deprecated_id: 2cdb91d2-542c-497f-b252-be495e71f38c
+ replacement_name: Malicious PowerShell Process - Encoded Command
+ replacement_id: c4db14d9-7909-48b4-a054-aa14d89dbb19
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Office Application Spawn Regsvr32 process
+ deprecated_id: 2d9fc90c-f11f-11eb-9300-acde48001122
+ replacement_name: Windows Office Product Spawned Uncommon Process
+ replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Detect API activity from users without MFA
+ deprecated_id: 4d46e8bd-4072-48e4-92db-0325889ef894
+ replacement_name: AWS Successful Single-Factor Authentication
+ replacement_id: a520b1fe-cc9e-4f56-b762-18354594c52f
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Kubernetes Azure detect sensitive object access
+ deprecated_id: 1bba382b-07fd-4ffa-b390-8002739b76e8
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Web Fraud - Password Sharing Across Accounts
+ deprecated_id: 31337a1a-53b9-4e05-96e9-55c934cb71d3
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Disabling Net User Account
+ deprecated_id: c0325326-acd6-11eb-98c2-acde48001122
+ replacement_name: Windows User Disabled Via Net
+ replacement_id: b0359e05-c87b-4354-83d8-aee0d890243f
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: GCP Detect accounts with high risk roles by project
+ deprecated_id: 27af8c15-38b0-4408-b339-920170724adb
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Kubernetes GCP detect service accounts forbidden failure access
+ deprecated_id: 7094808d-432a-48e7-bb3c-77e96c894f3b
+ replacement_name: '- '
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Extended Period Without Successful Netbackup Backups
+ deprecated_id: a34aae96-ccf8-4aef-952c-3ea214444440
+ replacement_name: '-'
+ replacement_id: ''
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Office Product Spawning Rundll32 with no DLL
+ deprecated_id: c661f6be-a38c-11eb-be57-acde48001122
+ replacement_name: Windows Office Product Spawned Rundll32 With No DLL
+ replacement_id: f28e787e-69ca-480e-9f98-ab970e6d4bcc
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Renamed and updated logic
+- deprecated_name: Okta ThreatInsight Suspected PasswordSpray Attack
+ deprecated_id: 25dbad05-6682-4dd5-9ce9-8adecf0d9ae2
+ replacement_name: Okta ThreatInsight Threat Detected
+ replacement_id: 140504ae-5fe2-4d65-b2bc-a211813fbca6
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+- deprecated_name: Net Localgroup Discovery
+ deprecated_id: 54f5201e-155b-11ec-a6e2-acde48001122
+ replacement_name: Windows Group Discovery Via Net
+ replacement_id: c5c8e0f3-147a-43da-bf04-4cfaec27dc44
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44
+ / Windows Group Discovery Via Net
+- deprecated_name: Uncommon Processes On Endpoint
+ deprecated_id: 29ccce64-a10c-4389-a45f-337cb29ba1f7
+ replacement_name: Attacker Tools On Endpoint
+ replacement_id: a51bfe1a-94f0-48cc-b4e4-16a110145893
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: ''
+- deprecated_name: Dump LSASS via procdump Rename
+ deprecated_id: 21276daa-663d-11eb-ae93-0242ac130002
+ replacement_name: Dump LSASS via procdump
+ replacement_id: 3742ebfe-64c2-11eb-ae93-0242ac130002
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Updated to a new detection name
+- deprecated_name: Okta Two or More Rejected Okta Pushes
+ deprecated_id: d93f785e-4c2c-4262-b8c7-12b77a13fd39
+ replacement_name: Okta Multiple Failed MFA Requests For User
+ replacement_id: 826dbaae-a1e6-4c8c-b384-d16898956e73
+ date: '2025-01-28'
+ escu_version: 5.0.0
+ migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
From f2247bc25127926c490a30ff66de97e2df265905 Mon Sep 17 00:00:00 2001
From: research-bot
Date: Tue, 28 Jan 2025 10:42:27 -0800
Subject: [PATCH 05/67] adding a file
---
.../deprecated_detection_mapping.yml | 0
1 file changed, 0 insertions(+), 0 deletions(-)
rename deprecated_detection_mapping.yml => deprecated/deprecated_detection_mapping.yml (100%)
diff --git a/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml
similarity index 100%
rename from deprecated_detection_mapping.yml
rename to deprecated/deprecated_detection_mapping.yml
From 0db344513f8c513f37e4079d243e1a2393da44e2 Mon Sep 17 00:00:00 2001
From: pyth0n1c
Date: Fri, 31 Jan 2025 16:00:48 -0800
Subject: [PATCH 06/67] add deprecation info into the detections themselves
---
...ly_high_aws_instances_launched_by_user.yml | 8 ++++
..._aws_instances_launched_by_user___mltk.yml | 6 +++
..._high_aws_instances_terminated_by_user.yml | 8 ++++
...ws_instances_terminated_by_user___mltk.yml | 6 +++
.../account_discovery_with_net_app.yml | 20 ++++++++-
.../deprecated/asl_aws_createaccesskey.yml | 8 ++++
.../asl_aws_excessive_security_scanning.yml | 6 +++
.../asl_aws_password_policy_changes.yml | 6 +++
.../attempt_to_stop_security_service.yml | 26 ++++++-----
...dential_dump_from_registry_via_reg_exe.yml | 25 +++++++----
...ovisioning_from_previously_unseen_city.yml | 12 ++++-
...sioning_from_previously_unseen_country.yml | 22 ++++++---
...ning_from_previously_unseen_ip_address.yml | 8 ++++
...isioning_from_previously_unseen_region.yml | 12 ++++-
...rnetes_cluster_sensitive_object_access.yml | 8 ++++
.../change_default_file_association.yml | 25 +++++++----
...nts_connecting_to_multiple_dns_servers.yml | 6 +++
...ud_network_access_control_list_deleted.yml | 8 ++++
...cmdline_tool_not_executed_in_cmd_shell.yml | 7 +++
.../correlation_by_repository_and_risk.yml | 7 +++
.../correlation_by_user_and_risk.yml | 7 +++
...ate_local_admin_accounts_using_net_exe.yml | 24 ++++++----
.../deprecated/deleting_of_net_users.yml | 23 ++++++----
...ivity_related_to_pass_the_hash_attacks.yml | 6 +++
...ct_api_activity_from_users_without_mfa.yml | 8 ++++
...pi_activities_from_unapproved_accounts.yml | 6 +++
...ct_critical_alerts_from_security_tools.yml | 45 +++++++++++++++++--
...to_phishing_sites_leveraging_evilginx2.yml | 12 +++--
.../detect_long_dns_txt_record_response.yml | 6 +++
.../detect_mimikatz_using_loaded_images.yml | 6 +++
...katz_via_powershell_and_eventcode_4703.yml | 7 +++
.../detect_new_api_calls_from_user_roles.yml | 14 ++++--
.../detect_new_user_aws_console_login.yml | 14 ++++--
...system_network_configuration_discovery.yml | 26 ++++++-----
.../detect_spike_in_aws_api_activity.yml | 7 +++
.../detect_spike_in_network_acl_activity.yml | 8 ++++
...etect_spike_in_security_group_activity.yml | 8 ++++
.../detect_usb_device_insertion.yml | 6 +++
...eb_traffic_to_dynamic_domain_providers.yml | 7 +++
.../detect_webshell_exploit_behavior.yml | 26 ++++++-----
.../deprecated/detection_of_dns_tunnels.yml | 6 +++
.../deprecated/disabling_net_user_account.yml | 23 ++++++----
...s_resolved_by_unauthorized_dns_servers.yml | 6 +++
detections/deprecated/dns_record_changed.yml | 6 +++
.../domain_account_discovery_with_net_app.yml | 20 ++++++++-
.../domain_group_discovery_with_net.yml | 17 ++++++-
.../dump_lsass_via_procdump_rename.yml | 7 +++
...e_modified_with_previously_unseen_user.yml | 8 ++++
...ce_started_in_previously_unseen_region.yml | 8 ++++
...nce_started_with_previously_unseen_ami.yml | 8 ++++
...d_with_previously_unseen_instance_type.yml | 8 ++++
...ce_started_with_previously_unseen_user.yml | 8 ++++
.../elevated_group_discovery_with_net.yml | 24 ++++++----
.../deprecated/excel_spawning_powershell.yml | 26 +++++++----
.../excessive_service_stop_attempt.yml | 24 ++++++----
.../deprecated/excessive_usage_of_net_app.yml | 24 ++++++----
...n_of_file_with_spaces_before_extension.yml | 7 +++
...d_without_successful_netbackup_backups.yml | 6 +++
.../extraction_of_registry_hives.yml | 25 +++++++----
.../first_time_seen_command_line_argument.yml | 7 +++
...counts_with_high_risk_roles_by_project.yml | 6 +++
...sk_permissions_by_resource_and_account.yml | 6 +++
.../gcp_detect_oauth_token_abuse.yml | 6 +++
.../gcp_kubernetes_cluster_scan_detection.yml | 8 ++++
.../deprecated/identify_new_user_accounts.yml | 7 +++
...ct_most_active_service_accounts_by_pod.yml | 7 +++
...s_detect_rbac_authorization_by_account.yml | 7 +++
...netes_aws_detect_sensitive_role_access.yml | 7 +++
...vice_accounts_forbidden_failure_access.yml | 7 +++
...tive_service_accounts_by_pod_namespace.yml | 7 +++
...e_detect_rbac_authorization_by_account.yml | 7 +++
...s_azure_detect_sensitive_object_access.yml | 7 +++
...tes_azure_detect_sensitive_role_access.yml | 7 +++
...vice_accounts_forbidden_failure_access.yml | 7 +++
..._azure_detect_suspicious_kubectl_calls.yml | 7 +++
.../kubernetes_azure_pod_scan_fingerprint.yml | 7 +++
.../kubernetes_azure_scan_fingerprint.yml | 7 +++
...ct_most_active_service_accounts_by_pod.yml | 7 +++
..._detect_rbac_authorizations_by_account.yml | 7 +++
...tes_gcp_detect_sensitive_object_access.yml | 7 +++
...netes_gcp_detect_sensitive_role_access.yml | 7 +++
...vice_accounts_forbidden_failure_access.yml | 7 +++
...es_gcp_detect_suspicious_kubectl_calls.yml | 7 +++
.../linux_auditd_find_private_keys.yml | 24 ++++++----
.../local_account_discovery_with_net.yml | 24 ++++++----
.../monitor_dns_for_brand_abuse.yml | 7 +++
.../mshtml_module_load_in_office_product.yml | 23 ++++++----
...h_invalid_credentials_from_the_same_ip.yml | 8 ++++
.../deprecated/net_localgroup_discovery.yml | 18 +++++++-
.../network_connection_discovery_with_net.yml | 25 +++++++----
...o365_suspicious_admin_email_forwarding.yml | 8 ++++
.../o365_suspicious_rights_delegation.yml | 8 ++++
.../o365_suspicious_user_email_forwarding.yml | 8 ++++
.../office_application_drop_executable.yml | 24 ++++++----
...ice_application_spawn_regsvr32_process.yml | 26 +++++++----
...ice_application_spawn_rundll32_process.yml | 24 ++++++----
...office_document_creating_schedule_task.yml | 23 ++++++----
.../office_document_executing_macro_code.yml | 22 +++++----
...ment_spawned_child_process_to_download.yml | 25 +++++++----
.../office_product_spawn_cmd_process.yml | 18 +++++++-
.../office_product_spawning_bitsadmin.yml | 26 +++++++----
.../office_product_spawning_certutil.yml | 25 +++++++----
.../office_product_spawning_mshta.yml | 28 +++++++-----
..._product_spawning_rundll32_with_no_dll.yml | 24 ++++++----
...e_product_spawning_windows_script_host.yml | 27 +++++++----
.../office_product_spawning_wmic.yml | 28 +++++++-----
.../office_product_writing_cab_or_inf.yml | 23 ++++++----
.../deprecated/office_spawning_control.yml | 24 ++++++----
.../deprecated/okta_account_locked_out.yml | 8 ++++
.../okta_account_lockout_events.yml | 8 ++++
.../deprecated/okta_failed_sso_attempts.yml | 8 ++++
..._login_failure_with_high_unknown_users.yml | 6 +++
...insight_suspected_passwordspray_attack.yml | 8 ++++
.../okta_two_or_more_rejected_okta_pushes.yml | 8 ++++
.../osquery_pack___coldroot_detection.yml | 6 +++
.../password_policy_discovery_with_net.yml | 26 ++++++-----
.../deprecated/processes_created_by_netsh.yml | 7 +++
.../prohibited_software_on_endpoint.yml | 7 +++
...de_files_directories_via_registry_keys.yml | 7 +++
.../remote_registry_key_modifications.yml | 6 +++
.../remote_system_discovery_with_net.yml | 38 ++++++++++++++--
...led_tasks_used_in_badrabbit_ransomware.yml | 7 +++
...pectre_and_meltdown_vulnerable_systems.yml | 6 +++
...uspicious_changes_to_file_associations.yml | 6 +++
.../suspicious_email___uba_anomaly.yml | 6 +++
.../deprecated/suspicious_file_write.yml | 7 +++
...ious_powershell_command_line_arguments.yml | 7 +++
.../deprecated/suspicious_rundll32_rename.yml | 6 +++
...us_writes_to_system_volume_information.yml | 6 +++
.../uncommon_processes_on_endpoint.yml | 7 +++
.../unsigned_image_loaded_by_lsass.yml | 7 +++
.../unsuccessful_netbackup_backups.yml | 6 +++
.../web_fraud___account_harvesting.yml | 6 +++
.../web_fraud___anomalous_user_clickspeed.yml | 6 +++
...aud___password_sharing_across_accounts.yml | 6 +++
...dows_command_shell_fetch_env_variables.yml | 24 ++++++----
...indows_connhost_exe_started_forcefully.yml | 6 +++
...indows_dll_search_order_hijacking_hunt.yml | 8 ++++
.../windows_hosts_file_modification.yml | 6 +++
.../windows_lateral_tool_transfer_remcom.yml | 7 +++
.../windows_modify_registry_reg_restore.yml | 25 +++++++----
...ndows_msiexec_with_network_connections.yml | 24 ++++++----
...ows_network_share_interaction_with_net.yml | 21 ++++++---
.../windows_office_product_spawning_msdt.yml | 27 ++++++-----
.../windows_query_registry_reg_save.yml | 23 ++++++----
...id_account_with_never_expires_password.yml | 24 ++++++----
.../deprecated/winword_spawning_cmd.yml | 29 +++++++-----
.../winword_spawning_powershell.yml | 29 +++++++-----
.../winword_spawning_windows_script_host.yml | 17 +++++--
149 files changed, 1545 insertions(+), 404 deletions(-)
diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml b/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml
index e46dec6369..a84ac20e7c 100644
--- a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml
+++ b/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml
@@ -4,6 +4,14 @@ version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Abnormally High Number Of Cloud Instances Launched
type: Anomaly
description: This search looks for AWS CloudTrail events where a user successfully
launches an abnormally high number of instances. This search is deprecated and have
diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml b/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml
index 9acc4411b2..8279df5c30 100644
--- a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml
+++ b/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml
@@ -4,6 +4,12 @@ version: 5
date: '2024-11-14'
author: Jason Brewer, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: Anomaly
description: This search looks for AWS CloudTrail events where a user successfully
launches an abnormally high number of instances. This search is deprecated and have
diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml
index ae3c15024b..f028df1a26 100644
--- a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml
+++ b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml
@@ -4,6 +4,14 @@ version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Abnormally High Number Of Cloud Instances Destroyed
type: Anomaly
description: This search looks for AWS CloudTrail events where an abnormally high
number of instances were successfully terminated by a user in a 10-minute window.
diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml
index 04f88a704a..adcfe17ca3 100644
--- a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml
+++ b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml
@@ -4,6 +4,12 @@ version: 5
date: '2024-11-14'
author: Jason Brewer, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: Anomaly
description: This search looks for AWS CloudTrail events where a user successfully
terminates an abnormally high number of instances. This search is deprecated and
diff --git a/detections/deprecated/account_discovery_with_net_app.yml b/detections/deprecated/account_discovery_with_net_app.yml
index ce8d2fa45f..323489ac89 100644
--- a/detections/deprecated/account_discovery_with_net_app.yml
+++ b/detections/deprecated/account_discovery_with_net_app.yml
@@ -4,8 +4,26 @@ version: 8
date: '2025-01-13'
author: Teoderick Contreras, Splunk, TheLawsOfChaos, Github Community
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: This analytic was a TTP that focused on unrelated things and called account
+ discovery. Since there were other detection that overlapped with it. I choose
+ to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122
+ / Windows Excessive Usage Of Net App.
+ replacement_content:
+ - Windows Excessive Usage Of Net App
type: TTP
-description: The following analytic has been deprecated in favour of the more generic "45e52536-ae42-11eb-b5c6-acde48001122". The following analytic detects potential account discovery activities using the 'net' command, commonly employed by malware like Trickbot for reconnaissance. It leverages Endpoint Detection and Response (EDR) data, focusing on specific command-line patterns and process relationships. This activity is significant as it often precedes further malicious actions, such as lateral movement or privilege escalation. If confirmed malicious, attackers could gain valuable information about user accounts, enabling them to escalate privileges or move laterally within the network, posing a significant security risk.
+description: The following analytic has been deprecated in favour of the more generic
+ "45e52536-ae42-11eb-b5c6-acde48001122". The following analytic detects potential
+ account discovery activities using the 'net' command, commonly employed by malware
+ like Trickbot for reconnaissance. It leverages Endpoint Detection and Response (EDR)
+ data, focusing on specific command-line patterns and process relationships. This
+ activity is significant as it often precedes further malicious actions, such as
+ lateral movement or privilege escalation. If confirmed malicious, attackers could
+ gain valuable information about user accounts, enabling them to escalate privileges
+ or move laterally within the network, posing a significant security risk.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/asl_aws_createaccesskey.yml b/detections/deprecated/asl_aws_createaccesskey.yml
index e7588388f6..33967e66c7 100644
--- a/detections/deprecated/asl_aws_createaccesskey.yml
+++ b/detections/deprecated/asl_aws_createaccesskey.yml
@@ -4,6 +4,14 @@ version: 3
date: '2024-11-14'
author: Patrick Bareiss, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - ASL AWS Create Access Key
type: Hunting
description: This detection rule monitors for the creation of AWS Identity and Access
Management (IAM) access keys. An IAM access key consists of an access key ID and
diff --git a/detections/deprecated/asl_aws_excessive_security_scanning.yml b/detections/deprecated/asl_aws_excessive_security_scanning.yml
index 0ee3a463e3..483db858df 100644
--- a/detections/deprecated/asl_aws_excessive_security_scanning.yml
+++ b/detections/deprecated/asl_aws_excessive_security_scanning.yml
@@ -4,6 +4,12 @@ version: 4
date: '2024-11-14'
author: Patrick Bareiss, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: Anomaly
description: This search looks for AWS CloudTrail events and analyse the amount of
eventNames which starts with Describe by a single user. This indicates that this
diff --git a/detections/deprecated/asl_aws_password_policy_changes.yml b/detections/deprecated/asl_aws_password_policy_changes.yml
index d791f17208..6ee31b185c 100644
--- a/detections/deprecated/asl_aws_password_policy_changes.yml
+++ b/detections/deprecated/asl_aws_password_policy_changes.yml
@@ -4,6 +4,12 @@ version: 3
date: '2024-11-14'
author: Patrick Bareiss, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: Hunting
description: This search looks for AWS CloudTrail events from Amazon Security Lake
where a user is making successful API calls to view/update/delete the existing password
diff --git a/detections/deprecated/attempt_to_stop_security_service.yml b/detections/deprecated/attempt_to_stop_security_service.yml
index 6527800094..864f401149 100644
--- a/detections/deprecated/attempt_to_stop_security_service.yml
+++ b/detections/deprecated/attempt_to_stop_security_service.yml
@@ -4,17 +4,23 @@ version: 9
date: '2025-01-24'
author: Rico Valdez, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Attempt To Stop Security Service
type: TTP
-description: The following analytic has been deprecated.
- The following analytic detects attempts to stop security-related services
- on an endpoint, which may indicate malicious activity. It leverages data from Endpoint
- Detection and Response (EDR) agents, specifically searching for processes involving
- the "sc.exe" command with the "stop" parameter. This activity is significant because
- disabling security services can undermine the organization's security posture, potentially
- leading to unauthorized access, data exfiltration, or further attacks like malware
- installation or privilege escalation. If confirmed malicious, this behavior could
- compromise the endpoint and the entire network, necessitating immediate investigation
- and response.
+description: The following analytic has been deprecated. The following analytic detects
+ attempts to stop security-related services on an endpoint, which may indicate malicious
+ activity. It leverages data from Endpoint Detection and Response (EDR) agents, specifically
+ searching for processes involving the "sc.exe" command with the "stop" parameter.
+ This activity is significant because disabling security services can undermine the
+ organization's security posture, potentially leading to unauthorized access, data
+ exfiltration, or further attacks like malware installation or privilege escalation.
+ If confirmed malicious, this behavior could compromise the endpoint and the entire
+ network, necessitating immediate investigation and response.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml
index 409c21747b..60166bd1f3 100644
--- a/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml
+++ b/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml
@@ -4,16 +4,25 @@ version: 12
date: '2025-01-15'
author: Patrick Bareiss, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: This analytic had some overlap with another one, hence the deprecation.
+ It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry
+ Hive Dump Via CommandLine
+ replacement_content:
+ - Windows Sensitive Registry Hive Dump Via CommandLine
type: TTP
description: The following analytic has been deprecated in favour of "8bbb7d58-b360-11eb-ba21-acde48001122".
- The following analytic detects the execution of reg.exe with parameters
- that export registry keys containing hashed credentials. It leverages data from
- Endpoint Detection and Response (EDR) agents, focusing on command-line executions
- involving reg.exe or cmd.exe with specific registry paths. This activity is significant
- because exporting these keys can allow attackers to obtain hashed credentials, which
- they may attempt to crack offline. If confirmed malicious, this could lead to unauthorized
- access to sensitive accounts, enabling further compromise and lateral movement within
- the network.
+ The following analytic detects the execution of reg.exe with parameters that export
+ registry keys containing hashed credentials. It leverages data from Endpoint Detection
+ and Response (EDR) agents, focusing on command-line executions involving reg.exe
+ or cmd.exe with specific registry paths. This activity is significant because exporting
+ these keys can allow attackers to obtain hashed credentials, which they may attempt
+ to crack offline. If confirmed malicious, this could lead to unauthorized access
+ to sensitive accounts, enabling further compromise and lateral movement within the
+ network.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml
index 91a576d2f0..6b328e1c99 100644
--- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml
+++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml
@@ -4,6 +4,14 @@ version: 5
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Provisioning Activity From Previously Unseen City
type: Anomaly
description: This search looks for AWS provisioning activities from previously unseen
cities. Provisioning activities are defined broadly as any event that begins with
@@ -15,8 +23,8 @@ search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceI
sourceIPAddress | search City=* | stats earliest(_time) as firstTime, latest(_time)
as lastTime by sourceIPAddress, City, Region, Country | inputlookup append=t previously_seen_provisioning_activity_src
| stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress,
- City, Region, Country | outputlookup previously_seen_provisioning_activity_src
- | stats min(firstTime) as firstTime max(lastTime) as lastTime by City | eval newCity=if(firstTime
+ City, Region, Country | outputlookup previously_seen_provisioning_activity_src |
+ stats min(firstTime) as firstTime max(lastTime) as lastTime by City | eval newCity=if(firstTime
>= relative_time(now(), "-70m@m"), 1, 0) | where newCity=1 | table City] | spath
output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time, user,
src_ip, City, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_city_filter`'
diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml
index 986a31d1f0..9fa34711fb 100644
--- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml
+++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml
@@ -4,6 +4,14 @@ version: 5
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Provisioning Activity From Previously Unseen Country
type: Anomaly
description: This search looks for AWS provisioning activities from previously unseen
countries. Provisioning activities are defined broadly as any event that begins
@@ -14,13 +22,13 @@ search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceI
| search Country=* [search `cloudtrail` (eventName=Run* OR eventName=Create*) |
iplocation sourceIPAddress | search Country=* | stats earliest(_time) as firstTime,
latest(_time) as lastTime by sourceIPAddress, City, Region, Country | inputlookup
- append=t previously_seen_provisioning_activity_src | stats min(firstTime) as
- firstTime max(lastTime) as lastTime by sourceIPAddress, City, Region, Country |
- outputlookup previously_seen_provisioning_activity_src | stats min(firstTime)
- as firstTime max(lastTime) as lastTime by Country | eval newCountry=if(firstTime
- >= relative_time(now(), "-70m@m"), 1, 0) | where newCountry=1 | table Country] |
- spath output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time,
- user, src_ip, Country, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_country_filter`'
+ append=t previously_seen_provisioning_activity_src | stats min(firstTime) as firstTime
+ max(lastTime) as lastTime by sourceIPAddress, City, Region, Country | outputlookup
+ previously_seen_provisioning_activity_src | stats min(firstTime) as firstTime max(lastTime)
+ as lastTime by Country | eval newCountry=if(firstTime >= relative_time(now(), "-70m@m"),
+ 1, 0) | where newCountry=1 | table Country] | spath output=user userIdentity.arn
+ | rename sourceIPAddress as src_ip | table _time, user, src_ip, Country, eventName,
+ errorCode | `aws_cloud_provisioning_from_previously_unseen_country_filter`'
how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later)
and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail
inputs. This search works best when you run the "Previously Seen AWS Provisioning
diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml
index 5568175da0..d90ad488c4 100644
--- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml
+++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml
@@ -4,6 +4,14 @@ version: 5
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Provisioning Activity From Previously Unseen IP Address
type: Anomaly
description: This search looks for AWS provisioning activities from previously unseen
IP addresses. Provisioning activities are defined broadly as any event that begins
diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml
index 5efa68a449..b3748cf690 100644
--- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml
+++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml
@@ -4,6 +4,14 @@ version: 4
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Provisioning Activity From Previously Unseen Region
type: Anomaly
description: This search looks for AWS provisioning activities from previously unseen
regions. Region in this context is similar to a state in the United States. Provisioning
@@ -15,8 +23,8 @@ search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceI
sourceIPAddress | search Region=* | stats earliest(_time) as firstTime, latest(_time)
as lastTime by sourceIPAddress, City, Region, Country | inputlookup append=t previously_seen_provisioning_activity_src
| stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress,
- City, Region, Country | outputlookup previously_seen_provisioning_activity_src
- | stats min(firstTime) as firstTime max(lastTime) as lastTime by Region | eval newRegion=if(firstTime
+ City, Region, Country | outputlookup previously_seen_provisioning_activity_src |
+ stats min(firstTime) as firstTime max(lastTime) as lastTime by Region | eval newRegion=if(firstTime
>= relative_time(now(), "-70m@m"), 1, 0) | where newRegion=1 | table Region] | spath
output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time, user,
src_ip, Region, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_region_filter`'
diff --git a/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml b/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml
index 866bca7809..016a68160e 100644
--- a/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml
+++ b/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml
@@ -4,6 +4,14 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Kubernetes Abuse of Secret by Unusual Location
type: Hunting
description: This search provides information on Kubernetes accounts accessing sensitve
objects such as configmaps or secrets
diff --git a/detections/deprecated/change_default_file_association.yml b/detections/deprecated/change_default_file_association.yml
index d552a13219..e3de336511 100644
--- a/detections/deprecated/change_default_file_association.yml
+++ b/detections/deprecated/change_default_file_association.yml
@@ -4,16 +4,23 @@ version: 5
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows New Default File Association Value Set
type: TTP
-description: The following analytic has been deprecated.
- The following analytic detects suspicious registry modifications that
- change the default file association to execute a malicious payload. It leverages
- data from the Endpoint data model, specifically monitoring registry paths under
- "*\\shell\\open\\command\\*" and "*HKCR\\*". This activity is significant because
- altering default file associations can allow attackers to execute arbitrary scripts
- or payloads when a user opens a file, leading to potential code execution. If confirmed
- malicious, this technique can enable attackers to persist on the compromised host
- and execute further malicious commands, posing a severe threat to the environment.
+description: The following analytic has been deprecated. The following analytic detects
+ suspicious registry modifications that change the default file association to execute
+ a malicious payload. It leverages data from the Endpoint data model, specifically
+ monitoring registry paths under "*\\shell\\open\\command\\*" and "*HKCR\\*". This
+ activity is significant because altering default file associations can allow attackers
+ to execute arbitrary scripts or payloads when a user opens a file, leading to potential
+ code execution. If confirmed malicious, this technique can enable attackers to persist
+ on the compromised host and execute further malicious commands, posing a severe
+ threat to the environment.
data_source:
- Sysmon EventID 12
- Sysmon EventID 13
diff --git a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml b/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml
index eb01c32ea2..7ea5a6c524 100644
--- a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml
+++ b/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml
@@ -4,6 +4,12 @@ version: 6
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: TTP
description: This search allows you to identify the endpoints that have connected
to more than five DNS servers and made DNS Queries over the time frame of the search.
diff --git a/detections/deprecated/cloud_network_access_control_list_deleted.yml b/detections/deprecated/cloud_network_access_control_list_deleted.yml
index 8a9036b76a..c5a273eb95 100644
--- a/detections/deprecated/cloud_network_access_control_list_deleted.yml
+++ b/detections/deprecated/cloud_network_access_control_list_deleted.yml
@@ -4,6 +4,14 @@ version: 4
date: '2024-11-14'
author: Peter Gael, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - AWS Network Access Control List Deleted
type: Anomaly
description: Enforcing network-access controls is one of the defensive mechanisms
used by cloud administrators to restrict access to a cloud instance. After the attacker
diff --git a/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml b/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml
index 1df440f488..98e8084d64 100644
--- a/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml
+++ b/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml
@@ -4,6 +4,13 @@ version: 7
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Cmdline Tool Execution From Non-Shell Process
type: TTP
description: The following analytic identifies instances where `ipconfig.exe`, `systeminfo.exe`,
or similar tools are executed by a non-standard parent process, excluding CMD, PowerShell,
diff --git a/detections/deprecated/correlation_by_repository_and_risk.yml b/detections/deprecated/correlation_by_repository_and_risk.yml
index 2629b408ff..afc868dcee 100644
--- a/detections/deprecated/correlation_by_repository_and_risk.yml
+++ b/detections/deprecated/correlation_by_repository_and_risk.yml
@@ -4,6 +4,13 @@ version: 3
date: '2024-11-14'
author: Patrick Bareiss, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the datamodel
+ replacement_content:
+ - Risk Rule for Dev Sec Ops by Repository
type: Correlation
description: |-
This search has been deprecated and updated with Risk Rule for Dev Sec Ops by Repository detection. The following analytic detects by correlating repository and risk score to identify patterns and trends in the data based on the level of risk associated. The analytic adds any null values and calculates the sum of the risk scores for each detection. Then, the analytic captures the source and user information for each detection and sorts the results in ascending order based on the risk score. Finally, the analytic filters the detections with a risk score below 80 and focuses only on high-risk detections.This detection is important because it provides valuable insights into the distribution of high-risk activities across different repositories. It also identifies the most vulnerable repositories that are frequently targeted by potential threats. Additionally, it proactively detects and responds to potential threats, thereby minimizing the impact of attacks and safeguarding critical assets. Finally, it provides a comprehensive view of the risk landscape and helps to make informed decisions to protect the organization's data and infrastructure. False positives might occur so it is important to identify the impact of the attack and prioritize response and mitigation efforts.
diff --git a/detections/deprecated/correlation_by_user_and_risk.yml b/detections/deprecated/correlation_by_user_and_risk.yml
index 63d9c738ae..0d95f474ec 100644
--- a/detections/deprecated/correlation_by_user_and_risk.yml
+++ b/detections/deprecated/correlation_by_user_and_risk.yml
@@ -4,6 +4,13 @@ version: 3
date: '2024-11-14'
author: Patrick Bareiss, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the datamodel
+ replacement_content:
+ - Risk Rule for Dev Sec Ops by Repository
type: Correlation
description: |-
The following analytic detects the correlation between the user and risk score and identifies users with a high risk score that pose a significant security risk such as unauthorized access attempts, suspicious behavior, or potential insider threats. Next, the analytic calculates the sum of the risk scores and groups the results by user, the corresponding signals, and the repository. The results are sorted in descending order based on the risk score and filtered to include records with a risk score greater than 80. Finally, the results are passed through a correlation filter specific to the user and risk. This detection is important because it identifies users who have a high risk score and helps to prioritize investigations and allocate resources. False positives might occur but the impact of such an attack can vary depending on the specific scenario such as data exfiltration, system compromise, or the disruption of critical services. Please investigate this notable event.
diff --git a/detections/deprecated/create_local_admin_accounts_using_net_exe.yml b/detections/deprecated/create_local_admin_accounts_using_net_exe.yml
index 08cc384790..b4553ed94f 100644
--- a/detections/deprecated/create_local_admin_accounts_using_net_exe.yml
+++ b/detections/deprecated/create_local_admin_accounts_using_net_exe.yml
@@ -4,16 +4,22 @@ version: 15
date: '2025-01-24'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Create Local Administrator Account Via Net
type: TTP
-description: The following analytic has been deprecated.
- The following analytic detects the creation of local administrator accounts
- using the net.exe command. It leverages Endpoint Detection and Response (EDR) data
- to identify processes named net.exe or net1.exe with the "/add" parameter and keywords
- related to administrator accounts. This activity is significant as it may indicate
- an attacker attempting to gain persistent access or escalate privileges. If confirmed
- malicious, this could lead to unauthorized access, data theft, or further system
- compromise. Review the process details, user context, and related artifacts to determine
- the legitimacy of the activity.
+description: The following analytic has been deprecated. The following analytic detects
+ the creation of local administrator accounts using the net.exe command. It leverages
+ Endpoint Detection and Response (EDR) data to identify processes named net.exe or
+ net1.exe with the "/add" parameter and keywords related to administrator accounts.
+ This activity is significant as it may indicate an attacker attempting to gain persistent
+ access or escalate privileges. If confirmed malicious, this could lead to unauthorized
+ access, data theft, or further system compromise. Review the process details, user
+ context, and related artifacts to determine the legitimacy of the activity.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/deleting_of_net_users.yml b/detections/deprecated/deleting_of_net_users.yml
index 53d81b2248..7d5ea4007a 100644
--- a/detections/deprecated/deleting_of_net_users.yml
+++ b/detections/deprecated/deleting_of_net_users.yml
@@ -4,15 +4,22 @@ version: 7
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows User Deletion Via Net
type: TTP
-description: The following analytic has been deprecated.
- The following analytic detects the use of net.exe or net1.exe command-line
- to delete a user account on a system. It leverages data from Endpoint Detection
- and Response (EDR) agents, focusing on process and command-line execution logs.
- This activity is significant as it may indicate an attempt to impair user accounts
- or cover tracks during lateral movement. If confirmed malicious, this could lead
- to unauthorized access removal, disruption of legitimate user activities, or concealment
- of adversarial actions, complicating incident response and forensic investigations.
+description: The following analytic has been deprecated. The following analytic detects
+ the use of net.exe or net1.exe command-line to delete a user account on a system.
+ It leverages data from Endpoint Detection and Response (EDR) agents, focusing on
+ process and command-line execution logs. This activity is significant as it may
+ indicate an attempt to impair user accounts or cover tracks during lateral movement.
+ If confirmed malicious, this could lead to unauthorized access removal, disruption
+ of legitimate user activities, or concealment of adversarial actions, complicating
+ incident response and forensic investigations.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml b/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml
index 0c13a55b87..92df160e8f 100644
--- a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml
+++ b/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml
@@ -4,6 +4,12 @@ version: 9
date: '2024-11-14'
author: Bhavin Patel, Patrick Bareiss, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: Hunting
description: This search looks for specific authentication events from the Windows
Security Event logs to detect potential attempts at using the Pass-the-Hash technique.
diff --git a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml b/detections/deprecated/detect_api_activity_from_users_without_mfa.yml
index e0ad2efcfc..82e5931e6a 100644
--- a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml
+++ b/detections/deprecated/detect_api_activity_from_users_without_mfa.yml
@@ -4,6 +4,14 @@ version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - AWS Successful Single-Factor Authentication
type: Hunting
description: This search looks for AWS CloudTrail events where a user logged into
the AWS account, is making API calls and has not enabled Multi Factor authentication.
diff --git a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml b/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml
index 23e833aac1..b97773f126 100644
--- a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml
+++ b/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml
@@ -4,6 +4,12 @@ version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: Hunting
description: This search looks for successful AWS CloudTrail activity by user accounts
that are not listed in the identity table or `aws_service_accounts.csv`. It returns
diff --git a/detections/deprecated/detect_critical_alerts_from_security_tools.yml b/detections/deprecated/detect_critical_alerts_from_security_tools.yml
index 79ba56809d..a956ec746a 100644
--- a/detections/deprecated/detect_critical_alerts_from_security_tools.yml
+++ b/detections/deprecated/detect_critical_alerts_from_security_tools.yml
@@ -4,14 +4,51 @@ version: 2
date: '2025-01-13'
author: Gowthamaraj Rajendran, Patrick Bareiss, Bhavin Patel, Bryan Pluta, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - Microsoft Defender Incident Alerts
type: TTP
data_source:
- Windows Defender Alerts
- MS365 Defender Incident Alerts
-description: The following analytic has been deprecated in favour of specific and dedicated product analytics such as "Microsoft Defender ATP Alerts". The following analytic is to detect high and critical alerts from endpoint security tools such as Microsoft Defender, Carbon Black, and Crowdstrike. This query aggregates and summarizes critical severity alerts from the Alerts data model, providing details such as the alert signature, application, description, source, destination, and timestamps, while applying custom filters and formatting for enhanced analysis in a SIEM environment.This capability allows security teams to efficiently allocate resources and maintain a strong security posture, while also supporting compliance with regulatory requirements by providing a clear record of critical security events. We tested these detections with logs from Microsoft Defender, however this detection should work for any security alerts that are ingested into the alerts data model. **Note** - We are dynamically creating the risk_score field based on the severity of the alert in the SPL and that supersedes the risk score set in the detection.
-search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Alerts.description) as description values(Alerts.mitre_technique_id) as annotations.mitre_attack.mitre_technique_id values(Alerts.severity) as severity values(Alerts.type) as type values(Alerts.severity_id) as severity_id values(Alerts.signature) as signature values(Alerts.signature_id) as signature_id values(Alerts.dest) as dest from datamodel=Alerts where Alerts.severity IN ("high","critical") by Alerts.src Alerts.user Alerts.id Alerts.vendor sourcetype | `drop_dm_object_name("Alerts")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | eval risk_score=case(severity="informational", 2, severity="low", 5, severity="medium", 10, severity="high", 50, severity="critical" , 100) | `detect_critical_alerts_from_security_tools_filter`'
-how_to_implement: In order to properly run this search, you to ingest alerts data from other security products such as Crowdstrike, Microsoft Defender, or Carbon Black using appropriate TAs for that technology. Once ingested, the fields should be mapped to the Alerts data model. Make sure to apply transformation on the data if necessary. The risk_score field is used to calculate the risk score for the alerts and the mitre_technique_id field is used to map the alerts to the MITRE ATT&CK framework is dynamically created by the detection when this is triggered. These fields need not be set in the adaptive response actions.
-known_false_positives: False positives may vary by endpoint protection tool; monitor and filter out the alerts that are not relevant to your environment.
+description: The following analytic has been deprecated in favour of specific and
+ dedicated product analytics such as "Microsoft Defender ATP Alerts". The following
+ analytic is to detect high and critical alerts from endpoint security tools such
+ as Microsoft Defender, Carbon Black, and Crowdstrike. This query aggregates and
+ summarizes critical severity alerts from the Alerts data model, providing details
+ such as the alert signature, application, description, source, destination, and
+ timestamps, while applying custom filters and formatting for enhanced analysis in
+ a SIEM environment.This capability allows security teams to efficiently allocate
+ resources and maintain a strong security posture, while also supporting compliance
+ with regulatory requirements by providing a clear record of critical security events.
+ We tested these detections with logs from Microsoft Defender, however this detection
+ should work for any security alerts that are ingested into the alerts data model.
+ **Note** - We are dynamically creating the risk_score field based on the severity
+ of the alert in the SPL and that supersedes the risk score set in the detection.
+search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
+ as lastTime values(Alerts.description) as description values(Alerts.mitre_technique_id)
+ as annotations.mitre_attack.mitre_technique_id values(Alerts.severity) as severity
+ values(Alerts.type) as type values(Alerts.severity_id) as severity_id values(Alerts.signature)
+ as signature values(Alerts.signature_id) as signature_id values(Alerts.dest) as
+ dest from datamodel=Alerts where Alerts.severity IN ("high","critical") by Alerts.src
+ Alerts.user Alerts.id Alerts.vendor sourcetype | `drop_dm_object_name("Alerts")`
+ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | eval
+ risk_score=case(severity="informational", 2, severity="low", 5, severity="medium",
+ 10, severity="high", 50, severity="critical" , 100) | `detect_critical_alerts_from_security_tools_filter`'
+how_to_implement: In order to properly run this search, you to ingest alerts data
+ from other security products such as Crowdstrike, Microsoft Defender, or Carbon
+ Black using appropriate TAs for that technology. Once ingested, the fields should
+ be mapped to the Alerts data model. Make sure to apply transformation on the data
+ if necessary. The risk_score field is used to calculate the risk score for the alerts
+ and the mitre_technique_id field is used to map the alerts to the MITRE ATT&CK framework
+ is dynamically created by the detection when this is triggered. These fields need
+ not be set in the adaptive response actions.
+known_false_positives: False positives may vary by endpoint protection tool; monitor
+ and filter out the alerts that are not relevant to your environment.
references:
- https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/accessing-microsoft-defender-for-cloud-alerts-in-splunk-using/ba-p/938228
- https://docs.splunk.com/Documentation/CIM/5.3.2/User/Alerts
diff --git a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml
index 2d4975f3ec..b76c9405f5 100644
--- a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml
+++ b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml
@@ -4,6 +4,12 @@ version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: TTP
description: This search looks for DNS requests for phishing domains that are leveraging
EvilGinx tools to mimic websites.
@@ -31,9 +37,9 @@ how_to_implement: "You need to ingest data from your DNS logs in the Network_Res
add the correct hostname to the \"Phantom Instance\" field in the Adaptive Response
Actions when configuring this detection search, and set the corresponding Playbook
to active.\n(Playbook link:`https://my.phantom.us/4.2/playbook/lets-encrypt-domain-investigate/`)"
-known_false_positives: If a known good domain is not listed in the `legit_domains` lookup,
- then the search could give you false postives. Please update that lookup file
- to filter out DNS requests to legitimate domains.
+known_false_positives: If a known good domain is not listed in the `legit_domains`
+ lookup, then the search could give you false postives. Please update that lookup
+ file to filter out DNS requests to legitimate domains.
references: []
rba:
message: DNS Request for EvilGinx2 Phishing Site
diff --git a/detections/deprecated/detect_long_dns_txt_record_response.yml b/detections/deprecated/detect_long_dns_txt_record_response.yml
index 57a2fb80be..98b0f46fdc 100644
--- a/detections/deprecated/detect_long_dns_txt_record_response.yml
+++ b/detections/deprecated/detect_long_dns_txt_record_response.yml
@@ -4,6 +4,12 @@ version: 5
date: '2024-11-14'
author: Rico Valdez, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: TTP
description: This search is used to detect attempts to use DNS tunneling, by calculating
the length of responses to DNS TXT queries. Endpoints using DNS as a method of transmission
diff --git a/detections/deprecated/detect_mimikatz_using_loaded_images.yml b/detections/deprecated/detect_mimikatz_using_loaded_images.yml
index b002ff2bcc..2b96f938f5 100644
--- a/detections/deprecated/detect_mimikatz_using_loaded_images.yml
+++ b/detections/deprecated/detect_mimikatz_using_loaded_images.yml
@@ -4,6 +4,12 @@ version: 3
date: '2024-11-14'
author: Patrick Bareiss, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: TTP
description: This search looks for reading loaded Images unique to credential dumping
with Mimikatz. Deprecated because mimikatz libraries changed and very noisy sysmon
diff --git a/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml b/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml
index aa9cabe8d3..4f622e2ba5 100644
--- a/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml
+++ b/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml
@@ -4,6 +4,13 @@ version: 5
date: '2024-11-14'
author: Rico Valdez, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Updated to a new detection name
+ replacement_content:
+ - Detect Mimikatz With PowerShell Script Block Logging
type: TTP
description: This search looks for PowerShell requesting privileges consistent with
credential dumping. Deprecated, looks like things changed from a logging perspective.
diff --git a/detections/deprecated/detect_new_api_calls_from_user_roles.yml b/detections/deprecated/detect_new_api_calls_from_user_roles.yml
index 5ed0943c52..a0a40a7079 100644
--- a/detections/deprecated/detect_new_api_calls_from_user_roles.yml
+++ b/detections/deprecated/detect_new_api_calls_from_user_roles.yml
@@ -4,6 +4,14 @@ version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud API Calls From Previously Unseen User Roles
type: Anomaly
description: This search detects new API calls that have either never been seen before
or that have not been seen in the previous hour, where the identity type is `AssumedRole`.
@@ -12,9 +20,9 @@ search: '`cloudtrail` eventType=AwsApiCall errorCode=success userIdentity.type=A
[search `cloudtrail` eventType=AwsApiCall errorCode=success userIdentity.type=AssumedRole
| stats earliest(_time) as earliest latest(_time) as latest by userName eventName
| inputlookup append=t previously_seen_api_calls_from_user_roles | stats min(earliest)
- as earliest, max(latest) as latest by userName eventName | outputlookup previously_seen_api_calls_from_user_roles |
- eval newApiCallfromUserRole=if(earliest>=relative_time(now(), "-70m@m"), 1, 0) |
- where newApiCallfromUserRole=1 | `security_content_ctime(earliest)` | `security_content_ctime(latest)`
+ as earliest, max(latest) as latest by userName eventName | outputlookup previously_seen_api_calls_from_user_roles
+ | eval newApiCallfromUserRole=if(earliest>=relative_time(now(), "-70m@m"), 1, 0)
+ | where newApiCallfromUserRole=1 | `security_content_ctime(earliest)` | `security_content_ctime(latest)`
| table eventName userName] |rename userName as user| stats values(eventName) earliest(_time)
as earliest latest(_time) as latest by user | `security_content_ctime(earliest)`
| `security_content_ctime(latest)` | `detect_new_api_calls_from_user_roles_filter`'
diff --git a/detections/deprecated/detect_new_user_aws_console_login.yml b/detections/deprecated/detect_new_user_aws_console_login.yml
index 1713d3b52d..3b7dee01f6 100644
--- a/detections/deprecated/detect_new_user_aws_console_login.yml
+++ b/detections/deprecated/detect_new_user_aws_console_login.yml
@@ -4,6 +4,14 @@ version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Detect AWS Console Login by New User
type: Hunting
description: This search looks for AWS CloudTrail events wherein a console login event
by a user was recorded within the last hour, then compares the event to a lookup
@@ -13,9 +21,9 @@ description: This search looks for AWS CloudTrail events wherein a console login
data_source: []
search: '`cloudtrail` eventName=ConsoleLogin | rename userIdentity.arn as user | stats
earliest(_time) as firstTime latest(_time) as lastTime by user | inputlookup append=t
- previously_seen_users_console_logins | stats min(firstTime) as firstTime
- max(lastTime) as lastTime by user | eval userStatus=if(firstTime >= relative_time(now(),
- "-70m@m"), "First Time Logging into AWS Console","Previously Seen User") | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`|
+ previously_seen_users_console_logins | stats min(firstTime) as firstTime max(lastTime)
+ as lastTime by user | eval userStatus=if(firstTime >= relative_time(now(), "-70m@m"),
+ "First Time Logging into AWS Console","Previously Seen User") | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`|
where userStatus ="First Time Logging into AWS Console" | `detect_new_user_aws_console_login_filter`'
how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later)
and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail
diff --git a/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml b/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml
index 077d4c8017..3abe50aa9b 100644
--- a/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml
+++ b/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml
@@ -4,17 +4,23 @@ version: 7
date: '2025-01-24'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Potential System Network Configuration Discovery Activity
type: TTP
-description: The following analytic has been deprecated.
- The following analytic identifies the rapid execution of processes used
- for system network configuration discovery on an endpoint. It leverages data from
- Endpoint Detection and Response (EDR) agents, focusing on process GUIDs, names,
- parent processes, and command-line executions. This activity is significant as it
- may indicate an attacker attempting to map the network, which is a common precursor
- to lateral movement or further exploitation. If confirmed malicious, this behavior
- could allow an attacker to gain insights into the network topology, identify critical
- systems, and plan subsequent attacks, potentially leading to data exfiltration or
- system compromise.
+description: The following analytic has been deprecated. The following analytic identifies
+ the rapid execution of processes used for system network configuration discovery
+ on an endpoint. It leverages data from Endpoint Detection and Response (EDR) agents,
+ focusing on process GUIDs, names, parent processes, and command-line executions.
+ This activity is significant as it may indicate an attacker attempting to map the
+ network, which is a common precursor to lateral movement or further exploitation.
+ If confirmed malicious, this behavior could allow an attacker to gain insights into
+ the network topology, identify critical systems, and plan subsequent attacks, potentially
+ leading to data exfiltration or system compromise.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/detect_spike_in_aws_api_activity.yml b/detections/deprecated/detect_spike_in_aws_api_activity.yml
index 5a7efe7007..7757834caf 100644
--- a/detections/deprecated/detect_spike_in_aws_api_activity.yml
+++ b/detections/deprecated/detect_spike_in_aws_api_activity.yml
@@ -4,6 +4,13 @@ version: 5
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - ''
type: Anomaly
description: This search will detect users creating spikes of API activity in your
AWS environment. It will also update the cache file that factors in the latest
diff --git a/detections/deprecated/detect_spike_in_network_acl_activity.yml b/detections/deprecated/detect_spike_in_network_acl_activity.yml
index a7e693bf9e..b35582dc49 100644
--- a/detections/deprecated/detect_spike_in_network_acl_activity.yml
+++ b/detections/deprecated/detect_spike_in_network_acl_activity.yml
@@ -4,6 +4,14 @@ version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Abnormally High Number Of Cloud Infrastructure API Calls
type: Anomaly
description: This search will detect users creating spikes in API activity related
to network access-control lists (ACLs)in your AWS environment. This search is deprecated
diff --git a/detections/deprecated/detect_spike_in_security_group_activity.yml b/detections/deprecated/detect_spike_in_security_group_activity.yml
index de1cad3b6d..a8e0579682 100644
--- a/detections/deprecated/detect_spike_in_security_group_activity.yml
+++ b/detections/deprecated/detect_spike_in_security_group_activity.yml
@@ -4,6 +4,14 @@ version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Abnormally High Number Of Cloud Security Group API Calls
type: Anomaly
description: This search will detect users creating spikes in API activity related
to security groups in your AWS environment. It will also update the cache file
diff --git a/detections/deprecated/detect_usb_device_insertion.yml b/detections/deprecated/detect_usb_device_insertion.yml
index 2d6dd088f5..c363556e53 100644
--- a/detections/deprecated/detect_usb_device_insertion.yml
+++ b/detections/deprecated/detect_usb_device_insertion.yml
@@ -4,6 +4,12 @@ version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: TTP
description: The search is used to detect hosts that generate Windows Event ID 4663
for successful attempts to write to or read from a removable storage and Event ID
diff --git a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml b/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml
index 853d302d85..885920c786 100644
--- a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml
+++ b/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml
@@ -4,6 +4,13 @@ version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Updated to use a different log source
+ replacement_content:
+ - Detect hosts connecting to dynamic domain providers
type: TTP
description: This search looks for web connections to dynamic DNS providers.
data_source: []
diff --git a/detections/deprecated/detect_webshell_exploit_behavior.yml b/detections/deprecated/detect_webshell_exploit_behavior.yml
index 3b28ad33f1..e921c3ffbf 100644
--- a/detections/deprecated/detect_webshell_exploit_behavior.yml
+++ b/detections/deprecated/detect_webshell_exploit_behavior.yml
@@ -4,17 +4,23 @@ version: 7
date: '2025-01-24'
author: Steven Dick
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Suspicious Child Process Spawned From WebServer
type: TTP
-description: The following analytic has been deprecated.
- The following analytic identifies the execution of suspicious processes
- typically associated with webshell activity on web servers. It detects when processes
- like `cmd.exe`, `powershell.exe`, or `bash.exe` are spawned by web server processes
- such as `w3wp.exe` or `nginx.exe`. This behavior is significant as it may indicate
- an adversary exploiting a web application vulnerability to install a webshell, providing
- persistent access and command execution capabilities. If confirmed malicious, this
- activity could allow attackers to maintain control over the compromised server,
- execute arbitrary commands, and potentially escalate privileges or exfiltrate sensitive
- data.
+description: The following analytic has been deprecated. The following analytic identifies
+ the execution of suspicious processes typically associated with webshell activity
+ on web servers. It detects when processes like `cmd.exe`, `powershell.exe`, or `bash.exe`
+ are spawned by web server processes such as `w3wp.exe` or `nginx.exe`. This behavior
+ is significant as it may indicate an adversary exploiting a web application vulnerability
+ to install a webshell, providing persistent access and command execution capabilities.
+ If confirmed malicious, this activity could allow attackers to maintain control
+ over the compromised server, execute arbitrary commands, and potentially escalate
+ privileges or exfiltrate sensitive data.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/detection_of_dns_tunnels.yml b/detections/deprecated/detection_of_dns_tunnels.yml
index e903bf4d9a..595ded0bd5 100644
--- a/detections/deprecated/detection_of_dns_tunnels.yml
+++ b/detections/deprecated/detection_of_dns_tunnels.yml
@@ -4,6 +4,12 @@ version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: TTP
description: "This search is used to detect DNS tunneling, by calculating the sum
of the length of DNS queries and DNS answers. The search also filters out potential
diff --git a/detections/deprecated/disabling_net_user_account.yml b/detections/deprecated/disabling_net_user_account.yml
index 2a10320558..3fee864584 100644
--- a/detections/deprecated/disabling_net_user_account.yml
+++ b/detections/deprecated/disabling_net_user_account.yml
@@ -4,15 +4,22 @@ version: 7
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows User Disabled Via Net
type: TTP
-description: The following analytic has been deprecated.
- The following analytic detects the use of the `net.exe` utility to disable
- a user account via the command line. It leverages data from Endpoint Detection and
- Response (EDR) agents, focusing on process execution logs and command-line arguments.
- This activity is significant as it may indicate an adversary's attempt to disrupt
- user availability, potentially as a precursor to further malicious actions. If confirmed
- malicious, this could lead to denial of service for legitimate users, aiding the
- attacker in maintaining control or covering their tracks.
+description: The following analytic has been deprecated. The following analytic detects
+ the use of the `net.exe` utility to disable a user account via the command line.
+ It leverages data from Endpoint Detection and Response (EDR) agents, focusing on
+ process execution logs and command-line arguments. This activity is significant
+ as it may indicate an adversary's attempt to disrupt user availability, potentially
+ as a precursor to further malicious actions. If confirmed malicious, this could
+ lead to denial of service for legitimate users, aiding the attacker in maintaining
+ control or covering their tracks.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml b/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml
index b52f87457a..20f966e9b1 100644
--- a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml
+++ b/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml
@@ -4,6 +4,12 @@ version: 6
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: TTP
description: This search will detect DNS requests resolved by unauthorized DNS servers.
Legitimate DNS servers should be identified in the Enterprise Security Assets and
diff --git a/detections/deprecated/dns_record_changed.yml b/detections/deprecated/dns_record_changed.yml
index 1da12999ba..c917402af4 100644
--- a/detections/deprecated/dns_record_changed.yml
+++ b/detections/deprecated/dns_record_changed.yml
@@ -4,6 +4,12 @@ version: 6
date: '2024-11-14'
author: Jose Hernandez, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: TTP
description: The search takes the DNS records and their answers results of the discovered_dns_records
lookup and finds if any records have changed by searching DNS response from the
diff --git a/detections/deprecated/domain_account_discovery_with_net_app.yml b/detections/deprecated/domain_account_discovery_with_net_app.yml
index 7299b21596..b4f21b70a2 100644
--- a/detections/deprecated/domain_account_discovery_with_net_app.yml
+++ b/detections/deprecated/domain_account_discovery_with_net_app.yml
@@ -4,8 +4,26 @@ version: 5
date: '2025-01-13'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: "This analytic was a TTP that looked only for commands that tries to query
+ info about the users via net user /do. This had a couple of issues, such as triggering
+ on creation of users via the /add flag etc..\nIt was deprecated in favor of a
+ more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122"
+ replacement_content:
+ - Windows User Discovery Via Net
type: TTP
-description: This following analytic has been deprecated in favour of the generic version "5d0d4830-0133-11ec-bae3-acde48001122". The following analytic detects the execution of `net.exe` or `net1.exe` with command-line arguments used to query domain users. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions. This activity is significant as it may indicate an attempt by adversaries to enumerate domain users for situational awareness and Active Directory discovery. If confirmed malicious, this behavior could allow attackers to map out user accounts, potentially leading to further exploitation or lateral movement within the network.
+description: This following analytic has been deprecated in favour of the generic
+ version "5d0d4830-0133-11ec-bae3-acde48001122". The following analytic detects the
+ execution of `net.exe` or `net1.exe` with command-line arguments used to query domain
+ users. It leverages data from Endpoint Detection and Response (EDR) agents, focusing
+ on process names and command-line executions. This activity is significant as it
+ may indicate an attempt by adversaries to enumerate domain users for situational
+ awareness and Active Directory discovery. If confirmed malicious, this behavior
+ could allow attackers to map out user accounts, potentially leading to further exploitation
+ or lateral movement within the network.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/domain_group_discovery_with_net.yml b/detections/deprecated/domain_group_discovery_with_net.yml
index af3f1f4e79..8d355cbccc 100644
--- a/detections/deprecated/domain_group_discovery_with_net.yml
+++ b/detections/deprecated/domain_group_discovery_with_net.yml
@@ -4,8 +4,23 @@ version: 6
date: '2025-01-13'
author: Mauricio Velazco, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - Windows Group Discovery Via Net
type: Hunting
-description: This search has been deprecated in favour of the more generic analytic "c5c8e0f3-147a-43da-bf04-4cfaec27dc44". The following analytic identifies the execution of `net.exe` with command-line arguments used to query domain groups, specifically `group /domain`. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments. This activity is significant as it indicates potential reconnaissance efforts by adversaries to enumerate domain groups, which is a common step in Active Directory Discovery. If confirmed malicious, this behavior could allow attackers to gain insights into the domain structure, aiding in further attacks such as privilege escalation or lateral movement.
+description: This search has been deprecated in favour of the more generic analytic
+ "c5c8e0f3-147a-43da-bf04-4cfaec27dc44". The following analytic identifies the execution
+ of `net.exe` with command-line arguments used to query domain groups, specifically
+ `group /domain`. It leverages data from Endpoint Detection and Response (EDR) agents,
+ focusing on process names and command-line arguments. This activity is significant
+ as it indicates potential reconnaissance efforts by adversaries to enumerate domain
+ groups, which is a common step in Active Directory Discovery. If confirmed malicious,
+ this behavior could allow attackers to gain insights into the domain structure,
+ aiding in further attacks such as privilege escalation or lateral movement.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/dump_lsass_via_procdump_rename.yml b/detections/deprecated/dump_lsass_via_procdump_rename.yml
index db67928fa4..db97b216a0 100644
--- a/detections/deprecated/dump_lsass_via_procdump_rename.yml
+++ b/detections/deprecated/dump_lsass_via_procdump_rename.yml
@@ -4,6 +4,13 @@ version: 4
date: '2024-11-14'
author: Michael Haag, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Updated to a new detection name
+ replacement_content:
+ - Dump LSASS via procdump
type: Hunting
description: "Detect a renamed instance of procdump.exe dumping the lsass process.
This query looks for both -mm and -ma usage. -mm will produce a mini dump file and
diff --git a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml b/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml
index c0dddee3ca..306a57bde9 100644
--- a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml
+++ b/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml
@@ -4,6 +4,14 @@ version: 6
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud API Calls From Previously Unseen User Roles
type: Anomaly
description: This search looks for EC2 instances being modified by users who have
not previously modified them. This search is deprecated and have been translated
diff --git a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml b/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml
index 0d7e62b234..21078ec309 100644
--- a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml
+++ b/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml
@@ -4,6 +4,14 @@ version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Compute Instance Created In Previously Unused Region
type: Hunting
description: This search looks for AWS CloudTrail events where an instance is started
in a particular region in the last one hour and then compares it to a lookup file
diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml
index 80a929eefb..7a08a8ab13 100644
--- a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml
+++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml
@@ -4,6 +4,14 @@ version: 5
date: '2025-01-16'
author: David Dorsey, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Compute Instance Created With Previously Unseen Image
type: Anomaly
description: This search looks for EC2 instances being created with previously unseen
AMIs. This search is deprecated and have been translated to use the latest Change
diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml
index e1a95404a0..1b2fbffdbb 100644
--- a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml
+++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml
@@ -4,6 +4,14 @@ version: 6
date: '2025-01-16'
author: David Dorsey, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Compute Instance Created With Previously Unseen Instance Type
type: Anomaly
description: This search looks for EC2 instances being created with previously unseen
instance types. This search is deprecated and have been translated to use the latest
diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml
index d43786da55..adaf0a181b 100644
--- a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml
+++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml
@@ -4,6 +4,14 @@ version: 6
date: '2025-01-16'
author: David Dorsey, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Compute Instance Created By Previously Unseen User
type: Anomaly
description: This search looks for EC2 instances being created by users who have not
created them before. This search is deprecated and have been translated to use the
diff --git a/detections/deprecated/elevated_group_discovery_with_net.yml b/detections/deprecated/elevated_group_discovery_with_net.yml
index 14e1b5ab5a..9712be51f2 100644
--- a/detections/deprecated/elevated_group_discovery_with_net.yml
+++ b/detections/deprecated/elevated_group_discovery_with_net.yml
@@ -4,16 +4,22 @@ version: 6
date: '2025-01-24'
author: Mauricio Velazco, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Sensitive Group Discovery With Net
type: TTP
-description: The following analytic has been deprecated.
- The following analytic detects the execution of `net.exe` or `net1.exe`
- with command-line arguments used to query elevated domain groups. It leverages data
- from Endpoint Detection and Response (EDR) agents, focusing on process names and
- command-line executions. This activity is significant as it indicates potential
- reconnaissance efforts by adversaries to identify high-privileged users within Active
- Directory. If confirmed malicious, this behavior could lead to further attacks aimed
- at compromising privileged accounts, escalating privileges, or gaining unauthorized
- access to sensitive systems and data.
+description: The following analytic has been deprecated. The following analytic detects
+ the execution of `net.exe` or `net1.exe` with command-line arguments used to query
+ elevated domain groups. It leverages data from Endpoint Detection and Response (EDR)
+ agents, focusing on process names and command-line executions. This activity is
+ significant as it indicates potential reconnaissance efforts by adversaries to identify
+ high-privileged users within Active Directory. If confirmed malicious, this behavior
+ could lead to further attacks aimed at compromising privileged accounts, escalating
+ privileges, or gaining unauthorized access to sensitive systems and data.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/excel_spawning_powershell.yml b/detections/deprecated/excel_spawning_powershell.yml
index a4808cc05e..eeb145c769 100644
--- a/detections/deprecated/excel_spawning_powershell.yml
+++ b/detections/deprecated/excel_spawning_powershell.yml
@@ -4,16 +4,24 @@ version: 7
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
type: TTP
-description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process".
- The following analytic detects Microsoft Excel spawning PowerShell, an
- uncommon and suspicious behavior. This detection leverages data from Endpoint Detection
- and Response (EDR) agents, focusing on process creation events where the parent
- process is "excel.exe" and the child process is PowerShell. This activity is significant
- because it is often associated with spearphishing attacks, where malicious attachments
- execute encoded PowerShell commands. If confirmed malicious, this behavior could
- allow an attacker to execute arbitrary code, potentially leading to data exfiltration,
- privilege escalation, or persistent access within the environment.
+description: The following analytic has been deprecated in favour of a more generic
+ approach in "Windows Office Product Spawned Uncommon Process". The following analytic
+ detects Microsoft Excel spawning PowerShell, an uncommon and suspicious behavior.
+ This detection leverages data from Endpoint Detection and Response (EDR) agents,
+ focusing on process creation events where the parent process is "excel.exe" and
+ the child process is PowerShell. This activity is significant because it is often
+ associated with spearphishing attacks, where malicious attachments execute encoded
+ PowerShell commands. If confirmed malicious, this behavior could allow an attacker
+ to execute arbitrary code, potentially leading to data exfiltration, privilege escalation,
+ or persistent access within the environment.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/excessive_service_stop_attempt.yml b/detections/deprecated/excessive_service_stop_attempt.yml
index 3e27dc456b..428f6c64e7 100644
--- a/detections/deprecated/excessive_service_stop_attempt.yml
+++ b/detections/deprecated/excessive_service_stop_attempt.yml
@@ -4,16 +4,22 @@ version: 7
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Excessive Service Stop Attempt
type: Anomaly
-description: The following analytic has been deprecated.
- The following analytic detects multiple attempts to stop or delete services
- on a system using `net.exe`, `sc.exe`, or `net1.exe`. It leverages Endpoint Detection
- and Response (EDR) telemetry, focusing on process names and command-line executions
- within a one-minute window. This activity is significant as it may indicate an adversary
- attempting to disable security or critical services to evade detection and further
- their objectives. If confirmed malicious, this could lead to the attacker gaining
- persistence, escalating privileges, or disrupting essential services, thereby compromising
- the system's security posture.
+description: The following analytic has been deprecated. The following analytic detects
+ multiple attempts to stop or delete services on a system using `net.exe`, `sc.exe`,
+ or `net1.exe`. It leverages Endpoint Detection and Response (EDR) telemetry, focusing
+ on process names and command-line executions within a one-minute window. This activity
+ is significant as it may indicate an adversary attempting to disable security or
+ critical services to evade detection and further their objectives. If confirmed
+ malicious, this could lead to the attacker gaining persistence, escalating privileges,
+ or disrupting essential services, thereby compromising the system's security posture.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/excessive_usage_of_net_app.yml b/detections/deprecated/excessive_usage_of_net_app.yml
index e48ea823d4..ea3c6f60ed 100644
--- a/detections/deprecated/excessive_usage_of_net_app.yml
+++ b/detections/deprecated/excessive_usage_of_net_app.yml
@@ -4,16 +4,22 @@ version: 6
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Excessive Usage Of Net App
type: Anomaly
-description: The following analytic has been deprecated.
- The following analytic detects excessive usage of `net.exe` or `net1.exe`
- within a one-minute interval. It leverages data from Endpoint Detection and Response
- (EDR) agents, focusing on process names, parent processes, and command-line executions.
- This behavior is significant as it may indicate an adversary attempting to create,
- delete, or disable multiple user accounts rapidly, a tactic observed in Monero mining
- incidents. If confirmed malicious, this activity could lead to unauthorized user
- account manipulation, potentially compromising system integrity and enabling further
- malicious actions.
+description: The following analytic has been deprecated. The following analytic detects
+ excessive usage of `net.exe` or `net1.exe` within a one-minute interval. It leverages
+ data from Endpoint Detection and Response (EDR) agents, focusing on process names,
+ parent processes, and command-line executions. This behavior is significant as it
+ may indicate an adversary attempting to create, delete, or disable multiple user
+ accounts rapidly, a tactic observed in Monero mining incidents. If confirmed malicious,
+ this activity could lead to unauthorized user account manipulation, potentially
+ compromising system integrity and enabling further malicious actions.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml b/detections/deprecated/execution_of_file_with_spaces_before_extension.yml
index 6e453a7f03..81f9becb23 100644
--- a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml
+++ b/detections/deprecated/execution_of_file_with_spaces_before_extension.yml
@@ -4,6 +4,13 @@ version: 6
date: '2024-11-14'
author: Rico Valdez, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Updated to a new detection name
+ replacement_content:
+ - Execution of File with Multiple Extensions
type: TTP
description: This search looks for processes launched from files with at least five
spaces in the name before the extension. This is typically done to obfuscate the
diff --git a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml b/detections/deprecated/extended_period_without_successful_netbackup_backups.yml
index c72e3977a2..995f48dd58 100644
--- a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml
+++ b/detections/deprecated/extended_period_without_successful_netbackup_backups.yml
@@ -4,6 +4,12 @@ version: 4
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: Hunting
description: This search returns a list of hosts that have not successfully completed
a backup in over a week. Deprecated because it's a infrastructure monitoring.
diff --git a/detections/deprecated/extraction_of_registry_hives.yml b/detections/deprecated/extraction_of_registry_hives.yml
index 565dccabfa..c4e3bdaee0 100644
--- a/detections/deprecated/extraction_of_registry_hives.yml
+++ b/detections/deprecated/extraction_of_registry_hives.yml
@@ -4,16 +4,23 @@ version: 6
date: '2025-01-24'
author: Michael Haag, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Sensitive Registry Hive Dump Via CommandLine
type: TTP
-description: The following analytic has been deprecated.
- The following analytic detects the use of `reg.exe` to export Windows
- Registry hives, which may contain sensitive credentials. This detection leverages
- data from Endpoint Detection and Response (EDR) agents, focusing on command-line
- executions involving `save` or `export` actions targeting the `sam`, `system`, or
- `security` hives. This activity is significant as it indicates potential offline
- credential access attacks, often executed from untrusted processes or scripts. If
- confirmed malicious, attackers could gain access to credential data, enabling further
- compromise and lateral movement within the network.
+description: The following analytic has been deprecated. The following analytic detects
+ the use of `reg.exe` to export Windows Registry hives, which may contain sensitive
+ credentials. This detection leverages data from Endpoint Detection and Response
+ (EDR) agents, focusing on command-line executions involving `save` or `export` actions
+ targeting the `sam`, `system`, or `security` hives. This activity is significant
+ as it indicates potential offline credential access attacks, often executed from
+ untrusted processes or scripts. If confirmed malicious, attackers could gain access
+ to credential data, enabling further compromise and lateral movement within the
+ network.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/first_time_seen_command_line_argument.yml b/detections/deprecated/first_time_seen_command_line_argument.yml
index 5df827cada..f2d43dec54 100644
--- a/detections/deprecated/first_time_seen_command_line_argument.yml
+++ b/detections/deprecated/first_time_seen_command_line_argument.yml
@@ -4,6 +4,13 @@ version: 8
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This search looks for command-line arguments that use a `/c` parameter
to execute a command that has not previously been seen.
diff --git a/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml b/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml
index 10a412fbc9..da59975438 100644
--- a/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml
+++ b/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml
@@ -4,6 +4,12 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: Hunting
description: This search provides detection of accounts with high risk roles by projects.
Compromised accounts with high risk roles can move laterally or even scalate privileges
diff --git a/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml b/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml
index 1291444493..38e56596e6 100644
--- a/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml
+++ b/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml
@@ -4,6 +4,12 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: Hunting
description: This search provides detection of high risk permissions by resource and
accounts. These are permissions that can allow attackers with compromised accounts
diff --git a/detections/deprecated/gcp_detect_oauth_token_abuse.yml b/detections/deprecated/gcp_detect_oauth_token_abuse.yml
index 25144dd436..bef84aaa87 100644
--- a/detections/deprecated/gcp_detect_oauth_token_abuse.yml
+++ b/detections/deprecated/gcp_detect_oauth_token_abuse.yml
@@ -4,6 +4,12 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: Hunting
description: This search provides detection of possible GCP Oauth token abuse. GCP
Oauth token without time limit can be exfiltrated and reused for keeping access
diff --git a/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml b/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml
index f8fabad5ff..88aad6f364 100644
--- a/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml
+++ b/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml
@@ -4,6 +4,14 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Kubernetes Scanning by Unauthenticated IP Address
type: TTP
description: This search provides information of unauthenticated requests via user
agent, and authentication data against Kubernetes cluster
diff --git a/detections/deprecated/identify_new_user_accounts.yml b/detections/deprecated/identify_new_user_accounts.yml
index 55b528d72a..5e43985eae 100644
--- a/detections/deprecated/identify_new_user_accounts.yml
+++ b/detections/deprecated/identify_new_user_accounts.yml
@@ -4,6 +4,13 @@ version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This detection search will help profile user accounts in your environment
by identifying newly created accounts that have been added to your network in the
diff --git a/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml b/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml
index 8aed9288a5..49a3f2cddb 100644
--- a/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml
+++ b/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml
@@ -4,6 +4,13 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This search provides information on Kubernetes service accounts,accessing
pods by IP address, verb and decision
diff --git a/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml b/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml
index 6d04bf8d94..2a269a69ce 100644
--- a/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml
+++ b/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml
@@ -4,6 +4,13 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This search provides information on Kubernetes RBAC authorizations by
accounts, this search can be modified by adding top to see both extremes of RBAC
diff --git a/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml b/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml
index bb7b707a96..7c08f4bb52 100644
--- a/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml
+++ b/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml
@@ -4,6 +4,13 @@ version: 5
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This search provides information on Kubernetes accounts accessing sensitve
objects such as configmpas or secrets
diff --git a/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml b/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml
index 17722e0587..3e8620e1f1 100644
--- a/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml
+++ b/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml
@@ -4,6 +4,13 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This search provides information on Kubernetes service accounts with
failure or forbidden access status, this search can be extended by using top or
diff --git a/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml b/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml
index ef9d02ecbe..ec37c0848f 100644
--- a/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml
+++ b/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml
@@ -4,6 +4,13 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This search provides information on Kubernetes service accounts,accessing
pods and namespaces by IP address and verb
diff --git a/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml b/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml
index 0adc47769d..d96925d545 100644
--- a/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml
+++ b/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml
@@ -4,6 +4,13 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This search provides information on Kubernetes RBAC authorizations by
accounts, this search can be modified by adding rare or top to see both extremes
diff --git a/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml b/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml
index 8ae1ee647e..80591ab342 100644
--- a/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml
+++ b/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml
@@ -4,6 +4,13 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This search provides information on Kubernetes accounts accessing sensitve
objects such as configmpas or secrets
diff --git a/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml b/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml
index 9993a0a115..b7243aff43 100644
--- a/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml
+++ b/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml
@@ -4,6 +4,13 @@ version: 5
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This search provides information on Kubernetes accounts accessing sensitve
objects such as configmpas or secrets
diff --git a/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml b/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml
index ccbf5daf0c..0740c5bc9e 100644
--- a/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml
+++ b/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml
@@ -4,6 +4,13 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This search provides information on Kubernetes service accounts with
failure or forbidden access status
diff --git a/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml b/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml
index ef3fed2b2d..94ba765c3e 100644
--- a/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml
+++ b/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml
@@ -4,6 +4,13 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This search provides information on rare Kubectl calls with IP, verb
namespace and object access context
diff --git a/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml b/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml
index 1b1378b2f7..d41ae9e248 100644
--- a/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml
+++ b/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml
@@ -4,6 +4,13 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This search provides information of unauthenticated requests via source
IP user agent, request URI and response status data against Kubernetes cluster pod
diff --git a/detections/deprecated/kubernetes_azure_scan_fingerprint.yml b/detections/deprecated/kubernetes_azure_scan_fingerprint.yml
index 8a6b44473d..5ad0876707 100644
--- a/detections/deprecated/kubernetes_azure_scan_fingerprint.yml
+++ b/detections/deprecated/kubernetes_azure_scan_fingerprint.yml
@@ -4,6 +4,13 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This search provides information of unauthenticated requests via source
IP user agent, request URI and response status data against Kubernetes cluster in
diff --git a/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml b/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml
index 0d3a4cdf11..32ad65ac4c 100644
--- a/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml
+++ b/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml
@@ -4,6 +4,13 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This search provides information on Kubernetes service accounts,accessing
pods by IP address, verb and decision
diff --git a/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml b/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml
index 09a26684ce..fc2bf51208 100644
--- a/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml
+++ b/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml
@@ -4,6 +4,13 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This search provides information on Kubernetes RBAC authorizations by
accounts, this search can be modified by adding top to see both extremes of RBAC
diff --git a/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml b/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml
index 557ab8a5c3..67d2e2979e 100644
--- a/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml
+++ b/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml
@@ -4,6 +4,13 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This search provides information on Kubernetes accounts accessing sensitve
objects such as configmaps or secrets
diff --git a/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml b/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml
index da1b2cf148..e37d0a15ab 100644
--- a/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml
+++ b/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml
@@ -4,6 +4,13 @@ version: 5
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This search provides information on Kubernetes accounts accessing sensitve
objects such as configmpas or secrets
diff --git a/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml b/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml
index fff4730076..7f03e97647 100644
--- a/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml
+++ b/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml
@@ -4,6 +4,13 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This search provides information on Kubernetes service accounts with
failure or forbidden access status, this search can be extended by using top or
diff --git a/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml b/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml
index a78e967c70..80d95194a1 100644
--- a/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml
+++ b/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml
@@ -4,6 +4,13 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: Hunting
description: This search provides information on anonymous Kubectl calls with IP,
verb namespace and object access context
diff --git a/detections/deprecated/linux_auditd_find_private_keys.yml b/detections/deprecated/linux_auditd_find_private_keys.yml
index e9b889bc9e..8ccb92c6c7 100644
--- a/detections/deprecated/linux_auditd_find_private_keys.yml
+++ b/detections/deprecated/linux_auditd_find_private_keys.yml
@@ -4,16 +4,22 @@ version: 5
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Linux Auditd Private Keys and Certificate Enumeration
type: TTP
-description: The following analytic has been deprecated.
- The following analytic detects suspicious attempts to find private keys,
- which may indicate an attacker's effort to access sensitive cryptographic information.
- Private keys are crucial for securing encrypted communications and data, and unauthorized
- access to them can lead to severe security breaches, including data decryption and
- identity theft. By monitoring for unusual or unauthorized searches for private keys,
- this analytic helps identify potential threats to cryptographic security, enabling
- security teams to take swift action to protect the integrity and confidentiality
- of encrypted information.
+description: The following analytic has been deprecated. The following analytic detects
+ suspicious attempts to find private keys, which may indicate an attacker's effort
+ to access sensitive cryptographic information. Private keys are crucial for securing
+ encrypted communications and data, and unauthorized access to them can lead to severe
+ security breaches, including data decryption and identity theft. By monitoring for
+ unusual or unauthorized searches for private keys, this analytic helps identify
+ potential threats to cryptographic security, enabling security teams to take swift
+ action to protect the integrity and confidentiality of encrypted information.
data_source:
- Linux Auditd Execve
search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as
diff --git a/detections/deprecated/local_account_discovery_with_net.yml b/detections/deprecated/local_account_discovery_with_net.yml
index 7ac754da20..6aa48ba58f 100644
--- a/detections/deprecated/local_account_discovery_with_net.yml
+++ b/detections/deprecated/local_account_discovery_with_net.yml
@@ -4,16 +4,22 @@ version: 6
date: '2025-01-24'
author: Mauricio Velazco, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows User Discovery Via Net
type: Hunting
-description: The following analytic has been deprecated.
- The following analytic detects the execution of `net.exe` or `net1.exe`
- with command-line arguments `user` or `users` to query local user accounts. It leverages
- data from Endpoint Detection and Response (EDR) agents, focusing on process names
- and command-line executions. This activity is significant as it indicates potential
- reconnaissance efforts by adversaries to enumerate local users, which is a common
- step in situational awareness and Active Directory discovery. If confirmed malicious,
- this behavior could lead to further attacks, including privilege escalation and
- lateral movement within the network.
+description: The following analytic has been deprecated. The following analytic detects
+ the execution of `net.exe` or `net1.exe` with command-line arguments `user` or `users`
+ to query local user accounts. It leverages data from Endpoint Detection and Response
+ (EDR) agents, focusing on process names and command-line executions. This activity
+ is significant as it indicates potential reconnaissance efforts by adversaries to
+ enumerate local users, which is a common step in situational awareness and Active
+ Directory discovery. If confirmed malicious, this behavior could lead to further
+ attacks, including privilege escalation and lateral movement within the network.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/monitor_dns_for_brand_abuse.yml b/detections/deprecated/monitor_dns_for_brand_abuse.yml
index 9ad520f284..dfe23ab2a6 100644
--- a/detections/deprecated/monitor_dns_for_brand_abuse.yml
+++ b/detections/deprecated/monitor_dns_for_brand_abuse.yml
@@ -4,6 +4,13 @@ version: 4
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: TTP
description: This search looks for DNS requests for faux domains similar to the domains
that you want to have monitored for abuse.
diff --git a/detections/deprecated/mshtml_module_load_in_office_product.yml b/detections/deprecated/mshtml_module_load_in_office_product.yml
index f617d2f40e..f9b620ec36 100644
--- a/detections/deprecated/mshtml_module_load_in_office_product.yml
+++ b/detections/deprecated/mshtml_module_load_in_office_product.yml
@@ -4,15 +4,22 @@ version: 7
date: '2025-01-24'
author: Michael Haag, Mauricio Velazco, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Loaded MSHTML Module
type: TTP
-description: The following analytic has been deprecated.
- The following analytic detects the loading of the mshtml.dll module into
- an Office product, which is indicative of CVE-2021-40444 exploitation. It leverages
- Sysmon EventID 7 to monitor image loads by specific Office processes. This activity
- is significant because it can indicate an attempt to exploit a vulnerability in
- the MSHTML component via a malicious document. If confirmed malicious, this could
- allow an attacker to execute arbitrary code, potentially leading to system compromise,
- data exfiltration, or further network penetration.
+description: The following analytic has been deprecated. The following analytic detects
+ the loading of the mshtml.dll module into an Office product, which is indicative
+ of CVE-2021-40444 exploitation. It leverages Sysmon EventID 7 to monitor image loads
+ by specific Office processes. This activity is significant because it can indicate
+ an attempt to exploit a vulnerability in the MSHTML component via a malicious document.
+ If confirmed malicious, this could allow an attacker to execute arbitrary code,
+ potentially leading to system compromise, data exfiltration, or further network
+ penetration.
data_source:
- Sysmon EventID 7
search: '`sysmon` EventID=7 process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe","wordpad.exe","wordview.exe","onenote.exe","onenotem.exe","onenoteviewer.exe","onenoteim.exe",
diff --git a/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml b/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml
index 68269b2e43..23ac3906f5 100644
--- a/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml
+++ b/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml
@@ -4,6 +4,14 @@ version: 5
date: '2024-11-14'
author: Michael Haag, Mauricio Velazco, Rico Valdez, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Okta Multiple Users Failing To Authenticate From Ip
type: TTP
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `Okta Multiple Users Failing To Authenticate From Ip`. This analytic identifies
diff --git a/detections/deprecated/net_localgroup_discovery.yml b/detections/deprecated/net_localgroup_discovery.yml
index e54388cb4c..13b349af7b 100644
--- a/detections/deprecated/net_localgroup_discovery.yml
+++ b/detections/deprecated/net_localgroup_discovery.yml
@@ -4,8 +4,24 @@ version: 5
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44
+ / Windows Group Discovery Via Net
+ replacement_content:
+ - Windows Group Discovery Via Net
type: Hunting
-description: This search has been deprecated in favour of the more generic analytic "c5c8e0f3-147a-43da-bf04-4cfaec27dc44". The following analytic detects the execution of the `net localgroup` command, which is used to enumerate local group memberships on a system. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process execution logs that include command-line details. This activity is significant because it can indicate an attacker is gathering information about local group memberships, potentially to identify privileged accounts. If confirmed malicious, this behavior could lead to further privilege escalation or lateral movement within the network.
+description: This search has been deprecated in favour of the more generic analytic
+ "c5c8e0f3-147a-43da-bf04-4cfaec27dc44". The following analytic detects the execution
+ of the `net localgroup` command, which is used to enumerate local group memberships
+ on a system. It leverages data from Endpoint Detection and Response (EDR) agents,
+ focusing on process execution logs that include command-line details. This activity
+ is significant because it can indicate an attacker is gathering information about
+ local group memberships, potentially to identify privileged accounts. If confirmed
+ malicious, this behavior could lead to further privilege escalation or lateral movement
+ within the network.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/network_connection_discovery_with_net.yml b/detections/deprecated/network_connection_discovery_with_net.yml
index 0002699f31..1785ae5ff7 100644
--- a/detections/deprecated/network_connection_discovery_with_net.yml
+++ b/detections/deprecated/network_connection_discovery_with_net.yml
@@ -4,16 +4,23 @@ version: 6
date: '2025-01-24'
author: Mauricio Velazco, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Network Connection Discovery Via Net
type: Hunting
-description: The following analytic has been deprecated.
- The following analytic identifies the execution of `net.exe` or `net1.exe`
- with command-line arguments used to list network connections on a compromised system.
- It leverages data from Endpoint Detection and Response (EDR) agents, focusing on
- process names and command-line executions. This activity is significant as it indicates
- potential network reconnaissance by adversaries or Red Teams, aiming to gather situational
- awareness and Active Directory information. If confirmed malicious, this behavior
- could allow attackers to map the network, identify critical assets, and plan further
- attacks, potentially leading to data exfiltration or lateral movement.
+description: The following analytic has been deprecated. The following analytic identifies
+ the execution of `net.exe` or `net1.exe` with command-line arguments used to list
+ network connections on a compromised system. It leverages data from Endpoint Detection
+ and Response (EDR) agents, focusing on process names and command-line executions.
+ This activity is significant as it indicates potential network reconnaissance by
+ adversaries or Red Teams, aiming to gather situational awareness and Active Directory
+ information. If confirmed malicious, this behavior could allow attackers to map
+ the network, identify critical assets, and plan further attacks, potentially leading
+ to data exfiltration or lateral movement.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/o365_suspicious_admin_email_forwarding.yml b/detections/deprecated/o365_suspicious_admin_email_forwarding.yml
index 13dddb8c18..23ed76cc7c 100644
--- a/detections/deprecated/o365_suspicious_admin_email_forwarding.yml
+++ b/detections/deprecated/o365_suspicious_admin_email_forwarding.yml
@@ -4,6 +4,14 @@ version: 3
date: '2024-11-14'
author: Patrick Bareiss, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - O365 Mailbox Email Forwarding Enabled
type: Anomaly
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `O365 Mailbox Email Forwarding Enabled`. This search detects when an admin
diff --git a/detections/deprecated/o365_suspicious_rights_delegation.yml b/detections/deprecated/o365_suspicious_rights_delegation.yml
index e9e6543750..a0fcb196a4 100644
--- a/detections/deprecated/o365_suspicious_rights_delegation.yml
+++ b/detections/deprecated/o365_suspicious_rights_delegation.yml
@@ -4,6 +4,14 @@ version: 4
date: '2024-11-14'
author: Patrick Bareiss, Mauricio Velazco, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - O365 Elevated Mailbox Permission Assigned
type: TTP
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `O365 Elevated Mailbox Permission Assigned`. This analytic identifies instances
diff --git a/detections/deprecated/o365_suspicious_user_email_forwarding.yml b/detections/deprecated/o365_suspicious_user_email_forwarding.yml
index 1a9c9c5c4c..682a9fff0c 100644
--- a/detections/deprecated/o365_suspicious_user_email_forwarding.yml
+++ b/detections/deprecated/o365_suspicious_user_email_forwarding.yml
@@ -4,6 +4,14 @@ version: 4
date: '2024-11-14'
author: Patrick Bareiss, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - O365 Mailbox Email Forwarding Enabled
type: Anomaly
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `O365 Mailbox Email Forwarding Enabled`. The following analytic detects when
diff --git a/detections/deprecated/office_application_drop_executable.yml b/detections/deprecated/office_application_drop_executable.yml
index 94ddc48e52..da7930df64 100644
--- a/detections/deprecated/office_application_drop_executable.yml
+++ b/detections/deprecated/office_application_drop_executable.yml
@@ -4,16 +4,22 @@ version: 9
date: '2025-01-24'
author: Teoderick Contreras, Michael Haag, Splunk, TheLawsOfChaos, Github
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Dropped Uncommon File
type: TTP
-description: The following analytic has been deprecated.
- The following analytic detects Microsoft Office applications dropping
- or creating executables or scripts on a Windows OS. It leverages process creation
- and file system events from the Endpoint data model to identify Office applications
- like Word or Excel generating files with extensions such as .exe, .dll, or .ps1.
- This behavior is significant as it is often associated with spear-phishing attacks
- where malicious files are dropped to compromise the host. If confirmed malicious,
- this activity could lead to code execution, privilege escalation, or persistent
- access, posing a severe threat to the environment.
+description: The following analytic has been deprecated. The following analytic detects
+ Microsoft Office applications dropping or creating executables or scripts on a Windows
+ OS. It leverages process creation and file system events from the Endpoint data
+ model to identify Office applications like Word or Excel generating files with extensions
+ such as .exe, .dll, or .ps1. This behavior is significant as it is often associated
+ with spear-phishing attacks where malicious files are dropped to compromise the
+ host. If confirmed malicious, this activity could lead to code execution, privilege
+ escalation, or persistent access, posing a severe threat to the environment.
data_source:
- Sysmon EventID 1 AND Sysmon EventID 11
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
diff --git a/detections/deprecated/office_application_spawn_regsvr32_process.yml b/detections/deprecated/office_application_spawn_regsvr32_process.yml
index 20aef6978a..0b35f87583 100644
--- a/detections/deprecated/office_application_spawn_regsvr32_process.yml
+++ b/detections/deprecated/office_application_spawn_regsvr32_process.yml
@@ -4,16 +4,24 @@ version: 8
date: '2025-01-13'
author: Teoderick Contreras, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
type: TTP
-description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process".
- The following analytic identifies instances where an Office application
- spawns a Regsvr32 process, which is often indicative of macro execution or malicious
- code. This detection leverages data from Endpoint Detection and Response (EDR) agents,
- focusing on process creation events where the parent process is a known Office application.
- This activity is significant because it is a common technique used by malware, such
- as IcedID, to initiate infections. If confirmed malicious, this behavior could lead
- to code execution, allowing attackers to gain control over the affected system and
- potentially escalate privileges.
+description: The following analytic has been deprecated in favour of a more generic
+ approach in "Windows Office Product Spawned Uncommon Process". The following analytic
+ identifies instances where an Office application spawns a Regsvr32 process, which
+ is often indicative of macro execution or malicious code. This detection leverages
+ data from Endpoint Detection and Response (EDR) agents, focusing on process creation
+ events where the parent process is a known Office application. This activity is
+ significant because it is a common technique used by malware, such as IcedID, to
+ initiate infections. If confirmed malicious, this behavior could lead to code execution,
+ allowing attackers to gain control over the affected system and potentially escalate
+ privileges.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/office_application_spawn_rundll32_process.yml b/detections/deprecated/office_application_spawn_rundll32_process.yml
index fd944b75cf..d9a37aaba7 100644
--- a/detections/deprecated/office_application_spawn_rundll32_process.yml
+++ b/detections/deprecated/office_application_spawn_rundll32_process.yml
@@ -4,15 +4,23 @@ version: 8
date: '2025-01-13'
author: Teoderick Contreras, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
type: TTP
-description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process".
- The following analytic identifies instances where an Office application
- spawns a rundll32 process, which is often indicative of macro execution or malicious
- code. This detection leverages data from Endpoint Detection and Response (EDR) agents,
- focusing on process creation events where the parent process is a known Office application.
- This activity is significant because it is a common technique used by malware, such
- as Trickbot, to initiate infections. If confirmed malicious, this behavior could
- lead to code execution, further system compromise, and potential data exfiltration.
+description: The following analytic has been deprecated in favour of a more generic
+ approach in "Windows Office Product Spawned Uncommon Process". The following analytic
+ identifies instances where an Office application spawns a rundll32 process, which
+ is often indicative of macro execution or malicious code. This detection leverages
+ data from Endpoint Detection and Response (EDR) agents, focusing on process creation
+ events where the parent process is a known Office application. This activity is
+ significant because it is a common technique used by malware, such as Trickbot,
+ to initiate infections. If confirmed malicious, this behavior could lead to code
+ execution, further system compromise, and potential data exfiltration.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/office_document_creating_schedule_task.yml b/detections/deprecated/office_document_creating_schedule_task.yml
index 0198d43de6..d317b98c6a 100644
--- a/detections/deprecated/office_document_creating_schedule_task.yml
+++ b/detections/deprecated/office_document_creating_schedule_task.yml
@@ -4,15 +4,22 @@ version: 10
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Loading Taskschd DLL
type: TTP
-description: The following analytic has been deprecated.
- The following analytic detects an Office document creating a scheduled
- task, either through a macro VBA API or by loading `taskschd.dll`. This detection
- leverages Sysmon EventCode 7 to identify when Office applications load the `taskschd.dll`
- file. This activity is significant as it is a common technique used by malicious
- macro malware to establish persistence or initiate beaconing. If confirmed malicious,
- this could allow an attacker to maintain persistence, execute arbitrary commands,
- or schedule future malicious activities, posing a significant threat to the environment.
+description: The following analytic has been deprecated. The following analytic detects
+ an Office document creating a scheduled task, either through a macro VBA API or
+ by loading `taskschd.dll`. This detection leverages Sysmon EventCode 7 to identify
+ when Office applications load the `taskschd.dll` file. This activity is significant
+ as it is a common technique used by malicious macro malware to establish persistence
+ or initiate beaconing. If confirmed malicious, this could allow an attacker to maintain
+ persistence, execute arbitrary commands, or schedule future malicious activities,
+ posing a significant threat to the environment.
data_source:
- Sysmon EventID 7
search: '`sysmon` EventCode=7 process_name IN ("WINWORD.EXE", "EXCEL.EXE", "POWERPNT.EXE","onenote.exe","onenotem.exe","onenoteviewer.exe","onenoteim.exe",
diff --git a/detections/deprecated/office_document_executing_macro_code.yml b/detections/deprecated/office_document_executing_macro_code.yml
index 920e9483f5..35c088e292 100644
--- a/detections/deprecated/office_document_executing_macro_code.yml
+++ b/detections/deprecated/office_document_executing_macro_code.yml
@@ -4,15 +4,21 @@ version: 9
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Loading VBE7 DLL
type: TTP
-description: The following analytic has been deprecated.
- The following analytic identifies office documents executing macro code.
- It leverages Sysmon EventCode 7 to detect when processes like WINWORD.EXE or EXCEL.EXE
- load specific DLLs associated with macros (e.g., VBE7.DLL). This activity is significant
- because macros are a common attack vector for delivering malicious payloads, such
- as malware. If confirmed malicious, this could lead to unauthorized code execution,
- data exfiltration, or further compromise of the system. Disabling macros by default
- is recommended to mitigate this risk.
+description: The following analytic has been deprecated. The following analytic identifies
+ office documents executing macro code. It leverages Sysmon EventCode 7 to detect
+ when processes like WINWORD.EXE or EXCEL.EXE load specific DLLs associated with
+ macros (e.g., VBE7.DLL). This activity is significant because macros are a common
+ attack vector for delivering malicious payloads, such as malware. If confirmed malicious,
+ this could lead to unauthorized code execution, data exfiltration, or further compromise
+ of the system. Disabling macros by default is recommended to mitigate this risk.
data_source:
- Sysmon EventID 7
search: '`sysmon` EventCode=7 process_name IN ("WINWORD.EXE", "EXCEL.EXE", "POWERPNT.EXE","onenote.exe","onenotem.exe","onenoteviewer.exe","onenoteim.exe","msaccess.exe")
diff --git a/detections/deprecated/office_document_spawned_child_process_to_download.yml b/detections/deprecated/office_document_spawned_child_process_to_download.yml
index def3130752..0763eb9df3 100644
--- a/detections/deprecated/office_document_spawned_child_process_to_download.yml
+++ b/detections/deprecated/office_document_spawned_child_process_to_download.yml
@@ -4,16 +4,23 @@ version: 10
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Spawned Child Process For Download
type: TTP
-description: The following analytic has been deprecated.
- The following analytic identifies Office applications spawning child
- processes to download content via HTTP/HTTPS. It leverages data from Endpoint Detection
- and Response (EDR) agents, focusing on process creation events where Office applications
- like Word or Excel initiate network connections, excluding common browsers. This
- activity is significant as it often indicates the use of malicious documents to
- execute living-off-the-land binaries (LOLBins) for payload delivery. If confirmed
- malicious, this behavior could lead to unauthorized code execution, data exfiltration,
- or further malware deployment, posing a severe threat to the organization's security.
+description: The following analytic has been deprecated. The following analytic identifies
+ Office applications spawning child processes to download content via HTTP/HTTPS.
+ It leverages data from Endpoint Detection and Response (EDR) agents, focusing on
+ process creation events where Office applications like Word or Excel initiate network
+ connections, excluding common browsers. This activity is significant as it often
+ indicates the use of malicious documents to execute living-off-the-land binaries
+ (LOLBins) for payload delivery. If confirmed malicious, this behavior could lead
+ to unauthorized code execution, data exfiltration, or further malware deployment,
+ posing a severe threat to the organization's security.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/office_product_spawn_cmd_process.yml b/detections/deprecated/office_product_spawn_cmd_process.yml
index acbe347fb7..d9d6ff558c 100644
--- a/detections/deprecated/office_product_spawn_cmd_process.yml
+++ b/detections/deprecated/office_product_spawn_cmd_process.yml
@@ -4,9 +4,23 @@ version: 8
date: '2025-01-13'
author: Teoderick Contreras, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
type: TTP
-description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process".
- The following analytic detects an Office product spawning a CMD process, which is indicative of a macro executing shell commands to download or run malicious code. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and parent process names. This activity is significant as it often signals the execution of malicious payloads, such as those seen in Trickbot spear-phishing campaigns. If confirmed malicious, this behavior could lead to unauthorized code execution, potentially compromising the system and allowing further malicious activities.
+description: The following analytic has been deprecated in favour of a more generic
+ approach in "Windows Office Product Spawned Uncommon Process". The following analytic
+ detects an Office product spawning a CMD process, which is indicative of a macro
+ executing shell commands to download or run malicious code. This detection leverages
+ data from Endpoint Detection and Response (EDR) agents, focusing on process and
+ parent process names. This activity is significant as it often signals the execution
+ of malicious payloads, such as those seen in Trickbot spear-phishing campaigns.
+ If confirmed malicious, this behavior could lead to unauthorized code execution,
+ potentially compromising the system and allowing further malicious activities.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/office_product_spawning_bitsadmin.yml b/detections/deprecated/office_product_spawning_bitsadmin.yml
index 8c3de51640..2b8a51389c 100644
--- a/detections/deprecated/office_product_spawning_bitsadmin.yml
+++ b/detections/deprecated/office_product_spawning_bitsadmin.yml
@@ -4,16 +4,24 @@ version: 9
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
type: TTP
-description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process".
- The following analytic detects any Windows Office Product spawning `bitsadmin.exe`,
- a behavior often associated with malware families like TA551 and IcedID. This detection
- leverages data from Endpoint Detection and Response (EDR) agents, focusing on process
- and parent process relationships. This activity is significant because `bitsadmin.exe`
- is commonly used for malicious file transfers, potentially indicating a malware
- infection. If confirmed malicious, this activity could allow attackers to download
- additional payloads, escalate privileges, or establish persistence, leading to further
- compromise of the affected system.
+description: The following analytic has been deprecated in favour of a more generic
+ approach in "Windows Office Product Spawned Uncommon Process". The following analytic
+ detects any Windows Office Product spawning `bitsadmin.exe`, a behavior often associated
+ with malware families like TA551 and IcedID. This detection leverages data from
+ Endpoint Detection and Response (EDR) agents, focusing on process and parent process
+ relationships. This activity is significant because `bitsadmin.exe` is commonly
+ used for malicious file transfers, potentially indicating a malware infection. If
+ confirmed malicious, this activity could allow attackers to download additional
+ payloads, escalate privileges, or establish persistence, leading to further compromise
+ of the affected system.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/office_product_spawning_certutil.yml b/detections/deprecated/office_product_spawning_certutil.yml
index d1e14b4181..d89056cb83 100644
--- a/detections/deprecated/office_product_spawning_certutil.yml
+++ b/detections/deprecated/office_product_spawning_certutil.yml
@@ -4,16 +4,23 @@ version: 9
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
type: TTP
-description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process".
- The following analytic detects any Windows Office Product spawning `certutil.exe`,
- a behavior often associated with malware families like TA551 and IcedID. This detection
- leverages Endpoint Detection and Response (EDR) data, focusing on process relationships
- and command-line executions. The significance lies in the fact that `certutil.exe`
- is frequently used for downloading malicious payloads from remote URLs. If confirmed
- malicious, this activity could lead to unauthorized code execution, data exfiltration,
- or further system compromise. Immediate investigation and containment are crucial
- to prevent potential damage.
+description: The following analytic has been deprecated in favour of a more generic
+ approach in "Windows Office Product Spawned Uncommon Process". The following analytic
+ detects any Windows Office Product spawning `certutil.exe`, a behavior often associated
+ with malware families like TA551 and IcedID. This detection leverages Endpoint Detection
+ and Response (EDR) data, focusing on process relationships and command-line executions.
+ The significance lies in the fact that `certutil.exe` is frequently used for downloading
+ malicious payloads from remote URLs. If confirmed malicious, this activity could
+ lead to unauthorized code execution, data exfiltration, or further system compromise.
+ Immediate investigation and containment are crucial to prevent potential damage.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/office_product_spawning_mshta.yml b/detections/deprecated/office_product_spawning_mshta.yml
index 966d3f3b98..4ba85dc480 100644
--- a/detections/deprecated/office_product_spawning_mshta.yml
+++ b/detections/deprecated/office_product_spawning_mshta.yml
@@ -4,16 +4,23 @@ version: 8
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
type: TTP
-description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process".
- The following analytic identifies instances where a Microsoft Office
- product spawns `mshta.exe`. This detection leverages data from Endpoint Detection
- and Response (EDR) agents, focusing on process creation events where the parent
- process is an Office application. This activity is significant because it is a common
- technique used by malware families like TA551 and IcedID to execute malicious scripts
- or payloads. If confirmed malicious, this behavior could allow attackers to execute
- arbitrary code, potentially leading to data exfiltration, system compromise, or
- further malware deployment.
+description: The following analytic has been deprecated in favour of a more generic
+ approach in "Windows Office Product Spawned Uncommon Process". The following analytic
+ identifies instances where a Microsoft Office product spawns `mshta.exe`. This detection
+ leverages data from Endpoint Detection and Response (EDR) agents, focusing on process
+ creation events where the parent process is an Office application. This activity
+ is significant because it is a common technique used by malware families like TA551
+ and IcedID to execute malicious scripts or payloads. If confirmed malicious, this
+ behavior could allow attackers to execute arbitrary code, potentially leading to
+ data exfiltration, system compromise, or further malware deployment.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
@@ -81,6 +88,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml b/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml
index 34040e8cb5..43530ad126 100644
--- a/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml
+++ b/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml
@@ -4,16 +4,22 @@ version: 10
date: '2025-01-24'
author: Michael Haag, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Spawned Rundll32 With No DLL
type: TTP
-description: The following analytic has been deprecated.
- The following analytic detects any Windows Office Product spawning `rundll32.exe`
- without a `.dll` file extension. This behavior is identified using Endpoint Detection
- and Response (EDR) telemetry, focusing on process and parent process relationships.
- This activity is significant as it is a known tactic of the IcedID malware family,
- which can lead to unauthorized code execution. If confirmed malicious, this could
- allow attackers to execute arbitrary code, potentially leading to data exfiltration,
- system compromise, or further malware deployment. Immediate investigation and containment
- are recommended.
+description: The following analytic has been deprecated. The following analytic detects
+ any Windows Office Product spawning `rundll32.exe` without a `.dll` file extension.
+ This behavior is identified using Endpoint Detection and Response (EDR) telemetry,
+ focusing on process and parent process relationships. This activity is significant
+ as it is a known tactic of the IcedID malware family, which can lead to unauthorized
+ code execution. If confirmed malicious, this could allow attackers to execute arbitrary
+ code, potentially leading to data exfiltration, system compromise, or further malware
+ deployment. Immediate investigation and containment are recommended.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/office_product_spawning_windows_script_host.yml b/detections/deprecated/office_product_spawning_windows_script_host.yml
index 20ee47bc5c..d6bfcc6025 100644
--- a/detections/deprecated/office_product_spawning_windows_script_host.yml
+++ b/detections/deprecated/office_product_spawning_windows_script_host.yml
@@ -4,15 +4,23 @@ version: 10
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
type: TTP
-description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process".
- The following analytic detects an Office product spawning WScript.exe
- or CScript.exe. It leverages data from Endpoint Detection and Response (EDR) agents,
- focusing on process creation events where Office applications are the parent processes.
- This activity is significant because it may indicate the execution of potentially
- malicious scripts through Office products, a common tactic in phishing attacks and
- malware delivery. If confirmed malicious, this behavior could lead to unauthorized
- code execution, data exfiltration, or further system compromise.
+description: The following analytic has been deprecated in favour of a more generic
+ approach in "Windows Office Product Spawned Uncommon Process". The following analytic
+ detects an Office product spawning WScript.exe or CScript.exe. It leverages data
+ from Endpoint Detection and Response (EDR) agents, focusing on process creation
+ events where Office applications are the parent processes. This activity is significant
+ because it may indicate the execution of potentially malicious scripts through Office
+ products, a common tactic in phishing attacks and malware delivery. If confirmed
+ malicious, this behavior could lead to unauthorized code execution, data exfiltration,
+ or further system compromise.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
@@ -84,6 +92,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.002/atomic_red_team/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.002/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/deprecated/office_product_spawning_wmic.yml b/detections/deprecated/office_product_spawning_wmic.yml
index 6360ea5c4e..c60f305eb0 100644
--- a/detections/deprecated/office_product_spawning_wmic.yml
+++ b/detections/deprecated/office_product_spawning_wmic.yml
@@ -4,16 +4,23 @@ version: 10
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
type: TTP
-description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process".
- The following analytic detects any Windows Office Product spawning `wmic.exe`,
- specifically when the command-line of `wmic.exe` contains `wmic process call create`.
- This behavior is identified using data from Endpoint Detection and Response (EDR)
- agents, focusing on process and parent process relationships. This activity is significant
- as it is commonly associated with the Ursnif malware family, indicating potential
- malicious activity. If confirmed malicious, this could allow an attacker to execute
- arbitrary commands, leading to further system compromise, data exfiltration, or
- lateral movement within the network.
+description: The following analytic has been deprecated in favour of a more generic
+ approach in "Windows Office Product Spawned Uncommon Process". The following analytic
+ detects any Windows Office Product spawning `wmic.exe`, specifically when the command-line
+ of `wmic.exe` contains `wmic process call create`. This behavior is identified using
+ data from Endpoint Detection and Response (EDR) agents, focusing on process and
+ parent process relationships. This activity is significant as it is commonly associated
+ with the Ursnif malware family, indicating potential malicious activity. If confirmed
+ malicious, this could allow an attacker to execute arbitrary commands, leading to
+ further system compromise, data exfiltration, or lateral movement within the network.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
@@ -82,6 +89,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/deprecated/office_product_writing_cab_or_inf.yml b/detections/deprecated/office_product_writing_cab_or_inf.yml
index dbea8b4ac3..cb9aafc883 100644
--- a/detections/deprecated/office_product_writing_cab_or_inf.yml
+++ b/detections/deprecated/office_product_writing_cab_or_inf.yml
@@ -4,15 +4,22 @@ version: 10
date: '2025-01-24'
author: Michael Haag, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Dropped Cab or Inf File
type: TTP
-description: The following analytic has been deprecated.
- The following analytic detects Office products writing .cab or .inf files,
- indicative of CVE-2021-40444 exploitation. It leverages the Endpoint.Processes and
- Endpoint.Filesystem data models to identify Office applications creating these file
- types. This activity is significant as it may signal an attempt to load malicious
- ActiveX controls and download remote payloads, a known attack vector. If confirmed
- malicious, this could lead to remote code execution, allowing attackers to gain
- control over the affected system and potentially compromise sensitive data.
+description: The following analytic has been deprecated. The following analytic detects
+ Office products writing .cab or .inf files, indicative of CVE-2021-40444 exploitation.
+ It leverages the Endpoint.Processes and Endpoint.Filesystem data models to identify
+ Office applications creating these file types. This activity is significant as it
+ may signal an attempt to load malicious ActiveX controls and download remote payloads,
+ a known attack vector. If confirmed malicious, this could lead to remote code execution,
+ allowing attackers to gain control over the affected system and potentially compromise
+ sensitive data.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/office_spawning_control.yml b/detections/deprecated/office_spawning_control.yml
index ac4c987bc2..389aa5d867 100644
--- a/detections/deprecated/office_spawning_control.yml
+++ b/detections/deprecated/office_spawning_control.yml
@@ -4,16 +4,22 @@ version: 10
date: '2025-01-24'
author: Michael Haag, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Spawned Control
type: TTP
-description: The following analytic has been deprecated.
- The following analytic identifies instances where `control.exe` is spawned
- by a Microsoft Office product. It leverages data from Endpoint Detection and Response
- (EDR) agents, focusing on process and parent process relationships. This activity
- is significant because it can indicate exploitation attempts related to CVE-2021-40444,
- where `control.exe` is used to execute malicious .cpl or .inf files. If confirmed
- malicious, this behavior could allow an attacker to execute arbitrary code, potentially
- leading to system compromise, data exfiltration, or further lateral movement within
- the network.
+description: The following analytic has been deprecated. The following analytic identifies
+ instances where `control.exe` is spawned by a Microsoft Office product. It leverages
+ data from Endpoint Detection and Response (EDR) agents, focusing on process and
+ parent process relationships. This activity is significant because it can indicate
+ exploitation attempts related to CVE-2021-40444, where `control.exe` is used to
+ execute malicious .cpl or .inf files. If confirmed malicious, this behavior could
+ allow an attacker to execute arbitrary code, potentially leading to system compromise,
+ data exfiltration, or further lateral movement within the network.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/okta_account_locked_out.yml b/detections/deprecated/okta_account_locked_out.yml
index 0ad8243973..0b1df607ad 100644
--- a/detections/deprecated/okta_account_locked_out.yml
+++ b/detections/deprecated/okta_account_locked_out.yml
@@ -4,6 +4,14 @@ version: 3
date: '2024-11-14'
author: Michael Haag, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Okta Multiple Accounts Locked Out
type: Anomaly
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `Okta Multiple Accounts Locked Out`. The following analytic utilizes the user.acount.lock
diff --git a/detections/deprecated/okta_account_lockout_events.yml b/detections/deprecated/okta_account_lockout_events.yml
index 07f8d09a9d..4049ec139c 100644
--- a/detections/deprecated/okta_account_lockout_events.yml
+++ b/detections/deprecated/okta_account_lockout_events.yml
@@ -4,6 +4,14 @@ version: 4
date: '2024-11-14'
author: Michael Haag, Rico Valdez, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Okta Multiple Accounts Locked Out
type: Anomaly
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `Okta Multiple Accounts Locked Out`. The following anomaly will generate based
diff --git a/detections/deprecated/okta_failed_sso_attempts.yml b/detections/deprecated/okta_failed_sso_attempts.yml
index 6516d32c67..cd83cc1cb9 100644
--- a/detections/deprecated/okta_failed_sso_attempts.yml
+++ b/detections/deprecated/okta_failed_sso_attempts.yml
@@ -4,6 +4,14 @@ version: 5
date: '2024-11-14'
author: Michael Haag, Rico Valdez, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Okta Unauthorized Access to Application
type: Anomaly
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with this detection `Okta Unauthorized Access to Application - DM`. The following
diff --git a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml b/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml
index 1f87cc42bf..018e6ec446 100644
--- a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml
+++ b/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml
@@ -5,6 +5,12 @@ date: '2024-11-14'
author: Okta, Inc, Michael Haag, Splunk
type: TTP
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
data_source: []
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `Okta ThreatInsight Threat Detected`. The following analytic utilizes Oktas
diff --git a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml b/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml
index 478b4895a1..e686982f42 100644
--- a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml
+++ b/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml
@@ -5,6 +5,14 @@ date: '2024-11-14'
author: Okta, Inc, Michael Haag, Splunk
type: TTP
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Okta ThreatInsight Threat Detected
data_source: []
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `Okta ThreatInsight Threat Detected`. The following analytic utilizes Oktas
diff --git a/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml b/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml
index 9817b5f845..971408a38b 100644
--- a/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml
+++ b/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml
@@ -4,6 +4,14 @@ version: 4
date: '2024-11-14'
author: Michael Haag, Marissa Bower, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Okta Multiple Failed MFA Requests For User
type: TTP
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `Okta Multiple Failed MFA Requests For User`. The following analytic identifies
diff --git a/detections/deprecated/osquery_pack___coldroot_detection.yml b/detections/deprecated/osquery_pack___coldroot_detection.yml
index 3ba9866bed..8c0a454e3c 100644
--- a/detections/deprecated/osquery_pack___coldroot_detection.yml
+++ b/detections/deprecated/osquery_pack___coldroot_detection.yml
@@ -4,6 +4,12 @@ version: 4
date: '2024-11-14'
author: Rico Valdez, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: TTP
description: This search looks for ColdRoot events from the osx-attacks osquery pack.
data_source: []
diff --git a/detections/deprecated/password_policy_discovery_with_net.yml b/detections/deprecated/password_policy_discovery_with_net.yml
index 0656e661c8..89def529b1 100644
--- a/detections/deprecated/password_policy_discovery_with_net.yml
+++ b/detections/deprecated/password_policy_discovery_with_net.yml
@@ -4,17 +4,23 @@ version: 7
date: '2025-01-24'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Password Policy Discovery with Net
type: Hunting
-description: The following analytic has been deprecated.
- The following analytic identifies the execution of `net.exe` or `net1.exe`
- with command line arguments aimed at obtaining the domain password policy. It leverages
- data from Endpoint Detection and Response (EDR) agents, focusing on process names
- and command-line executions. This activity is significant as it indicates potential
- reconnaissance efforts by adversaries to gather information about Active Directory
- password policies. If confirmed malicious, this behavior could allow attackers to
- understand password complexity requirements, aiding in brute-force or password-guessing
- attacks, ultimately compromising user accounts and gaining unauthorized access to
- the network.
+description: The following analytic has been deprecated. The following analytic identifies
+ the execution of `net.exe` or `net1.exe` with command line arguments aimed at obtaining
+ the domain password policy. It leverages data from Endpoint Detection and Response
+ (EDR) agents, focusing on process names and command-line executions. This activity
+ is significant as it indicates potential reconnaissance efforts by adversaries to
+ gather information about Active Directory password policies. If confirmed malicious,
+ this behavior could allow attackers to understand password complexity requirements,
+ aiding in brute-force or password-guessing attacks, ultimately compromising user
+ accounts and gaining unauthorized access to the network.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/processes_created_by_netsh.yml b/detections/deprecated/processes_created_by_netsh.yml
index cb947299d8..c82728a2d9 100644
--- a/detections/deprecated/processes_created_by_netsh.yml
+++ b/detections/deprecated/processes_created_by_netsh.yml
@@ -4,6 +4,13 @@ version: 8
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Updated to a new detection name
+ replacement_content:
+ - Processes launching netsh
type: TTP
description: This search looks for processes launching netsh.exe to execute various
commands via the netsh command-line utility. Netsh.exe is a command-line scripting
diff --git a/detections/deprecated/prohibited_software_on_endpoint.yml b/detections/deprecated/prohibited_software_on_endpoint.yml
index 243c1c8374..86593fcbf9 100644
--- a/detections/deprecated/prohibited_software_on_endpoint.yml
+++ b/detections/deprecated/prohibited_software_on_endpoint.yml
@@ -4,6 +4,13 @@ version: 5
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - Attacker Tools On Endpoint
type: Hunting
description: This search looks for applications on the endpoint that you have marked
as prohibited.
diff --git a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml b/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml
index b003f3bd58..6947837938 100644
--- a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml
+++ b/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml
@@ -4,6 +4,13 @@ version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - '- '
type: TTP
description: The search looks for command-line arguments used to hide a file or directory
using the reg add command.
diff --git a/detections/deprecated/remote_registry_key_modifications.yml b/detections/deprecated/remote_registry_key_modifications.yml
index 71f902a8ad..4a417c4fa6 100644
--- a/detections/deprecated/remote_registry_key_modifications.yml
+++ b/detections/deprecated/remote_registry_key_modifications.yml
@@ -4,6 +4,12 @@ version: 6
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: TTP
description: This search monitors for remote modifications to registry keys.
data_source:
diff --git a/detections/deprecated/remote_system_discovery_with_net.yml b/detections/deprecated/remote_system_discovery_with_net.yml
index 2377264b52..8b19a36706 100644
--- a/detections/deprecated/remote_system_discovery_with_net.yml
+++ b/detections/deprecated/remote_system_discovery_with_net.yml
@@ -4,14 +4,43 @@ version: 5
date: '2025-01-13'
author: Mauricio Velazco, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - Windows Sensitive Group Discovery With Net
type: Hunting
-description: The following analytic has been deprecated in favour of two dedicated analytics "4dc3951f-b3f8-4f46-b412-76a483f72277" and "a23a0e20-0b1b-4a07-82e5-ec5f70811e7a" .The following analytic identifies the execution of `net.exe` or `net1.exe` with command-line arguments used to discover remote systems, such as `domain computers /domain`. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments. This activity is significant as it indicates potential reconnaissance efforts by adversaries or Red Teams to map out networked systems and Active Directory structures. If confirmed malicious, this behavior could lead to further network exploitation, privilege escalation, or lateral movement within the environment.
+description: The following analytic has been deprecated in favour of two dedicated
+ analytics "4dc3951f-b3f8-4f46-b412-76a483f72277" and "a23a0e20-0b1b-4a07-82e5-ec5f70811e7a"
+ .The following analytic identifies the execution of `net.exe` or `net1.exe` with
+ command-line arguments used to discover remote systems, such as `domain computers
+ /domain`. This detection leverages data from Endpoint Detection and Response (EDR)
+ agents, focusing on process names and command-line arguments. This activity is significant
+ as it indicates potential reconnaissance efforts by adversaries or Red Teams to
+ map out networked systems and Active Directory structures. If confirmed malicious,
+ this behavior could lead to further network exploitation, privilege escalation,
+ or lateral movement within the environment.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
-search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` AND (Processes.process="*domain computers*" AND Processes.process=*/do*) OR (Processes.process="*view*" AND Processes.process=*/do*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `remote_system_discovery_with_net_filter`'
-how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
+search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
+ as lastTime from datamodel=Endpoint.Processes where `process_net` AND (Processes.process="*domain
+ computers*" AND Processes.process=*/do*) OR (Processes.process="*view*" AND Processes.process=*/do*)
+ by Processes.dest Processes.user Processes.parent_process Processes.process_name
+ Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
+ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `remote_system_discovery_with_net_filter`'
+how_to_implement: The detection is based on data that originates from Endpoint Detection
+ and Response (EDR) agents. These agents are designed to provide security-related
+ telemetry from the endpoints where the agent is installed. To implement this search,
+ you must ingest logs that contain the process GUID, process name, and parent process.
+ Additionally, you must ingest complete command-line executions. These logs must
+ be processed using the appropriate Splunk Technology Add-ons that are specific to
+ the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
+ data model. Use the Splunk Common Information Model (CIM) to normalize the field
+ names and speed up the data modeling process.
known_false_positives: Administrators or power users may use this command for troubleshooting.
references:
- https://attack.mitre.org/techniques/T1018/
@@ -31,6 +60,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml b/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml
index 0197ba45a3..d3d1e1b499 100644
--- a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml
+++ b/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml
@@ -4,6 +4,13 @@ version: 6
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Updated to a new detection name
+ replacement_content:
+ - Scheduled Task Deleted Or Created via CMD
type: TTP
description: This search looks for flags passed to schtasks.exe on the command-line
that indicate that task names related to the execution of Bad Rabbit ransomware
diff --git a/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml b/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml
index 1f4a043402..c894e4fa3a 100644
--- a/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml
+++ b/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml
@@ -4,6 +4,12 @@ version: 4
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: TTP
description: The search is used to detect systems that are still vulnerable to the
Spectre and Meltdown vulnerabilities.
diff --git a/detections/deprecated/suspicious_changes_to_file_associations.yml b/detections/deprecated/suspicious_changes_to_file_associations.yml
index e9438be5a1..f1c5eb5d31 100644
--- a/detections/deprecated/suspicious_changes_to_file_associations.yml
+++ b/detections/deprecated/suspicious_changes_to_file_associations.yml
@@ -4,6 +4,12 @@ version: 7
date: '2024-11-14'
author: Rico Valdez, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: TTP
description: This search looks for changes to registry values that control Windows
file associations, executed by a process that is not typical for legitimate, routine
diff --git a/detections/deprecated/suspicious_email___uba_anomaly.yml b/detections/deprecated/suspicious_email___uba_anomaly.yml
index 0e3a3f31d6..0b77fd20a8 100644
--- a/detections/deprecated/suspicious_email___uba_anomaly.yml
+++ b/detections/deprecated/suspicious_email___uba_anomaly.yml
@@ -4,6 +4,12 @@ version: 6
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: Anomaly
description: This detection looks for emails that are suspicious because of their
sender, domain rareness, or behavior differences. This is an anomaly generated by
diff --git a/detections/deprecated/suspicious_file_write.yml b/detections/deprecated/suspicious_file_write.yml
index 8630632e57..ce7ce09da0 100644
--- a/detections/deprecated/suspicious_file_write.yml
+++ b/detections/deprecated/suspicious_file_write.yml
@@ -4,6 +4,13 @@ version: 6
date: '2024-11-14'
author: Rico Valdez, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - ''
type: Hunting
description: The search looks for files created with names that have been linked to
malicious activity.
diff --git a/detections/deprecated/suspicious_powershell_command_line_arguments.yml b/detections/deprecated/suspicious_powershell_command_line_arguments.yml
index b2efc4ee51..a6c19ed8d7 100644
--- a/detections/deprecated/suspicious_powershell_command_line_arguments.yml
+++ b/detections/deprecated/suspicious_powershell_command_line_arguments.yml
@@ -4,6 +4,13 @@ version: 9
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - Malicious PowerShell Process - Encoded Command
type: TTP
description: This search looks for PowerShell processes started with a base64 encoded
command-line passed to it, with parameters to modify the execution policy for the
diff --git a/detections/deprecated/suspicious_rundll32_rename.yml b/detections/deprecated/suspicious_rundll32_rename.yml
index 48fdc6b2d5..eff58f4873 100644
--- a/detections/deprecated/suspicious_rundll32_rename.yml
+++ b/detections/deprecated/suspicious_rundll32_rename.yml
@@ -4,6 +4,12 @@ version: 7
date: '2024-11-14'
author: Michael Haag, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: Hunting
description: The following hunting analytic identifies renamed instances of rundll32.exe
executing. rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64.
diff --git a/detections/deprecated/suspicious_writes_to_system_volume_information.yml b/detections/deprecated/suspicious_writes_to_system_volume_information.yml
index 866160575b..cc6e0fa6ae 100644
--- a/detections/deprecated/suspicious_writes_to_system_volume_information.yml
+++ b/detections/deprecated/suspicious_writes_to_system_volume_information.yml
@@ -4,6 +4,12 @@ version: 5
date: '2024-11-14'
author: Rico Valdez, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: Hunting
description: This search detects writes to the 'System Volume Information' folder
by something other than the System process.
diff --git a/detections/deprecated/uncommon_processes_on_endpoint.yml b/detections/deprecated/uncommon_processes_on_endpoint.yml
index e0378b0e1f..4c90b29fdc 100644
--- a/detections/deprecated/uncommon_processes_on_endpoint.yml
+++ b/detections/deprecated/uncommon_processes_on_endpoint.yml
@@ -4,6 +4,13 @@ version: 7
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - Attacker Tools On Endpoint
type: Hunting
description: This search looks for applications on the endpoint that you have marked
as uncommon.
diff --git a/detections/deprecated/unsigned_image_loaded_by_lsass.yml b/detections/deprecated/unsigned_image_loaded_by_lsass.yml
index db021a2bf3..38f74b6f6d 100644
--- a/detections/deprecated/unsigned_image_loaded_by_lsass.yml
+++ b/detections/deprecated/unsigned_image_loaded_by_lsass.yml
@@ -4,6 +4,13 @@ version: 4
date: '2024-11-14'
author: Patrick Bareiss, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - ''
type: TTP
description: This search detects loading of unsigned images by LSASS. Deprecated because
too noisy.
diff --git a/detections/deprecated/unsuccessful_netbackup_backups.yml b/detections/deprecated/unsuccessful_netbackup_backups.yml
index 3e8fc0b5af..feafa5361e 100644
--- a/detections/deprecated/unsuccessful_netbackup_backups.yml
+++ b/detections/deprecated/unsuccessful_netbackup_backups.yml
@@ -4,6 +4,12 @@ version: 4
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: Hunting
description: This search gives you the hosts where a backup was attempted and then
failed.
diff --git a/detections/deprecated/web_fraud___account_harvesting.yml b/detections/deprecated/web_fraud___account_harvesting.yml
index 4fb3b3b784..17f3be4b4f 100644
--- a/detections/deprecated/web_fraud___account_harvesting.yml
+++ b/detections/deprecated/web_fraud___account_harvesting.yml
@@ -4,6 +4,12 @@ version: 4
date: '2024-11-14'
author: Jim Apger, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: TTP
description: This search is used to identify the creation of multiple user accounts
using the same email domain name.
diff --git a/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml b/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml
index 518a5be28e..69a013dabf 100644
--- a/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml
+++ b/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml
@@ -4,6 +4,12 @@ version: 4
date: '2024-11-14'
author: Jim Apger, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: Anomaly
description: This search is used to examine web sessions to identify those where the
clicks are occurring too quickly for a human or are occurring with a near-perfect
diff --git a/detections/deprecated/web_fraud___password_sharing_across_accounts.yml b/detections/deprecated/web_fraud___password_sharing_across_accounts.yml
index 48c9b3908c..0fe79ab5ff 100644
--- a/detections/deprecated/web_fraud___password_sharing_across_accounts.yml
+++ b/detections/deprecated/web_fraud___password_sharing_across_accounts.yml
@@ -4,6 +4,12 @@ version: 4
date: '2024-11-14'
author: Jim Apger, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: Anomaly
description: This search is used to identify user accounts that share a common password.
data_source: []
diff --git a/detections/deprecated/windows_command_shell_fetch_env_variables.yml b/detections/deprecated/windows_command_shell_fetch_env_variables.yml
index 90618ba3e5..80ddcb7db1 100644
--- a/detections/deprecated/windows_command_shell_fetch_env_variables.yml
+++ b/detections/deprecated/windows_command_shell_fetch_env_variables.yml
@@ -4,16 +4,22 @@ version: 5
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows List ENV Variables Via SET Command From Uncommon Parent
type: TTP
-description: The following analytic has been deprecated.
- The following analytic identifies a suspicious process command line fetching
- environment variables with a non-shell parent process. It leverages data from Endpoint
- Detection and Response (EDR) agents, focusing on command-line executions and parent
- process names. This activity is significant as it is commonly associated with malware
- like Qakbot, which uses this technique to gather system information. If confirmed
- malicious, this behavior could indicate that the parent process has been compromised,
- potentially allowing attackers to execute arbitrary commands, escalate privileges,
- or persist within the environment.
+description: The following analytic has been deprecated. The following analytic identifies
+ a suspicious process command line fetching environment variables with a non-shell
+ parent process. It leverages data from Endpoint Detection and Response (EDR) agents,
+ focusing on command-line executions and parent process names. This activity is significant
+ as it is commonly associated with malware like Qakbot, which uses this technique
+ to gather system information. If confirmed malicious, this behavior could indicate
+ that the parent process has been compromised, potentially allowing attackers to
+ execute arbitrary commands, escalate privileges, or persist within the environment.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/windows_connhost_exe_started_forcefully.yml b/detections/deprecated/windows_connhost_exe_started_forcefully.yml
index 2718083864..8bb950c864 100644
--- a/detections/deprecated/windows_connhost_exe_started_forcefully.yml
+++ b/detections/deprecated/windows_connhost_exe_started_forcefully.yml
@@ -4,6 +4,12 @@ version: 5
date: '2024-11-14'
author: Rod Soto, Jose Hernandez, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: TTP
description: The search looks for the Console Window Host process (connhost.exe) executed
using the force flag -ForceV1. This is not regular behavior in the Windows OS and
diff --git a/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml b/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml
index 38d777ae9a..f452743951 100644
--- a/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml
+++ b/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml
@@ -4,6 +4,14 @@ version: 5
date: '2024-11-14'
author: Michael Haag, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Windows DLL Search Order Hijacking Hunt with Sysmon
type: Hunting
description: The following hunting analytic is an experimental query built against
a accidental feature using the latest Sysmon TA 3.0 (https://splunkbase.splunk.com/app/5709/)
diff --git a/detections/deprecated/windows_hosts_file_modification.yml b/detections/deprecated/windows_hosts_file_modification.yml
index 0c7453eab3..fd6fa8ec88 100644
--- a/detections/deprecated/windows_hosts_file_modification.yml
+++ b/detections/deprecated/windows_hosts_file_modification.yml
@@ -4,6 +4,12 @@ version: 4
date: '2024-11-14'
author: Rico Valdez, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content: []
type: TTP
description: The search looks for modifications to the hosts file on all Windows endpoints
across your environment.
diff --git a/detections/deprecated/windows_lateral_tool_transfer_remcom.yml b/detections/deprecated/windows_lateral_tool_transfer_remcom.yml
index 0611c1c8f6..dd1d040b65 100644
--- a/detections/deprecated/windows_lateral_tool_transfer_remcom.yml
+++ b/detections/deprecated/windows_lateral_tool_transfer_remcom.yml
@@ -5,6 +5,13 @@ date: '2024-12-10'
author: Michael Haag, Splunk
type: TTP
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Updated to a new detection name
+ replacement_content:
+ - Windows Service Execution RemCom
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/windows_modify_registry_reg_restore.yml b/detections/deprecated/windows_modify_registry_reg_restore.yml
index f63d1b0214..324a5baed9 100644
--- a/detections/deprecated/windows_modify_registry_reg_restore.yml
+++ b/detections/deprecated/windows_modify_registry_reg_restore.yml
@@ -4,16 +4,23 @@ version: 5
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Registry Entries Restored Via Reg
type: Hunting
-description: The following analytic has been deprecated.
- The following analytic detects the execution of reg.exe with the "restore"
- parameter, indicating an attempt to restore registry backup data on a host. This
- detection leverages data from Endpoint Detection and Response (EDR) agents, focusing
- on process execution logs and command-line arguments. This activity is significant
- as it may indicate post-exploitation actions, such as those performed by tools like
- winpeas, which use "reg save" and "reg restore" to manipulate registry settings.
- If confirmed malicious, this could allow an attacker to revert registry changes,
- potentially bypassing security controls and maintaining persistence.
+description: The following analytic has been deprecated. The following analytic detects
+ the execution of reg.exe with the "restore" parameter, indicating an attempt to
+ restore registry backup data on a host. This detection leverages data from Endpoint
+ Detection and Response (EDR) agents, focusing on process execution logs and command-line
+ arguments. This activity is significant as it may indicate post-exploitation actions,
+ such as those performed by tools like winpeas, which use "reg save" and "reg restore"
+ to manipulate registry settings. If confirmed malicious, this could allow an attacker
+ to revert registry changes, potentially bypassing security controls and maintaining
+ persistence.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/windows_msiexec_with_network_connections.yml b/detections/deprecated/windows_msiexec_with_network_connections.yml
index 26347f6535..2331bd6952 100644
--- a/detections/deprecated/windows_msiexec_with_network_connections.yml
+++ b/detections/deprecated/windows_msiexec_with_network_connections.yml
@@ -4,16 +4,22 @@ version: 6
date: '2025-01-24'
author: Michael Haag, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows HTTP Network Communication From MSIExec
type: TTP
-description: The following analytic has been deprecated.
- The following analytic detects MSIExec making network connections over
- ports 443 or 80. This behavior is identified by correlating process creation events
- from Endpoint Detection and Response (EDR) agents with network traffic logs. Typically,
- MSIExec does not perform network communication to the internet, making this activity
- unusual and potentially indicative of malicious behavior. If confirmed malicious,
- an attacker could be using MSIExec to download or communicate with external servers,
- potentially leading to data exfiltration, command and control (C2) communication,
- or further malware deployment.
+description: The following analytic has been deprecated. The following analytic detects
+ MSIExec making network connections over ports 443 or 80. This behavior is identified
+ by correlating process creation events from Endpoint Detection and Response (EDR)
+ agents with network traffic logs. Typically, MSIExec does not perform network communication
+ to the internet, making this activity unusual and potentially indicative of malicious
+ behavior. If confirmed malicious, an attacker could be using MSIExec to download
+ or communicate with external servers, potentially leading to data exfiltration,
+ command and control (C2) communication, or further malware deployment.
data_source:
- Sysmon EventID 1 AND Sysmon EventID 3
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
diff --git a/detections/deprecated/windows_network_share_interaction_with_net.yml b/detections/deprecated/windows_network_share_interaction_with_net.yml
index fea71519c1..ab7de51ef6 100644
--- a/detections/deprecated/windows_network_share_interaction_with_net.yml
+++ b/detections/deprecated/windows_network_share_interaction_with_net.yml
@@ -4,16 +4,23 @@ version: 6
date: '2025-01-24'
author: Dean Luxton
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Network Share Interaction Via Net
type: TTP
data_source:
- Sysmon EventID 1
-description: The following analytic has been deprecated.
- This analytic detects network share discovery and collection activities
- performed on Windows systems using the Net command. Attackers often use network
- share discovery to identify accessible shared resources within a network, which
- can be a precursor to privilege escalation or data exfiltration. By monitoring Windows
- Event Logs for the usage of the Net command to list and interact with network shares,
- this detection helps identify potential reconnaissance and collection activities.
+description: The following analytic has been deprecated. This analytic detects network
+ share discovery and collection activities performed on Windows systems using the
+ Net command. Attackers often use network share discovery to identify accessible
+ shared resources within a network, which can be a precursor to privilege escalation
+ or data exfiltration. By monitoring Windows Event Logs for the usage of the Net
+ command to list and interact with network shares, this detection helps identify
+ potential reconnaissance and collection activities.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime values(Processes.user_category) as user_category values(Processes.user_bunit)
as user_bunit FROM datamodel=Endpoint.Processes WHERE `process_net` BY Processes.user
diff --git a/detections/deprecated/windows_office_product_spawning_msdt.yml b/detections/deprecated/windows_office_product_spawning_msdt.yml
index ad36ac3325..73517da1ff 100644
--- a/detections/deprecated/windows_office_product_spawning_msdt.yml
+++ b/detections/deprecated/windows_office_product_spawning_msdt.yml
@@ -4,16 +4,22 @@ version: 9
date: '2025-01-24'
author: Michael Haag, Teoderick Contreras, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Spawned MSDT
type: TTP
-description: The following analytic has been deprecated.
- The following analytic detects a Microsoft Office product spawning the
- Windows msdt.exe process. This detection leverages data from Endpoint Detection
- and Response (EDR) agents, focusing on process creation events where Office applications
- are the parent process. This activity is significant as it may indicate an attempt
- to exploit protocol handlers to bypass security controls, even if macros are disabled.
- If confirmed malicious, this behavior could allow an attacker to execute arbitrary
- code, potentially leading to system compromise, data exfiltration, or further lateral
- movement within the network.
+description: The following analytic has been deprecated. The following analytic detects
+ a Microsoft Office product spawning the Windows msdt.exe process. This detection
+ leverages data from Endpoint Detection and Response (EDR) agents, focusing on process
+ creation events where Office applications are the parent process. This activity
+ is significant as it may indicate an attempt to exploit protocol handlers to bypass
+ security controls, even if macros are disabled. If confirmed malicious, this behavior
+ could allow an attacker to execute arbitrary code, potentially leading to system
+ compromise, data exfiltration, or further lateral movement within the network.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
@@ -91,6 +97,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/msdt.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/msdt.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/deprecated/windows_query_registry_reg_save.yml b/detections/deprecated/windows_query_registry_reg_save.yml
index 291c0cf7a0..2ef3993258 100644
--- a/detections/deprecated/windows_query_registry_reg_save.yml
+++ b/detections/deprecated/windows_query_registry_reg_save.yml
@@ -4,15 +4,22 @@ version: 6
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Registry Entries Exported Via Reg
type: Hunting
-description: The following analytic has been deprecated.
- The following analytic detects the execution of the reg.exe process with
- the "save" parameter. This detection leverages data from Endpoint Detection and
- Response (EDR) agents, focusing on process execution logs and command-line arguments.
- This activity is significant because threat actors often use the "reg save" command
- to dump credentials or test registry modification capabilities on compromised hosts.
- If confirmed malicious, this behavior could allow attackers to escalate privileges,
- persist in the environment, or access sensitive information stored in the registry.
+description: The following analytic has been deprecated. The following analytic detects
+ the execution of the reg.exe process with the "save" parameter. This detection leverages
+ data from Endpoint Detection and Response (EDR) agents, focusing on process execution
+ logs and command-line arguments. This activity is significant because threat actors
+ often use the "reg save" command to dump credentials or test registry modification
+ capabilities on compromised hosts. If confirmed malicious, this behavior could allow
+ attackers to escalate privileges, persist in the environment, or access sensitive
+ information stored in the registry.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/windows_valid_account_with_never_expires_password.yml b/detections/deprecated/windows_valid_account_with_never_expires_password.yml
index 01b416d1d5..65421b5a51 100644
--- a/detections/deprecated/windows_valid_account_with_never_expires_password.yml
+++ b/detections/deprecated/windows_valid_account_with_never_expires_password.yml
@@ -4,16 +4,22 @@ version: 6
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Set Account Password Policy To Unlimited Via Net
type: TTP
-description: The following analytic has been deprecated.
- The following analytic detects the use of net.exe to update user account
- policies to set passwords as non-expiring. It leverages data from Endpoint Detection
- and Response (EDR) agents, focusing on command-line executions involving "/maxpwage:unlimited".
- This activity is significant as it can indicate an attempt to maintain persistence,
- escalate privileges, evade defenses, or facilitate lateral movement. If confirmed
- malicious, this behavior could allow an attacker to maintain long-term access to
- compromised accounts, potentially leading to further exploitation and unauthorized
- access to sensitive information.
+description: The following analytic has been deprecated. The following analytic detects
+ the use of net.exe to update user account policies to set passwords as non-expiring.
+ It leverages data from Endpoint Detection and Response (EDR) agents, focusing on
+ command-line executions involving "/maxpwage:unlimited". This activity is significant
+ as it can indicate an attempt to maintain persistence, escalate privileges, evade
+ defenses, or facilitate lateral movement. If confirmed malicious, this behavior
+ could allow an attacker to maintain long-term access to compromised accounts, potentially
+ leading to further exploitation and unauthorized access to sensitive information.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/winword_spawning_cmd.yml b/detections/deprecated/winword_spawning_cmd.yml
index 5760517a84..de643bfb78 100644
--- a/detections/deprecated/winword_spawning_cmd.yml
+++ b/detections/deprecated/winword_spawning_cmd.yml
@@ -4,16 +4,24 @@ version: 7
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
type: TTP
-description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process".
- The following analytic identifies instances where Microsoft Word (winword.exe)
- spawns the command prompt (cmd.exe). This behavior is detected using Endpoint Detection
- and Response (EDR) telemetry, focusing on process creation events where the parent
- process is winword.exe. This activity is significant because it is uncommon and
- often associated with spearphishing attacks, where malicious attachments execute
- commands via cmd.exe. If confirmed malicious, this could allow an attacker to execute
- arbitrary commands, potentially leading to further system compromise, data exfiltration,
- or lateral movement within the network.
+description: The following analytic has been deprecated in favour of a more generic
+ approach in "Windows Office Product Spawned Uncommon Process". The following analytic
+ identifies instances where Microsoft Word (winword.exe) spawns the command prompt
+ (cmd.exe). This behavior is detected using Endpoint Detection and Response (EDR)
+ telemetry, focusing on process creation events where the parent process is winword.exe.
+ This activity is significant because it is uncommon and often associated with spearphishing
+ attacks, where malicious attachments execute commands via cmd.exe. If confirmed
+ malicious, this could allow an attacker to execute arbitrary commands, potentially
+ leading to further system compromise, data exfiltration, or lateral movement within
+ the network.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
@@ -82,6 +90,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/deprecated/winword_spawning_powershell.yml b/detections/deprecated/winword_spawning_powershell.yml
index b2e102dc75..74a7ae6560 100644
--- a/detections/deprecated/winword_spawning_powershell.yml
+++ b/detections/deprecated/winword_spawning_powershell.yml
@@ -4,16 +4,24 @@ version: 7
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
type: TTP
-description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process".
- The following analytic identifies instances where Microsoft Word (winword.exe)
- spawns a PowerShell process. This behavior is detected using Endpoint Detection
- and Response (EDR) telemetry, focusing on process creation events where the parent
- process is winword.exe. This activity is significant because it is uncommon and
- often associated with spearphishing attacks, where malicious documents execute encoded
- PowerShell commands. If confirmed malicious, this could allow an attacker to execute
- arbitrary code, potentially leading to data exfiltration, system compromise, or
- further lateral movement within the network.
+description: The following analytic has been deprecated in favour of a more generic
+ approach in "Windows Office Product Spawned Uncommon Process". The following analytic
+ identifies instances where Microsoft Word (winword.exe) spawns a PowerShell process.
+ This behavior is detected using Endpoint Detection and Response (EDR) telemetry,
+ focusing on process creation events where the parent process is winword.exe. This
+ activity is significant because it is uncommon and often associated with spearphishing
+ attacks, where malicious documents execute encoded PowerShell commands. If confirmed
+ malicious, this could allow an attacker to execute arbitrary code, potentially leading
+ to data exfiltration, system compromise, or further lateral movement within the
+ network.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
@@ -85,6 +93,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/deprecated/winword_spawning_windows_script_host.yml b/detections/deprecated/winword_spawning_windows_script_host.yml
index 16ee7d84c1..606abeabb3 100644
--- a/detections/deprecated/winword_spawning_windows_script_host.yml
+++ b/detections/deprecated/winword_spawning_windows_script_host.yml
@@ -4,9 +4,19 @@ version: 6
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
+deprecation_info:
+ deprecation_date: '2025-02-26'
+ deprecation_version: 5.2.0
+ content_type: detection
+ reason: "The following analytics was deprecated in favour of a more generic approach.
+ Where instead of creating specific analytic for every potentially suspicious child
+ of an office product. We group them by threat level.\nThis would ease management
+ and false positives tuning."
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
type: TTP
-description: The following analytic has been deprecated in favour of a more generic approach.
- The following analytic identifies instances where Microsoft Winword.exe
+description: The following analytic has been deprecated in favour of a more generic
+ approach. The following analytic identifies instances where Microsoft Winword.exe
spawns Windows Script Host processes (cscript.exe or wscript.exe). This behavior
is detected using Endpoint Detection and Response (EDR) telemetry, focusing on process
creation events where the parent process is Winword.exe. This activity is significant
@@ -80,6 +90,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_wsh.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_wsh.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
From ebc1d84058f5366480fd7719f70d37b8b099eca8 Mon Sep 17 00:00:00 2001
From: pyth0n1c
Date: Fri, 14 Feb 2025 10:10:20 -0800
Subject: [PATCH 07/67] remove the deprecation_info section that was previously
added to detections
---
.../abnormally_high_aws_instances_launched_by_user.yml | 8 --------
...ally_high_aws_instances_launched_by_user___mltk.yml | 6 ------
...bnormally_high_aws_instances_terminated_by_user.yml | 8 --------
...ly_high_aws_instances_terminated_by_user___mltk.yml | 6 ------
.../deprecated/account_discovery_with_net_app.yml | 10 ----------
detections/deprecated/asl_aws_createaccesskey.yml | 8 --------
.../deprecated/asl_aws_excessive_security_scanning.yml | 6 ------
.../deprecated/asl_aws_password_policy_changes.yml | 6 ------
.../deprecated/attempt_to_stop_security_service.yml | 7 -------
...mpted_credential_dump_from_registry_via_reg_exe.yml | 9 ---------
..._cloud_provisioning_from_previously_unseen_city.yml | 8 --------
...oud_provisioning_from_previously_unseen_country.yml | 8 --------
..._provisioning_from_previously_unseen_ip_address.yml | 8 --------
...loud_provisioning_from_previously_unseen_region.yml | 8 --------
..._eks_kubernetes_cluster_sensitive_object_access.yml | 8 --------
.../deprecated/change_default_file_association.yml | 7 -------
.../clients_connecting_to_multiple_dns_servers.yml | 6 ------
.../cloud_network_access_control_list_deleted.yml | 8 --------
.../cmdline_tool_not_executed_in_cmd_shell.yml | 7 -------
.../deprecated/correlation_by_repository_and_risk.yml | 7 -------
detections/deprecated/correlation_by_user_and_risk.yml | 7 -------
.../create_local_admin_accounts_using_net_exe.yml | 7 -------
detections/deprecated/deleting_of_net_users.yml | 7 -------
...etect_activity_related_to_pass_the_hash_attacks.yml | 6 ------
.../detect_api_activity_from_users_without_mfa.yml | 8 --------
...ect_aws_api_activities_from_unapproved_accounts.yml | 6 ------
.../detect_critical_alerts_from_security_tools.yml | 7 -------
...requests_to_phishing_sites_leveraging_evilginx2.yml | 6 ------
.../deprecated/detect_long_dns_txt_record_response.yml | 6 ------
.../deprecated/detect_mimikatz_using_loaded_images.yml | 6 ------
...tect_mimikatz_via_powershell_and_eventcode_4703.yml | 7 -------
.../detect_new_api_calls_from_user_roles.yml | 8 --------
.../deprecated/detect_new_user_aws_console_login.yml | 8 --------
...used_for_system_network_configuration_discovery.yml | 7 -------
.../deprecated/detect_spike_in_aws_api_activity.yml | 7 -------
.../detect_spike_in_network_acl_activity.yml | 8 --------
.../detect_spike_in_security_group_activity.yml | 8 --------
detections/deprecated/detect_usb_device_insertion.yml | 6 ------
.../detect_web_traffic_to_dynamic_domain_providers.yml | 7 -------
.../deprecated/detect_webshell_exploit_behavior.yml | 7 -------
detections/deprecated/detection_of_dns_tunnels.yml | 6 ------
detections/deprecated/disabling_net_user_account.yml | 7 -------
...y_requests_resolved_by_unauthorized_dns_servers.yml | 6 ------
detections/deprecated/dns_record_changed.yml | 6 ------
.../domain_account_discovery_with_net_app.yml | 10 ----------
.../deprecated/domain_group_discovery_with_net.yml | 7 -------
.../deprecated/dump_lsass_via_procdump_rename.yml | 7 -------
...2_instance_modified_with_previously_unseen_user.yml | 8 --------
...c2_instance_started_in_previously_unseen_region.yml | 8 --------
...ec2_instance_started_with_previously_unseen_ami.yml | 8 --------
...ce_started_with_previously_unseen_instance_type.yml | 8 --------
...c2_instance_started_with_previously_unseen_user.yml | 8 --------
.../deprecated/elevated_group_discovery_with_net.yml | 7 -------
detections/deprecated/excel_spawning_powershell.yml | 7 -------
.../deprecated/excessive_service_stop_attempt.yml | 7 -------
detections/deprecated/excessive_usage_of_net_app.yml | 7 -------
.../execution_of_file_with_spaces_before_extension.yml | 7 -------
...ded_period_without_successful_netbackup_backups.yml | 6 ------
detections/deprecated/extraction_of_registry_hives.yml | 7 -------
.../first_time_seen_command_line_argument.yml | 7 -------
...detect_accounts_with_high_risk_roles_by_project.yml | 6 ------
...t_high_risk_permissions_by_resource_and_account.yml | 6 ------
detections/deprecated/gcp_detect_oauth_token_abuse.yml | 6 ------
.../gcp_kubernetes_cluster_scan_detection.yml | 8 --------
detections/deprecated/identify_new_user_accounts.yml | 7 -------
..._aws_detect_most_active_service_accounts_by_pod.yml | 7 -------
...rnetes_aws_detect_rbac_authorization_by_account.yml | 7 -------
.../kubernetes_aws_detect_sensitive_role_access.yml | 7 -------
...etect_service_accounts_forbidden_failure_access.yml | 7 -------
..._azure_active_service_accounts_by_pod_namespace.yml | 7 -------
...etes_azure_detect_rbac_authorization_by_account.yml | 7 -------
...kubernetes_azure_detect_sensitive_object_access.yml | 7 -------
.../kubernetes_azure_detect_sensitive_role_access.yml | 7 -------
...etect_service_accounts_forbidden_failure_access.yml | 7 -------
...ubernetes_azure_detect_suspicious_kubectl_calls.yml | 7 -------
.../kubernetes_azure_pod_scan_fingerprint.yml | 7 -------
.../deprecated/kubernetes_azure_scan_fingerprint.yml | 7 -------
..._gcp_detect_most_active_service_accounts_by_pod.yml | 7 -------
...netes_gcp_detect_rbac_authorizations_by_account.yml | 7 -------
.../kubernetes_gcp_detect_sensitive_object_access.yml | 7 -------
.../kubernetes_gcp_detect_sensitive_role_access.yml | 7 -------
...etect_service_accounts_forbidden_failure_access.yml | 7 -------
.../kubernetes_gcp_detect_suspicious_kubectl_calls.yml | 7 -------
.../deprecated/linux_auditd_find_private_keys.yml | 7 -------
.../deprecated/local_account_discovery_with_net.yml | 7 -------
detections/deprecated/monitor_dns_for_brand_abuse.yml | 7 -------
.../mshtml_module_load_in_office_product.yml | 7 -------
...users_with_invalid_credentials_from_the_same_ip.yml | 8 --------
detections/deprecated/net_localgroup_discovery.yml | 8 --------
.../network_connection_discovery_with_net.yml | 7 -------
.../o365_suspicious_admin_email_forwarding.yml | 8 --------
.../deprecated/o365_suspicious_rights_delegation.yml | 8 --------
.../o365_suspicious_user_email_forwarding.yml | 8 --------
.../deprecated/office_application_drop_executable.yml | 7 -------
.../office_application_spawn_regsvr32_process.yml | 7 -------
.../office_application_spawn_rundll32_process.yml | 7 -------
.../office_document_creating_schedule_task.yml | 7 -------
.../office_document_executing_macro_code.yml | 7 -------
...fice_document_spawned_child_process_to_download.yml | 7 -------
.../deprecated/office_product_spawn_cmd_process.yml | 7 -------
.../deprecated/office_product_spawning_bitsadmin.yml | 7 -------
.../deprecated/office_product_spawning_certutil.yml | 7 -------
.../deprecated/office_product_spawning_mshta.yml | 7 -------
.../office_product_spawning_rundll32_with_no_dll.yml | 7 -------
.../office_product_spawning_windows_script_host.yml | 7 -------
detections/deprecated/office_product_spawning_wmic.yml | 7 -------
.../deprecated/office_product_writing_cab_or_inf.yml | 7 -------
detections/deprecated/office_spawning_control.yml | 7 -------
detections/deprecated/okta_account_locked_out.yml | 8 --------
detections/deprecated/okta_account_lockout_events.yml | 8 --------
detections/deprecated/okta_failed_sso_attempts.yml | 8 --------
...atinsight_login_failure_with_high_unknown_users.yml | 6 ------
...ta_threatinsight_suspected_passwordspray_attack.yml | 8 --------
.../okta_two_or_more_rejected_okta_pushes.yml | 8 --------
.../deprecated/osquery_pack___coldroot_detection.yml | 6 ------
.../deprecated/password_policy_discovery_with_net.yml | 7 -------
detections/deprecated/processes_created_by_netsh.yml | 7 -------
.../deprecated/prohibited_software_on_endpoint.yml | 7 -------
...sed_to_hide_files_directories_via_registry_keys.yml | 7 -------
.../deprecated/remote_registry_key_modifications.yml | 6 ------
.../deprecated/remote_system_discovery_with_net.yml | 7 -------
.../scheduled_tasks_used_in_badrabbit_ransomware.yml | 7 -------
.../spectre_and_meltdown_vulnerable_systems.yml | 6 ------
.../suspicious_changes_to_file_associations.yml | 6 ------
.../deprecated/suspicious_email___uba_anomaly.yml | 6 ------
detections/deprecated/suspicious_file_write.yml | 7 -------
.../suspicious_powershell_command_line_arguments.yml | 7 -------
detections/deprecated/suspicious_rundll32_rename.yml | 6 ------
.../suspicious_writes_to_system_volume_information.yml | 6 ------
.../deprecated/uncommon_processes_on_endpoint.yml | 7 -------
.../deprecated/unsigned_image_loaded_by_lsass.yml | 7 -------
.../deprecated/unsuccessful_netbackup_backups.yml | 6 ------
.../deprecated/web_fraud___account_harvesting.yml | 6 ------
.../web_fraud___anomalous_user_clickspeed.yml | 6 ------
.../web_fraud___password_sharing_across_accounts.yml | 6 ------
.../windows_command_shell_fetch_env_variables.yml | 7 -------
.../windows_connhost_exe_started_forcefully.yml | 6 ------
.../windows_dll_search_order_hijacking_hunt.yml | 8 --------
.../deprecated/windows_hosts_file_modification.yml | 6 ------
.../windows_lateral_tool_transfer_remcom.yml | 7 -------
.../deprecated/windows_modify_registry_reg_restore.yml | 7 -------
.../windows_msiexec_with_network_connections.yml | 7 -------
.../windows_network_share_interaction_with_net.yml | 7 -------
.../windows_office_product_spawning_msdt.yml | 7 -------
.../deprecated/windows_query_registry_reg_save.yml | 7 -------
...ndows_valid_account_with_never_expires_password.yml | 7 -------
detections/deprecated/winword_spawning_cmd.yml | 7 -------
detections/deprecated/winword_spawning_powershell.yml | 7 -------
.../winword_spawning_windows_script_host.yml | 10 ----------
149 files changed, 1053 deletions(-)
diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml b/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml
index a84ac20e7c..e46dec6369 100644
--- a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml
+++ b/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml
@@ -4,14 +4,6 @@ version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Abnormally High Number Of Cloud Instances Launched
type: Anomaly
description: This search looks for AWS CloudTrail events where a user successfully
launches an abnormally high number of instances. This search is deprecated and have
diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml b/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml
index 8279df5c30..9acc4411b2 100644
--- a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml
+++ b/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml
@@ -4,12 +4,6 @@ version: 5
date: '2024-11-14'
author: Jason Brewer, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: Anomaly
description: This search looks for AWS CloudTrail events where a user successfully
launches an abnormally high number of instances. This search is deprecated and have
diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml
index f028df1a26..ae3c15024b 100644
--- a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml
+++ b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml
@@ -4,14 +4,6 @@ version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Abnormally High Number Of Cloud Instances Destroyed
type: Anomaly
description: This search looks for AWS CloudTrail events where an abnormally high
number of instances were successfully terminated by a user in a 10-minute window.
diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml
index adcfe17ca3..04f88a704a 100644
--- a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml
+++ b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml
@@ -4,12 +4,6 @@ version: 5
date: '2024-11-14'
author: Jason Brewer, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: Anomaly
description: This search looks for AWS CloudTrail events where a user successfully
terminates an abnormally high number of instances. This search is deprecated and
diff --git a/detections/deprecated/account_discovery_with_net_app.yml b/detections/deprecated/account_discovery_with_net_app.yml
index 323489ac89..bf2568a3f0 100644
--- a/detections/deprecated/account_discovery_with_net_app.yml
+++ b/detections/deprecated/account_discovery_with_net_app.yml
@@ -4,16 +4,6 @@ version: 8
date: '2025-01-13'
author: Teoderick Contreras, Splunk, TheLawsOfChaos, Github Community
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: This analytic was a TTP that focused on unrelated things and called account
- discovery. Since there were other detection that overlapped with it. I choose
- to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122
- / Windows Excessive Usage Of Net App.
- replacement_content:
- - Windows Excessive Usage Of Net App
type: TTP
description: The following analytic has been deprecated in favour of the more generic
"45e52536-ae42-11eb-b5c6-acde48001122". The following analytic detects potential
diff --git a/detections/deprecated/asl_aws_createaccesskey.yml b/detections/deprecated/asl_aws_createaccesskey.yml
index 33967e66c7..e7588388f6 100644
--- a/detections/deprecated/asl_aws_createaccesskey.yml
+++ b/detections/deprecated/asl_aws_createaccesskey.yml
@@ -4,14 +4,6 @@ version: 3
date: '2024-11-14'
author: Patrick Bareiss, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - ASL AWS Create Access Key
type: Hunting
description: This detection rule monitors for the creation of AWS Identity and Access
Management (IAM) access keys. An IAM access key consists of an access key ID and
diff --git a/detections/deprecated/asl_aws_excessive_security_scanning.yml b/detections/deprecated/asl_aws_excessive_security_scanning.yml
index 483db858df..0ee3a463e3 100644
--- a/detections/deprecated/asl_aws_excessive_security_scanning.yml
+++ b/detections/deprecated/asl_aws_excessive_security_scanning.yml
@@ -4,12 +4,6 @@ version: 4
date: '2024-11-14'
author: Patrick Bareiss, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: Anomaly
description: This search looks for AWS CloudTrail events and analyse the amount of
eventNames which starts with Describe by a single user. This indicates that this
diff --git a/detections/deprecated/asl_aws_password_policy_changes.yml b/detections/deprecated/asl_aws_password_policy_changes.yml
index 6ee31b185c..d791f17208 100644
--- a/detections/deprecated/asl_aws_password_policy_changes.yml
+++ b/detections/deprecated/asl_aws_password_policy_changes.yml
@@ -4,12 +4,6 @@ version: 3
date: '2024-11-14'
author: Patrick Bareiss, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: Hunting
description: This search looks for AWS CloudTrail events from Amazon Security Lake
where a user is making successful API calls to view/update/delete the existing password
diff --git a/detections/deprecated/attempt_to_stop_security_service.yml b/detections/deprecated/attempt_to_stop_security_service.yml
index 864f401149..09f69ad572 100644
--- a/detections/deprecated/attempt_to_stop_security_service.yml
+++ b/detections/deprecated/attempt_to_stop_security_service.yml
@@ -4,13 +4,6 @@ version: 9
date: '2025-01-24'
author: Rico Valdez, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Attempt To Stop Security Service
type: TTP
description: The following analytic has been deprecated. The following analytic detects
attempts to stop security-related services on an endpoint, which may indicate malicious
diff --git a/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml
index 60166bd1f3..38fdbf95b5 100644
--- a/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml
+++ b/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml
@@ -4,15 +4,6 @@ version: 12
date: '2025-01-15'
author: Patrick Bareiss, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: This analytic had some overlap with another one, hence the deprecation.
- It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry
- Hive Dump Via CommandLine
- replacement_content:
- - Windows Sensitive Registry Hive Dump Via CommandLine
type: TTP
description: The following analytic has been deprecated in favour of "8bbb7d58-b360-11eb-ba21-acde48001122".
The following analytic detects the execution of reg.exe with parameters that export
diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml
index 6b328e1c99..d59e586b5a 100644
--- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml
+++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml
@@ -4,14 +4,6 @@ version: 5
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud Provisioning Activity From Previously Unseen City
type: Anomaly
description: This search looks for AWS provisioning activities from previously unseen
cities. Provisioning activities are defined broadly as any event that begins with
diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml
index 9fa34711fb..05ecc67be0 100644
--- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml
+++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml
@@ -4,14 +4,6 @@ version: 5
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud Provisioning Activity From Previously Unseen Country
type: Anomaly
description: This search looks for AWS provisioning activities from previously unseen
countries. Provisioning activities are defined broadly as any event that begins
diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml
index d90ad488c4..5568175da0 100644
--- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml
+++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml
@@ -4,14 +4,6 @@ version: 5
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud Provisioning Activity From Previously Unseen IP Address
type: Anomaly
description: This search looks for AWS provisioning activities from previously unseen
IP addresses. Provisioning activities are defined broadly as any event that begins
diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml
index b3748cf690..7adba589db 100644
--- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml
+++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml
@@ -4,14 +4,6 @@ version: 4
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud Provisioning Activity From Previously Unseen Region
type: Anomaly
description: This search looks for AWS provisioning activities from previously unseen
regions. Region in this context is similar to a state in the United States. Provisioning
diff --git a/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml b/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml
index 016a68160e..866bca7809 100644
--- a/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml
+++ b/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml
@@ -4,14 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Kubernetes Abuse of Secret by Unusual Location
type: Hunting
description: This search provides information on Kubernetes accounts accessing sensitve
objects such as configmaps or secrets
diff --git a/detections/deprecated/change_default_file_association.yml b/detections/deprecated/change_default_file_association.yml
index e3de336511..b524230015 100644
--- a/detections/deprecated/change_default_file_association.yml
+++ b/detections/deprecated/change_default_file_association.yml
@@ -4,13 +4,6 @@ version: 5
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows New Default File Association Value Set
type: TTP
description: The following analytic has been deprecated. The following analytic detects
suspicious registry modifications that change the default file association to execute
diff --git a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml b/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml
index 7ea5a6c524..eb01c32ea2 100644
--- a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml
+++ b/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml
@@ -4,12 +4,6 @@ version: 6
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: TTP
description: This search allows you to identify the endpoints that have connected
to more than five DNS servers and made DNS Queries over the time frame of the search.
diff --git a/detections/deprecated/cloud_network_access_control_list_deleted.yml b/detections/deprecated/cloud_network_access_control_list_deleted.yml
index c5a273eb95..8a9036b76a 100644
--- a/detections/deprecated/cloud_network_access_control_list_deleted.yml
+++ b/detections/deprecated/cloud_network_access_control_list_deleted.yml
@@ -4,14 +4,6 @@ version: 4
date: '2024-11-14'
author: Peter Gael, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - AWS Network Access Control List Deleted
type: Anomaly
description: Enforcing network-access controls is one of the defensive mechanisms
used by cloud administrators to restrict access to a cloud instance. After the attacker
diff --git a/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml b/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml
index 98e8084d64..1df440f488 100644
--- a/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml
+++ b/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml
@@ -4,13 +4,6 @@ version: 7
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Cmdline Tool Execution From Non-Shell Process
type: TTP
description: The following analytic identifies instances where `ipconfig.exe`, `systeminfo.exe`,
or similar tools are executed by a non-standard parent process, excluding CMD, PowerShell,
diff --git a/detections/deprecated/correlation_by_repository_and_risk.yml b/detections/deprecated/correlation_by_repository_and_risk.yml
index afc868dcee..2629b408ff 100644
--- a/detections/deprecated/correlation_by_repository_and_risk.yml
+++ b/detections/deprecated/correlation_by_repository_and_risk.yml
@@ -4,13 +4,6 @@ version: 3
date: '2024-11-14'
author: Patrick Bareiss, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the datamodel
- replacement_content:
- - Risk Rule for Dev Sec Ops by Repository
type: Correlation
description: |-
This search has been deprecated and updated with Risk Rule for Dev Sec Ops by Repository detection. The following analytic detects by correlating repository and risk score to identify patterns and trends in the data based on the level of risk associated. The analytic adds any null values and calculates the sum of the risk scores for each detection. Then, the analytic captures the source and user information for each detection and sorts the results in ascending order based on the risk score. Finally, the analytic filters the detections with a risk score below 80 and focuses only on high-risk detections.This detection is important because it provides valuable insights into the distribution of high-risk activities across different repositories. It also identifies the most vulnerable repositories that are frequently targeted by potential threats. Additionally, it proactively detects and responds to potential threats, thereby minimizing the impact of attacks and safeguarding critical assets. Finally, it provides a comprehensive view of the risk landscape and helps to make informed decisions to protect the organization's data and infrastructure. False positives might occur so it is important to identify the impact of the attack and prioritize response and mitigation efforts.
diff --git a/detections/deprecated/correlation_by_user_and_risk.yml b/detections/deprecated/correlation_by_user_and_risk.yml
index 0d95f474ec..63d9c738ae 100644
--- a/detections/deprecated/correlation_by_user_and_risk.yml
+++ b/detections/deprecated/correlation_by_user_and_risk.yml
@@ -4,13 +4,6 @@ version: 3
date: '2024-11-14'
author: Patrick Bareiss, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the datamodel
- replacement_content:
- - Risk Rule for Dev Sec Ops by Repository
type: Correlation
description: |-
The following analytic detects the correlation between the user and risk score and identifies users with a high risk score that pose a significant security risk such as unauthorized access attempts, suspicious behavior, or potential insider threats. Next, the analytic calculates the sum of the risk scores and groups the results by user, the corresponding signals, and the repository. The results are sorted in descending order based on the risk score and filtered to include records with a risk score greater than 80. Finally, the results are passed through a correlation filter specific to the user and risk. This detection is important because it identifies users who have a high risk score and helps to prioritize investigations and allocate resources. False positives might occur but the impact of such an attack can vary depending on the specific scenario such as data exfiltration, system compromise, or the disruption of critical services. Please investigate this notable event.
diff --git a/detections/deprecated/create_local_admin_accounts_using_net_exe.yml b/detections/deprecated/create_local_admin_accounts_using_net_exe.yml
index b4553ed94f..cf89f5b1ac 100644
--- a/detections/deprecated/create_local_admin_accounts_using_net_exe.yml
+++ b/detections/deprecated/create_local_admin_accounts_using_net_exe.yml
@@ -4,13 +4,6 @@ version: 15
date: '2025-01-24'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Create Local Administrator Account Via Net
type: TTP
description: The following analytic has been deprecated. The following analytic detects
the creation of local administrator accounts using the net.exe command. It leverages
diff --git a/detections/deprecated/deleting_of_net_users.yml b/detections/deprecated/deleting_of_net_users.yml
index 7d5ea4007a..cb8dc58817 100644
--- a/detections/deprecated/deleting_of_net_users.yml
+++ b/detections/deprecated/deleting_of_net_users.yml
@@ -4,13 +4,6 @@ version: 7
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows User Deletion Via Net
type: TTP
description: The following analytic has been deprecated. The following analytic detects
the use of net.exe or net1.exe command-line to delete a user account on a system.
diff --git a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml b/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml
index 92df160e8f..0c13a55b87 100644
--- a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml
+++ b/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml
@@ -4,12 +4,6 @@ version: 9
date: '2024-11-14'
author: Bhavin Patel, Patrick Bareiss, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: Hunting
description: This search looks for specific authentication events from the Windows
Security Event logs to detect potential attempts at using the Pass-the-Hash technique.
diff --git a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml b/detections/deprecated/detect_api_activity_from_users_without_mfa.yml
index 82e5931e6a..e0ad2efcfc 100644
--- a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml
+++ b/detections/deprecated/detect_api_activity_from_users_without_mfa.yml
@@ -4,14 +4,6 @@ version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - AWS Successful Single-Factor Authentication
type: Hunting
description: This search looks for AWS CloudTrail events where a user logged into
the AWS account, is making API calls and has not enabled Multi Factor authentication.
diff --git a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml b/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml
index b97773f126..23e833aac1 100644
--- a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml
+++ b/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml
@@ -4,12 +4,6 @@ version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: Hunting
description: This search looks for successful AWS CloudTrail activity by user accounts
that are not listed in the identity table or `aws_service_accounts.csv`. It returns
diff --git a/detections/deprecated/detect_critical_alerts_from_security_tools.yml b/detections/deprecated/detect_critical_alerts_from_security_tools.yml
index a956ec746a..75848f931f 100644
--- a/detections/deprecated/detect_critical_alerts_from_security_tools.yml
+++ b/detections/deprecated/detect_critical_alerts_from_security_tools.yml
@@ -4,13 +4,6 @@ version: 2
date: '2025-01-13'
author: Gowthamaraj Rajendran, Patrick Bareiss, Bhavin Patel, Bryan Pluta, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - Microsoft Defender Incident Alerts
type: TTP
data_source:
- Windows Defender Alerts
diff --git a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml
index b76c9405f5..67c72e7e14 100644
--- a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml
+++ b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml
@@ -4,12 +4,6 @@ version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: TTP
description: This search looks for DNS requests for phishing domains that are leveraging
EvilGinx tools to mimic websites.
diff --git a/detections/deprecated/detect_long_dns_txt_record_response.yml b/detections/deprecated/detect_long_dns_txt_record_response.yml
index 98b0f46fdc..57a2fb80be 100644
--- a/detections/deprecated/detect_long_dns_txt_record_response.yml
+++ b/detections/deprecated/detect_long_dns_txt_record_response.yml
@@ -4,12 +4,6 @@ version: 5
date: '2024-11-14'
author: Rico Valdez, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: TTP
description: This search is used to detect attempts to use DNS tunneling, by calculating
the length of responses to DNS TXT queries. Endpoints using DNS as a method of transmission
diff --git a/detections/deprecated/detect_mimikatz_using_loaded_images.yml b/detections/deprecated/detect_mimikatz_using_loaded_images.yml
index 2b96f938f5..b002ff2bcc 100644
--- a/detections/deprecated/detect_mimikatz_using_loaded_images.yml
+++ b/detections/deprecated/detect_mimikatz_using_loaded_images.yml
@@ -4,12 +4,6 @@ version: 3
date: '2024-11-14'
author: Patrick Bareiss, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: TTP
description: This search looks for reading loaded Images unique to credential dumping
with Mimikatz. Deprecated because mimikatz libraries changed and very noisy sysmon
diff --git a/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml b/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml
index 4f622e2ba5..aa9cabe8d3 100644
--- a/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml
+++ b/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml
@@ -4,13 +4,6 @@ version: 5
date: '2024-11-14'
author: Rico Valdez, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Updated to a new detection name
- replacement_content:
- - Detect Mimikatz With PowerShell Script Block Logging
type: TTP
description: This search looks for PowerShell requesting privileges consistent with
credential dumping. Deprecated, looks like things changed from a logging perspective.
diff --git a/detections/deprecated/detect_new_api_calls_from_user_roles.yml b/detections/deprecated/detect_new_api_calls_from_user_roles.yml
index a0a40a7079..cc41aecff1 100644
--- a/detections/deprecated/detect_new_api_calls_from_user_roles.yml
+++ b/detections/deprecated/detect_new_api_calls_from_user_roles.yml
@@ -4,14 +4,6 @@ version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud API Calls From Previously Unseen User Roles
type: Anomaly
description: This search detects new API calls that have either never been seen before
or that have not been seen in the previous hour, where the identity type is `AssumedRole`.
diff --git a/detections/deprecated/detect_new_user_aws_console_login.yml b/detections/deprecated/detect_new_user_aws_console_login.yml
index 3b7dee01f6..68c62a8d9c 100644
--- a/detections/deprecated/detect_new_user_aws_console_login.yml
+++ b/detections/deprecated/detect_new_user_aws_console_login.yml
@@ -4,14 +4,6 @@ version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Detect AWS Console Login by New User
type: Hunting
description: This search looks for AWS CloudTrail events wherein a console login event
by a user was recorded within the last hour, then compares the event to a lookup
diff --git a/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml b/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml
index 3abe50aa9b..05f6ff2bd6 100644
--- a/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml
+++ b/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml
@@ -4,13 +4,6 @@ version: 7
date: '2025-01-24'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Potential System Network Configuration Discovery Activity
type: TTP
description: The following analytic has been deprecated. The following analytic identifies
the rapid execution of processes used for system network configuration discovery
diff --git a/detections/deprecated/detect_spike_in_aws_api_activity.yml b/detections/deprecated/detect_spike_in_aws_api_activity.yml
index 7757834caf..5a7efe7007 100644
--- a/detections/deprecated/detect_spike_in_aws_api_activity.yml
+++ b/detections/deprecated/detect_spike_in_aws_api_activity.yml
@@ -4,13 +4,6 @@ version: 5
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - ''
type: Anomaly
description: This search will detect users creating spikes of API activity in your
AWS environment. It will also update the cache file that factors in the latest
diff --git a/detections/deprecated/detect_spike_in_network_acl_activity.yml b/detections/deprecated/detect_spike_in_network_acl_activity.yml
index b35582dc49..a7e693bf9e 100644
--- a/detections/deprecated/detect_spike_in_network_acl_activity.yml
+++ b/detections/deprecated/detect_spike_in_network_acl_activity.yml
@@ -4,14 +4,6 @@ version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Abnormally High Number Of Cloud Infrastructure API Calls
type: Anomaly
description: This search will detect users creating spikes in API activity related
to network access-control lists (ACLs)in your AWS environment. This search is deprecated
diff --git a/detections/deprecated/detect_spike_in_security_group_activity.yml b/detections/deprecated/detect_spike_in_security_group_activity.yml
index a8e0579682..de1cad3b6d 100644
--- a/detections/deprecated/detect_spike_in_security_group_activity.yml
+++ b/detections/deprecated/detect_spike_in_security_group_activity.yml
@@ -4,14 +4,6 @@ version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Abnormally High Number Of Cloud Security Group API Calls
type: Anomaly
description: This search will detect users creating spikes in API activity related
to security groups in your AWS environment. It will also update the cache file
diff --git a/detections/deprecated/detect_usb_device_insertion.yml b/detections/deprecated/detect_usb_device_insertion.yml
index c363556e53..2d6dd088f5 100644
--- a/detections/deprecated/detect_usb_device_insertion.yml
+++ b/detections/deprecated/detect_usb_device_insertion.yml
@@ -4,12 +4,6 @@ version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: TTP
description: The search is used to detect hosts that generate Windows Event ID 4663
for successful attempts to write to or read from a removable storage and Event ID
diff --git a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml b/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml
index 885920c786..853d302d85 100644
--- a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml
+++ b/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml
@@ -4,13 +4,6 @@ version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Updated to use a different log source
- replacement_content:
- - Detect hosts connecting to dynamic domain providers
type: TTP
description: This search looks for web connections to dynamic DNS providers.
data_source: []
diff --git a/detections/deprecated/detect_webshell_exploit_behavior.yml b/detections/deprecated/detect_webshell_exploit_behavior.yml
index e921c3ffbf..5f61b3c0c8 100644
--- a/detections/deprecated/detect_webshell_exploit_behavior.yml
+++ b/detections/deprecated/detect_webshell_exploit_behavior.yml
@@ -4,13 +4,6 @@ version: 7
date: '2025-01-24'
author: Steven Dick
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Suspicious Child Process Spawned From WebServer
type: TTP
description: The following analytic has been deprecated. The following analytic identifies
the execution of suspicious processes typically associated with webshell activity
diff --git a/detections/deprecated/detection_of_dns_tunnels.yml b/detections/deprecated/detection_of_dns_tunnels.yml
index 595ded0bd5..e903bf4d9a 100644
--- a/detections/deprecated/detection_of_dns_tunnels.yml
+++ b/detections/deprecated/detection_of_dns_tunnels.yml
@@ -4,12 +4,6 @@ version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: TTP
description: "This search is used to detect DNS tunneling, by calculating the sum
of the length of DNS queries and DNS answers. The search also filters out potential
diff --git a/detections/deprecated/disabling_net_user_account.yml b/detections/deprecated/disabling_net_user_account.yml
index 3fee864584..615c9dea0b 100644
--- a/detections/deprecated/disabling_net_user_account.yml
+++ b/detections/deprecated/disabling_net_user_account.yml
@@ -4,13 +4,6 @@ version: 7
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows User Disabled Via Net
type: TTP
description: The following analytic has been deprecated. The following analytic detects
the use of the `net.exe` utility to disable a user account via the command line.
diff --git a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml b/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml
index 20f966e9b1..b52f87457a 100644
--- a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml
+++ b/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml
@@ -4,12 +4,6 @@ version: 6
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: TTP
description: This search will detect DNS requests resolved by unauthorized DNS servers.
Legitimate DNS servers should be identified in the Enterprise Security Assets and
diff --git a/detections/deprecated/dns_record_changed.yml b/detections/deprecated/dns_record_changed.yml
index c917402af4..1da12999ba 100644
--- a/detections/deprecated/dns_record_changed.yml
+++ b/detections/deprecated/dns_record_changed.yml
@@ -4,12 +4,6 @@ version: 6
date: '2024-11-14'
author: Jose Hernandez, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: TTP
description: The search takes the DNS records and their answers results of the discovered_dns_records
lookup and finds if any records have changed by searching DNS response from the
diff --git a/detections/deprecated/domain_account_discovery_with_net_app.yml b/detections/deprecated/domain_account_discovery_with_net_app.yml
index b4f21b70a2..92ad5bcfa8 100644
--- a/detections/deprecated/domain_account_discovery_with_net_app.yml
+++ b/detections/deprecated/domain_account_discovery_with_net_app.yml
@@ -4,16 +4,6 @@ version: 5
date: '2025-01-13'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: "This analytic was a TTP that looked only for commands that tries to query
- info about the users via net user /do. This had a couple of issues, such as triggering
- on creation of users via the /add flag etc..\nIt was deprecated in favor of a
- more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122"
- replacement_content:
- - Windows User Discovery Via Net
type: TTP
description: This following analytic has been deprecated in favour of the generic
version "5d0d4830-0133-11ec-bae3-acde48001122". The following analytic detects the
diff --git a/detections/deprecated/domain_group_discovery_with_net.yml b/detections/deprecated/domain_group_discovery_with_net.yml
index 8d355cbccc..b01c32e127 100644
--- a/detections/deprecated/domain_group_discovery_with_net.yml
+++ b/detections/deprecated/domain_group_discovery_with_net.yml
@@ -4,13 +4,6 @@ version: 6
date: '2025-01-13'
author: Mauricio Velazco, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - Windows Group Discovery Via Net
type: Hunting
description: This search has been deprecated in favour of the more generic analytic
"c5c8e0f3-147a-43da-bf04-4cfaec27dc44". The following analytic identifies the execution
diff --git a/detections/deprecated/dump_lsass_via_procdump_rename.yml b/detections/deprecated/dump_lsass_via_procdump_rename.yml
index db97b216a0..db67928fa4 100644
--- a/detections/deprecated/dump_lsass_via_procdump_rename.yml
+++ b/detections/deprecated/dump_lsass_via_procdump_rename.yml
@@ -4,13 +4,6 @@ version: 4
date: '2024-11-14'
author: Michael Haag, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Updated to a new detection name
- replacement_content:
- - Dump LSASS via procdump
type: Hunting
description: "Detect a renamed instance of procdump.exe dumping the lsass process.
This query looks for both -mm and -ma usage. -mm will produce a mini dump file and
diff --git a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml b/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml
index 306a57bde9..c0dddee3ca 100644
--- a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml
+++ b/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml
@@ -4,14 +4,6 @@ version: 6
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud API Calls From Previously Unseen User Roles
type: Anomaly
description: This search looks for EC2 instances being modified by users who have
not previously modified them. This search is deprecated and have been translated
diff --git a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml b/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml
index 21078ec309..0d7e62b234 100644
--- a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml
+++ b/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml
@@ -4,14 +4,6 @@ version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud Compute Instance Created In Previously Unused Region
type: Hunting
description: This search looks for AWS CloudTrail events where an instance is started
in a particular region in the last one hour and then compares it to a lookup file
diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml
index 7a08a8ab13..80a929eefb 100644
--- a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml
+++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml
@@ -4,14 +4,6 @@ version: 5
date: '2025-01-16'
author: David Dorsey, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud Compute Instance Created With Previously Unseen Image
type: Anomaly
description: This search looks for EC2 instances being created with previously unseen
AMIs. This search is deprecated and have been translated to use the latest Change
diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml
index 1b2fbffdbb..e1a95404a0 100644
--- a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml
+++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml
@@ -4,14 +4,6 @@ version: 6
date: '2025-01-16'
author: David Dorsey, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud Compute Instance Created With Previously Unseen Instance Type
type: Anomaly
description: This search looks for EC2 instances being created with previously unseen
instance types. This search is deprecated and have been translated to use the latest
diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml
index adaf0a181b..d43786da55 100644
--- a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml
+++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml
@@ -4,14 +4,6 @@ version: 6
date: '2025-01-16'
author: David Dorsey, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud Compute Instance Created By Previously Unseen User
type: Anomaly
description: This search looks for EC2 instances being created by users who have not
created them before. This search is deprecated and have been translated to use the
diff --git a/detections/deprecated/elevated_group_discovery_with_net.yml b/detections/deprecated/elevated_group_discovery_with_net.yml
index 9712be51f2..45c777516b 100644
--- a/detections/deprecated/elevated_group_discovery_with_net.yml
+++ b/detections/deprecated/elevated_group_discovery_with_net.yml
@@ -4,13 +4,6 @@ version: 6
date: '2025-01-24'
author: Mauricio Velazco, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Sensitive Group Discovery With Net
type: TTP
description: The following analytic has been deprecated. The following analytic detects
the execution of `net.exe` or `net1.exe` with command-line arguments used to query
diff --git a/detections/deprecated/excel_spawning_powershell.yml b/detections/deprecated/excel_spawning_powershell.yml
index eeb145c769..28ca3fa40a 100644
--- a/detections/deprecated/excel_spawning_powershell.yml
+++ b/detections/deprecated/excel_spawning_powershell.yml
@@ -4,13 +4,6 @@ version: 7
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/detections/deprecated/excessive_service_stop_attempt.yml b/detections/deprecated/excessive_service_stop_attempt.yml
index 428f6c64e7..9c51626bde 100644
--- a/detections/deprecated/excessive_service_stop_attempt.yml
+++ b/detections/deprecated/excessive_service_stop_attempt.yml
@@ -4,13 +4,6 @@ version: 7
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Excessive Service Stop Attempt
type: Anomaly
description: The following analytic has been deprecated. The following analytic detects
multiple attempts to stop or delete services on a system using `net.exe`, `sc.exe`,
diff --git a/detections/deprecated/excessive_usage_of_net_app.yml b/detections/deprecated/excessive_usage_of_net_app.yml
index ea3c6f60ed..050c4047c9 100644
--- a/detections/deprecated/excessive_usage_of_net_app.yml
+++ b/detections/deprecated/excessive_usage_of_net_app.yml
@@ -4,13 +4,6 @@ version: 6
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Excessive Usage Of Net App
type: Anomaly
description: The following analytic has been deprecated. The following analytic detects
excessive usage of `net.exe` or `net1.exe` within a one-minute interval. It leverages
diff --git a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml b/detections/deprecated/execution_of_file_with_spaces_before_extension.yml
index 81f9becb23..6e453a7f03 100644
--- a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml
+++ b/detections/deprecated/execution_of_file_with_spaces_before_extension.yml
@@ -4,13 +4,6 @@ version: 6
date: '2024-11-14'
author: Rico Valdez, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Updated to a new detection name
- replacement_content:
- - Execution of File with Multiple Extensions
type: TTP
description: This search looks for processes launched from files with at least five
spaces in the name before the extension. This is typically done to obfuscate the
diff --git a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml b/detections/deprecated/extended_period_without_successful_netbackup_backups.yml
index 995f48dd58..c72e3977a2 100644
--- a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml
+++ b/detections/deprecated/extended_period_without_successful_netbackup_backups.yml
@@ -4,12 +4,6 @@ version: 4
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: Hunting
description: This search returns a list of hosts that have not successfully completed
a backup in over a week. Deprecated because it's a infrastructure monitoring.
diff --git a/detections/deprecated/extraction_of_registry_hives.yml b/detections/deprecated/extraction_of_registry_hives.yml
index c4e3bdaee0..7e1ddbc2bc 100644
--- a/detections/deprecated/extraction_of_registry_hives.yml
+++ b/detections/deprecated/extraction_of_registry_hives.yml
@@ -4,13 +4,6 @@ version: 6
date: '2025-01-24'
author: Michael Haag, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Sensitive Registry Hive Dump Via CommandLine
type: TTP
description: The following analytic has been deprecated. The following analytic detects
the use of `reg.exe` to export Windows Registry hives, which may contain sensitive
diff --git a/detections/deprecated/first_time_seen_command_line_argument.yml b/detections/deprecated/first_time_seen_command_line_argument.yml
index f2d43dec54..5df827cada 100644
--- a/detections/deprecated/first_time_seen_command_line_argument.yml
+++ b/detections/deprecated/first_time_seen_command_line_argument.yml
@@ -4,13 +4,6 @@ version: 8
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This search looks for command-line arguments that use a `/c` parameter
to execute a command that has not previously been seen.
diff --git a/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml b/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml
index da59975438..10a412fbc9 100644
--- a/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml
+++ b/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml
@@ -4,12 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: Hunting
description: This search provides detection of accounts with high risk roles by projects.
Compromised accounts with high risk roles can move laterally or even scalate privileges
diff --git a/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml b/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml
index 38e56596e6..1291444493 100644
--- a/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml
+++ b/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml
@@ -4,12 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: Hunting
description: This search provides detection of high risk permissions by resource and
accounts. These are permissions that can allow attackers with compromised accounts
diff --git a/detections/deprecated/gcp_detect_oauth_token_abuse.yml b/detections/deprecated/gcp_detect_oauth_token_abuse.yml
index bef84aaa87..25144dd436 100644
--- a/detections/deprecated/gcp_detect_oauth_token_abuse.yml
+++ b/detections/deprecated/gcp_detect_oauth_token_abuse.yml
@@ -4,12 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: Hunting
description: This search provides detection of possible GCP Oauth token abuse. GCP
Oauth token without time limit can be exfiltrated and reused for keeping access
diff --git a/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml b/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml
index 88aad6f364..f8fabad5ff 100644
--- a/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml
+++ b/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml
@@ -4,14 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Kubernetes Scanning by Unauthenticated IP Address
type: TTP
description: This search provides information of unauthenticated requests via user
agent, and authentication data against Kubernetes cluster
diff --git a/detections/deprecated/identify_new_user_accounts.yml b/detections/deprecated/identify_new_user_accounts.yml
index 5e43985eae..55b528d72a 100644
--- a/detections/deprecated/identify_new_user_accounts.yml
+++ b/detections/deprecated/identify_new_user_accounts.yml
@@ -4,13 +4,6 @@ version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This detection search will help profile user accounts in your environment
by identifying newly created accounts that have been added to your network in the
diff --git a/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml b/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml
index 49a3f2cddb..8aed9288a5 100644
--- a/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml
+++ b/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml
@@ -4,13 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This search provides information on Kubernetes service accounts,accessing
pods by IP address, verb and decision
diff --git a/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml b/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml
index 2a269a69ce..6d04bf8d94 100644
--- a/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml
+++ b/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml
@@ -4,13 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This search provides information on Kubernetes RBAC authorizations by
accounts, this search can be modified by adding top to see both extremes of RBAC
diff --git a/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml b/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml
index 7c08f4bb52..bb7b707a96 100644
--- a/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml
+++ b/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml
@@ -4,13 +4,6 @@ version: 5
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This search provides information on Kubernetes accounts accessing sensitve
objects such as configmpas or secrets
diff --git a/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml b/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml
index 3e8620e1f1..17722e0587 100644
--- a/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml
+++ b/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml
@@ -4,13 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This search provides information on Kubernetes service accounts with
failure or forbidden access status, this search can be extended by using top or
diff --git a/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml b/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml
index ec37c0848f..ef9d02ecbe 100644
--- a/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml
+++ b/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml
@@ -4,13 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This search provides information on Kubernetes service accounts,accessing
pods and namespaces by IP address and verb
diff --git a/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml b/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml
index d96925d545..0adc47769d 100644
--- a/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml
+++ b/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml
@@ -4,13 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This search provides information on Kubernetes RBAC authorizations by
accounts, this search can be modified by adding rare or top to see both extremes
diff --git a/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml b/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml
index 80591ab342..8ae1ee647e 100644
--- a/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml
+++ b/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml
@@ -4,13 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This search provides information on Kubernetes accounts accessing sensitve
objects such as configmpas or secrets
diff --git a/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml b/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml
index b7243aff43..9993a0a115 100644
--- a/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml
+++ b/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml
@@ -4,13 +4,6 @@ version: 5
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This search provides information on Kubernetes accounts accessing sensitve
objects such as configmpas or secrets
diff --git a/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml b/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml
index 0740c5bc9e..ccbf5daf0c 100644
--- a/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml
+++ b/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml
@@ -4,13 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This search provides information on Kubernetes service accounts with
failure or forbidden access status
diff --git a/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml b/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml
index 94ba765c3e..ef3fed2b2d 100644
--- a/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml
+++ b/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml
@@ -4,13 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This search provides information on rare Kubectl calls with IP, verb
namespace and object access context
diff --git a/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml b/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml
index d41ae9e248..1b1378b2f7 100644
--- a/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml
+++ b/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml
@@ -4,13 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This search provides information of unauthenticated requests via source
IP user agent, request URI and response status data against Kubernetes cluster pod
diff --git a/detections/deprecated/kubernetes_azure_scan_fingerprint.yml b/detections/deprecated/kubernetes_azure_scan_fingerprint.yml
index 5ad0876707..8a6b44473d 100644
--- a/detections/deprecated/kubernetes_azure_scan_fingerprint.yml
+++ b/detections/deprecated/kubernetes_azure_scan_fingerprint.yml
@@ -4,13 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This search provides information of unauthenticated requests via source
IP user agent, request URI and response status data against Kubernetes cluster in
diff --git a/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml b/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml
index 32ad65ac4c..0d3a4cdf11 100644
--- a/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml
+++ b/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml
@@ -4,13 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This search provides information on Kubernetes service accounts,accessing
pods by IP address, verb and decision
diff --git a/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml b/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml
index fc2bf51208..09a26684ce 100644
--- a/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml
+++ b/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml
@@ -4,13 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This search provides information on Kubernetes RBAC authorizations by
accounts, this search can be modified by adding top to see both extremes of RBAC
diff --git a/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml b/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml
index 67d2e2979e..557ab8a5c3 100644
--- a/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml
+++ b/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml
@@ -4,13 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This search provides information on Kubernetes accounts accessing sensitve
objects such as configmaps or secrets
diff --git a/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml b/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml
index e37d0a15ab..da1b2cf148 100644
--- a/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml
+++ b/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml
@@ -4,13 +4,6 @@ version: 5
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This search provides information on Kubernetes accounts accessing sensitve
objects such as configmpas or secrets
diff --git a/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml b/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml
index 7f03e97647..fff4730076 100644
--- a/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml
+++ b/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml
@@ -4,13 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This search provides information on Kubernetes service accounts with
failure or forbidden access status, this search can be extended by using top or
diff --git a/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml b/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml
index 80d95194a1..a78e967c70 100644
--- a/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml
+++ b/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml
@@ -4,13 +4,6 @@ version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: Hunting
description: This search provides information on anonymous Kubectl calls with IP,
verb namespace and object access context
diff --git a/detections/deprecated/linux_auditd_find_private_keys.yml b/detections/deprecated/linux_auditd_find_private_keys.yml
index 8ccb92c6c7..756073da56 100644
--- a/detections/deprecated/linux_auditd_find_private_keys.yml
+++ b/detections/deprecated/linux_auditd_find_private_keys.yml
@@ -4,13 +4,6 @@ version: 5
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Linux Auditd Private Keys and Certificate Enumeration
type: TTP
description: The following analytic has been deprecated. The following analytic detects
suspicious attempts to find private keys, which may indicate an attacker's effort
diff --git a/detections/deprecated/local_account_discovery_with_net.yml b/detections/deprecated/local_account_discovery_with_net.yml
index 6aa48ba58f..8af80acf03 100644
--- a/detections/deprecated/local_account_discovery_with_net.yml
+++ b/detections/deprecated/local_account_discovery_with_net.yml
@@ -4,13 +4,6 @@ version: 6
date: '2025-01-24'
author: Mauricio Velazco, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows User Discovery Via Net
type: Hunting
description: The following analytic has been deprecated. The following analytic detects
the execution of `net.exe` or `net1.exe` with command-line arguments `user` or `users`
diff --git a/detections/deprecated/monitor_dns_for_brand_abuse.yml b/detections/deprecated/monitor_dns_for_brand_abuse.yml
index dfe23ab2a6..9ad520f284 100644
--- a/detections/deprecated/monitor_dns_for_brand_abuse.yml
+++ b/detections/deprecated/monitor_dns_for_brand_abuse.yml
@@ -4,13 +4,6 @@ version: 4
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: TTP
description: This search looks for DNS requests for faux domains similar to the domains
that you want to have monitored for abuse.
diff --git a/detections/deprecated/mshtml_module_load_in_office_product.yml b/detections/deprecated/mshtml_module_load_in_office_product.yml
index f9b620ec36..870c4aea9d 100644
--- a/detections/deprecated/mshtml_module_load_in_office_product.yml
+++ b/detections/deprecated/mshtml_module_load_in_office_product.yml
@@ -4,13 +4,6 @@ version: 7
date: '2025-01-24'
author: Michael Haag, Mauricio Velazco, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Office Product Loaded MSHTML Module
type: TTP
description: The following analytic has been deprecated. The following analytic detects
the loading of the mshtml.dll module into an Office product, which is indicative
diff --git a/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml b/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml
index 23ac3906f5..68269b2e43 100644
--- a/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml
+++ b/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml
@@ -4,14 +4,6 @@ version: 5
date: '2024-11-14'
author: Michael Haag, Mauricio Velazco, Rico Valdez, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Okta Multiple Users Failing To Authenticate From Ip
type: TTP
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `Okta Multiple Users Failing To Authenticate From Ip`. This analytic identifies
diff --git a/detections/deprecated/net_localgroup_discovery.yml b/detections/deprecated/net_localgroup_discovery.yml
index 13b349af7b..b3d15becdf 100644
--- a/detections/deprecated/net_localgroup_discovery.yml
+++ b/detections/deprecated/net_localgroup_discovery.yml
@@ -4,14 +4,6 @@ version: 5
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44
- / Windows Group Discovery Via Net
- replacement_content:
- - Windows Group Discovery Via Net
type: Hunting
description: This search has been deprecated in favour of the more generic analytic
"c5c8e0f3-147a-43da-bf04-4cfaec27dc44". The following analytic detects the execution
diff --git a/detections/deprecated/network_connection_discovery_with_net.yml b/detections/deprecated/network_connection_discovery_with_net.yml
index 1785ae5ff7..e2caea92c7 100644
--- a/detections/deprecated/network_connection_discovery_with_net.yml
+++ b/detections/deprecated/network_connection_discovery_with_net.yml
@@ -4,13 +4,6 @@ version: 6
date: '2025-01-24'
author: Mauricio Velazco, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Network Connection Discovery Via Net
type: Hunting
description: The following analytic has been deprecated. The following analytic identifies
the execution of `net.exe` or `net1.exe` with command-line arguments used to list
diff --git a/detections/deprecated/o365_suspicious_admin_email_forwarding.yml b/detections/deprecated/o365_suspicious_admin_email_forwarding.yml
index 23ed76cc7c..13dddb8c18 100644
--- a/detections/deprecated/o365_suspicious_admin_email_forwarding.yml
+++ b/detections/deprecated/o365_suspicious_admin_email_forwarding.yml
@@ -4,14 +4,6 @@ version: 3
date: '2024-11-14'
author: Patrick Bareiss, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - O365 Mailbox Email Forwarding Enabled
type: Anomaly
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `O365 Mailbox Email Forwarding Enabled`. This search detects when an admin
diff --git a/detections/deprecated/o365_suspicious_rights_delegation.yml b/detections/deprecated/o365_suspicious_rights_delegation.yml
index a0fcb196a4..e9e6543750 100644
--- a/detections/deprecated/o365_suspicious_rights_delegation.yml
+++ b/detections/deprecated/o365_suspicious_rights_delegation.yml
@@ -4,14 +4,6 @@ version: 4
date: '2024-11-14'
author: Patrick Bareiss, Mauricio Velazco, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - O365 Elevated Mailbox Permission Assigned
type: TTP
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `O365 Elevated Mailbox Permission Assigned`. This analytic identifies instances
diff --git a/detections/deprecated/o365_suspicious_user_email_forwarding.yml b/detections/deprecated/o365_suspicious_user_email_forwarding.yml
index 682a9fff0c..1a9c9c5c4c 100644
--- a/detections/deprecated/o365_suspicious_user_email_forwarding.yml
+++ b/detections/deprecated/o365_suspicious_user_email_forwarding.yml
@@ -4,14 +4,6 @@ version: 4
date: '2024-11-14'
author: Patrick Bareiss, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - O365 Mailbox Email Forwarding Enabled
type: Anomaly
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `O365 Mailbox Email Forwarding Enabled`. The following analytic detects when
diff --git a/detections/deprecated/office_application_drop_executable.yml b/detections/deprecated/office_application_drop_executable.yml
index da7930df64..792556a6d3 100644
--- a/detections/deprecated/office_application_drop_executable.yml
+++ b/detections/deprecated/office_application_drop_executable.yml
@@ -4,13 +4,6 @@ version: 9
date: '2025-01-24'
author: Teoderick Contreras, Michael Haag, Splunk, TheLawsOfChaos, Github
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Office Product Dropped Uncommon File
type: TTP
description: The following analytic has been deprecated. The following analytic detects
Microsoft Office applications dropping or creating executables or scripts on a Windows
diff --git a/detections/deprecated/office_application_spawn_regsvr32_process.yml b/detections/deprecated/office_application_spawn_regsvr32_process.yml
index 0b35f87583..ceec84dba1 100644
--- a/detections/deprecated/office_application_spawn_regsvr32_process.yml
+++ b/detections/deprecated/office_application_spawn_regsvr32_process.yml
@@ -4,13 +4,6 @@ version: 8
date: '2025-01-13'
author: Teoderick Contreras, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/detections/deprecated/office_application_spawn_rundll32_process.yml b/detections/deprecated/office_application_spawn_rundll32_process.yml
index d9a37aaba7..6d10c2b8c8 100644
--- a/detections/deprecated/office_application_spawn_rundll32_process.yml
+++ b/detections/deprecated/office_application_spawn_rundll32_process.yml
@@ -4,13 +4,6 @@ version: 8
date: '2025-01-13'
author: Teoderick Contreras, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/detections/deprecated/office_document_creating_schedule_task.yml b/detections/deprecated/office_document_creating_schedule_task.yml
index d317b98c6a..1275c00579 100644
--- a/detections/deprecated/office_document_creating_schedule_task.yml
+++ b/detections/deprecated/office_document_creating_schedule_task.yml
@@ -4,13 +4,6 @@ version: 10
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Office Product Loading Taskschd DLL
type: TTP
description: The following analytic has been deprecated. The following analytic detects
an Office document creating a scheduled task, either through a macro VBA API or
diff --git a/detections/deprecated/office_document_executing_macro_code.yml b/detections/deprecated/office_document_executing_macro_code.yml
index 35c088e292..9bf6ad3357 100644
--- a/detections/deprecated/office_document_executing_macro_code.yml
+++ b/detections/deprecated/office_document_executing_macro_code.yml
@@ -4,13 +4,6 @@ version: 9
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Office Product Loading VBE7 DLL
type: TTP
description: The following analytic has been deprecated. The following analytic identifies
office documents executing macro code. It leverages Sysmon EventCode 7 to detect
diff --git a/detections/deprecated/office_document_spawned_child_process_to_download.yml b/detections/deprecated/office_document_spawned_child_process_to_download.yml
index 0763eb9df3..73220f4027 100644
--- a/detections/deprecated/office_document_spawned_child_process_to_download.yml
+++ b/detections/deprecated/office_document_spawned_child_process_to_download.yml
@@ -4,13 +4,6 @@ version: 10
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Office Product Spawned Child Process For Download
type: TTP
description: The following analytic has been deprecated. The following analytic identifies
Office applications spawning child processes to download content via HTTP/HTTPS.
diff --git a/detections/deprecated/office_product_spawn_cmd_process.yml b/detections/deprecated/office_product_spawn_cmd_process.yml
index d9d6ff558c..4193c23ca8 100644
--- a/detections/deprecated/office_product_spawn_cmd_process.yml
+++ b/detections/deprecated/office_product_spawn_cmd_process.yml
@@ -4,13 +4,6 @@ version: 8
date: '2025-01-13'
author: Teoderick Contreras, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/detections/deprecated/office_product_spawning_bitsadmin.yml b/detections/deprecated/office_product_spawning_bitsadmin.yml
index 2b8a51389c..3bda779c35 100644
--- a/detections/deprecated/office_product_spawning_bitsadmin.yml
+++ b/detections/deprecated/office_product_spawning_bitsadmin.yml
@@ -4,13 +4,6 @@ version: 9
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/detections/deprecated/office_product_spawning_certutil.yml b/detections/deprecated/office_product_spawning_certutil.yml
index d89056cb83..00bc0797c9 100644
--- a/detections/deprecated/office_product_spawning_certutil.yml
+++ b/detections/deprecated/office_product_spawning_certutil.yml
@@ -4,13 +4,6 @@ version: 9
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/detections/deprecated/office_product_spawning_mshta.yml b/detections/deprecated/office_product_spawning_mshta.yml
index 4ba85dc480..ef07f76ce2 100644
--- a/detections/deprecated/office_product_spawning_mshta.yml
+++ b/detections/deprecated/office_product_spawning_mshta.yml
@@ -4,13 +4,6 @@ version: 8
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml b/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml
index 43530ad126..a74965e373 100644
--- a/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml
+++ b/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml
@@ -4,13 +4,6 @@ version: 10
date: '2025-01-24'
author: Michael Haag, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Office Product Spawned Rundll32 With No DLL
type: TTP
description: The following analytic has been deprecated. The following analytic detects
any Windows Office Product spawning `rundll32.exe` without a `.dll` file extension.
diff --git a/detections/deprecated/office_product_spawning_windows_script_host.yml b/detections/deprecated/office_product_spawning_windows_script_host.yml
index d6bfcc6025..659a4b48ed 100644
--- a/detections/deprecated/office_product_spawning_windows_script_host.yml
+++ b/detections/deprecated/office_product_spawning_windows_script_host.yml
@@ -4,13 +4,6 @@ version: 10
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/detections/deprecated/office_product_spawning_wmic.yml b/detections/deprecated/office_product_spawning_wmic.yml
index c60f305eb0..a06d97a5d7 100644
--- a/detections/deprecated/office_product_spawning_wmic.yml
+++ b/detections/deprecated/office_product_spawning_wmic.yml
@@ -4,13 +4,6 @@ version: 10
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/detections/deprecated/office_product_writing_cab_or_inf.yml b/detections/deprecated/office_product_writing_cab_or_inf.yml
index cb9aafc883..30adac14d5 100644
--- a/detections/deprecated/office_product_writing_cab_or_inf.yml
+++ b/detections/deprecated/office_product_writing_cab_or_inf.yml
@@ -4,13 +4,6 @@ version: 10
date: '2025-01-24'
author: Michael Haag, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Office Product Dropped Cab or Inf File
type: TTP
description: The following analytic has been deprecated. The following analytic detects
Office products writing .cab or .inf files, indicative of CVE-2021-40444 exploitation.
diff --git a/detections/deprecated/office_spawning_control.yml b/detections/deprecated/office_spawning_control.yml
index 389aa5d867..984e8bf0a8 100644
--- a/detections/deprecated/office_spawning_control.yml
+++ b/detections/deprecated/office_spawning_control.yml
@@ -4,13 +4,6 @@ version: 10
date: '2025-01-24'
author: Michael Haag, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Office Product Spawned Control
type: TTP
description: The following analytic has been deprecated. The following analytic identifies
instances where `control.exe` is spawned by a Microsoft Office product. It leverages
diff --git a/detections/deprecated/okta_account_locked_out.yml b/detections/deprecated/okta_account_locked_out.yml
index 0b1df607ad..0ad8243973 100644
--- a/detections/deprecated/okta_account_locked_out.yml
+++ b/detections/deprecated/okta_account_locked_out.yml
@@ -4,14 +4,6 @@ version: 3
date: '2024-11-14'
author: Michael Haag, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Okta Multiple Accounts Locked Out
type: Anomaly
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `Okta Multiple Accounts Locked Out`. The following analytic utilizes the user.acount.lock
diff --git a/detections/deprecated/okta_account_lockout_events.yml b/detections/deprecated/okta_account_lockout_events.yml
index 4049ec139c..07f8d09a9d 100644
--- a/detections/deprecated/okta_account_lockout_events.yml
+++ b/detections/deprecated/okta_account_lockout_events.yml
@@ -4,14 +4,6 @@ version: 4
date: '2024-11-14'
author: Michael Haag, Rico Valdez, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Okta Multiple Accounts Locked Out
type: Anomaly
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `Okta Multiple Accounts Locked Out`. The following anomaly will generate based
diff --git a/detections/deprecated/okta_failed_sso_attempts.yml b/detections/deprecated/okta_failed_sso_attempts.yml
index cd83cc1cb9..6516d32c67 100644
--- a/detections/deprecated/okta_failed_sso_attempts.yml
+++ b/detections/deprecated/okta_failed_sso_attempts.yml
@@ -4,14 +4,6 @@ version: 5
date: '2024-11-14'
author: Michael Haag, Rico Valdez, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Okta Unauthorized Access to Application
type: Anomaly
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with this detection `Okta Unauthorized Access to Application - DM`. The following
diff --git a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml b/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml
index 018e6ec446..1f87cc42bf 100644
--- a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml
+++ b/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml
@@ -5,12 +5,6 @@ date: '2024-11-14'
author: Okta, Inc, Michael Haag, Splunk
type: TTP
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
data_source: []
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `Okta ThreatInsight Threat Detected`. The following analytic utilizes Oktas
diff --git a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml b/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml
index e686982f42..478b4895a1 100644
--- a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml
+++ b/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml
@@ -5,14 +5,6 @@ date: '2024-11-14'
author: Okta, Inc, Michael Haag, Splunk
type: TTP
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Okta ThreatInsight Threat Detected
data_source: []
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `Okta ThreatInsight Threat Detected`. The following analytic utilizes Oktas
diff --git a/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml b/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml
index 971408a38b..9817b5f845 100644
--- a/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml
+++ b/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml
@@ -4,14 +4,6 @@ version: 4
date: '2024-11-14'
author: Michael Haag, Marissa Bower, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Okta Multiple Failed MFA Requests For User
type: TTP
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `Okta Multiple Failed MFA Requests For User`. The following analytic identifies
diff --git a/detections/deprecated/osquery_pack___coldroot_detection.yml b/detections/deprecated/osquery_pack___coldroot_detection.yml
index 8c0a454e3c..3ba9866bed 100644
--- a/detections/deprecated/osquery_pack___coldroot_detection.yml
+++ b/detections/deprecated/osquery_pack___coldroot_detection.yml
@@ -4,12 +4,6 @@ version: 4
date: '2024-11-14'
author: Rico Valdez, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: TTP
description: This search looks for ColdRoot events from the osx-attacks osquery pack.
data_source: []
diff --git a/detections/deprecated/password_policy_discovery_with_net.yml b/detections/deprecated/password_policy_discovery_with_net.yml
index 89def529b1..66ef237307 100644
--- a/detections/deprecated/password_policy_discovery_with_net.yml
+++ b/detections/deprecated/password_policy_discovery_with_net.yml
@@ -4,13 +4,6 @@ version: 7
date: '2025-01-24'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Password Policy Discovery with Net
type: Hunting
description: The following analytic has been deprecated. The following analytic identifies
the execution of `net.exe` or `net1.exe` with command line arguments aimed at obtaining
diff --git a/detections/deprecated/processes_created_by_netsh.yml b/detections/deprecated/processes_created_by_netsh.yml
index c82728a2d9..cb947299d8 100644
--- a/detections/deprecated/processes_created_by_netsh.yml
+++ b/detections/deprecated/processes_created_by_netsh.yml
@@ -4,13 +4,6 @@ version: 8
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Updated to a new detection name
- replacement_content:
- - Processes launching netsh
type: TTP
description: This search looks for processes launching netsh.exe to execute various
commands via the netsh command-line utility. Netsh.exe is a command-line scripting
diff --git a/detections/deprecated/prohibited_software_on_endpoint.yml b/detections/deprecated/prohibited_software_on_endpoint.yml
index 86593fcbf9..243c1c8374 100644
--- a/detections/deprecated/prohibited_software_on_endpoint.yml
+++ b/detections/deprecated/prohibited_software_on_endpoint.yml
@@ -4,13 +4,6 @@ version: 5
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - Attacker Tools On Endpoint
type: Hunting
description: This search looks for applications on the endpoint that you have marked
as prohibited.
diff --git a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml b/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml
index 6947837938..b003f3bd58 100644
--- a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml
+++ b/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml
@@ -4,13 +4,6 @@ version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - '- '
type: TTP
description: The search looks for command-line arguments used to hide a file or directory
using the reg add command.
diff --git a/detections/deprecated/remote_registry_key_modifications.yml b/detections/deprecated/remote_registry_key_modifications.yml
index 4a417c4fa6..71f902a8ad 100644
--- a/detections/deprecated/remote_registry_key_modifications.yml
+++ b/detections/deprecated/remote_registry_key_modifications.yml
@@ -4,12 +4,6 @@ version: 6
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: TTP
description: This search monitors for remote modifications to registry keys.
data_source:
diff --git a/detections/deprecated/remote_system_discovery_with_net.yml b/detections/deprecated/remote_system_discovery_with_net.yml
index 8b19a36706..6e730569fc 100644
--- a/detections/deprecated/remote_system_discovery_with_net.yml
+++ b/detections/deprecated/remote_system_discovery_with_net.yml
@@ -4,13 +4,6 @@ version: 5
date: '2025-01-13'
author: Mauricio Velazco, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - Windows Sensitive Group Discovery With Net
type: Hunting
description: The following analytic has been deprecated in favour of two dedicated
analytics "4dc3951f-b3f8-4f46-b412-76a483f72277" and "a23a0e20-0b1b-4a07-82e5-ec5f70811e7a"
diff --git a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml b/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml
index d3d1e1b499..0197ba45a3 100644
--- a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml
+++ b/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml
@@ -4,13 +4,6 @@ version: 6
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Updated to a new detection name
- replacement_content:
- - Scheduled Task Deleted Or Created via CMD
type: TTP
description: This search looks for flags passed to schtasks.exe on the command-line
that indicate that task names related to the execution of Bad Rabbit ransomware
diff --git a/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml b/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml
index c894e4fa3a..1f4a043402 100644
--- a/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml
+++ b/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml
@@ -4,12 +4,6 @@ version: 4
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: TTP
description: The search is used to detect systems that are still vulnerable to the
Spectre and Meltdown vulnerabilities.
diff --git a/detections/deprecated/suspicious_changes_to_file_associations.yml b/detections/deprecated/suspicious_changes_to_file_associations.yml
index f1c5eb5d31..e9438be5a1 100644
--- a/detections/deprecated/suspicious_changes_to_file_associations.yml
+++ b/detections/deprecated/suspicious_changes_to_file_associations.yml
@@ -4,12 +4,6 @@ version: 7
date: '2024-11-14'
author: Rico Valdez, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: TTP
description: This search looks for changes to registry values that control Windows
file associations, executed by a process that is not typical for legitimate, routine
diff --git a/detections/deprecated/suspicious_email___uba_anomaly.yml b/detections/deprecated/suspicious_email___uba_anomaly.yml
index 0b77fd20a8..0e3a3f31d6 100644
--- a/detections/deprecated/suspicious_email___uba_anomaly.yml
+++ b/detections/deprecated/suspicious_email___uba_anomaly.yml
@@ -4,12 +4,6 @@ version: 6
date: '2024-11-14'
author: Bhavin Patel, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: Anomaly
description: This detection looks for emails that are suspicious because of their
sender, domain rareness, or behavior differences. This is an anomaly generated by
diff --git a/detections/deprecated/suspicious_file_write.yml b/detections/deprecated/suspicious_file_write.yml
index ce7ce09da0..8630632e57 100644
--- a/detections/deprecated/suspicious_file_write.yml
+++ b/detections/deprecated/suspicious_file_write.yml
@@ -4,13 +4,6 @@ version: 6
date: '2024-11-14'
author: Rico Valdez, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - ''
type: Hunting
description: The search looks for files created with names that have been linked to
malicious activity.
diff --git a/detections/deprecated/suspicious_powershell_command_line_arguments.yml b/detections/deprecated/suspicious_powershell_command_line_arguments.yml
index a6c19ed8d7..b2efc4ee51 100644
--- a/detections/deprecated/suspicious_powershell_command_line_arguments.yml
+++ b/detections/deprecated/suspicious_powershell_command_line_arguments.yml
@@ -4,13 +4,6 @@ version: 9
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - Malicious PowerShell Process - Encoded Command
type: TTP
description: This search looks for PowerShell processes started with a base64 encoded
command-line passed to it, with parameters to modify the execution policy for the
diff --git a/detections/deprecated/suspicious_rundll32_rename.yml b/detections/deprecated/suspicious_rundll32_rename.yml
index eff58f4873..48fdc6b2d5 100644
--- a/detections/deprecated/suspicious_rundll32_rename.yml
+++ b/detections/deprecated/suspicious_rundll32_rename.yml
@@ -4,12 +4,6 @@ version: 7
date: '2024-11-14'
author: Michael Haag, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: Hunting
description: The following hunting analytic identifies renamed instances of rundll32.exe
executing. rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64.
diff --git a/detections/deprecated/suspicious_writes_to_system_volume_information.yml b/detections/deprecated/suspicious_writes_to_system_volume_information.yml
index cc6e0fa6ae..866160575b 100644
--- a/detections/deprecated/suspicious_writes_to_system_volume_information.yml
+++ b/detections/deprecated/suspicious_writes_to_system_volume_information.yml
@@ -4,12 +4,6 @@ version: 5
date: '2024-11-14'
author: Rico Valdez, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: Hunting
description: This search detects writes to the 'System Volume Information' folder
by something other than the System process.
diff --git a/detections/deprecated/uncommon_processes_on_endpoint.yml b/detections/deprecated/uncommon_processes_on_endpoint.yml
index 4c90b29fdc..e0378b0e1f 100644
--- a/detections/deprecated/uncommon_processes_on_endpoint.yml
+++ b/detections/deprecated/uncommon_processes_on_endpoint.yml
@@ -4,13 +4,6 @@ version: 7
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - Attacker Tools On Endpoint
type: Hunting
description: This search looks for applications on the endpoint that you have marked
as uncommon.
diff --git a/detections/deprecated/unsigned_image_loaded_by_lsass.yml b/detections/deprecated/unsigned_image_loaded_by_lsass.yml
index 38f74b6f6d..db021a2bf3 100644
--- a/detections/deprecated/unsigned_image_loaded_by_lsass.yml
+++ b/detections/deprecated/unsigned_image_loaded_by_lsass.yml
@@ -4,13 +4,6 @@ version: 4
date: '2024-11-14'
author: Patrick Bareiss, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - ''
type: TTP
description: This search detects loading of unsigned images by LSASS. Deprecated because
too noisy.
diff --git a/detections/deprecated/unsuccessful_netbackup_backups.yml b/detections/deprecated/unsuccessful_netbackup_backups.yml
index feafa5361e..3e8fc0b5af 100644
--- a/detections/deprecated/unsuccessful_netbackup_backups.yml
+++ b/detections/deprecated/unsuccessful_netbackup_backups.yml
@@ -4,12 +4,6 @@ version: 4
date: '2024-11-14'
author: David Dorsey, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: Hunting
description: This search gives you the hosts where a backup was attempted and then
failed.
diff --git a/detections/deprecated/web_fraud___account_harvesting.yml b/detections/deprecated/web_fraud___account_harvesting.yml
index 17f3be4b4f..4fb3b3b784 100644
--- a/detections/deprecated/web_fraud___account_harvesting.yml
+++ b/detections/deprecated/web_fraud___account_harvesting.yml
@@ -4,12 +4,6 @@ version: 4
date: '2024-11-14'
author: Jim Apger, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: TTP
description: This search is used to identify the creation of multiple user accounts
using the same email domain name.
diff --git a/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml b/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml
index 69a013dabf..518a5be28e 100644
--- a/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml
+++ b/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml
@@ -4,12 +4,6 @@ version: 4
date: '2024-11-14'
author: Jim Apger, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: Anomaly
description: This search is used to examine web sessions to identify those where the
clicks are occurring too quickly for a human or are occurring with a near-perfect
diff --git a/detections/deprecated/web_fraud___password_sharing_across_accounts.yml b/detections/deprecated/web_fraud___password_sharing_across_accounts.yml
index 0fe79ab5ff..48c9b3908c 100644
--- a/detections/deprecated/web_fraud___password_sharing_across_accounts.yml
+++ b/detections/deprecated/web_fraud___password_sharing_across_accounts.yml
@@ -4,12 +4,6 @@ version: 4
date: '2024-11-14'
author: Jim Apger, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: Anomaly
description: This search is used to identify user accounts that share a common password.
data_source: []
diff --git a/detections/deprecated/windows_command_shell_fetch_env_variables.yml b/detections/deprecated/windows_command_shell_fetch_env_variables.yml
index 80ddcb7db1..8fcaf15950 100644
--- a/detections/deprecated/windows_command_shell_fetch_env_variables.yml
+++ b/detections/deprecated/windows_command_shell_fetch_env_variables.yml
@@ -4,13 +4,6 @@ version: 5
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows List ENV Variables Via SET Command From Uncommon Parent
type: TTP
description: The following analytic has been deprecated. The following analytic identifies
a suspicious process command line fetching environment variables with a non-shell
diff --git a/detections/deprecated/windows_connhost_exe_started_forcefully.yml b/detections/deprecated/windows_connhost_exe_started_forcefully.yml
index 8bb950c864..2718083864 100644
--- a/detections/deprecated/windows_connhost_exe_started_forcefully.yml
+++ b/detections/deprecated/windows_connhost_exe_started_forcefully.yml
@@ -4,12 +4,6 @@ version: 5
date: '2024-11-14'
author: Rod Soto, Jose Hernandez, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: TTP
description: The search looks for the Console Window Host process (connhost.exe) executed
using the force flag -ForceV1. This is not regular behavior in the Windows OS and
diff --git a/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml b/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml
index f452743951..38d777ae9a 100644
--- a/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml
+++ b/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml
@@ -4,14 +4,6 @@ version: 5
date: '2024-11-14'
author: Michael Haag, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Windows DLL Search Order Hijacking Hunt with Sysmon
type: Hunting
description: The following hunting analytic is an experimental query built against
a accidental feature using the latest Sysmon TA 3.0 (https://splunkbase.splunk.com/app/5709/)
diff --git a/detections/deprecated/windows_hosts_file_modification.yml b/detections/deprecated/windows_hosts_file_modification.yml
index fd6fa8ec88..0c7453eab3 100644
--- a/detections/deprecated/windows_hosts_file_modification.yml
+++ b/detections/deprecated/windows_hosts_file_modification.yml
@@ -4,12 +4,6 @@ version: 4
date: '2024-11-14'
author: Rico Valdez, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content: []
type: TTP
description: The search looks for modifications to the hosts file on all Windows endpoints
across your environment.
diff --git a/detections/deprecated/windows_lateral_tool_transfer_remcom.yml b/detections/deprecated/windows_lateral_tool_transfer_remcom.yml
index dd1d040b65..0611c1c8f6 100644
--- a/detections/deprecated/windows_lateral_tool_transfer_remcom.yml
+++ b/detections/deprecated/windows_lateral_tool_transfer_remcom.yml
@@ -5,13 +5,6 @@ date: '2024-12-10'
author: Michael Haag, Splunk
type: TTP
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Updated to a new detection name
- replacement_content:
- - Windows Service Execution RemCom
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/windows_modify_registry_reg_restore.yml b/detections/deprecated/windows_modify_registry_reg_restore.yml
index 324a5baed9..e1fcad055a 100644
--- a/detections/deprecated/windows_modify_registry_reg_restore.yml
+++ b/detections/deprecated/windows_modify_registry_reg_restore.yml
@@ -4,13 +4,6 @@ version: 5
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Registry Entries Restored Via Reg
type: Hunting
description: The following analytic has been deprecated. The following analytic detects
the execution of reg.exe with the "restore" parameter, indicating an attempt to
diff --git a/detections/deprecated/windows_msiexec_with_network_connections.yml b/detections/deprecated/windows_msiexec_with_network_connections.yml
index 2331bd6952..39ac9d4465 100644
--- a/detections/deprecated/windows_msiexec_with_network_connections.yml
+++ b/detections/deprecated/windows_msiexec_with_network_connections.yml
@@ -4,13 +4,6 @@ version: 6
date: '2025-01-24'
author: Michael Haag, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows HTTP Network Communication From MSIExec
type: TTP
description: The following analytic has been deprecated. The following analytic detects
MSIExec making network connections over ports 443 or 80. This behavior is identified
diff --git a/detections/deprecated/windows_network_share_interaction_with_net.yml b/detections/deprecated/windows_network_share_interaction_with_net.yml
index ab7de51ef6..29047d8992 100644
--- a/detections/deprecated/windows_network_share_interaction_with_net.yml
+++ b/detections/deprecated/windows_network_share_interaction_with_net.yml
@@ -4,13 +4,6 @@ version: 6
date: '2025-01-24'
author: Dean Luxton
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Network Share Interaction Via Net
type: TTP
data_source:
- Sysmon EventID 1
diff --git a/detections/deprecated/windows_office_product_spawning_msdt.yml b/detections/deprecated/windows_office_product_spawning_msdt.yml
index 73517da1ff..88be1f1298 100644
--- a/detections/deprecated/windows_office_product_spawning_msdt.yml
+++ b/detections/deprecated/windows_office_product_spawning_msdt.yml
@@ -4,13 +4,6 @@ version: 9
date: '2025-01-24'
author: Michael Haag, Teoderick Contreras, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Office Product Spawned MSDT
type: TTP
description: The following analytic has been deprecated. The following analytic detects
a Microsoft Office product spawning the Windows msdt.exe process. This detection
diff --git a/detections/deprecated/windows_query_registry_reg_save.yml b/detections/deprecated/windows_query_registry_reg_save.yml
index 2ef3993258..f44d4b8617 100644
--- a/detections/deprecated/windows_query_registry_reg_save.yml
+++ b/detections/deprecated/windows_query_registry_reg_save.yml
@@ -4,13 +4,6 @@ version: 6
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Registry Entries Exported Via Reg
type: Hunting
description: The following analytic has been deprecated. The following analytic detects
the execution of the reg.exe process with the "save" parameter. This detection leverages
diff --git a/detections/deprecated/windows_valid_account_with_never_expires_password.yml b/detections/deprecated/windows_valid_account_with_never_expires_password.yml
index 65421b5a51..6bd2c46133 100644
--- a/detections/deprecated/windows_valid_account_with_never_expires_password.yml
+++ b/detections/deprecated/windows_valid_account_with_never_expires_password.yml
@@ -4,13 +4,6 @@ version: 6
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: Renamed and updated logic
- replacement_content:
- - Windows Set Account Password Policy To Unlimited Via Net
type: TTP
description: The following analytic has been deprecated. The following analytic detects
the use of net.exe to update user account policies to set passwords as non-expiring.
diff --git a/detections/deprecated/winword_spawning_cmd.yml b/detections/deprecated/winword_spawning_cmd.yml
index de643bfb78..f16575033c 100644
--- a/detections/deprecated/winword_spawning_cmd.yml
+++ b/detections/deprecated/winword_spawning_cmd.yml
@@ -4,13 +4,6 @@ version: 7
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/detections/deprecated/winword_spawning_powershell.yml b/detections/deprecated/winword_spawning_powershell.yml
index 74a7ae6560..50d598f95b 100644
--- a/detections/deprecated/winword_spawning_powershell.yml
+++ b/detections/deprecated/winword_spawning_powershell.yml
@@ -4,13 +4,6 @@ version: 7
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/detections/deprecated/winword_spawning_windows_script_host.yml b/detections/deprecated/winword_spawning_windows_script_host.yml
index 606abeabb3..b1d17ca5a5 100644
--- a/detections/deprecated/winword_spawning_windows_script_host.yml
+++ b/detections/deprecated/winword_spawning_windows_script_host.yml
@@ -4,16 +4,6 @@ version: 6
date: '2025-01-13'
author: Michael Haag, Splunk
status: deprecated
-deprecation_info:
- deprecation_date: '2025-02-26'
- deprecation_version: 5.2.0
- content_type: detection
- reason: "The following analytics was deprecated in favour of a more generic approach.
- Where instead of creating specific analytic for every potentially suspicious child
- of an office product. We group them by threat level.\nThis would ease management
- and false positives tuning."
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach. The following analytic identifies instances where Microsoft Winword.exe
From f1dd70da1ea344a8285d2adbfa591eecb9c00868 Mon Sep 17 00:00:00 2001
From: pyth0n1c
Date: Fri, 14 Feb 2025 10:22:46 -0800
Subject: [PATCH 08/67] update and pull in all the latest changes from develop
branch
---
...ct_distributed_password_spray_attempts.yml | 5 +-
.../detect_password_spray_attempts.yml | 5 +-
...itten_outside_of_the_outlook_directory.yml | 5 +-
...s_sending_high_volume_traffic_to_hosts.yml | 5 +-
...entication_failed_during_mfa_challenge.yml | 8 +-
...a_multi_factor_authentication_disabled.yml | 5 +-
.../okta_new_api_token_created.yml | 5 +-
.../okta_new_device_enrolled_on_account.yml | 5 +-
...g_detection_with_fastpass_origin_check.yml | 5 +-
...uccessful_single_factor_authentication.yml | 8 +-
.../okta_suspicious_activity_reported.yml | 5 +-
.../okta_threatinsight_threat_detected.yml | 5 +-
..._auth_source_and_verification_response.yml | 2 +-
...suspicious_email_attachment_extensions.yml | 5 +-
...ows_ad_dangerous_deny_acl_modification.yml | 7 +-
...ws_ad_dangerous_group_acl_modification.yml | 7 +-
...ows_ad_dangerous_user_acl_modification.yml | 7 +-
.../windows_ad_domain_root_acl_deletion.yml | 7 +-
...indows_ad_domain_root_acl_modification.yml | 7 +-
.../windows_ad_gpo_new_cse_addition.yml | 8 +-
.../windows_ad_hidden_ou_creation.yml | 7 +-
.../windows_ad_object_owner_updated.yml | 7 +-
...s_ad_suspicious_attribute_modification.yml | 7 +-
...windows_ad_suspicious_gpo_modification.yml | 8 +-
...mber_of_cloud_infrastructure_api_calls.yml | 5 +-
...gh_number_of_cloud_instances_destroyed.yml | 5 +-
...igh_number_of_cloud_instances_launched.yml | 5 +-
...mber_of_cloud_security_group_api_calls.yml | 5 +-
.../cloud/asl_aws_create_access_key.yml | 35 +++--
..._policy_version_to_allow_all_resources.yml | 48 ++++--
..._aws_credential_access_getpassworddata.yml | 46 ++++--
...s_credential_access_rds_password_reset.yml | 44 ++++--
..._aws_defense_evasion_delete_cloudtrail.yml | 35 +++--
...se_evasion_delete_cloudwatch_log_group.yml | 33 +++-
...fense_evasion_impair_security_services.yml | 37 +++--
...aws_defense_evasion_putbucketlifecycle.yml | 39 +++--
...efense_evasion_stop_logging_cloudtrail.yml | 39 +++--
..._aws_defense_evasion_update_cloudtrail.yml | 37 +++--
...ontainer_upload_outside_business_hours.yml | 40 +++--
..._aws_ecr_container_upload_unknown_user.yml | 35 ++++-
.../asl_aws_iam_successful_group_deletion.yml | 34 +++--
...s_multi_factor_authentication_disabled.yml | 39 +++--
...ntrol_list_created_with_all_open_ports.yml | 58 ++++---
...ws_network_access_control_list_deleted.yml | 49 ++++--
...aws_new_mfa_method_registered_for_user.yml | 36 +++--
.../cloud/asl_aws_updateloginprofile.yml | 52 +++++--
...sole_login_failed_during_mfa_challenge.yml | 5 +-
..._policy_version_to_allow_all_resources.yml | 5 +-
detections/cloud/aws_createaccesskey.yml | 5 +-
detections/cloud/aws_createloginprofile.yml | 5 +-
.../aws_credential_access_failed_login.yml | 8 +-
.../aws_credential_access_getpassworddata.yml | 8 +-
...s_credential_access_rds_password_reset.yml | 7 +-
.../aws_defense_evasion_delete_cloudtrail.yml | 5 +-
...se_evasion_delete_cloudwatch_log_group.yml | 5 +-
...fense_evasion_impair_security_services.yml | 5 +-
...aws_defense_evasion_putbucketlifecycle.yml | 8 +-
...efense_evasion_stop_logging_cloudtrail.yml | 5 +-
.../aws_defense_evasion_update_cloudtrail.yml | 5 +-
...s_ecr_container_scanning_findings_high.yml | 5 +-
...ing_findings_low_informational_unknown.yml | 5 +-
...ecr_container_scanning_findings_medium.yml | 5 +-
...ontainer_upload_outside_business_hours.yml | 5 +-
.../aws_ecr_container_upload_unknown_user.yml | 5 +-
...mber_of_failed_authentications_from_ip.yml | 5 +-
.../aws_iam_successful_group_deletion.yml | 5 +-
...s_multi_factor_authentication_disabled.yml | 8 +-
..._multiple_failed_mfa_requests_for_user.yml | 5 +-
..._users_failing_to_authenticate_from_ip.yml | 5 +-
...ntrol_list_created_with_all_open_ports.yml | 5 +-
...ws_network_access_control_list_deleted.yml | 5 +-
...aws_new_mfa_method_registered_for_user.yml | 5 +-
.../cloud/aws_setdefaultpolicyversion.yml | 5 +-
...uccessful_single_factor_authentication.yml | 8 +-
...mber_of_failed_authentications_from_ip.yml | 8 +-
detections/cloud/aws_updateloginprofile.yml | 5 +-
...ure_active_directory_high_risk_sign_in.yml | 8 +-
...pplication_administrator_role_assigned.yml | 5 +-
...entication_failed_during_mfa_challenge.yml | 8 +-
...azure_ad_azurehound_useragent_detected.yml | 2 +-
.../azure_ad_device_code_authentication.yml | 5 +-
.../azure_ad_external_guest_user_invited.yml | 2 +-
...ber_of_failed_authentications_for_user.yml | 5 +-
...mber_of_failed_authentications_from_ip.yml | 5 +-
...d_multi_factor_authentication_disabled.yml | 8 +-
...ti_source_failed_authentications_spike.yml | 8 +-
..._multiple_failed_mfa_requests_for_user.yml | 8 +-
..._users_failing_to_authenticate_from_ip.yml | 8 +-
.../azure_ad_new_custom_domain_added.yml | 5 +-
.../azure_ad_new_federated_domain_added.yml | 5 +-
.../azure_ad_new_mfa_method_registered.yml | 5 +-
..._ad_new_mfa_method_registered_for_user.yml | 5 +-
.../cloud/azure_ad_pim_role_assigned.yml | 5 +-
...azure_ad_pim_role_assignment_activated.yml | 5 +-
.../azure_ad_privileged_role_assigned.yml | 5 +-
...ged_role_assigned_to_service_principal.yml | 5 +-
...azure_ad_service_principal_enumeration.yml | 2 +-
...rvice_principal_new_client_credentials.yml | 5 +-
...azure_ad_service_principal_owner_added.yml | 2 +-
...service_principal_privilege_escalation.yml | 45 ++++--
...sful_authentication_from_different_ips.yml | 5 +-
...d_successful_powershell_authentication.yml | 8 +-
...uccessful_single_factor_authentication.yml | 8 +-
...e_ad_tenant_wide_admin_consent_granted.yml | 5 +-
...mber_of_failed_authentications_from_ip.yml | 8 +-
...ure_ad_user_enabled_and_password_reset.yml | 2 +-
..._ad_user_immutableid_attribute_updated.yml | 2 +-
.../azure_automation_account_created.yml | 5 +-
.../azure_automation_runbook_created.yml | 5 +-
.../cloud/azure_runbook_webhook_created.yml | 5 +-
...ance_created_by_previously_unseen_user.yml | 5 +-
...nce_modified_by_previously_unseen_user.yml | 5 +-
.../detect_aws_console_login_by_new_user.yml | 7 +-
...ws_console_login_by_user_from_new_city.yml | 7 +-
...console_login_by_user_from_new_country.yml | 7 +-
..._console_login_by_user_from_new_region.yml | 7 +-
...entication_failed_during_mfa_challenge.yml | 8 +-
...p_multi_factor_authentication_disabled.yml | 8 +-
..._multiple_failed_mfa_requests_for_user.yml | 8 +-
..._users_failing_to_authenticate_from_ip.yml | 8 +-
...uccessful_single_factor_authentication.yml | 8 +-
...mber_of_failed_authentications_from_ip.yml | 8 +-
...thub_actions_disable_security_workflow.yml | 5 +-
detections/cloud/github_dependabot_alert.yml | 5 +-
.../github_pull_request_from_unknown_user.yml | 5 +-
.../gsuite_drive_share_in_external_email.yml | 5 +-
.../gsuite_email_suspicious_attachment.yml | 5 +-
...ail_suspicious_subject_with_attachment.yml | 5 +-
...mail_with_known_abuse_web_service_link.yml | 5 +-
...ail_with_attachment_to_external_domain.yml | 5 +-
.../gsuite_suspicious_shared_file_name.yml | 5 +-
...of_login_failures_from_a_single_source.yml | 5 +-
...365_add_app_role_assignment_grant_user.yml | 5 +-
.../cloud/o365_added_service_principal.yml | 5 +-
.../cloud/o365_advanced_audit_disabled.yml | 5 +-
...application_available_to_other_tenants.yml | 5 +-
...applicationimpersonation_role_assigned.yml | 5 +-
.../cloud/o365_bypass_mfa_via_trusted_ip.yml | 5 +-
...365_compliance_content_search_exported.yml | 5 +-
...o365_compliance_content_search_started.yml | 5 +-
...5_elevated_mailbox_permission_assigned.yml | 5 +-
...email_access_by_security_administrator.yml | 7 +-
...mail_reported_by_admin_found_malicious.yml | 5 +-
...email_reported_by_user_found_malicious.yml | 5 +-
.../o365_email_security_feature_changed.yml | 7 +-
.../o365_email_suspicious_behavior_alert.yml | 5 +-
.../o365_email_transport_rule_changed.yml | 67 ++++++++
...ber_of_failed_authentications_for_user.yml | 5 +-
.../o365_high_privilege_role_granted.yml | 5 +-
.../o365_mailbox_email_forwarding_enabled.yml | 5 +-
...ailbox_folder_read_permission_assigned.yml | 5 +-
...mailbox_folder_read_permission_granted.yml | 5 +-
...box_inbox_folder_shared_with_all_users.yml | 5 +-
...box_read_access_granted_to_application.yml | 8 +-
...ti_source_failed_authentications_spike.yml | 8 +-
...le_os_vendors_authenticating_from_user.yml | 66 ++++++++
..._users_failing_to_authenticate_from_ip.yml | 8 +-
...o365_new_email_forwarding_rule_created.yml | 5 +-
...o365_new_email_forwarding_rule_enabled.yml | 5 +-
.../cloud/o365_new_federated_domain_added.yml | 5 +-
.../cloud/o365_new_mfa_method_registered.yml | 5 +-
.../cloud/o365_privileged_role_assigned.yml | 5 +-
...ged_role_assigned_to_service_principal.yml | 5 +-
.../cloud/o365_safe_links_detection.yml | 5 +-
...ecurity_and_compliance_alert_triggered.yml | 5 +-
...rvice_principal_new_client_credentials.yml | 5 +-
...service_principal_privilege_escalation.yml | 39 +++--
.../o365_sharepoint_malware_detection.yml | 5 +-
..._sharepoint_suspicious_search_behavior.yml | 67 ++++++++
...o365_tenant_wide_admin_consent_granted.yml | 5 +-
...ntelligence_suspicious_email_delivered.yml | 5 +-
..._intelligence_suspicious_file_detected.yml | 5 +-
.../cloud/o365_zap_activity_detection.yml | 5 +-
...isk_rule_for_dev_sec_ops_by_repository.yml | 5 +-
.../account_discovery_with_net_app.yml | 5 +-
.../attempt_to_stop_security_service.yml | 5 +-
...dential_dump_from_registry_via_reg_exe.yml | 5 +-
...ovisioning_from_previously_unseen_city.yml | 4 +-
...sioning_from_previously_unseen_country.yml | 14 +-
...isioning_from_previously_unseen_region.yml | 4 +-
.../change_default_file_association.yml | 5 +-
...cmdline_tool_not_executed_in_cmd_shell.yml | 5 +-
.../correlation_by_repository_and_risk.yml | 5 +-
.../correlation_by_user_and_risk.yml | 5 +-
...ate_local_admin_accounts_using_net_exe.yml | 5 +-
.../deprecated/deleting_of_net_users.yml | 18 +--
...ivity_related_to_pass_the_hash_attacks.yml | 5 +-
...ct_critical_alerts_from_security_tools.yml | 38 +----
...to_phishing_sites_leveraging_evilginx2.yml | 6 +-
.../detect_mimikatz_using_loaded_images.yml | 5 +-
.../detect_new_api_calls_from_user_roles.yml | 6 +-
.../detect_new_user_aws_console_login.yml | 6 +-
...system_network_configuration_discovery.yml | 21 +--
.../detect_webshell_exploit_behavior.yml | 5 +-
.../deprecated/disabling_net_user_account.yml | 18 +--
.../domain_account_discovery_with_net_app.yml | 5 +-
.../domain_group_discovery_with_net.yml | 5 +-
.../elevated_group_discovery_with_net.yml | 5 +-
.../deprecated/excel_spawning_powershell.yml | 5 +-
.../excel_spawning_windows_script_host.yml | 12 +-
.../excessive_service_stop_attempt.yml | 17 ++-
.../deprecated/excessive_usage_of_net_app.yml | 19 +--
.../extraction_of_registry_hives.yml | 5 +-
.../known_services_killed_by_ransomware.yml | 10 +-
.../linux_auditd_find_private_keys.yml | 5 +-
.../local_account_discovery_with_net.yml | 5 +-
.../mshtml_module_load_in_office_product.yml | 5 +-
...h_invalid_credentials_from_the_same_ip.yml | 7 +-
.../deprecated/net_localgroup_discovery.yml | 5 +-
.../network_connection_discovery_with_net.yml | 18 +--
...o365_suspicious_admin_email_forwarding.yml | 5 +-
.../o365_suspicious_rights_delegation.yml | 8 +-
.../o365_suspicious_user_email_forwarding.yml | 5 +-
.../office_application_drop_executable.yml | 5 +-
...ice_application_spawn_regsvr32_process.yml | 5 +-
...ice_application_spawn_rundll32_process.yml | 5 +-
...office_document_creating_schedule_task.yml | 5 +-
.../office_document_executing_macro_code.yml | 5 +-
...ment_spawned_child_process_to_download.yml | 5 +-
.../office_product_spawn_cmd_process.yml | 5 +-
.../office_product_spawning_bitsadmin.yml | 5 +-
.../office_product_spawning_certutil.yml | 5 +-
.../office_product_spawning_mshta.yml | 5 +-
..._product_spawning_rundll32_with_no_dll.yml | 5 +-
...e_product_spawning_windows_script_host.yml | 5 +-
.../office_product_spawning_wmic.yml | 5 +-
.../office_product_writing_cab_or_inf.yml | 5 +-
.../deprecated/office_spawning_control.yml | 5 +-
.../okta_account_lockout_events.yml | 5 +-
.../deprecated/okta_failed_sso_attempts.yml | 5 +-
..._login_failure_with_high_unknown_users.yml | 5 +-
...insight_suspected_passwordspray_attack.yml | 5 +-
.../osquery_pack___coldroot_detection.yml | 2 +-
.../password_policy_discovery_with_net.yml | 19 +--
.../remote_desktop_network_bruteforce.yml | 58 +++++++
.../remote_system_discovery_with_net.yml | 31 +---
.../suspicious_driver_loaded_path.yml | 9 +-
.../suspicious_process_file_path.yml | 10 +-
.../deprecated/suspicious_rundll32_rename.yml | 8 +-
...dows_command_shell_fetch_env_variables.yml | 17 ++-
...indows_dll_search_order_hijacking_hunt.yml | 5 +-
.../windows_lateral_tool_transfer_remcom.yml | 2 +-
.../windows_modify_registry_reg_restore.yml | 18 +--
...ndows_msiexec_with_network_connections.yml | 19 +--
...ows_network_share_interaction_with_net.yml | 14 +-
.../windows_office_product_spawning_msdt.yml | 5 +-
.../windows_query_registry_reg_save.yml | 16 +-
...id_account_with_never_expires_password.yml | 17 ++-
.../deprecated/winword_spawning_cmd.yml | 5 +-
.../winword_spawning_powershell.yml | 5 +-
.../winword_spawning_windows_script_host.yml | 5 +-
.../7zip_commandline_to_smb_share_path.yml | 5 +-
.../access_lsass_memory_for_dump_creation.yml | 5 +-
.../active_setup_registry_autostart.yml | 5 +-
...d_defaultuser_and_password_in_registry.yml | 5 +-
.../add_or_set_windows_defender_exclusion.yml | 5 +-
.../adsisearcher_account_discovery.yml | 5 +-
..._file_and_printing_sharing_in_firewall.yml | 5 +-
...ound_traffic_by_firewall_rule_registry.yml | 5 +-
...allow_inbound_traffic_in_firewall_rule.yml | 5 +-
.../allow_network_discovery_in_firewall.yml | 5 +-
.../endpoint/anomalous_usage_of_7zip.yml | 5 +-
.../endpoint/any_powershell_downloadfile.yml | 8 +-
.../any_powershell_downloadstring.yml | 5 +-
.../endpoint/attacker_tools_on_endpoint.yml | 7 +-
..._to_add_certificate_to_untrusted_store.yml | 5 +-
.../auto_admin_logon_registry_entry.yml | 5 +-
.../endpoint/batch_file_write_to_system32.yml | 5 +-
.../bcdedit_failure_recovery_modification.yml | 2 +-
detections/endpoint/bits_job_persistence.yml | 2 +-
.../endpoint/bitsadmin_download_file.yml | 2 +-
...load_with_urlcache_and_split_arguments.yml | 2 +-
...oad_with_verifyctl_and_split_arguments.yml | 2 +-
.../certutil_exe_certificate_extraction.yml | 2 +-
.../certutil_with_decode_argument.yml | 2 +-
.../check_elevated_cmd_using_whoami.yml | 2 +-
...ar_unallocated_sector_using_cipher_app.yml | 5 +-
.../endpoint/clop_common_exec_parameter.yml | 2 +-
...cmd_carry_out_string_command_parameter.yml | 5 +-
.../endpoint/cmd_echo_pipe___escalation.yml | 6 +-
.../endpoint/cmlua_or_cmstplua_uac_bypass.yml | 5 +-
.../endpoint/common_ransomware_extensions.yml | 2 +-
.../endpoint/conti_common_exec_parameter.yml | 2 +-
..._loading_from_world_writable_directory.yml | 5 +-
...or_delete_windows_shares_using_net_exe.yml | 5 +-
.../create_remote_thread_into_lsass.yml | 5 +-
.../creation_of_lsass_dump_with_taskmgr.yml | 5 +-
.../endpoint/creation_of_shadow_copy.yml | 5 +-
...f_shadow_copy_with_wmic_and_powershell.yml | 5 +-
...ping_via_copy_command_from_shadow_copy.yml | 5 +-
...ial_dumping_via_symlink_to_shadow_copy.yml | 5 +-
.../csc_net_on_the_fly_compilation.yml | 5 +-
.../endpoint/deleting_shadow_copies.yml | 2 +-
...tect_azurehound_command_line_arguments.yml | 12 +-
.../detect_azurehound_file_modifications.yml | 12 +-
...y_with_powershell_script_block_logging.yml | 7 +-
.../detect_certipy_file_modifications.yml | 2 +-
...f_shadowcopy_with_script_block_logging.yml | 5 +-
...redential_dumping_through_lsass_access.yml | 5 +-
...e_with_powershell_script_block_logging.yml | 5 +-
...cessive_account_lockouts_from_endpoint.yml | 5 +-
...detect_excessive_user_account_lockouts.yml | 5 +-
.../endpoint/detect_exchange_web_shell.yml | 31 ++--
.../endpoint/detect_html_help_renamed.yml | 5 +-
.../detect_html_help_spawn_child_process.yml | 5 +-
.../detect_html_help_url_in_command_line.yml | 5 +-
...l_help_using_infotech_storage_handlers.yml | 5 +-
...z_with_powershell_script_block_logging.yml | 2 +-
.../detect_mshta_inline_hta_execution.yml | 5 +-
detections/endpoint/detect_mshta_renamed.yml | 5 +-
.../detect_mshta_url_in_command_line.yml | 5 +-
.../detect_new_local_admin_account.yml | 5 +-
.../detect_outlook_exe_writing_a_zip_file.yml | 5 +-
...word_spray_attack_behavior_from_source.yml | 5 +-
...password_spray_attack_behavior_on_user.yml | 5 +-
...nterception_by_creation_of_program_exe.yml | 5 +-
...ohibited_applications_spawning_cmd_exe.yml | 5 +-
.../detect_psexec_with_accepteula_flag.yml | 5 +-
.../detect_rclone_command_line_usage.yml | 2 +-
.../detect_regasm_spawning_a_process.yml | 5 +-
.../detect_regasm_with_network_connection.yml | 5 +-
..._regasm_with_no_command_line_arguments.yml | 5 +-
.../detect_regsvcs_spawning_a_process.yml | 5 +-
...detect_regsvcs_with_network_connection.yml | 5 +-
...regsvcs_with_no_command_line_arguments.yml | 5 +-
...ct_regsvr32_application_control_bypass.yml | 5 +-
...tect_remote_access_software_usage_file.yml | 9 +-
..._remote_access_software_usage_fileinfo.yml | 12 +-
...t_remote_access_software_usage_process.yml | 9 +-
..._remote_access_software_usage_registry.yml | 3 +-
detections/endpoint/detect_renamed_7_zip.yml | 5 +-
detections/endpoint/detect_renamed_psexec.yml | 8 +-
detections/endpoint/detect_renamed_winrar.yml | 8 +-
.../endpoint/detect_rtlo_in_file_name.yml | 5 +-
.../endpoint/detect_rtlo_in_process.yml | 5 +-
...2_application_control_bypass___advpack.yml | 5 +-
..._application_control_bypass___setupapi.yml | 5 +-
..._application_control_bypass___syssetup.yml | 5 +-
.../detect_rundll32_inline_hta_execution.yml | 5 +-
...tect_sharphound_command_line_arguments.yml | 12 +-
.../detect_sharphound_file_modifications.yml | 12 +-
.../endpoint/detect_sharphound_usage.yml | 12 +-
...ssnames_using_pretrained_model_in_dsdl.yml | 2 +-
..._cmd_exe_to_launch_script_interpreters.yml | 5 +-
...ect_wmi_event_subscription_persistence.yml | 5 +-
.../disable_amsi_through_registry.yml | 5 +-
.../disable_defender_antivirus_registry.yml | 5 +-
...able_defender_blockatfirstseen_feature.yml | 5 +-
...disable_defender_enhanced_notification.yml | 5 +-
.../disable_defender_mpengine_registry.yml | 5 +-
.../disable_defender_spynet_reporting.yml | 5 +-
...efender_submit_samples_consent_feature.yml | 5 +-
.../endpoint/disable_etw_through_registry.yml | 5 +-
.../endpoint/disable_logs_using_wevtutil.yml | 5 +-
detections/endpoint/disable_registry_tool.yml | 7 +-
detections/endpoint/disable_schedule_task.yml | 5 +-
.../endpoint/disable_show_hidden_files.yml | 10 +-
.../disable_uac_remote_restriction.yml | 5 +-
.../endpoint/disable_windows_app_hotkeys.yml | 7 +-
.../disable_windows_behavior_monitoring.yml | 5 +-
...disable_windows_smartscreen_protection.yml | 5 +-
...thentication_discovery_with_get_aduser.yml | 5 +-
...uthentication_discovery_with_powerview.yml | 5 +-
.../endpoint/disabling_cmd_application.yml | 7 +-
.../endpoint/disabling_controlpanel.yml | 7 +-
.../endpoint/disabling_defender_services.yml | 5 +-
.../disabling_firewall_with_netsh.yml | 5 +-
...isabling_folderoptions_windows_feature.yml | 5 +-
.../endpoint/disabling_norun_windows_app.yml | 7 +-
.../disabling_remote_user_account_control.yml | 5 +-
.../endpoint/disabling_task_manager.yml | 5 +-
.../dns_exfiltration_using_nslookup_app.yml | 2 +-
.../domain_account_discovery_with_dsquery.yml | 5 +-
.../domain_account_discovery_with_wmic.yml | 5 +-
...main_group_discovery_with_adsisearcher.yml | 5 +-
.../domain_group_discovery_with_dsquery.yml | 5 +-
.../domain_group_discovery_with_wmic.yml | 5 +-
.../endpoint/drop_icedid_license_dat.yml | 5 +-
.../endpoint/dsquery_domain_discovery.yml | 2 +-
.../endpoint/dump_lsass_via_comsvcs_dll.yml | 5 +-
.../endpoint/dump_lsass_via_procdump.yml | 5 +-
...levated_group_discovery_with_powerview.yml | 5 +-
.../elevated_group_discovery_with_wmic.yml | 5 +-
detections/endpoint/esentutl_sam_copy.yml | 5 +-
detections/endpoint/etw_registry_disabled.yml | 7 +-
detections/endpoint/eventvwr_uac_bypass.yml | 5 +-
...r_of_service_control_start_as_disabled.yml | 5 +-
.../excessive_usage_of_sc_service_utility.yml | 5 +-
.../endpoint/excessive_usage_of_taskkill.yml | 5 +-
.../exchange_powershell_module_usage.yml | 5 +-
...le_written_in_administrative_smb_share.yml | 5 +-
...cute_javascript_with_jscript_com_clsid.yml | 5 +-
...ution_of_file_with_multiple_extensions.yml | 5 +-
.../endpoint/file_with_samsam_extension.yml | 2 +-
.../firewall_allowed_program_enable.yml | 5 +-
...irst_time_seen_running_windows_service.yml | 5 +-
detections/endpoint/fodhelper_uac_bypass.yml | 5 +-
.../endpoint/get_aduser_with_powershell.yml | 5 +-
...et_aduser_with_powershell_script_block.yml | 5 +-
.../get_domainuser_with_powershell.yml | 5 +-
...omainuser_with_powershell_script_block.yml | 5 +-
.../get_wmiobject_group_discovery.yml | 5 +-
...up_discovery_with_script_block_logging.yml | 5 +-
.../endpoint/getadgroup_with_powershell.yml | 5 +-
...etadgroup_with_powershell_script_block.yml | 5 +-
.../getdomaingroup_with_powershell.yml | 5 +-
...maingroup_with_powershell_script_block.yml | 5 +-
.../endpoint/getlocaluser_with_powershell.yml | 5 +-
...localuser_with_powershell_script_block.yml | 7 +-
.../getwmiobject_ds_group_with_powershell.yml | 5 +-
..._ds_group_with_powershell_script_block.yml | 5 +-
.../getwmiobject_ds_user_with_powershell.yml | 5 +-
...t_ds_user_with_powershell_script_block.yml | 5 +-
...wmiobject_user_account_with_powershell.yml | 5 +-
...r_account_with_powershell_script_block.yml | 7 +-
...no_command_line_arguments_with_network.yml | 2 +-
...dless_browser_mockbin_or_mocky_request.yml | 2 +-
.../hide_user_account_from_sign_in_screen.yml | 5 +-
..._files_and_directories_with_attrib_exe.yml | 5 +-
...did_exfiltrated_archived_file_creation.yml | 5 +-
...ateral_movement_commandline_parameters.yml | 5 +-
...ovement_smbexec_commandline_parameters.yml | 5 +-
...ovement_wmiexec_commandline_parameters.yml | 5 +-
...ion_on_remote_endpoint_with_powershell.yml | 5 +-
.../jscript_execution_using_cscript_app.yml | 5 +-
...asting_spn_request_with_rc4_encryption.yml | 5 +-
...on_flag_disabled_in_useraccountcontrol.yml | 8 +-
...tication_flag_disabled_with_powershell.yml | 5 +-
...ce_ticket_request_using_rc4_encryption.yml | 5 +-
.../endpoint/kerberos_user_enumeration.yml | 5 +-
...nt_manipulation_of_ssh_config_and_keys.yml | 7 +-
...add_files_in_known_crontab_directories.yml | 5 +-
.../endpoint/linux_add_user_account.yml | 5 +-
...ux_adding_crontab_using_list_parameter.yml | 5 +-
.../linux_apt_get_privilege_escalation.yml | 5 +-
.../linux_apt_privilege_escalation.yml | 5 +-
.../linux_at_allow_config_file_creation.yml | 5 +-
.../linux_at_application_execution.yml | 5 +-
.../linux_auditd_add_user_account.yml | 5 +-
.../linux_auditd_add_user_account_type.yml | 5 +-
.../linux_auditd_at_application_execution.yml | 5 +-
...linux_auditd_change_file_owner_to_root.yml | 42 +++--
...ditd_disable_or_modify_system_firewall.yml | 5 +-
.../linux_auditd_doas_conf_file_creation.yml | 5 +-
.../linux_auditd_doas_tool_execution.yml | 5 +-
...linux_auditd_edit_cron_table_parameter.yml | 5 +-
...file_permission_modification_via_chmod.yml | 10 +-
...le_permissions_modification_via_chattr.yml | 39 +++--
...ind_credentials_from_password_managers.yml | 26 +++-
..._find_credentials_from_password_stores.yml | 45 ++++--
.../linux_auditd_find_ssh_private_keys.yml | 45 ++++--
..._hidden_files_and_directories_creation.yml | 8 +-
...ert_kernel_module_using_insmod_utility.yml | 11 +-
...l_kernel_module_using_modprobe_utility.yml | 41 +++--
...ditd_kernel_module_using_rmmod_utility.yml | 5 +-
..._auditd_nopasswd_entry_in_sudoers_file.yml | 8 +-
...ss_or_modification_of_sshd_config_file.yml | 5 +-
...td_possible_access_to_credential_files.yml | 8 +-
...auditd_possible_access_to_sudoers_file.yml | 8 +-
...cronjob_entry_on_existing_cronjob_file.yml | 11 +-
...ux_auditd_preload_hijack_library_calls.yml | 8 +-
...auditd_preload_hijack_via_preload_file.yml | 8 +-
...ivate_keys_and_certificate_enumeration.yml | 47 ++++--
.../linux_auditd_service_restarted.yml | 5 +-
.../endpoint/linux_auditd_service_started.yml | 9 +-
...inux_auditd_setuid_using_chmod_utility.yml | 5 +-
...nux_auditd_setuid_using_setcap_utility.yml | 45 ++++--
.../linux_auditd_sudo_or_su_execution.yml | 42 +++--
..._unix_shell_configuration_modification.yml | 5 +-
...inux_auditd_unload_module_via_modprobe.yml | 43 ++++--
.../linux_awk_privilege_escalation.yml | 5 +-
.../linux_busybox_privilege_escalation.yml | 5 +-
.../linux_c89_privilege_escalation.yml | 5 +-
.../linux_c99_privilege_escalation.yml | 5 +-
.../linux_change_file_owner_to_root.yml | 5 +-
...x_common_process_for_elevation_control.yml | 8 +-
.../linux_composer_privilege_escalation.yml | 5 +-
.../linux_cpulimit_privilege_escalation.yml | 5 +-
.../linux_csvtool_privilege_escalation.yml | 5 +-
.../linux_data_destruction_command.yml | 2 +-
.../endpoint/linux_decode_base64_to_shell.yml | 2 +-
.../endpoint/linux_deletion_of_cron_jobs.yml | 7 +-
.../linux_deletion_of_init_daemon_script.yml | 7 +-
.../endpoint/linux_deletion_of_services.yml | 7 +-
.../linux_deletion_of_ssl_certificate.yml | 7 +-
.../linux_doas_conf_file_creation.yml | 5 +-
.../endpoint/linux_doas_tool_execution.yml | 5 +-
.../linux_docker_privilege_escalation.yml | 5 +-
.../linux_edit_cron_table_parameter.yml | 5 +-
.../linux_emacs_privilege_escalation.yml | 5 +-
...ile_created_in_kernel_driver_directory.yml | 5 +-
...x_file_creation_in_init_boot_directory.yml | 8 +-
...nux_file_creation_in_profile_directory.yml | 5 +-
.../linux_find_privilege_escalation.yml | 5 +-
.../linux_gdb_privilege_escalation.yml | 5 +-
.../linux_gem_privilege_escalation.yml | 5 +-
.../linux_gnu_awk_privilege_escalation.yml | 5 +-
...quency_of_file_deletion_in_boot_folder.yml | 7 +-
...equency_of_file_deletion_in_etc_folder.yml | 7 +-
.../linux_impair_defenses_process_kill.yml | 5 +-
...ndicator_removal_service_file_deletion.yml | 5 +-
...ert_kernel_module_using_insmod_utility.yml | 5 +-
...l_kernel_module_using_modprobe_utility.yml | 5 +-
.../linux_iptables_firewall_modification.yml | 8 +-
.../endpoint/linux_java_spawning_shell.yml | 2 +-
.../linux_kernel_module_enumeration.yml | 2 +-
...orker_process_in_writable_process_path.yml | 5 +-
.../linux_make_privilege_escalation.yml | 5 +-
.../linux_mysql_privilege_escalation.yml | 5 +-
.../linux_ngrok_reverse_proxy_usage.yml | 2 +-
.../linux_node_privilege_escalation.yml | 5 +-
.../linux_nopasswd_entry_in_sudoers_file.yml | 8 +-
...ted_files_or_information_base64_decode.yml | 2 +-
.../linux_octave_privilege_escalation.yml | 5 +-
.../linux_openvpn_privilege_escalation.yml | 5 +-
.../linux_php_privilege_escalation.yml | 5 +-
.../linux_pkexec_privilege_escalation.yml | 2 +-
...ss_or_modification_of_sshd_config_file.yml | 5 +-
...ux_possible_access_to_credential_files.yml | 8 +-
.../linux_possible_access_to_sudoers_file.yml | 8 +-
...append_command_to_at_allow_config_file.yml | 5 +-
..._append_command_to_profile_config_file.yml | 5 +-
...cronjob_entry_on_existing_cronjob_file.yml | 5 +-
...sible_cronjob_modification_with_editor.yml | 5 +-
.../linux_possible_ssh_key_file_creation.yml | 5 +-
.../linux_preload_hijack_library_calls.yml | 8 +-
.../endpoint/linux_proxy_socks_curl.yml | 2 +-
.../linux_puppet_privilege_escalation.yml | 5 +-
.../linux_rpm_privilege_escalation.yml | 5 +-
.../linux_ruby_privilege_escalation.yml | 5 +-
...vice_file_created_in_systemd_directory.yml | 5 +-
.../endpoint/linux_service_restarted.yml | 5 +-
.../linux_service_started_or_enabled.yml | 5 +-
.../linux_setuid_using_chmod_utility.yml | 5 +-
.../linux_setuid_using_setcap_utility.yml | 5 +-
.../linux_sqlite3_privilege_escalation.yml | 5 +-
...linux_ssh_authorized_keys_modification.yml | 2 +-
...nux_ssh_remote_services_script_execute.yml | 2 +-
...ux_stdout_redirection_to_dev_null_file.yml | 5 +-
.../endpoint/linux_sudo_or_su_execution.yml | 5 +-
.../linux_sudoers_tmp_file_creation.yml | 8 +-
..._unix_shell_enable_all_sysrq_functions.yml | 5 +-
.../linux_visudo_utility_execution.yml | 5 +-
.../endpoint/loading_of_dynwrapx_module.yml | 5 +-
.../local_account_discovery_with_wmic.yml | 5 +-
.../logon_script_event_trigger_execution.yml | 5 +-
detections/endpoint/macos_lolbin.yml | 5 +-
.../endpoint/mailsniper_invoke_functions.yml | 5 +-
...cious_powershell_executed_as_a_service.yml | 5 +-
...hell_process___execution_policy_bypass.yml | 8 +-
...ll_process_with_obfuscation_techniques.yml | 5 +-
.../microsoft_defender_atp_alerts.yml | 2 +-
.../microsoft_defender_incident_alerts.yml | 2 +-
...z_passtheticket_commandline_parameters.yml | 5 +-
.../mmc_lolbas_execution_process_spawn.yml | 5 +-
...nitor_registry_keys_for_print_monitors.yml | 5 +-
...on_service_writing_active_server_pages.yml | 9 +-
..._scripting_process_loading_ldap_module.yml | 5 +-
...s_scripting_process_loading_wmi_module.yml | 5 +-
...d_suspicious_spawned_by_script_process.yml | 5 +-
..._spawning_rundll32_or_regsvr32_process.yml | 5 +-
...msi_module_loaded_by_non_system_binary.yml | 5 +-
.../msmpeng_application_dll_side_loading.yml | 5 +-
.../endpoint/net_profiler_uac_bypass.yml | 5 +-
...work_discovery_using_route_windows_app.yml | 5 +-
...active_directory_web_services_protocol.yml | 12 +-
.../endpoint/nishang_powershelltcponeline.yml | 5 +-
...e_process_accessing_chrome_default_dir.yml | 8 +-
...fox_process_access_firefox_profile_dir.yml | 5 +-
...notepad_with_no_command_line_arguments.yml | 2 +-
detections/endpoint/ntdsutil_export_ntds.yml | 5 +-
.../overwriting_accessibility_binaries.yml | 5 +-
...mission_modification_using_takeown_app.yml | 8 +-
.../endpoint/ping_sleep_batch_command.yml | 5 +-
.../possible_browser_pass_view_parameter.yml | 5 +-
...ible_lateral_movement_powershell_spawn.yml | 7 +-
...twork_configuration_discovery_activity.yml | 2 +-
.../endpoint/powershell_4104_hunting.yml | 8 +-
...connect_to_internet_with_hidden_window.yml | 5 +-
..._hijacking_inprocserver32_modification.yml | 7 +-
.../powershell_creating_thread_mutex.yml | 5 +-
...powershell_disable_security_monitoring.yml | 5 +-
.../powershell_domain_enumeration.yml | 5 +-
.../powershell_enable_powershell_remoting.yml | 5 +-
...powershell_enable_smb1protocol_feature.yml | 5 +-
.../powershell_execute_com_object.yml | 7 +-
...s_process_injection_via_getprocaddress.yml | 5 +-
...script_contains_base64_encoded_content.yml | 5 +-
.../powershell_get_localgroup_discovery.yml | 5 +-
...up_discovery_with_script_block_logging.yml | 5 +-
.../powershell_load_module_in_meterpreter.yml | 5 +-
...ding_dotnet_into_memory_via_reflection.yml | 40 +++--
.../powershell_processing_stream_of_data.yml | 5 +-
...rshell_remote_services_add_trustedhost.yml | 5 +-
...hell_remove_windows_defender_directory.yml | 5 +-
.../powershell_start_bitstransfer.yml | 2 +-
...wershell_using_memory_as_backing_store.yml | 5 +-
...ll_windows_defender_exclusion_commands.yml | 5 +-
...nt_automatic_repair_mode_using_bcdedit.yml | 2 +-
.../print_processor_registry_autostart.yml | 5 +-
.../print_spooler_adding_a_printer_driver.yml | 5 +-
...print_spooler_failed_to_load_a_plug_in.yml | 5 +-
...eating_lnk_file_in_suspicious_location.yml | 5 +-
.../process_kill_base_on_file_path.yml | 5 +-
.../endpoint/processes_launching_netsh.yml | 5 +-
...randomly_generated_scheduled_task_name.yml | 5 +-
...andomly_generated_windows_service_name.yml | 5 +-
.../recon_avproduct_through_pwh_or_wmi.yml | 2 +-
...rsive_delete_of_directory_in_batch_cmd.yml | 5 +-
...ulating_windows_services_registry_keys.yml | 5 +-
...istry_keys_for_creating_shim_databases.yml | 5 +-
.../registry_keys_used_for_persistence.yml | 8 +-
...try_keys_used_for_privilege_escalation.yml | 5 +-
...2_silent_and_install_param_dll_loading.yml | 5 +-
...svr32_with_known_silent_switch_cmdline.yml | 5 +-
...mote_desktop_process_running_on_system.yml | 5 +-
..._instantiation_via_dcom_and_powershell.yml | 5 +-
...n_via_dcom_and_powershell_script_block.yml | 5 +-
...instantiation_via_winrm_and_powershell.yml | 5 +-
..._via_winrm_and_powershell_script_block.yml | 5 +-
...cess_instantiation_via_winrm_and_winrs.yml | 5 +-
.../rubeus_command_line_parameters.yml | 6 +-
...ticket_exports_through_winlogon_access.yml | 5 +-
.../runas_execution_in_commandline.yml | 5 +-
.../endpoint/rundll32_control_rundll_hunt.yml | 5 +-
...ontrol_rundll_world_writable_directory.yml | 5 +-
detections/endpoint/rundll32_dnsquery.yml | 5 +-
.../endpoint/rundll32_lockworkstation.yml | 5 +-
...undll32_process_creating_exe_dll_files.yml | 5 +-
...no_command_line_arguments_with_network.yml | 5 +-
.../rundll_loading_dll_by_ordinal.yml | 5 +-
.../endpoint/ryuk_wake_on_lan_command.yml | 5 +-
.../sam_database_file_access_attempt.yml | 5 +-
.../sc_exe_manipulating_windows_services.yml | 5 +-
..._by_app_connect_and_create_adsi_object.yml | 5 +-
...k_creation_on_remote_endpoint_using_at.yml | 5 +-
...eduled_task_deleted_or_created_via_cmd.yml | 8 +-
...led_task_initiation_on_remote_endpoint.yml | 5 +-
...htasks_scheduling_job_on_remote_system.yml | 5 +-
.../schtasks_used_for_forcing_a_reboot.yml | 5 +-
.../screensaver_event_trigger_execution.yml | 5 +-
detections/endpoint/sdclt_uac_bypass.yml | 5 +-
.../sdelete_application_execution.yml | 7 +-
.../secretdumps_offline_ntds_dumping_tool.yml | 5 +-
...ceprincipalnames_discovery_with_setspn.yml | 2 +-
...ervices_lolbas_execution_process_spawn.yml | 5 +-
...ution_policy_to_unrestricted_or_bypass.yml | 5 +-
.../endpoint/shim_database_file_creation.yml | 5 +-
...nstallation_with_suspicious_parameters.yml | 25 ++-
.../endpoint/short_lived_windows_accounts.yml | 7 +-
.../endpoint/silentcleanup_uac_bypass.yml | 5 +-
.../single_letter_process_on_endpoint.yml | 5 +-
detections/endpoint/slui_runas_elevated.yml | 5 +-
.../endpoint/slui_spawning_a_process.yml | 5 +-
.../endpoint/spoolsv_spawning_rundll32.yml | 5 +-
.../spoolsv_suspicious_loaded_modules.yml | 5 +-
.../spoolsv_suspicious_process_access.yml | 2 +-
detections/endpoint/spoolsv_writing_a_dll.yml | 5 +-
.../spoolsv_writing_a_dll___sysmon.yml | 5 +-
...uspicious_computer_account_name_change.yml | 5 +-
.../endpoint/suspicious_copy_on_system32.yml | 5 +-
.../suspicious_event_log_service_behavior.yml | 5 +-
.../suspicious_icedid_rundll32_cmdline.yml | 5 +-
...icious_kerberos_service_ticket_request.yml | 5 +-
...ous_microsoft_workflow_compiler_rename.yml | 7 +-
.../endpoint/suspicious_msbuild_path.yml | 6 +-
.../endpoint/suspicious_msbuild_rename.yml | 6 +-
.../endpoint/suspicious_msbuild_spawn.yml | 5 +-
.../suspicious_mshta_child_process.yml | 5 +-
.../endpoint/suspicious_mshta_spawn.yml | 5 +-
.../endpoint/suspicious_plistbuddy_usage.yml | 5 +-
...uspicious_plistbuddy_usage_via_osquery.yml | 5 +-
...ess_dns_query_known_abuse_web_services.yml | 5 +-
...picious_process_with_discord_dns_query.yml | 5 +-
.../endpoint/suspicious_reg_exe_process.yml | 2 +-
...ious_regsvr32_register_suspicious_path.yml | 8 +-
.../suspicious_rundll32_dllregisterserver.yml | 5 +-
...ous_rundll32_no_command_line_arguments.yml | 5 +-
.../suspicious_rundll32_plugininit.yml | 5 +-
.../endpoint/suspicious_rundll32_startw.yml | 5 +-
...s_scheduled_task_from_public_directory.yml | 8 +-
...picious_ticket_granting_ticket_request.yml | 5 +-
.../endpoint/suspicious_wevtutil_usage.yml | 5 +-
...svchost_lolbas_execution_process_spawn.yml | 5 +-
...rocesses_run_from_unexpected_locations.yml | 5 +-
.../system_user_discovery_with_query.yml | 9 +-
.../time_provider_persistence_registry.yml | 5 +-
.../uac_bypass_mmc_load_unsigned_dll.yml | 7 +-
.../uac_bypass_with_colorui_com_object.yml | 5 +-
.../endpoint/uninstall_app_using_msiexec.yml | 5 +-
.../endpoint/unload_sysmon_filter_driver.yml | 5 +-
.../unloading_amsi_via_reflection.yml | 7 +-
..._of_kerberos_service_tickets_requested.yml | 5 +-
.../vbscript_execution_using_wscript_app.yml | 5 +-
.../endpoint/verclsid_clsid_execution.yml | 5 +-
detections/endpoint/w3wp_spawning_shell.yml | 5 +-
.../wbemprox_com_object_execution.yml | 5 +-
...ss_connecting_to_ip_check_web_services.yml | 5 +-
...ss_token_manipulation_sedebugprivilege.yml | 8 +-
...lation_winlogon_duplicate_token_handle.yml | 5 +-
...ogon_duplicate_handle_in_uncommon_path.yml | 5 +-
...account_access_removal_via_logoff_exec.yml | 41 +++--
...iscovery_for_none_disable_user_account.yml | 5 +-
...ows_ad_abnormal_object_access_activity.yml | 5 +-
.../windows_ad_adminsdholder_acl_modified.yml | 2 +-
...s_ad_cross_domain_sid_history_addition.yml | 5 +-
...ows_ad_domain_replication_acl_addition.yml | 2 +-
...rivileged_account_sid_history_addition.yml | 5 +-
...s_ad_privileged_object_access_activity.yml | 5 +-
...tion_request_initiated_by_user_account.yml | 5 +-
...t_initiated_from_unsanctioned_location.yml | 5 +-
...ws_ad_same_domain_sid_history_addition.yml | 5 +-
...dows_ad_sid_history_attribute_modified.yml | 5 +-
...n_default_group_policy_object_modified.yml | 5 +-
...dows_admon_group_policy_object_created.yml | 5 +-
..._alternate_datastream___base64_content.yml | 5 +-
...ernate_datastream___executable_content.yml | 5 +-
...ternate_datastream___process_execution.yml | 5 +-
.../windows_apache_benchmark_binary.yml | 2 +-
...windows_archive_collected_data_via_rar.yml | 8 +-
...ndows_attempt_to_stop_security_service.yml | 47 ++++--
.../endpoint/windows_autoit3_execution.yml | 2 +-
...roxy_execution_mavinject_dll_injection.yml | 5 +-
...indows_bitlockertogo_process_execution.yml | 4 +-
..._autostart_execution_in_startup_folder.yml | 5 +-
.../endpoint/windows_bootloader_inventory.yml | 5 +-
...ws_cached_domain_credentials_reg_query.yml | 5 +-
...ws_certutil_download_with_url_argument.yml | 2 +-
...fault_file_association_for_no_file_ext.yml | 5 +-
..._tool_execution_from_non_shell_process.yml | 47 ++++--
..._hijacking_inprocserver32_modification.yml | 5 +-
...s_command_shell_dcrat_forkbomb_payload.yml | 5 +-
.../endpoint/windows_create_local_account.yml | 5 +-
...te_local_administrator_account_via_net.yml | 44 +++++-
...ential_dumping_lsass_memory_createdump.yml | 2 +-
...sword_stores_chrome_copied_in_temp_dir.yml | 5 +-
...from_web_browsers_saved_in_temp_folder.yml | 5 +-
...dows_credentials_in_registry_reg_query.yml | 5 +-
...ndows_curl_download_to_suspicious_path.yml | 2 +-
...dows_curl_upload_to_remote_destination.yml | 2 +-
...s_default_group_policy_object_modified.yml | 5 +-
...group_policy_object_modified_with_gpme.yml | 5 +-
...dows_defender_exclusion_registry_entry.yml | 5 +-
...ndows_delete_or_modify_system_firewall.yml | 5 +-
...indows_detect_network_scanner_behavior.yml | 143 ++++++++++--------
.../windows_disable_memory_crash_dump.yml | 2 +-
...s_disable_or_modify_tools_via_taskkill.yml | 5 +-
...indows_disable_or_stop_browser_process.yml | 7 +-
...ows_event_logging_disable_http_logging.yml | 8 +-
.../windows_disableantispyware_registry.yml | 5 +-
.../endpoint/windows_dism_remove_defender.yml | 5 +-
...earch_order_hijacking_hunt_with_sysmon.yml | 5 +-
...l_search_order_hijacking_with_iscsicpl.yml | 2 +-
.../windows_dll_side_loading_in_calc.yml | 5 +-
...dll_side_loading_process_child_of_calc.yml | 5 +-
..._dns_query_request_by_telegram_bot_api.yml | 39 +++--
..._account_discovery_via_get_netcomputer.yml | 5 +-
...ows_dotnet_binary_in_non_standard_path.yml | 6 +-
.../windows_driver_load_non_standard_path.yml | 6 +-
...dows_esx_admins_group_creation_via_net.yml | 2 +-
...x_admins_group_creation_via_powershell.yml | 2 +-
.../windows_event_for_service_disabled.yml | 5 +-
.../endpoint/windows_event_log_cleared.yml | 5 +-
...dows_excessive_disabled_services_event.yml | 5 +-
.../windows_excessive_usage_of_net_app.yml | 2 +-
...s_execute_arbitrary_commands_with_msdt.yml | 2 +-
.../endpoint/windows_export_certificate.yml | 5 +-
...er_protocol_in_non_common_process_path.yml | 5 +-
..._access_rights_modification_via_icacls.yml | 5 +-
..._organizational_units_with_getdomainou.yml | 5 +-
...ting_acl_with_findinterestingdomainacl.yml | 5 +-
.../windows_findstr_gpp_discovery.yml | 5 +-
..._forest_discovery_with_getforestdomain.yml | 5 +-
..._gather_victim_host_information_camera.yml | 5 +-
...indows_gather_victim_identity_sam_info.yml | 5 +-
...ork_info_through_ip_check_web_services.yml | 5 +-
..._local_admin_with_findlocaladminaccess.yml | 5 +-
.../windows_group_discovery_via_net.yml | 39 +++--
.../windows_group_policy_object_created.yml | 7 +-
...k_execution_flow_version_dll_side_load.yml | 5 +-
...ttp_network_communication_from_msiexec.yml | 2 +-
...hunting_system_account_targeting_lsass.yml | 5 +-
.../windows_iis_components_add_new_module.yml | 5 +-
...nents_get_webglobalmodule_module_query.yml | 5 +-
...s_iis_components_module_failed_to_load.yml | 5 +-
...indows_iis_components_new_module_added.yml | 5 +-
...impair_defense_add_xml_applocker_rules.yml | 5 +-
...ge_win_defender_health_check_intervals.yml | 5 +-
...hange_win_defender_quick_scan_interval.yml | 5 +-
...ense_change_win_defender_throttle_rate.yml | 5 +-
...ense_change_win_defender_tracing_level.yml | 5 +-
..._defense_configure_app_install_control.yml | 5 +-
...ense_define_win_defender_threat_action.yml | 5 +-
...fense_delete_win_defender_context_menu.yml | 5 +-
...e_delete_win_defender_profile_registry.yml | 5 +-
..._deny_security_software_with_applocker.yml | 5 +-
...fense_disable_controlled_folder_access.yml | 5 +-
..._disable_defender_firewall_and_network.yml | 5 +-
..._disable_defender_protocol_recognition.yml | 5 +-
..._impair_defense_disable_pua_protection.yml | 5 +-
...se_disable_realtime_signature_delivery.yml | 5 +-
..._impair_defense_disable_web_evaluation.yml | 5 +-
...defense_disable_win_defender_app_guard.yml | 5 +-
...sable_win_defender_compute_file_hashes.yml | 5 +-
...fense_disable_win_defender_gen_reports.yml | 5 +-
...isable_win_defender_network_protection.yml | 5 +-
..._disable_win_defender_report_infection.yml | 5 +-
...se_disable_win_defender_scan_on_update.yml | 5 +-
...able_win_defender_signature_retirement.yml | 5 +-
...e_overide_win_defender_phishing_filter.yml | 5 +-
...ir_defense_override_smartscreen_prompt.yml | 5 +-
...in_defender_smart_screen_level_to_warn.yml | 5 +-
...r_defenses_disable_auto_logger_session.yml | 8 +-
...nses_disable_av_autostart_via_registry.yml | 2 +-
.../windows_impair_defenses_disable_hvci.yml | 5 +-
...nses_disable_win_defender_auto_logging.yml | 5 +-
...s_ingress_tool_transfer_using_explorer.yml | 2 +-
..._input_capture_using_credential_ui_dll.yml | 5 +-
.../windows_installutil_credential_theft.yml | 5 +-
...ndows_installutil_in_non_standard_path.yml | 6 +-
..._installutil_remote_network_connection.yml | 5 +-
.../windows_installutil_uninstall_option.yml | 5 +-
...tallutil_uninstall_option_with_network.yml | 5 +-
...indows_installutil_url_in_command_line.yml | 5 +-
.../windows_iso_lnk_file_creation.yml | 8 +-
.../endpoint/windows_java_spawning_shells.yml | 2 +-
.../windows_known_abused_dll_created.yml | 5 +-
...s_known_abused_dll_loaded_suspiciously.yml | 5 +-
...s_known_graphicalproton_loaded_modules.yml | 5 +-
...ndows_ldifde_directory_object_behavior.yml | 2 +-
...dows_linked_policies_in_adsi_discovery.yml | 5 +-
...ocal_administrator_credential_stuffing.yml | 5 +-
...indows_lolbas_executed_as_renamed_file.yml | 5 +-
..._lolbas_executed_outside_expected_path.yml | 5 +-
...il_protocol_in_non_common_process_path.yml | 5 +-
...masquerading_explorer_as_child_process.yml | 5 +-
.../windows_mimikatz_binary_execution.yml | 2 +-
...ws_modify_registry_valleyrat_c2_config.yml | 2 +-
...odify_registry_valleyrat_pwn_reg_entry.yml | 2 +-
...tem_firewall_with_notable_process_path.yml | 5 +-
..._mof_event_triggered_execution_via_wmi.yml | 2 +-
...change_management_mailbox_cmdlet_usage.yml | 5 +-
.../windows_msiexec_dllregisterserver.yml | 2 +-
..._msiexec_hidewindow_rundll32_execution.yml | 5 +-
.../windows_msiexec_remote_download.yml | 2 +-
...indows_msiexec_spawn_discovery_command.yml | 2 +-
.../endpoint/windows_msiexec_spawn_windbg.yml | 2 +-
...s_msiexec_unregister_dllregisterserver.yml | 2 +-
...dows_multi_hop_proxy_tor_website_query.yml | 5 +-
...rs_failed_to_authenticate_wth_kerberos.yml | 5 +-
...rs_fail_to_authenticate_using_kerberos.yml | 5 +-
...sers_failed_to_authenticate_using_ntlm.yml | 5 +-
...tiple_ntlm_null_domain_authentications.yml | 5 +-
...o_authenticate_wth_explicitcredentials.yml | 5 +-
...d_to_authenticate_from_host_using_ntlm.yml | 5 +-
...rs_failed_to_authenticate_from_process.yml | 5 +-
..._failed_to_authenticate_using_kerberos.yml | 5 +-
...otely_failed_to_authenticate_from_host.yml | 5 +-
...ity_descriptor_set_on_eventlog_channel.yml | 19 +--
...new_default_file_association_value_set.yml | 42 +++--
.../windows_ngrok_reverse_proxy_usage.yml | 2 +-
.../endpoint/windows_nirsoft_advancedrun.yml | 2 +-
...ws_njrat_fileless_storage_via_registry.yml | 5 +-
...ows_non_system_account_targeting_lsass.yml | 5 +-
.../endpoint/windows_odbcconf_load_dll.yml | 2 +-
.../windows_odbcconf_load_response_file.yml | 2 +-
...office_product_dropped_cab_or_inf_file.yml | 33 +++-
...s_office_product_dropped_uncommon_file.yml | 34 ++++-
...ws_office_product_loaded_mshtml_module.yml | 38 +++--
...ws_office_product_loading_taskschd_dll.yml | 40 +++--
...indows_office_product_loading_vbe7_dll.yml | 40 +++--
...uct_spawned_child_process_for_download.yml | 42 ++++-
...windows_office_product_spawned_control.yml | 15 +-
.../windows_office_product_spawned_msdt.yml | 15 +-
...e_product_spawned_rundll32_with_no_dll.yml | 15 +-
...ffice_product_spawned_uncommon_process.yml | 50 ++++--
.../windows_papercut_ng_spawn_shell.yml | 2 +-
...dows_parent_pid_spoofing_with_explorer.yml | 5 +-
...ws_phishing_pdf_file_executes_url_link.yml | 5 +-
...dows_phishing_recent_iso_exec_registry.yml | 5 +-
.../windows_possible_credential_dumping.yml | 5 +-
...ll_add_module_to_global_assembly_cache.yml | 5 +-
...dows_powershell_cryptography_namespace.yml | 5 +-
...indows_powershell_disable_http_logging.yml | 8 +-
.../windows_powershell_export_certificate.yml | 5 +-
...ndows_powershell_export_pfxcertificate.yml | 5 +-
...l_iis_components_webglobalmodule_usage.yml | 5 +-
...ows_powershell_import_applocker_policy.yml | 6 +-
...ndows_powershell_logoff_user_via_quser.yml | 42 +++--
.../windows_powershell_remotesigned_file.yml | 5 +-
.../windows_powershell_scheduletask.yml | 5 +-
...dows_powershell_wmi_win32_scheduledjob.yml | 5 +-
.../windows_powersploit_gpp_discovery.yml | 5 +-
...erview_kerberos_service_ticket_request.yml | 5 +-
.../windows_powerview_spn_discovery.yml | 5 +-
.../windows_private_keys_discovery.yml | 5 +-
...scalation_suspicious_process_elevation.yml | 2 +-
..._process_executed_from_removable_media.yml | 81 ++++++++++
.../windows_process_execution_in_temp_dir.yml | 87 +++++++++++
...windows_process_injection_into_notepad.yml | 5 +-
...s_injection_of_wermgr_to_known_browser.yml | 5 +-
...indows_process_injection_remote_thread.yml | 5 +-
...cess_injection_with_public_source_path.yml | 5 +-
...s_with_netexec_command_line_parameters.yml | 138 +++++++++--------
.../windows_protocol_tunneling_with_plink.yml | 2 +-
.../endpoint/windows_proxy_via_netsh.yml | 5 +-
.../endpoint/windows_proxy_via_registry.yml | 5 +-
...indows_raccine_scheduled_task_deletion.yml | 2 +-
.../windows_rasautou_dll_execution.yml | 5 +-
...ws_raw_access_to_disk_volume_partition.yml | 10 +-
...raw_access_to_master_boot_record_drive.yml | 10 +-
.../windows_registry_certificate_added.yml | 5 +-
...y_dotnet_etw_disabled_via_env_variable.yml | 5 +-
...modification_for_safe_mode_persistence.yml | 5 +-
.../windows_registry_payload_injection.yml | 5 +-
.../windows_regsvr32_renamed_binary.yml | 5 +-
...ows_remote_assistance_spawning_process.yml | 2 +-
.../windows_remote_create_service.yml | 5 +-
...remote_service_rdpwinst_tool_execution.yml | 5 +-
..._remote_services_allow_rdp_in_firewall.yml | 5 +-
...emote_services_allow_remote_assistance.yml | 5 +-
.../windows_remote_services_rdp_enable.yml | 5 +-
..._root_domain_linked_policies_discovery.yml | 5 +-
...s_rundll32_apply_user_settings_changes.yml | 5 +-
.../windows_rundll32_webdav_request.yml | 2 +-
...undll32_webdav_with_network_connection.yml | 2 +-
...windows_scheduled_task_created_via_xml.yml | 5 +-
...scheduled_task_with_highest_privileges.yml | 5 +-
.../windows_schtasks_create_run_as_system.yml | 5 +-
...dows_security_and_backup_services_stop.yml | 78 ++++++++++
...ws_security_support_provider_reg_query.yml | 5 +-
...ows_sensitive_group_discovery_with_net.yml | 43 +++++-
...ive_registry_hive_dump_via_commandline.yml | 46 ++++--
...tware_component_gacutil_install_to_gac.yml | 5 +-
...dows_service_create_kernel_mode_driver.yml | 7 +-
.../windows_service_create_remcomsvc.yml | 5 +-
.../windows_service_create_sliverc2.yml | 5 +-
.../windows_service_create_with_tscon.yml | 7 +-
...e_created_with_suspicious_service_path.yml | 8 +-
...ows_service_created_within_public_path.yml | 5 +-
...ws_service_creation_on_remote_endpoint.yml | 5 +-
.../windows_service_execution_remcom.yml | 2 +-
..._service_initiation_on_remote_endpoint.yml | 5 +-
.../windows_soaphound_binary_execution.yml | 12 +-
...hment_connect_to_none_ms_office_domain.yml | 5 +-
...hishing_attachment_onenote_spawn_mshta.yml | 5 +-
.../windows_sql_spawning_certutil.yml | 2 +-
...thentication_certificates___esc1_abuse.yml | 2 +-
...ion_certificates___esc1_authentication.yml | 2 +-
...ntication_certificates_certutil_backup.yml | 2 +-
...cation_certificates_export_certificate.yml | 2 +-
...ion_certificates_export_pfxcertificate.yml | 2 +-
...ct_process_with_authentication_traffic.yml | 6 +-
...s_child_process_spawned_from_webserver.yml | 5 +-
.../windows_suspicious_driver_loaded_path.yml | 75 +++++++++
.../windows_suspicious_process_file_path.yml | 121 +++++++++++++++
...execution_compiled_html_file_decompile.yml | 5 +-
...ows_system_remote_discovery_with_query.yml | 64 ++++++++
...oxy_execution_syncappvpublishingserver.yml | 2 +-
.../windows_terminating_lsass_process.yml | 5 +-
.../endpoint/windows_time_based_evasion.yml | 5 +-
...ows_time_based_evasion_via_choice_exec.yml | 5 +-
...ws_uac_bypass_suspicious_child_process.yml | 5 +-
..._bypass_suspicious_escalation_behavior.yml | 5 +-
..._dll_side_loading_in_same_process_path.yml | 8 +-
...abled_users_failed_auth_using_kerberos.yml | 5 +-
...alid_users_fail_to_auth_using_kerberos.yml | 5 +-
...nvalid_users_failed_to_auth_using_ntlm.yml | 5 +-
...s_fail_to_auth_wth_explicitcredentials.yml | 5 +-
...of_users_failed_to_auth_using_kerberos.yml | 5 +-
...rs_failed_to_authenticate_from_process.yml | 5 +-
...sers_failed_to_authenticate_using_ntlm.yml | 5 +-
...sers_remotely_failed_to_auth_from_host.yml | 5 +-
..._authentication_destinations_by_source.yml | 5 +-
...lm_authentication_destinations_by_user.yml | 5 +-
...lm_authentication_users_by_destination.yml | 5 +-
...al_ntlm_authentication_users_by_source.yml | 5 +-
...dows_usbstor_registry_key_modification.yml | 67 ++++++++
.../windows_user_deletion_via_net.yml | 2 +-
.../windows_user_disabled_via_net.yml | 2 +-
.../windows_user_discovery_via_net.yml | 23 ++-
..._execution_malicious_url_shortcut_file.yml | 5 +-
.../windows_windbg_spawning_autoit3.yml | 2 +-
...s_wpdbusenum_registry_key_modification.yml | 67 ++++++++
..._scheduled_task_created_to_spawn_shell.yml | 8 +-
...eduled_task_created_within_public_path.yml | 8 +-
.../endpoint/winhlp32_spawning_a_process.yml | 2 +-
.../winrar_spawning_shell_application.yml | 2 +-
..._permanent_event_subscription___sysmon.yml | 5 +-
detections/endpoint/wmic_group_discovery.yml | 5 +-
...wmic_noninteractive_app_uninstallation.yml | 5 +-
.../endpoint/wmic_xsl_execution_via_url.yml | 2 +-
...pt_or_cscript_suspicious_child_process.yml | 7 +-
...rovhost_lolbas_execution_process_spawn.yml | 5 +-
detections/endpoint/wsreset_uac_bypass.yml | 5 +-
detections/endpoint/xmrig_driver_loaded.yml | 5 +-
.../xsl_script_execution_with_wmic.yml | 2 +-
detections/network/detect_arp_poisoning.yml | 5 +-
...ct_ipv6_network_infrastructure_threats.yml | 5 +-
.../detect_large_outbound_icmp_packets.yml | 2 +-
.../network/detect_outbound_smb_traffic.yml | 13 +-
.../detect_port_security_violation.yml | 5 +-
...etect_remote_access_software_usage_dns.yml | 11 +-
...t_remote_access_software_usage_traffic.yml | 14 +-
...ct_software_download_to_network_device.yml | 5 +-
.../network/detect_traffic_mirroring.yml | 9 +-
.../dns_query_length_outliers___mltk.yml | 5 +-
...ry_length_with_high_standard_deviation.yml | 5 +-
detections/network/excessive_dns_failures.yml | 5 +-
...e_of_network_traffic_from_email_server.yml | 5 +-
.../large_volume_of_dns_any_queries.yml | 5 +-
.../network/protocol_or_port_mismatch.yml | 5 +-
.../remote_desktop_network_bruteforce.yml | 51 -------
.../remote_desktop_network_traffic.yml | 5 +-
detections/network/smb_traffic_spike.yml | 5 +-
.../network/smb_traffic_spike___mltk.yml | 14 +-
detections/network/tor_traffic.yml | 5 +-
...windows_ad_replication_service_traffic.yml | 5 +-
...ote_desktop_network_bruteforce_attempt.yml | 60 ++++++++
...etect_remote_access_software_usage_url.yml | 9 +-
...ng_application_via_apache_commons_text.yml | 9 +-
...ltiple_archive_files_http_post_traffic.yml | 5 +-
.../web/plain_http_post_exfiltrated_data.yml | 5 +-
.../web/spring4shell_payload_url_request.yml | 9 +-
detections/web/web_jsp_request_via_url.yml | 9 +-
...caler_adware_activities_threat_blocked.yml | 2 +-
...caler_behavior_analysis_threat_blocked.yml | 2 +-
.../web/zscaler_exploit_threat_blocked.yml | 2 +-
...scaler_malware_activity_threat_blocked.yml | 2 +-
...caler_potentially_abused_file_download.yml | 2 +-
...ivacy_risk_destinations_threat_blocked.yml | 2 +-
...caler_scam_destinations_threat_blocked.yml | 2 +-
.../zscaler_virus_download_threat_blocked.yml | 2 +-
1033 files changed, 4864 insertions(+), 3734 deletions(-)
create mode 100644 detections/cloud/o365_email_transport_rule_changed.yml
create mode 100644 detections/cloud/o365_multiple_os_vendors_authenticating_from_user.yml
create mode 100644 detections/cloud/o365_sharepoint_suspicious_search_behavior.yml
rename detections/{endpoint => deprecated}/known_services_killed_by_ransomware.yml (93%)
create mode 100644 detections/deprecated/remote_desktop_network_bruteforce.yml
rename detections/{endpoint => deprecated}/suspicious_driver_loaded_path.yml (93%)
rename detections/{endpoint => deprecated}/suspicious_process_file_path.yml (95%)
create mode 100644 detections/endpoint/windows_process_executed_from_removable_media.yml
create mode 100644 detections/endpoint/windows_process_execution_in_temp_dir.yml
create mode 100644 detections/endpoint/windows_security_and_backup_services_stop.yml
create mode 100644 detections/endpoint/windows_suspicious_driver_loaded_path.yml
create mode 100644 detections/endpoint/windows_suspicious_process_file_path.yml
create mode 100644 detections/endpoint/windows_system_remote_discovery_with_query.yml
create mode 100644 detections/endpoint/windows_usbstor_registry_key_modification.yml
create mode 100644 detections/endpoint/windows_wpdbusenum_registry_key_modification.yml
delete mode 100644 detections/network/remote_desktop_network_bruteforce.yml
create mode 100644 detections/network/windows_remote_desktop_network_bruteforce_attempt.yml
diff --git a/detections/application/detect_distributed_password_spray_attempts.yml b/detections/application/detect_distributed_password_spray_attempts.yml
index a25a797b90..db367690c3 100644
--- a/detections/application/detect_distributed_password_spray_attempts.yml
+++ b/detections/application/detect_distributed_password_spray_attempts.yml
@@ -1,7 +1,7 @@
name: Detect Distributed Password Spray Attempts
id: b1a82fc8-8a9f-4344-9ec2-bde5c5331b57
-version: 3
-date: '2025-01-21'
+version: 4
+date: '2025-02-10'
author: Dean Luxton
status: production
type: Hunting
@@ -65,7 +65,6 @@ tags:
- 90bc2e54-6c84-47a5-9439-0a2a92b4b175
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/application/detect_password_spray_attempts.yml b/detections/application/detect_password_spray_attempts.yml
index 9089026b9d..62c51cbc0e 100644
--- a/detections/application/detect_password_spray_attempts.yml
+++ b/detections/application/detect_password_spray_attempts.yml
@@ -1,7 +1,7 @@
name: Detect Password Spray Attempts
id: 086ab581-8877-42b3-9aee-4a7ecb0923af
-version: 5
-date: '2025-01-21'
+version: 6
+date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -83,7 +83,6 @@ tags:
- 90bc2e54-6c84-47a5-9439-0a2a92b4b175
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/application/email_files_written_outside_of_the_outlook_directory.yml b/detections/application/email_files_written_outside_of_the_outlook_directory.yml
index b60204ed4f..0530cd1aa9 100644
--- a/detections/application/email_files_written_outside_of_the_outlook_directory.yml
+++ b/detections/application/email_files_written_outside_of_the_outlook_directory.yml
@@ -1,7 +1,7 @@
name: Email files written outside of the Outlook directory
id: 8d52cf03-ba25-4101-aa78-07994aed4f74
-version: 6
-date: '2025-01-21'
+version: 7
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: experimental
type: TTP
@@ -44,7 +44,6 @@ tags:
- Collection and Staging
asset_type: Endpoint
mitre_attack_id:
- - T1114
- T1114.001
product:
- Splunk Enterprise
diff --git a/detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml b/detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml
index 7a4e2f7bd3..ccbe394899 100644
--- a/detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml
+++ b/detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml
@@ -1,7 +1,7 @@
name: Email servers sending high volume traffic to hosts
id: 7f5fb3e1-4209-4914-90db-0ec21b556378
-version: 5
-date: '2025-01-21'
+version: 6
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: experimental
type: Anomaly
@@ -51,7 +51,6 @@ tags:
- HAFNIUM Group
asset_type: Endpoint
mitre_attack_id:
- - T1114
- T1114.002
product:
- Splunk Enterprise
diff --git a/detections/application/okta_authentication_failed_during_mfa_challenge.yml b/detections/application/okta_authentication_failed_during_mfa_challenge.yml
index 48faea347a..67546ddaf4 100644
--- a/detections/application/okta_authentication_failed_during_mfa_challenge.yml
+++ b/detections/application/okta_authentication_failed_during_mfa_challenge.yml
@@ -1,7 +1,7 @@
name: Okta Authentication Failed During MFA Challenge
id: e2b99e7d-d956-411a-a120-2b14adfdde93
-version: 4
-date: '2025-01-21'
+version: 5
+date: '2025-02-10'
author: Bhavin Patel, Splunk
data_source:
- Okta
@@ -59,10 +59,8 @@ tags:
- Okta Account Takeover
asset_type: Okta Tenant
mitre_attack_id:
- - T1586
- - T1586.003
- - T1078
- T1078.004
+ - T1586.003
- T1621
product:
- Splunk Enterprise
diff --git a/detections/application/okta_multi_factor_authentication_disabled.yml b/detections/application/okta_multi_factor_authentication_disabled.yml
index fbef02e3e1..96cda4186d 100644
--- a/detections/application/okta_multi_factor_authentication_disabled.yml
+++ b/detections/application/okta_multi_factor_authentication_disabled.yml
@@ -1,7 +1,7 @@
name: Okta Multi-Factor Authentication Disabled
id: 7c0348ce-bdf9-45f6-8a57-c18b5976f00a
-version: 5
-date: '2025-01-21'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source:
- Okta
@@ -57,7 +57,6 @@ tags:
- Okta Account Takeover
asset_type: Okta Tenant
mitre_attack_id:
- - T1556
- T1556.006
product:
- Splunk Enterprise
diff --git a/detections/application/okta_new_api_token_created.yml b/detections/application/okta_new_api_token_created.yml
index 7a8e0e78e3..27e4bf7c50 100644
--- a/detections/application/okta_new_api_token_created.yml
+++ b/detections/application/okta_new_api_token_created.yml
@@ -1,7 +1,7 @@
name: Okta New API Token Created
id: c3d22720-35d3-4da4-bd0a-740d37192bd4
-version: 6
-date: '2025-01-21'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -54,7 +54,6 @@ tags:
- Okta Account Takeover
asset_type: Okta Tenant
mitre_attack_id:
- - T1078
- T1078.001
product:
- Splunk Enterprise
diff --git a/detections/application/okta_new_device_enrolled_on_account.yml b/detections/application/okta_new_device_enrolled_on_account.yml
index a95db4b8ce..0b28586594 100644
--- a/detections/application/okta_new_device_enrolled_on_account.yml
+++ b/detections/application/okta_new_device_enrolled_on_account.yml
@@ -1,7 +1,7 @@
name: Okta New Device Enrolled on Account
id: bb27cbce-d4de-432c-932f-2e206e9130fb
-version: 6
-date: '2025-01-21'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -54,7 +54,6 @@ tags:
- Okta Account Takeover
asset_type: Okta Tenant
mitre_attack_id:
- - T1098
- T1098.005
product:
- Splunk Enterprise
diff --git a/detections/application/okta_phishing_detection_with_fastpass_origin_check.yml b/detections/application/okta_phishing_detection_with_fastpass_origin_check.yml
index 8171b96c75..f2fe0f1b3c 100644
--- a/detections/application/okta_phishing_detection_with_fastpass_origin_check.yml
+++ b/detections/application/okta_phishing_detection_with_fastpass_origin_check.yml
@@ -1,7 +1,7 @@
name: Okta Phishing Detection with FastPass Origin Check
id: f4ca0057-cbf3-44f8-82ea-4e330ee901d3
-version: 4
-date: '2025-01-21'
+version: 5
+date: '2025-02-10'
author: Okta, Inc, Michael Haag, Splunk
type: TTP
status: experimental
@@ -38,7 +38,6 @@ tags:
- Okta Account Takeover
asset_type: Infrastructure
mitre_attack_id:
- - T1078
- T1078.001
- T1556
product:
diff --git a/detections/application/okta_successful_single_factor_authentication.yml b/detections/application/okta_successful_single_factor_authentication.yml
index 1c0f03def8..a5a4a3bf14 100644
--- a/detections/application/okta_successful_single_factor_authentication.yml
+++ b/detections/application/okta_successful_single_factor_authentication.yml
@@ -1,7 +1,7 @@
name: Okta Successful Single Factor Authentication
id: 98f6ad4f-4325-4096-9d69-45dc8e638e82
-version: 4
-date: '2025-01-21'
+version: 5
+date: '2025-02-10'
author: Bhavin Patel, Splunk
data_source:
- Okta
@@ -55,10 +55,8 @@ tags:
- Okta Account Takeover
asset_type: Okta Tenant
mitre_attack_id:
- - T1586
- - T1586.003
- - T1078
- T1078.004
+ - T1586.003
- T1621
product:
- Splunk Enterprise
diff --git a/detections/application/okta_suspicious_activity_reported.yml b/detections/application/okta_suspicious_activity_reported.yml
index 363f2487b6..1f2662268e 100644
--- a/detections/application/okta_suspicious_activity_reported.yml
+++ b/detections/application/okta_suspicious_activity_reported.yml
@@ -1,7 +1,7 @@
name: Okta Suspicious Activity Reported
id: bfc840f5-c9c6-454c-aa13-b46fd0bf1e79
-version: 5
-date: '2025-01-21'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -55,7 +55,6 @@ tags:
- Okta Account Takeover
asset_type: Okta Tenant
mitre_attack_id:
- - T1078
- T1078.001
product:
- Splunk Enterprise
diff --git a/detections/application/okta_threatinsight_threat_detected.yml b/detections/application/okta_threatinsight_threat_detected.yml
index 04d5e1e5fe..264bf76c91 100644
--- a/detections/application/okta_threatinsight_threat_detected.yml
+++ b/detections/application/okta_threatinsight_threat_detected.yml
@@ -1,7 +1,7 @@
name: Okta ThreatInsight Threat Detected
id: 140504ae-5fe2-4d65-b2bc-a211813fbca6
-version: 5
-date: '2025-01-21'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Mauricio Velazco, Splunk
status: production
type: Anomaly
@@ -56,7 +56,6 @@ tags:
- Okta Account Takeover
asset_type: Infrastructure
mitre_attack_id:
- - T1078
- T1078.004
product:
- Splunk Enterprise
diff --git a/detections/application/pingid_mismatch_auth_source_and_verification_response.yml b/detections/application/pingid_mismatch_auth_source_and_verification_response.yml
index 021ec93c2e..17e059d927 100644
--- a/detections/application/pingid_mismatch_auth_source_and_verification_response.yml
+++ b/detections/application/pingid_mismatch_auth_source_and_verification_response.yml
@@ -1,6 +1,6 @@
name: PingID Mismatch Auth Source and Verification Response
id: 15b0694e-caa2-4009-8d83-a1f98b86d086
-version: 4
+version: 5
date: '2025-01-21'
author: Steven Dick
status: production
diff --git a/detections/application/suspicious_email_attachment_extensions.yml b/detections/application/suspicious_email_attachment_extensions.yml
index 3a44f76bfa..f557b97bca 100644
--- a/detections/application/suspicious_email_attachment_extensions.yml
+++ b/detections/application/suspicious_email_attachment_extensions.yml
@@ -1,7 +1,7 @@
name: Suspicious Email Attachment Extensions
id: 473bd65f-06ca-4dfe-a2b8-ba04ab4a0084
-version: 6
-date: '2025-01-21'
+version: 7
+date: '2025-02-10'
author: David Dorsey, Splunk
status: experimental
type: Anomaly
@@ -48,7 +48,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1566.001
- - T1566
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/application/windows_ad_dangerous_deny_acl_modification.yml b/detections/application/windows_ad_dangerous_deny_acl_modification.yml
index 40076288f5..29ab4c180d 100644
--- a/detections/application/windows_ad_dangerous_deny_acl_modification.yml
+++ b/detections/application/windows_ad_dangerous_deny_acl_modification.yml
@@ -1,7 +1,7 @@
name: Windows AD Dangerous Deny ACL Modification
id: 8e897153-2ebd-4cb2-85d3-09ad57db2fb7
-version: 3
-date: '2025-01-21'
+version: 4
+date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -76,9 +76,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- - T1484
- - T1222
- T1222.001
+ - T1484
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/application/windows_ad_dangerous_group_acl_modification.yml b/detections/application/windows_ad_dangerous_group_acl_modification.yml
index c6bffd639e..047d9274eb 100644
--- a/detections/application/windows_ad_dangerous_group_acl_modification.yml
+++ b/detections/application/windows_ad_dangerous_group_acl_modification.yml
@@ -1,7 +1,7 @@
name: Windows AD Dangerous Group ACL Modification
id: 59b0fc85-7a0d-4585-97ec-06a382801990
-version: 3
-date: '2025-01-21'
+version: 4
+date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -85,9 +85,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- - T1484
- - T1222
- T1222.001
+ - T1484
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/application/windows_ad_dangerous_user_acl_modification.yml b/detections/application/windows_ad_dangerous_user_acl_modification.yml
index f298e0616d..7163e0aa3a 100644
--- a/detections/application/windows_ad_dangerous_user_acl_modification.yml
+++ b/detections/application/windows_ad_dangerous_user_acl_modification.yml
@@ -1,7 +1,7 @@
name: Windows AD Dangerous User ACL Modification
id: ec5b6790-595a-4fb8-ad43-56e5b55a9617
-version: 3
-date: '2025-01-21'
+version: 4
+date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -82,9 +82,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- - T1484
- - T1222
- T1222.001
+ - T1484
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/application/windows_ad_domain_root_acl_deletion.yml b/detections/application/windows_ad_domain_root_acl_deletion.yml
index c4bfa9c916..8ca60c13b1 100644
--- a/detections/application/windows_ad_domain_root_acl_deletion.yml
+++ b/detections/application/windows_ad_domain_root_acl_deletion.yml
@@ -1,7 +1,7 @@
name: Windows AD Domain Root ACL Deletion
id: 3cb56e57-5642-4638-907f-8dfde9afb889
-version: 3
-date: '2025-01-21'
+version: 4
+date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -75,9 +75,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- - T1484
- - T1222
- T1222.001
+ - T1484
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/application/windows_ad_domain_root_acl_modification.yml b/detections/application/windows_ad_domain_root_acl_modification.yml
index 56d121c7d2..4b30ed7b3a 100644
--- a/detections/application/windows_ad_domain_root_acl_modification.yml
+++ b/detections/application/windows_ad_domain_root_acl_modification.yml
@@ -1,7 +1,7 @@
name: Windows AD Domain Root ACL Modification
id: 4981e2db-1372-440d-816e-3e7e2ed74433
-version: 3
-date: '2025-01-21'
+version: 4
+date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -75,9 +75,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- - T1484
- - T1222
- T1222.001
+ - T1484
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/application/windows_ad_gpo_new_cse_addition.yml b/detections/application/windows_ad_gpo_new_cse_addition.yml
index 4f0f4fce8f..194bf251ab 100644
--- a/detections/application/windows_ad_gpo_new_cse_addition.yml
+++ b/detections/application/windows_ad_gpo_new_cse_addition.yml
@@ -1,7 +1,7 @@
name: Windows AD GPO New CSE Addition
id: 700c11d1-da09-47b2-81aa-358c143c7986
-version: 3
-date: '2025-01-21'
+version: 4
+date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -64,10 +64,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- - T1484
- - T1484.001
- - T1222
- T1222.001
+ - T1484.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/application/windows_ad_hidden_ou_creation.yml b/detections/application/windows_ad_hidden_ou_creation.yml
index 2885f00678..358a32bc0f 100644
--- a/detections/application/windows_ad_hidden_ou_creation.yml
+++ b/detections/application/windows_ad_hidden_ou_creation.yml
@@ -1,7 +1,7 @@
name: Windows AD Hidden OU Creation
id: 66b6ad5e-339a-40af-b721-dacefc7bdb75
-version: 3
-date: '2025-01-21'
+version: 4
+date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -74,9 +74,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- - T1484
- - T1222
- T1222.001
+ - T1484
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/application/windows_ad_object_owner_updated.yml b/detections/application/windows_ad_object_owner_updated.yml
index fb234c3f1a..51abfc6ca8 100644
--- a/detections/application/windows_ad_object_owner_updated.yml
+++ b/detections/application/windows_ad_object_owner_updated.yml
@@ -1,7 +1,7 @@
name: Windows AD Object Owner Updated
id: 4af01f6b-d8d4-4f96-8635-758a01557130
-version: 4
-date: '2025-01-21'
+version: 5
+date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -66,9 +66,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- - T1484
- - T1222
- T1222.001
+ - T1484
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/application/windows_ad_suspicious_attribute_modification.yml b/detections/application/windows_ad_suspicious_attribute_modification.yml
index df005bfae6..da62dd68ba 100644
--- a/detections/application/windows_ad_suspicious_attribute_modification.yml
+++ b/detections/application/windows_ad_suspicious_attribute_modification.yml
@@ -1,7 +1,7 @@
name: Windows AD Suspicious Attribute Modification
id: 5682052e-ce55-4f9f-8d28-59191420b7e0
-version: 3
-date: '2025-01-21'
+version: 5
+date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -62,9 +62,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- - T1550
- - T1222
- T1222.001
+ - T1550
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/application/windows_ad_suspicious_gpo_modification.yml b/detections/application/windows_ad_suspicious_gpo_modification.yml
index 976ed7ea7d..c70acfb5ed 100644
--- a/detections/application/windows_ad_suspicious_gpo_modification.yml
+++ b/detections/application/windows_ad_suspicious_gpo_modification.yml
@@ -1,7 +1,7 @@
name: Windows AD Suspicious GPO Modification
id: 0a2afc18-a3b5-4452-b60a-2e774214f9bf
-version: 3
-date: '2025-01-21'
+version: 5
+date: '2025-02-10'
author: Dean Luxton
status: experimental
type: TTP
@@ -70,10 +70,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- - T1484
- - T1484.001
- - T1222
- T1222.001
+ - T1484.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml
index 969f05f721..6581d23fca 100644
--- a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml
+++ b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml
@@ -1,7 +1,7 @@
name: Abnormally High Number Of Cloud Infrastructure API Calls
id: 0840ddf1-8c89-46ff-b730-c8d6722478c0
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: David Dorsey, Splunk
status: experimental
type: Anomaly
@@ -46,7 +46,6 @@ tags:
asset_type: AWS Instance
mitre_attack_id:
- T1078.004
- - T1078
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml b/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml
index 8175e9709c..e9bcb75db0 100644
--- a/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml
+++ b/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml
@@ -1,7 +1,7 @@
name: Abnormally High Number Of Cloud Instances Destroyed
id: ef629fc9-1583-4590-b62a-f2247fbf7bbf
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: David Dorsey, Splunk
status: experimental
type: Anomaly
@@ -48,7 +48,6 @@ tags:
asset_type: Cloud Instance
mitre_attack_id:
- T1078.004
- - T1078
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml b/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml
index e88f2c8f16..9edf6d5b9a 100644
--- a/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml
+++ b/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml
@@ -1,7 +1,7 @@
name: Abnormally High Number Of Cloud Instances Launched
id: f2361e9f-3928-496c-a556-120cd4223a65
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: David Dorsey, Splunk
status: experimental
type: Anomaly
@@ -48,7 +48,6 @@ tags:
asset_type: Cloud Instance
mitre_attack_id:
- T1078.004
- - T1078
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml
index 2360113251..761e9de23d 100644
--- a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml
+++ b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml
@@ -1,7 +1,7 @@
name: Abnormally High Number Of Cloud Security Group API Calls
id: d4dfb7f3-7a37-498a-b5df-f19334e871af
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: David Dorsey, Splunk
status: experimental
type: Anomaly
@@ -46,7 +46,6 @@ tags:
asset_type: AWS Instance
mitre_attack_id:
- T1078.004
- - T1078
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/asl_aws_create_access_key.yml b/detections/cloud/asl_aws_create_access_key.yml
index eeb433eaa8..f73e4719af 100644
--- a/detections/cloud/asl_aws_create_access_key.yml
+++ b/detections/cloud/asl_aws_create_access_key.yml
@@ -1,16 +1,33 @@
name: ASL AWS Create Access Key
id: 81a9f2fe-1697-473c-af1d-086b0d8b63c8
-version: 1
-date: '2024-12-12'
+version: 2
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Hunting
-description: The following analytic identifies the creation of AWS IAM access keys by a user for another user, which can indicate privilege escalation. It leverages AWS CloudTrail logs to detect instances where the user creating the access key is different from the user for whom the key is created. This activity is significant because unauthorized access key creation can allow attackers to establish persistence or exfiltrate data via AWS APIs. If confirmed malicious, this could lead to unauthorized access to AWS services, data exfiltration, and long-term persistence in the environment.
-data_source:
+description: The following analytic identifies the creation of AWS IAM access keys
+ by a user for another user, which can indicate privilege escalation. It leverages
+ AWS CloudTrail logs to detect instances where the user creating the access key is
+ different from the user for whom the key is created. This activity is significant
+ because unauthorized access key creation can allow attackers to establish persistence
+ or exfiltrate data via AWS APIs. If confirmed malicious, this could lead to unauthorized
+ access to AWS services, data exfiltration, and long-term persistence in the environment.
+data_source:
- ASL AWS CloudTrail
-search: '`amazon_security_lake` api.operation=CreateAccessKey | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`asl_aws_create_access_key_filter`'
-how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
-known_false_positives: While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user.
+search: '`amazon_security_lake` api.operation=CreateAccessKey | fillnull | stats count
+ min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
+ http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as
+ user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
+ as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
+ |`asl_aws_create_access_key_filter`'
+how_to_implement: The detection is based on Amazon Security Lake events from Amazon
+ Web Services (AWS), which is a centralized data lake that provides security-related
+ data from AWS services. To use this detection, you must ingest CloudTrail logs from
+ Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
+ using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
+ or the Federated Analytics App.
+known_false_positives: While this search has no known false positives, it is possible
+ that an AWS admin has legitimately created keys for another user.
references:
- https://bishopfox.com/blog/privilege-escalation-in-aws
- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/
@@ -20,7 +37,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1136.003
- - T1136
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -29,6 +45,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/asl_ocsf_cloudtrail.json
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
diff --git a/detections/cloud/asl_aws_create_policy_version_to_allow_all_resources.yml b/detections/cloud/asl_aws_create_policy_version_to_allow_all_resources.yml
index d4620bd070..d7f2b0d689 100644
--- a/detections/cloud/asl_aws_create_policy_version_to_allow_all_resources.yml
+++ b/detections/cloud/asl_aws_create_policy_version_to_allow_all_resources.yml
@@ -1,16 +1,36 @@
name: ASL AWS Create Policy Version to allow all resources
id: 22cc7a62-3884-48c4-82da-592b8199b72f
-version: 1
-date: '2024-12-12'
+version: 2
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
-description: The following analytic identifies the creation of a new AWS IAM policy version that allows access to all resources. It detects this activity by analyzing AWS CloudTrail logs for the CreatePolicyVersion event with a policy document that grants broad permissions. This behavior is significant because it violates the principle of least privilege, potentially exposing the environment to misuse or abuse. If confirmed malicious, an attacker could gain extensive access to AWS resources, leading to unauthorized actions, data exfiltration, or further compromise of the AWS environment.
-data_source:
+description: The following analytic identifies the creation of a new AWS IAM policy
+ version that allows access to all resources. It detects this activity by analyzing
+ AWS CloudTrail logs for the CreatePolicyVersion event with a policy document that
+ grants broad permissions. This behavior is significant because it violates the principle
+ of least privilege, potentially exposing the environment to misuse or abuse. If
+ confirmed malicious, an attacker could gain extensive access to AWS resources, leading
+ to unauthorized actions, data exfiltration, or further compromise of the AWS environment.
+data_source:
- ASL AWS CloudTrail
-search: '`amazon_security_lake` api.operation=CreatePolicy | spath input=api.request.data | spath input=policyDocument | regex Statement{}.Action="\*" | regex Statement{}.Resource="\*" | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region api.request.data | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|`asl_aws_create_policy_version_to_allow_all_resources_filter`'
-how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
-known_false_positives: While this search has no known false positives, it is possible that an AWS admin has legitimately created a policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources and you must verify this activity.
+search: '`amazon_security_lake` api.operation=CreatePolicy | spath input=api.request.data
+ | spath input=policyDocument | regex Statement{}.Action="\*" | regex Statement{}.Resource="\*"
+ | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation
+ actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region
+ api.request.data | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region
+ as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`|`asl_aws_create_policy_version_to_allow_all_resources_filter`'
+how_to_implement: The detection is based on Amazon Security Lake events from Amazon
+ Web Services (AWS), which is a centralized data lake that provides security-related
+ data from AWS services. To use this detection, you must ingest CloudTrail logs from
+ Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
+ using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
+ or the Federated Analytics App.
+known_false_positives: While this search has no known false positives, it is possible
+ that an AWS admin has legitimately created a policy to allow a user to access all
+ resources. That said, AWS strongly advises against granting full control to all
+ AWS resources and you must verify this activity.
references:
- https://bishopfox.com/blog/privilege-escalation-in-aws
- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/
@@ -20,11 +40,17 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
- message: User $user$ created a policy version that allows them to access any resource in their account
+ message: User $user$ created a policy version that allows them to access any resource
+ in their account
risk_objects:
- field: user
type: user
@@ -36,7 +62,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1078.004
- - T1078
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -45,6 +70,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/asl_ocsf_cloudtrail.json
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
diff --git a/detections/cloud/asl_aws_credential_access_getpassworddata.yml b/detections/cloud/asl_aws_credential_access_getpassworddata.yml
index 4c112af04c..808dfd47e7 100644
--- a/detections/cloud/asl_aws_credential_access_getpassworddata.yml
+++ b/detections/cloud/asl_aws_credential_access_getpassworddata.yml
@@ -1,16 +1,34 @@
name: ASL AWS Credential Access GetPasswordData
id: a79b607a-50cc-4704-bb9d-eff280cb78c2
-version: 1
-date: '2024-12-12'
+version: 2
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
-description: The following analytic identifiesGetPasswordData API calls in your AWS account. It leverages CloudTrail logs from Amazon Security Lake to detect this activity by counting the distinct instance IDs accessed. This behavior is significant as it may indicate an attempt to retrieve encrypted administrator passwords for running Windows instances, which is a critical security concern. If confirmed malicious, attackers could gain unauthorized access to administrative credentials, potentially leading to full control over the affected instances and further compromise of the AWS environment.
-data_source:
+description: The following analytic identifiesGetPasswordData API calls in your AWS
+ account. It leverages CloudTrail logs from Amazon Security Lake to detect this
+ activity by counting the distinct instance IDs accessed. This behavior is significant
+ as it may indicate an attempt to retrieve encrypted administrator passwords for
+ running Windows instances, which is a critical security concern. If confirmed malicious,
+ attackers could gain unauthorized access to administrative credentials, potentially
+ leading to full control over the affected instances and further compromise of the
+ AWS environment.
+data_source:
- ASL AWS CloudTrail
-search: '`amazon_security_lake` api.operation=GetPasswordData | spath input=api.request.data | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region instanceId | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`asl_aws_credential_access_getpassworddata_filter`'
-how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
-known_false_positives: Administrator tooling or automated scripts may make these calls but it is highly unlikely to make several calls in a short period of time.
+search: '`amazon_security_lake` api.operation=GetPasswordData | spath input=api.request.data
+ | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation
+ actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region
+ instanceId | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region
+ as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)` |`asl_aws_credential_access_getpassworddata_filter`'
+how_to_implement: The detection is based on Amazon Security Lake events from Amazon
+ Web Services (AWS), which is a centralized data lake that provides security-related
+ data from AWS services. To use this detection, you must ingest CloudTrail logs from
+ Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
+ using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
+ or the Federated Analytics App.
+known_false_positives: Administrator tooling or automated scripts may make these calls
+ but it is highly unlikely to make several calls in a short period of time.
references:
- https://attack.mitre.org/techniques/T1552/
- https://stratus-red-team.cloud/attack-techniques/AWS/aws.credential-access.ec2-get-password-data/
@@ -20,7 +38,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -37,10 +60,8 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- - T1586
- - T1586.003
- - T1110
- T1110.001
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -49,6 +70,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552/aws_getpassworddata/asl_ocsf_cloudtrail.json
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552/aws_getpassworddata/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
diff --git a/detections/cloud/asl_aws_credential_access_rds_password_reset.yml b/detections/cloud/asl_aws_credential_access_rds_password_reset.yml
index 300892fee9..c7248c18e7 100644
--- a/detections/cloud/asl_aws_credential_access_rds_password_reset.yml
+++ b/detections/cloud/asl_aws_credential_access_rds_password_reset.yml
@@ -1,15 +1,34 @@
name: ASL AWS Credential Access RDS Password reset
id: d15e9bd9-ef64-4d84-bc04-f62955a9fee8
-version: 1
-date: '2024-12-12'
+version: 2
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
-description: The following analytic detects the resetting of the master user password for an Amazon RDS DB instance. It leverages AWS CloudTrail logs from Amazon Security Lake to identify events where the `ModifyDBInstance` API call includes a new `masterUserPassword` parameter. This activity is significant because unauthorized password resets can grant attackers access to sensitive data stored in production databases, such as credit card information, PII, and healthcare data. If confirmed malicious, this could lead to data breaches, regulatory non-compliance, and significant reputational damage. Immediate investigation is required to determine the legitimacy of the password reset.
-data_source:
+description: The following analytic detects the resetting of the master user password
+ for an Amazon RDS DB instance. It leverages AWS CloudTrail logs from Amazon Security
+ Lake to identify events where the `ModifyDBInstance` API call includes a new `masterUserPassword`
+ parameter. This activity is significant because unauthorized password resets can
+ grant attackers access to sensitive data stored in production databases, such as
+ credit card information, PII, and healthcare data. If confirmed malicious, this
+ could lead to data breaches, regulatory non-compliance, and significant reputational
+ damage. Immediate investigation is required to determine the legitimacy of the password
+ reset.
+data_source:
- ASL AWS CloudTrail
-search: '`amazon_security_lake` api.operation=ModifyDBInstance OR api.operation=ModifyDBCluster | spath input=api.request.data | search masterUserPassword=* | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region api.request.data | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`asl_aws_credential_access_rds_password_reset_filter`'
-how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
+search: '`amazon_security_lake` api.operation=ModifyDBInstance OR api.operation=ModifyDBCluster
+ | spath input=api.request.data | search masterUserPassword=* | fillnull | stats
+ count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid
+ actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region api.request.data
+ | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region,
+ http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
+ |`asl_aws_credential_access_rds_password_reset_filter`'
+how_to_implement: The detection is based on Amazon Security Lake events from Amazon
+ Web Services (AWS), which is a centralized data lake that provides security-related
+ data from AWS services. To use this detection, you must ingest CloudTrail logs from
+ Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
+ using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
+ or the Federated Analytics App.
known_false_positives: Users may genuinely reset the RDS password.
references:
- https://aws.amazon.com/premiumsupport/knowledge-center/reset-master-user-password-rds
@@ -19,7 +38,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -36,9 +60,8 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- - T1586
- - T1586.003
- T1110
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -47,6 +70,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.002/aws_rds_password_reset/asl_ocsf_cloudtrail.json
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.002/aws_rds_password_reset/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
diff --git a/detections/cloud/asl_aws_defense_evasion_delete_cloudtrail.yml b/detections/cloud/asl_aws_defense_evasion_delete_cloudtrail.yml
index bc99f507d0..a04efd1649 100644
--- a/detections/cloud/asl_aws_defense_evasion_delete_cloudtrail.yml
+++ b/detections/cloud/asl_aws_defense_evasion_delete_cloudtrail.yml
@@ -1,16 +1,33 @@
name: ASL AWS Defense Evasion Delete Cloudtrail
id: 1f0b47e5-0134-43eb-851c-e3258638945e
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
-description: The following analytic detects AWS `DeleteTrail` events within CloudTrail logs. It leverages Amazon Security Lake logs parsed in the Open Cybersecurity Schema Framework (OCSF) format to identify when a CloudTrail is deleted. This activity is significant because adversaries may delete CloudTrail logs to evade detection and operate with stealth. If confirmed malicious, this action could allow attackers to cover their tracks, making it difficult to trace their activities and investigate other potential compromises within the AWS environment.
-data_source:
+description: The following analytic detects AWS `DeleteTrail` events within CloudTrail
+ logs. It leverages Amazon Security Lake logs parsed in the Open Cybersecurity Schema
+ Framework (OCSF) format to identify when a CloudTrail is deleted. This activity
+ is significant because adversaries may delete CloudTrail logs to evade detection
+ and operate with stealth. If confirmed malicious, this action could allow attackers
+ to cover their tracks, making it difficult to trace their activities and investigate
+ other potential compromises within the AWS environment.
+data_source:
- ASL AWS CloudTrail
-search: '`amazon_security_lake` api.operation=DeleteTrail | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `asl_aws_defense_evasion_delete_cloudtrail_filter`'
-how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
-known_false_positives: While this search has no known false positives, it is possible that an AWS admin has stopped cloudTrail logging. Please investigate this activity.
+search: '`amazon_security_lake` api.operation=DeleteTrail | fillnull | stats count
+ min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
+ http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as
+ user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
+ as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
+ `asl_aws_defense_evasion_delete_cloudtrail_filter`'
+how_to_implement: The detection is based on Amazon Security Lake events from Amazon
+ Web Services (AWS), which is a centralized data lake that provides security-related
+ data from AWS services. To use this detection, you must ingest CloudTrail logs from
+ Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
+ using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
+ or the Federated Analytics App.
+known_false_positives: While this search has no known false positives, it is possible
+ that an AWS admin has stopped cloudTrail logging. Please investigate this activity.
references:
- https://attack.mitre.org/techniques/T1562/008/
drilldown_searches:
@@ -42,7 +59,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -51,6 +67,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail.json
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
diff --git a/detections/cloud/asl_aws_defense_evasion_delete_cloudwatch_log_group.yml b/detections/cloud/asl_aws_defense_evasion_delete_cloudwatch_log_group.yml
index 7a1806f3c9..cccf09434f 100644
--- a/detections/cloud/asl_aws_defense_evasion_delete_cloudwatch_log_group.yml
+++ b/detections/cloud/asl_aws_defense_evasion_delete_cloudwatch_log_group.yml
@@ -1,16 +1,34 @@
name: ASL AWS Defense Evasion Delete CloudWatch Log Group
id: 0f701b38-a0fb-43fd-a83d-d12265f71f33
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
-description: The following analytic detects the deletion of CloudWatch log groups in AWS, identified through `DeleteLogGroup` events in CloudTrail logs. This method leverages Amazon Security Lake logs parsed in the OCSF format. The activity is significant because attackers may delete log groups to evade detection and disrupt logging capabilities, hindering incident response efforts. If confirmed malicious, this action could allow attackers to cover their tracks, making it difficult to trace their activities and potentially leading to undetected data breaches or further malicious actions within the compromised AWS environment.
-data_source:
+description: The following analytic detects the deletion of CloudWatch log groups
+ in AWS, identified through `DeleteLogGroup` events in CloudTrail logs. This method
+ leverages Amazon Security Lake logs parsed in the OCSF format. The activity is significant
+ because attackers may delete log groups to evade detection and disrupt logging capabilities,
+ hindering incident response efforts. If confirmed malicious, this action could allow
+ attackers to cover their tracks, making it difficult to trace their activities and
+ potentially leading to undetected data breaches or further malicious actions within
+ the compromised AWS environment.
+data_source:
- ASL AWS CloudTrail
-search: '`amazon_security_lake` api.operation=DeleteLogGroup | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `asl_aws_defense_evasion_delete_cloudwatch_log_group_filter`'
-how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
-known_false_positives: While this search has no known false positives, it is possible that an AWS admin has deleted CloudWatch logging. Please investigate this activity.
+search: '`amazon_security_lake` api.operation=DeleteLogGroup | fillnull | stats count
+ min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
+ http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as
+ user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
+ as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
+ `asl_aws_defense_evasion_delete_cloudwatch_log_group_filter`'
+how_to_implement: The detection is based on Amazon Security Lake events from Amazon
+ Web Services (AWS), which is a centralized data lake that provides security-related
+ data from AWS services. To use this detection, you must ingest CloudTrail logs from
+ Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
+ using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
+ or the Federated Analytics App.
+known_false_positives: While this search has no known false positives, it is possible
+ that an AWS admin has deleted CloudWatch logging. Please investigate this activity.
references:
- https://attack.mitre.org/techniques/T1562/008/
drilldown_searches:
@@ -41,7 +59,6 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- - T1562
- T1562.008
product:
- Splunk Enterprise
diff --git a/detections/cloud/asl_aws_defense_evasion_impair_security_services.yml b/detections/cloud/asl_aws_defense_evasion_impair_security_services.yml
index a6a76f9130..33368956c8 100644
--- a/detections/cloud/asl_aws_defense_evasion_impair_security_services.yml
+++ b/detections/cloud/asl_aws_defense_evasion_impair_security_services.yml
@@ -1,16 +1,35 @@
name: ASL AWS Defense Evasion Impair Security Services
id: 5029b681-0462-47b7-82e7-f7e3d37f5a2d
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Patrick Bareiss, Bhavin Patel, Gowthamaraj Rajendran, Splunk
status: production
type: Hunting
-description: The following analytic detects the deletion of critical AWS Security Services configurations, such as CloudWatch alarms, GuardDuty detectors, and Web Application Firewall rules. It leverages Amazon Security Lake logs to identify specific API calls like "DeleteLogStream" and "DeleteDetector." This activity is significant because adversaries often use these actions to disable security monitoring and evade detection. If confirmed malicious, this could allow attackers to operate undetected, leading to potential data breaches, unauthorized access, and prolonged persistence within the AWS environment.
-data_source:
+description: The following analytic detects the deletion of critical AWS Security
+ Services configurations, such as CloudWatch alarms, GuardDuty detectors, and Web
+ Application Firewall rules. It leverages Amazon Security Lake logs to identify specific
+ API calls like "DeleteLogStream" and "DeleteDetector." This activity is significant
+ because adversaries often use these actions to disable security monitoring and evade
+ detection. If confirmed malicious, this could allow attackers to operate undetected,
+ leading to potential data breaches, unauthorized access, and prolonged persistence
+ within the AWS environment.
+data_source:
- ASL AWS CloudTrail
-search: '`amazon_security_lake` api.operation IN ("DeleteLogStream","DeleteDetector","DeleteIPSet","DeleteWebACL","DeleteRule","DeleteRuleGroup","DeleteLoggingConfiguration","DeleteAlarms") | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account_uid as aws_account_id | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_impair_security_services_filter`'
-how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
-known_false_positives: While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names.
+search: '`amazon_security_lake` api.operation IN ("DeleteLogStream","DeleteDetector","DeleteIPSet","DeleteWebACL","DeleteRule","DeleteRuleGroup","DeleteLoggingConfiguration","DeleteAlarms")
+ | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation
+ actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region
+ | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region,
+ http_request.user_agent as user_agent, actor.user.account_uid as aws_account_id
+ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_impair_security_services_filter`'
+how_to_implement: The detection is based on Amazon Security Lake events from Amazon
+ Web Services (AWS), which is a centralized data lake that provides security-related
+ data from AWS services. To use this detection, you must ingest CloudTrail logs from
+ Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
+ using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
+ or the Federated Analytics App.
+known_false_positives: While this search has no known false positives, it is possible
+ that it is a legitimate admin activity. Please consider filtering out these noisy
+ events using userAgent, user_arn field names.
references:
- https://docs.aws.amazon.com/cli/latest/reference/guardduty/index.html
- https://docs.aws.amazon.com/cli/latest/reference/waf/index.html
@@ -21,7 +40,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -30,6 +48,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/aws_delete_security_services/asl_ocsf_cloudtrail.json
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/aws_delete_security_services/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
diff --git a/detections/cloud/asl_aws_defense_evasion_putbucketlifecycle.yml b/detections/cloud/asl_aws_defense_evasion_putbucketlifecycle.yml
index 2b843cd24f..1ae40f392d 100644
--- a/detections/cloud/asl_aws_defense_evasion_putbucketlifecycle.yml
+++ b/detections/cloud/asl_aws_defense_evasion_putbucketlifecycle.yml
@@ -1,16 +1,36 @@
name: ASL AWS Defense Evasion PutBucketLifecycle
id: 986565a2-7707-48ea-9590-37929cebc938
-version: 1
-date: '2024-12-16'
+version: 2
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Hunting
-description: The following analytic detects `PutBucketLifecycle` events in AWS CloudTrail logs where a user sets a lifecycle rule for an S3 bucket with an expiration period of fewer than three days. This detection leverages CloudTrail logs to identify suspicious lifecycle configurations. This activity is significant because attackers may use it to delete CloudTrail logs quickly, thereby evading detection and impairing forensic investigations. If confirmed malicious, this could allow attackers to cover their tracks, making it difficult to trace their actions and respond to the breach effectively.
+description: The following analytic detects `PutBucketLifecycle` events in AWS CloudTrail
+ logs where a user sets a lifecycle rule for an S3 bucket with an expiration period
+ of fewer than three days. This detection leverages CloudTrail logs to identify suspicious
+ lifecycle configurations. This activity is significant because attackers may use
+ it to delete CloudTrail logs quickly, thereby evading detection and impairing forensic
+ investigations. If confirmed malicious, this could allow attackers to cover their
+ tracks, making it difficult to trace their actions and respond to the breach effectively.
data_source:
- ASL AWS CloudTrail
-search: '`amazon_security_lake` api.operation=PutBucketLifecycle | spath input=api.request.data path=LifecycleConfiguration.Rule.NoncurrentVersionExpiration.NoncurrentDays output=NoncurrentDays | where NoncurrentDays < 3 | spath input=api.request.data | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region NoncurrentDays bucketName | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_putbucketlifecycle_filter`'
-how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
-known_false_positives: While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names.
+search: '`amazon_security_lake` api.operation=PutBucketLifecycle | spath input=api.request.data
+ path=LifecycleConfiguration.Rule.NoncurrentVersionExpiration.NoncurrentDays output=NoncurrentDays
+ | where NoncurrentDays < 3 | spath input=api.request.data | fillnull | stats count
+ min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
+ http_request.user_agent src_endpoint.ip cloud.region NoncurrentDays bucketName |
+ rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region,
+ http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
+ | `asl_aws_defense_evasion_putbucketlifecycle_filter`'
+how_to_implement: The detection is based on Amazon Security Lake events from Amazon
+ Web Services (AWS), which is a centralized data lake that provides security-related
+ data from AWS services. To use this detection, you must ingest CloudTrail logs from
+ Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
+ using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
+ or the Federated Analytics App.
+known_false_positives: While this search has no known false positives, it is possible
+ that it is a legitimate admin activity. Please consider filtering out these noisy
+ events using userAgent, user_arn field names.
references:
- https://stratus-red-team.cloud/attack-techniques/AWS/aws.defense-evasion.cloudtrail-lifecycle-rule/
tags:
@@ -18,10 +38,8 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- - T1562.008
- - T1562
- T1485.001
- - T1485
+ - T1562.008
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -30,6 +48,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/put_bucketlifecycle/asl_ocsf_cloudtrail.json
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/put_bucketlifecycle/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
diff --git a/detections/cloud/asl_aws_defense_evasion_stop_logging_cloudtrail.yml b/detections/cloud/asl_aws_defense_evasion_stop_logging_cloudtrail.yml
index 28a9d9a628..ab0b74e5d6 100644
--- a/detections/cloud/asl_aws_defense_evasion_stop_logging_cloudtrail.yml
+++ b/detections/cloud/asl_aws_defense_evasion_stop_logging_cloudtrail.yml
@@ -1,17 +1,36 @@
name: ASL AWS Defense Evasion Stop Logging Cloudtrail
id: 0b78a8f9-1d31-4d23-85c8-56ad13d5b4c1
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
-description: The following analytic detects `StopLogging` events within AWS CloudTrail logs, a critical action that adversaries may use to evade detection. By halting the logging of their malicious activities, attackers aim to operate undetected within a compromised AWS environment. This detection is achieved by monitoring for specific CloudTrail log entries that indicate the cessation of logging activities. Identifying such behavior is crucial for a Security Operations Center (SOC), as it signals an attempt to undermine the integrity of logging mechanisms, potentially allowing malicious activities to proceed without observation. The impact of this evasion tactic is significant, as it can severely hamper incident response and forensic investigations by obscuring the attacker's actions.
-data_source:
+description: The following analytic detects `StopLogging` events within AWS CloudTrail
+ logs, a critical action that adversaries may use to evade detection. By halting
+ the logging of their malicious activities, attackers aim to operate undetected within
+ a compromised AWS environment. This detection is achieved by monitoring for specific
+ CloudTrail log entries that indicate the cessation of logging activities. Identifying
+ such behavior is crucial for a Security Operations Center (SOC), as it signals an
+ attempt to undermine the integrity of logging mechanisms, potentially allowing malicious
+ activities to proceed without observation. The impact of this evasion tactic is
+ significant, as it can severely hamper incident response and forensic investigations
+ by obscuring the attacker's actions.
+data_source:
- ASL AWS CloudTrail
-search: '`amazon_security_lake` api.operation=StopLogging | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid
- as aws_account_id | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_stop_logging_cloudtrail_filter`'
-how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
-known_false_positives: While this search has no known false positives, it is possible that an AWS admin has stopped cloudtrail logging. Please investigate this activity.
+search: '`amazon_security_lake` api.operation=StopLogging | fillnull | stats count
+ min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
+ http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as
+ user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
+ as user_agent, actor.user.account.uid as aws_account_id | `security_content_ctime(firstTime)`|
+ `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_stop_logging_cloudtrail_filter`'
+how_to_implement: The detection is based on Amazon Security Lake events from Amazon
+ Web Services (AWS), which is a centralized data lake that provides security-related
+ data from AWS services. To use this detection, you must ingest CloudTrail logs from
+ Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
+ using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
+ or the Federated Analytics App.
+known_false_positives: While this search has no known false positives, it is possible
+ that an AWS admin has stopped cloudtrail logging. Please investigate this activity.
references:
- https://attack.mitre.org/techniques/T1562/008/
drilldown_searches:
@@ -44,7 +63,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -53,6 +71,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail_2.json
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail_2.json
sourcetype: aws:asl
source: aws_asl
diff --git a/detections/cloud/asl_aws_defense_evasion_update_cloudtrail.yml b/detections/cloud/asl_aws_defense_evasion_update_cloudtrail.yml
index 1b45a81b7f..55888e23cc 100644
--- a/detections/cloud/asl_aws_defense_evasion_update_cloudtrail.yml
+++ b/detections/cloud/asl_aws_defense_evasion_update_cloudtrail.yml
@@ -1,16 +1,35 @@
name: ASL AWS Defense Evasion Update Cloudtrail
id: f3eb471c-16d0-404d-897c-7653f0a78cba
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
-description: The following analytic detects `UpdateTrail` events within AWS CloudTrail logs, aiming to identify attempts by attackers to evade detection by altering logging configurations. By updating CloudTrail settings with incorrect parameters, such as changing multi-regional logging to a single region, attackers can impair the logging of their activities across other regions. This behavior is crucial for Security Operations Centers (SOCs) to identify, as it indicates an adversary's intent to operate undetected within a compromised AWS environment. The impact of such evasion tactics is significant, potentially allowing malicious activities to proceed without being logged, thereby hindering incident response and forensic investigations.
-data_source:
+description: The following analytic detects `UpdateTrail` events within AWS CloudTrail
+ logs, aiming to identify attempts by attackers to evade detection by altering logging
+ configurations. By updating CloudTrail settings with incorrect parameters, such
+ as changing multi-regional logging to a single region, attackers can impair the
+ logging of their activities across other regions. This behavior is crucial for Security
+ Operations Centers (SOCs) to identify, as it indicates an adversary's intent to
+ operate undetected within a compromised AWS environment. The impact of such evasion
+ tactics is significant, potentially allowing malicious activities to proceed without
+ being logged, thereby hindering incident response and forensic investigations.
+data_source:
- ASL AWS CloudTrail
-search: '`amazon_security_lake` api.operation=UpdateTrail | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid as aws_account_id | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_update_cloudtrail_filter`'
-how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
-known_false_positives: While this search has no known false positives, it is possible that an AWS admin has updated cloudtrail logging. Please investigate this activity.
+search: '`amazon_security_lake` api.operation=UpdateTrail | fillnull | stats count
+ min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
+ http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as
+ user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
+ as user_agent, actor.user.account.uid as aws_account_id | `security_content_ctime(firstTime)`|
+ `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_update_cloudtrail_filter`'
+how_to_implement: The detection is based on Amazon Security Lake events from Amazon
+ Web Services (AWS), which is a centralized data lake that provides security-related
+ data from AWS services. To use this detection, you must ingest CloudTrail logs from
+ Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
+ using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
+ or the Federated Analytics App.
+known_false_positives: While this search has no known false positives, it is possible
+ that an AWS admin has updated cloudtrail logging. Please investigate this activity.
references:
- https://attack.mitre.org/techniques/T1562/008/
drilldown_searches:
@@ -42,7 +61,6 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- - T1562
- T1562.008
product:
- Splunk Enterprise
@@ -52,6 +70,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/update_cloudtrail/asl_ocsf_cloudtrail.json
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/update_cloudtrail/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
diff --git a/detections/cloud/asl_aws_ecr_container_upload_outside_business_hours.yml b/detections/cloud/asl_aws_ecr_container_upload_outside_business_hours.yml
index 6222a0b4f0..c4a461916e 100644
--- a/detections/cloud/asl_aws_ecr_container_upload_outside_business_hours.yml
+++ b/detections/cloud/asl_aws_ecr_container_upload_outside_business_hours.yml
@@ -1,16 +1,35 @@
name: ASL AWS ECR Container Upload Outside Business Hours
id: 739ed682-27e9-4ba0-80e5-a91b97698213
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
-description: The following analytic detects the upload of new containers to AWS Elastic Container Service (ECR) outside of standard business hours through AWS CloudTrail events. It identifies this behavior by monitoring for `PutImage` events occurring before 8 AM or after 8 PM, as well as any uploads on weekends. This activity is significant for a SOC to investigate as it may indicate unauthorized access or malicious deployments, potentially leading to compromised services or data breaches. Identifying and addressing such uploads promptly can mitigate the risk of security incidents and their associated impacts.
-data_source:
+description: The following analytic detects the upload of new containers to AWS Elastic
+ Container Service (ECR) outside of standard business hours through AWS CloudTrail
+ events. It identifies this behavior by monitoring for `PutImage` events occurring
+ before 8 AM or after 8 PM, as well as any uploads on weekends. This activity is
+ significant for a SOC to investigate as it may indicate unauthorized access or malicious
+ deployments, potentially leading to compromised services or data breaches. Identifying
+ and addressing such uploads promptly can mitigate the risk of security incidents
+ and their associated impacts.
+data_source:
- ASL AWS CloudTrail
-search: '`amazon_security_lake` api.operation=PutImage | eval hour=strftime(time/pow(10,3), "%H"), weekday=strftime(time/pow(10,3), "%A") | where hour >= 20 OR hour < 8 OR weekday=Saturday OR weekday=Sunday | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent cloud.region | rename actor.user.uid as user, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_ecr_container_upload_outside_business_hours_filter`'
-how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
-known_false_positives: When your development is spreaded in different time zones, applying this rule can be difficult.
+search: '`amazon_security_lake` api.operation=PutImage | eval hour=strftime(time/pow(10,3),
+ "%H"), weekday=strftime(time/pow(10,3), "%A") | where hour >= 20 OR hour < 8 OR
+ weekday=Saturday OR weekday=Sunday | fillnull | stats count min(_time) as firstTime
+ max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent
+ cloud.region | rename actor.user.uid as user, cloud.region as region, http_request.user_agent
+ as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
+ | `asl_aws_ecr_container_upload_outside_business_hours_filter`'
+how_to_implement: The detection is based on Amazon Security Lake events from Amazon
+ Web Services (AWS), which is a centralized data lake that provides security-related
+ data from AWS services. To use this detection, you must ingest CloudTrail logs from
+ Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
+ using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
+ or the Federated Analytics App.
+known_false_positives: When your development is spreaded in different time zones,
+ applying this rule can be difficult.
references:
- https://attack.mitre.org/techniques/T1204/003/
drilldown_searches:
@@ -40,16 +59,17 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1204.003
- - T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
security_domain: network
- manual_test: Can't be tested automatically because of outside of business hours time
+ manual_test: Can't be tested automatically because of outside of business hours
+ time
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
diff --git a/detections/cloud/asl_aws_ecr_container_upload_unknown_user.yml b/detections/cloud/asl_aws_ecr_container_upload_unknown_user.yml
index 156aab0bc0..9f92aaa8b3 100644
--- a/detections/cloud/asl_aws_ecr_container_upload_unknown_user.yml
+++ b/detections/cloud/asl_aws_ecr_container_upload_unknown_user.yml
@@ -1,15 +1,34 @@
name: ASL AWS ECR Container Upload Unknown User
id: 886a8f46-d7e2-4439-b9ba-aec238e31732
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
-description: The following analytic detects unauthorized container uploads to AWS Elastic Container Service (ECR) by monitoring AWS CloudTrail events. It identifies instances where a new container is uploaded by a user not previously recognized as authorized. This detection is crucial for a SOC as it can indicate a potential compromise or misuse of AWS ECR, which could lead to unauthorized access to sensitive data or the deployment of malicious containers. By identifying and investigating these events, organizations can mitigate the risk of data breaches or other security incidents resulting from unauthorized container uploads. The impact of such an attack could be significant, compromising the integrity and security of the organization's cloud environment.
-data_source:
+description: The following analytic detects unauthorized container uploads to AWS
+ Elastic Container Service (ECR) by monitoring AWS CloudTrail events. It identifies
+ instances where a new container is uploaded by a user not previously recognized
+ as authorized. This detection is crucial for a SOC as it can indicate a potential
+ compromise or misuse of AWS ECR, which could lead to unauthorized access to sensitive
+ data or the deployment of malicious containers. By identifying and investigating
+ these events, organizations can mitigate the risk of data breaches or other security
+ incidents resulting from unauthorized container uploads. The impact of such an attack
+ could be significant, compromising the integrity and security of the organization's
+ cloud environment.
+data_source:
- ASL AWS CloudTrail
-search: '`amazon_security_lake` api.operation=PutImage NOT `aws_ecr_users_asl` | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_ecr_container_upload_unknown_user_filter`'
-how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
+search: '`amazon_security_lake` api.operation=PutImage NOT `aws_ecr_users_asl` | stats
+ count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid
+ actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename
+ actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
+ as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
+ | `asl_aws_ecr_container_upload_unknown_user_filter`'
+how_to_implement: The detection is based on Amazon Security Lake events from Amazon
+ Web Services (AWS), which is a centralized data lake that provides security-related
+ data from AWS services. To use this detection, you must ingest CloudTrail logs from
+ Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
+ using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
+ or the Federated Analytics App.
known_false_positives: unknown
references:
- https://attack.mitre.org/techniques/T1204/003/
@@ -42,7 +61,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1204.003
- - T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -51,6 +69,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
diff --git a/detections/cloud/asl_aws_iam_successful_group_deletion.yml b/detections/cloud/asl_aws_iam_successful_group_deletion.yml
index 0eb874ecb5..c6b0e18965 100644
--- a/detections/cloud/asl_aws_iam_successful_group_deletion.yml
+++ b/detections/cloud/asl_aws_iam_successful_group_deletion.yml
@@ -1,16 +1,32 @@
name: ASL AWS IAM Successful Group Deletion
id: 1bbe54f1-93d7-4764-8a01-ddaa12ece7ac
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Hunting
-description: The following analytic detects the successful deletion of a group within AWS IAM, leveraging CloudTrail IAM events. This action, while not inherently malicious, can serve as a precursor to more sinister activities, such as unauthorized access or privilege escalation attempts. By monitoring for such deletions, the analytic aids in identifying potential preparatory steps towards an attack, allowing for early detection and mitigation. The identification of this behavior is crucial for a SOC to prevent the potential impact of an attack, which could include unauthorized access to sensitive resources or disruption of AWS environment operations.
-data_source:
+description: The following analytic detects the successful deletion of a group within
+ AWS IAM, leveraging CloudTrail IAM events. This action, while not inherently malicious,
+ can serve as a precursor to more sinister activities, such as unauthorized access
+ or privilege escalation attempts. By monitoring for such deletions, the analytic
+ aids in identifying potential preparatory steps towards an attack, allowing for
+ early detection and mitigation. The identification of this behavior is crucial for
+ a SOC to prevent the potential impact of an attack, which could include unauthorized
+ access to sensitive resources or disruption of AWS environment operations.
+data_source:
- ASL AWS CloudTrail
-search: '`amazon_security_lake` api.operation=DeleteGroup status=Success | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_iam_successful_group_deletion_filter`'
-how_to_implement: You must install the Data Lake Federated Analytics App and ingest the logs into Splunk.
-known_false_positives: This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users. Not every user with AWS access should have permission to delete groups (least privilege).
+search: '`amazon_security_lake` api.operation=DeleteGroup status=Success | fillnull
+ | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid
+ actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename
+ actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
+ as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
+ | `asl_aws_iam_successful_group_deletion_filter`'
+how_to_implement: You must install the Data Lake Federated Analytics App and ingest
+ the logs into Splunk.
+known_false_positives: This detection will require tuning to provide high fidelity
+ detection capabilties. Tune based on src addresses (corporate offices, VPN terminations)
+ or by groups of users. Not every user with AWS access should have permission to
+ delete groups (least privilege).
references:
- https://awscli.amazonaws.com/v2/documentation/api/latest/reference/iam/delete-group.html
- https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteGroup.html
@@ -21,7 +37,6 @@ tags:
mitre_attack_id:
- T1069.003
- T1098
- - T1069
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -30,6 +45,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_successful_group_deletion/asl_ocsf_cloudtrail.json
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_successful_group_deletion/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
diff --git a/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml b/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml
index a26e3c1500..0a6a467261 100644
--- a/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml
+++ b/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml
@@ -1,16 +1,34 @@
name: ASL AWS Multi-Factor Authentication Disabled
id: 4d2df5e0-1092-4817-88a8-79c7fa054668
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
-description: The following analytic detects attempts to disable multi-factor authentication (MFA) for an AWS IAM user. It leverages Amazon Security Lake logs, specifically monitoring for `DeleteVirtualMFADevice` or `DeactivateMFADevice` API operations. This activity is significant as disabling MFA can indicate an adversary attempting to weaken account security to maintain persistence using a compromised account. If confirmed malicious, this action could allow attackers to retain access to the AWS environment without detection, potentially leading to unauthorized access to sensitive resources and prolonged compromise.
-data_source:
+description: The following analytic detects attempts to disable multi-factor authentication
+ (MFA) for an AWS IAM user. It leverages Amazon Security Lake logs, specifically
+ monitoring for `DeleteVirtualMFADevice` or `DeactivateMFADevice` API operations.
+ This activity is significant as disabling MFA can indicate an adversary attempting
+ to weaken account security to maintain persistence using a compromised account.
+ If confirmed malicious, this action could allow attackers to retain access to the
+ AWS environment without detection, potentially leading to unauthorized access to
+ sensitive resources and prolonged compromise.
+data_source:
- ASL AWS CloudTrail
-search: '`amazon_security_lake` (api.operation=DeleteVirtualMFADevice OR api.operation=DeactivateMFADevice) | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_multi_factor_authentication_disabled_filter`'
-how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
-known_false_positives: AWS Administrators may disable MFA but it is highly unlikely for this event to occur without prior notice to the company
+search: '`amazon_security_lake` (api.operation=DeleteVirtualMFADevice OR api.operation=DeactivateMFADevice)
+ | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation
+ actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region
+ | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region,
+ http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
+ | `asl_aws_multi_factor_authentication_disabled_filter`'
+how_to_implement: The detection is based on Amazon Security Lake events from Amazon
+ Web Services (AWS), which is a centralized data lake that provides security-related
+ data from AWS services. To use this detection, you must ingest CloudTrail logs from
+ Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
+ using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
+ or the Federated Analytics App.
+known_false_positives: AWS Administrators may disable MFA but it is highly unlikely
+ for this event to occur without prior notice to the company
references:
- https://attack.mitre.org/techniques/T1621/
- https://aws.amazon.com/what-is/mfa/
@@ -42,11 +60,9 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- - T1586
+ - T1556.006
- T1586.003
- T1621
- - T1556
- - T1556.006
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -55,6 +71,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/aws_mfa_disabled/asl_ocsf_cloudtrail.json
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/aws_mfa_disabled/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
diff --git a/detections/cloud/asl_aws_network_access_control_list_created_with_all_open_ports.yml b/detections/cloud/asl_aws_network_access_control_list_created_with_all_open_ports.yml
index 7d42dfa04e..62a56cf3bb 100644
--- a/detections/cloud/asl_aws_network_access_control_list_created_with_all_open_ports.yml
+++ b/detections/cloud/asl_aws_network_access_control_list_created_with_all_open_ports.yml
@@ -1,26 +1,41 @@
name: ASL AWS Network Access Control List Created with All Open Ports
id: a2625034-c2de-44fc-b45c-7bac9c4a7974
-version: 1
-date: '2025-01-09'
+version: 2
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
-description: The following analytic detects the creation of AWS Network Access Control Lists (ACLs) with all ports open to a specified CIDR. It leverages AWS CloudTrail events, specifically monitoring for `CreateNetworkAclEntry` or `ReplaceNetworkAclEntry` actions with rules allowing all traffic. This activity is significant because it can expose the network to unauthorized access, increasing the risk of data breaches and other malicious activities. If confirmed malicious, an attacker could exploit this misconfiguration to gain unrestricted access to the network, potentially leading to data exfiltration, service disruption, or further compromise of the AWS environment.
-data_source:
+description: The following analytic detects the creation of AWS Network Access Control
+ Lists (ACLs) with all ports open to a specified CIDR. It leverages AWS CloudTrail
+ events, specifically monitoring for `CreateNetworkAclEntry` or `ReplaceNetworkAclEntry`
+ actions with rules allowing all traffic. This activity is significant because it
+ can expose the network to unauthorized access, increasing the risk of data breaches
+ and other malicious activities. If confirmed malicious, an attacker could exploit
+ this misconfiguration to gain unrestricted access to the network, potentially leading
+ to data exfiltration, service disruption, or further compromise of the AWS environment.
+data_source:
- ASL AWS CloudTrail
-search: '`amazon_security_lake` api.operation=CreateNetworkAclEntry OR api.operation=ReplaceNetworkAclEntry status=Success
- | spath input=api.request.data path=ruleAction output=ruleAction
- | spath input=api.request.data path=egress output=egress
- | spath input=api.request.data path=aclProtocol output=aclProtocol
- | spath input=api.request.data path=cidrBlock output=cidrBlock
- | spath input=api.request.data path=networkAclId output=networkAclId
+search: '`amazon_security_lake` api.operation=CreateNetworkAclEntry OR api.operation=ReplaceNetworkAclEntry
+ status=Success | spath input=api.request.data path=ruleAction output=ruleAction
+ | spath input=api.request.data path=egress output=egress | spath input=api.request.data
+ path=aclProtocol output=aclProtocol | spath input=api.request.data path=cidrBlock
+ output=cidrBlock | spath input=api.request.data path=networkAclId output=networkAclId
| search ruleAction=allow AND egress=false AND aclProtocol=-1 AND cidrBlock=0.0.0.0/0
- | fillnull
- | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region networkAclId cidrBlock
- | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid as aws_account_id
- | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_network_access_control_list_created_with_all_open_ports_filter`'
-how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
-known_false_positives: It's possible that an admin has created this ACL with all ports open for some legitimate purpose however, this should be scoped and not allowed in production environment.
+ | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation
+ actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region
+ networkAclId cidrBlock | rename actor.user.uid as user, src_endpoint.ip as src_ip,
+ cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid
+ as aws_account_id | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
+ | `asl_aws_network_access_control_list_created_with_all_open_ports_filter`'
+how_to_implement: The detection is based on Amazon Security Lake events from Amazon
+ Web Services (AWS), which is a centralized data lake that provides security-related
+ data from AWS services. To use this detection, you must ingest CloudTrail logs from
+ Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
+ using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
+ or the Federated Analytics App.
+known_false_positives: It's possible that an admin has created this ACL with all ports
+ open for some legitimate purpose however, this should be scoped and not allowed
+ in production environment.
references: []
drilldown_searches:
- name: View the detection results for - "$user$"
@@ -28,7 +43,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -46,7 +66,6 @@ tags:
asset_type: AWS Instance
mitre_attack_id:
- T1562.007
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -55,6 +74,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_create_acl/asl_ocsf_cloudtrail.json
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_create_acl/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
diff --git a/detections/cloud/asl_aws_network_access_control_list_deleted.yml b/detections/cloud/asl_aws_network_access_control_list_deleted.yml
index 067e4b543f..23067c2c55 100644
--- a/detections/cloud/asl_aws_network_access_control_list_deleted.yml
+++ b/detections/cloud/asl_aws_network_access_control_list_deleted.yml
@@ -1,23 +1,35 @@
name: ASL AWS Network Access Control List Deleted
id: e010ddf5-e9a5-44e5-bdd6-0c919ba8fc8b
-version: 1
-date: '2025-01-09'
+version: 2
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
-description: The following analytic detects the deletion of AWS Network Access Control Lists (ACLs). It leverages AWS CloudTrail logs to identify events where a user deletes a network ACL entry. This activity is significant because deleting a network ACL can remove critical access restrictions, potentially allowing unauthorized access to cloud instances. If confirmed malicious, this action could enable attackers to bypass network security controls, leading to unauthorized access, data exfiltration, or further compromise of the cloud environment.
-data_source:
+description: The following analytic detects the deletion of AWS Network Access Control
+ Lists (ACLs). It leverages AWS CloudTrail logs to identify events where a user deletes
+ a network ACL entry. This activity is significant because deleting a network ACL
+ can remove critical access restrictions, potentially allowing unauthorized access
+ to cloud instances. If confirmed malicious, this action could enable attackers to
+ bypass network security controls, leading to unauthorized access, data exfiltration,
+ or further compromise of the cloud environment.
+data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` api.operation=DeleteNetworkAclEntry status=Success
- | spath input=api.request.data path=egress output=egress
- | spath input=api.request.data path=networkAclId output=networkAclId
- | search egress=false
- | fillnull
- | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region networkAclId
- | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account_uid as aws_account_id
- | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_network_access_control_list_deleted_filter`'
-how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
-known_false_positives: It's possible that a user has legitimately deleted a network ACL.
+ | spath input=api.request.data path=egress output=egress | spath input=api.request.data
+ path=networkAclId output=networkAclId | search egress=false | fillnull | stats count
+ min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
+ http_request.user_agent src_endpoint.ip cloud.region networkAclId | rename actor.user.uid
+ as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
+ as user_agent, actor.user.account_uid as aws_account_id | `security_content_ctime(firstTime)`|
+ `security_content_ctime(lastTime)` | `asl_aws_network_access_control_list_deleted_filter`'
+how_to_implement: The detection is based on Amazon Security Lake events from Amazon
+ Web Services (AWS), which is a centralized data lake that provides security-related
+ data from AWS services. To use this detection, you must ingest CloudTrail logs from
+ Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
+ using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
+ or the Federated Analytics App.
+known_false_positives: It's possible that a user has legitimately deleted a network
+ ACL.
references: []
drilldown_searches:
- name: View the detection results for - "$user$"
@@ -25,7 +37,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -43,7 +60,6 @@ tags:
asset_type: AWS Instance
mitre_attack_id:
- T1562.007
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -52,6 +68,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_delete_acl/asl_ocsf_cloudtrail.json
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_delete_acl/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
diff --git a/detections/cloud/asl_aws_new_mfa_method_registered_for_user.yml b/detections/cloud/asl_aws_new_mfa_method_registered_for_user.yml
index bf67c362b9..e787dbcf30 100644
--- a/detections/cloud/asl_aws_new_mfa_method_registered_for_user.yml
+++ b/detections/cloud/asl_aws_new_mfa_method_registered_for_user.yml
@@ -1,16 +1,34 @@
name: ASL AWS New MFA Method Registered For User
id: 33ae0931-2a03-456b-b1d7-b016c5557fbd
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: experimental
type: TTP
-description: The following analytic identifies the registration of a new Multi-Factor Authentication (MFA) method for an AWS account, as logged through Amazon Security Lake (ASL). It detects this activity by monitoring the `CreateVirtualMFADevice` API operation within ASL logs. This behavior is significant because adversaries who gain unauthorized access to an AWS account may register a new MFA method to maintain persistence. If confirmed malicious, this activity could allow attackers to secure their access, making it harder to detect and remove their presence from the compromised environment.
-data_source:
+description: The following analytic identifies the registration of a new Multi-Factor
+ Authentication (MFA) method for an AWS account, as logged through Amazon Security
+ Lake (ASL). It detects this activity by monitoring the `CreateVirtualMFADevice`
+ API operation within ASL logs. This behavior is significant because adversaries
+ who gain unauthorized access to an AWS account may register a new MFA method to
+ maintain persistence. If confirmed malicious, this activity could allow attackers
+ to secure their access, making it harder to detect and remove their presence from
+ the compromised environment.
+data_source:
- ASL AWS CloudTrail
-search: '`amazon_security_lake` api.operation=CreateVirtualMFADevice | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_new_mfa_method_registered_for_user_filter`'
-how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
-known_false_positives: Newly onboarded users who are registering an MFA method for the first time will also trigger this detection.
+search: '`amazon_security_lake` api.operation=CreateVirtualMFADevice | fillnull |
+ stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid
+ actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename
+ actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
+ as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
+ | `asl_aws_new_mfa_method_registered_for_user_filter`'
+how_to_implement: The detection is based on Amazon Security Lake events from Amazon
+ Web Services (AWS), which is a centralized data lake that provides security-related
+ data from AWS services. To use this detection, you must ingest CloudTrail logs from
+ Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
+ using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
+ or the Federated Analytics App.
+known_false_positives: Newly onboarded users who are registering an MFA method for
+ the first time will also trigger this detection.
references:
- https://aws.amazon.com/blogs/security/you-can-now-assign-multiple-mfa-devices-in-iam/
- https://attack.mitre.org/techniques/T1556/
@@ -30,7 +48,6 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- - T1556
- T1556.006
product:
- Splunk Enterprise
@@ -40,6 +57,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.006/aws_new_mfa_method_registered_for_user/asl_ocsf_cloudtrail.json
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.006/aws_new_mfa_method_registered_for_user/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
diff --git a/detections/cloud/asl_aws_updateloginprofile.yml b/detections/cloud/asl_aws_updateloginprofile.yml
index eab3050952..c6f1588db7 100644
--- a/detections/cloud/asl_aws_updateloginprofile.yml
+++ b/detections/cloud/asl_aws_updateloginprofile.yml
@@ -1,20 +1,34 @@
name: ASL AWS UpdateLoginProfile
id: 5b3f63a3-865b-4637-9941-f98bd1a50c0d
-version: 1
-date: '2025-01-09'
+version: 2
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
-description: The following analytic detects an AWS CloudTrail event where a user with permissions updates the login profile of another user. It leverages CloudTrail logs to identify instances where the user making the change is different from the user whose profile is being updated. This activity is significant because it can indicate privilege escalation attempts, where an attacker uses a compromised account to gain higher privileges. If confirmed malicious, this could allow the attacker to escalate their privileges, potentially leading to unauthorized access and control over sensitive resources within the AWS environment.
-data_source:
+description: The following analytic detects an AWS CloudTrail event where a user with
+ permissions updates the login profile of another user. It leverages CloudTrail logs
+ to identify instances where the user making the change is different from the user
+ whose profile is being updated. This activity is significant because it can indicate
+ privilege escalation attempts, where an attacker uses a compromised account to gain
+ higher privileges. If confirmed malicious, this could allow the attacker to escalate
+ their privileges, potentially leading to unauthorized access and control over sensitive
+ resources within the AWS environment.
+data_source:
- ASL AWS CloudTrail
-search: '`amazon_security_lake` api.operation=UpdateLoginProfile
- | fillnull
- | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region
- | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent
- | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_updateloginprofile_filter`'
-how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
-known_false_positives: While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user.
+search: '`amazon_security_lake` api.operation=UpdateLoginProfile | fillnull | stats
+ count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid
+ actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename
+ actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
+ as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
+ | `asl_aws_updateloginprofile_filter`'
+how_to_implement: The detection is based on Amazon Security Lake events from Amazon
+ Web Services (AWS), which is a centralized data lake that provides security-related
+ data from AWS services. To use this detection, you must ingest CloudTrail logs from
+ Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
+ using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
+ or the Federated Analytics App.
+known_false_positives: While this search has no known false positives, it is possible
+ that an AWS admin has legitimately created keys for another user.
references:
- https://bishopfox.com/blog/privilege-escalation-in-aws
- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/
@@ -24,12 +38,18 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
- message: User $user$ from IP address $src_ip$ updated the login profile of another user
- risk_objects:
+ message: User $user$ from IP address $src_ip$ updated the login profile of another
+ user
+ risk_objects:
- field: user
type: user
score: 30
@@ -42,7 +62,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1136.003
- - T1136
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -51,6 +70,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_updateloginprofile/asl_ocsf_cloudtrail.json
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_updateloginprofile/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
diff --git a/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml b/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml
index 7938f15e75..f8f6815c8d 100644
--- a/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml
+++ b/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml
@@ -1,7 +1,7 @@
name: AWS Console Login Failed During MFA Challenge
id: 55349868-5583-466f-98ab-d3beb321961e
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
- Compromised User Account
asset_type: AWS Account
mitre_attack_id:
- - T1586
- T1586.003
- T1621
product:
diff --git a/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml b/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml
index 5f46f6eb98..13339e55f9 100644
--- a/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml
+++ b/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml
@@ -1,7 +1,7 @@
name: AWS Create Policy Version to allow all resources
id: 2a9b80d3-6340-4345-b5ad-212bf3d0dac4
-version: 7
-date: '2024-11-14'
+version: 8
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1078.004
- - T1078
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_createaccesskey.yml b/detections/cloud/aws_createaccesskey.yml
index 5e4a3636e3..8e4db2dd78 100644
--- a/detections/cloud/aws_createaccesskey.yml
+++ b/detections/cloud/aws_createaccesskey.yml
@@ -1,7 +1,7 @@
name: AWS CreateAccessKey
id: 2a9b80d3-6340-4345-11ad-212bf3d0d111
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: Hunting
@@ -33,7 +33,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1136.003
- - T1136
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_createloginprofile.yml b/detections/cloud/aws_createloginprofile.yml
index d72c2ed8a9..8e8b47aab4 100644
--- a/detections/cloud/aws_createloginprofile.yml
+++ b/detections/cloud/aws_createloginprofile.yml
@@ -1,7 +1,7 @@
name: AWS CreateLoginProfile
id: 2a9b80d3-6340-4345-11ad-212bf444d111
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -59,7 +59,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1136.003
- - T1136
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_credential_access_failed_login.yml b/detections/cloud/aws_credential_access_failed_login.yml
index 7b19d32062..4034c85a31 100644
--- a/detections/cloud/aws_credential_access_failed_login.yml
+++ b/detections/cloud/aws_credential_access_failed_login.yml
@@ -1,7 +1,7 @@
name: AWS Credential Access Failed Login
id: a19b354d-0d7f-47f3-8ea6-1a7c36434968
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Bhavin Patel, Splunk
status: production
type: TTP
@@ -54,10 +54,8 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- - T1586
- - T1586.003
- - T1110
- T1110.001
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_credential_access_getpassworddata.yml b/detections/cloud/aws_credential_access_getpassworddata.yml
index 24b5b4f9f6..78e473d83e 100644
--- a/detections/cloud/aws_credential_access_getpassworddata.yml
+++ b/detections/cloud/aws_credential_access_getpassworddata.yml
@@ -1,7 +1,7 @@
name: AWS Credential Access GetPasswordData
id: 4d347c4a-306e-41db-8d10-b46baf71b3e2
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: Anomaly
@@ -57,10 +57,8 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- - T1586
- - T1586.003
- - T1110
- T1110.001
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_credential_access_rds_password_reset.yml b/detections/cloud/aws_credential_access_rds_password_reset.yml
index 16d5d8fce2..344ab68bfa 100644
--- a/detections/cloud/aws_credential_access_rds_password_reset.yml
+++ b/detections/cloud/aws_credential_access_rds_password_reset.yml
@@ -1,7 +1,7 @@
name: AWS Credential Access RDS Password reset
id: 6153c5ea-ed30-4878-81e6-21ecdb198189
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -52,9 +52,8 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- - T1586
- - T1586.003
- T1110
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml b/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml
index 15acf34a9a..94cb3378c3 100644
--- a/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml
+++ b/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml
@@ -1,7 +1,7 @@
name: AWS Defense Evasion Delete Cloudtrail
id: 82092925-9ca1-4e06-98b8-85a2d3889552
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -56,7 +56,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml b/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml
index 50d8d4f9f7..1ed54c1b07 100644
--- a/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml
+++ b/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml
@@ -1,7 +1,7 @@
name: AWS Defense Evasion Delete CloudWatch Log Group
id: d308b0f1-edb7-4a62-a614-af321160710f
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -55,7 +55,6 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- - T1562
- T1562.008
product:
- Splunk Enterprise
diff --git a/detections/cloud/aws_defense_evasion_impair_security_services.yml b/detections/cloud/aws_defense_evasion_impair_security_services.yml
index 1f05298c2f..e4575b1b7d 100644
--- a/detections/cloud/aws_defense_evasion_impair_security_services.yml
+++ b/detections/cloud/aws_defense_evasion_impair_security_services.yml
@@ -1,7 +1,7 @@
name: AWS Defense Evasion Impair Security Services
id: b28c4957-96a6-47e0-a965-6c767aac1458
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Bhavin Patel, Gowthamaraj Rajendran, Splunk
status: production
type: Hunting
@@ -42,7 +42,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml b/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml
index 4d98499ce9..036da0fa9e 100644
--- a/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml
+++ b/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml
@@ -1,7 +1,7 @@
name: AWS Defense Evasion PutBucketLifecycle
id: ce1c0e2b-9303-4903-818b-0d9002fc6ea4
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Bhavin Patel
status: production
type: Hunting
@@ -33,10 +33,8 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- - T1562.008
- - T1562
- T1485.001
- - T1485
+ - T1562.008
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml b/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml
index e59c2100ae..e459980cb4 100644
--- a/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml
+++ b/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml
@@ -1,7 +1,7 @@
name: AWS Defense Evasion Stop Logging Cloudtrail
id: 8a2f3ca2-4eb5-4389-a549-14063882e537
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -56,7 +56,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_defense_evasion_update_cloudtrail.yml b/detections/cloud/aws_defense_evasion_update_cloudtrail.yml
index 89559d06de..8e6052f1b5 100644
--- a/detections/cloud/aws_defense_evasion_update_cloudtrail.yml
+++ b/detections/cloud/aws_defense_evasion_update_cloudtrail.yml
@@ -1,7 +1,7 @@
name: AWS Defense Evasion Update Cloudtrail
id: 7c921d28-ef48-4f1b-85b3-0af8af7697db
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -55,7 +55,6 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- - T1562
- T1562.008
product:
- Splunk Enterprise
diff --git a/detections/cloud/aws_ecr_container_scanning_findings_high.yml b/detections/cloud/aws_ecr_container_scanning_findings_high.yml
index 2d8b0c01a9..5725fbb00d 100644
--- a/detections/cloud/aws_ecr_container_scanning_findings_high.yml
+++ b/detections/cloud/aws_ecr_container_scanning_findings_high.yml
@@ -1,7 +1,7 @@
name: AWS ECR Container Scanning Findings High
id: 30a0e9f8-f1dd-4f9d-8fc2-c622461d781c
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1204.003
- - T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml b/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml
index 12c75e5cdc..b9aa8443f3 100644
--- a/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml
+++ b/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml
@@ -1,7 +1,7 @@
name: AWS ECR Container Scanning Findings Low Informational Unknown
id: cbc95e44-7c22-443f-88fd-0424478f5589
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Patrick Bareiss, Eric McGinnis Splunk
status: production
type: Anomaly
@@ -57,7 +57,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1204.003
- - T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_ecr_container_scanning_findings_medium.yml b/detections/cloud/aws_ecr_container_scanning_findings_medium.yml
index 74e533680f..92b1b9ea7d 100644
--- a/detections/cloud/aws_ecr_container_scanning_findings_medium.yml
+++ b/detections/cloud/aws_ecr_container_scanning_findings_medium.yml
@@ -1,7 +1,7 @@
name: AWS ECR Container Scanning Findings Medium
id: 0b80e2c8-c746-4ddb-89eb-9efd892220cf
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -56,7 +56,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1204.003
- - T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml b/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml
index 0f3a5de777..c72dfc4012 100644
--- a/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml
+++ b/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml
@@ -1,7 +1,7 @@
name: AWS ECR Container Upload Outside Business Hours
id: d4c4d4eb-3994-41ca-a25e-a82d64e125bb
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -56,7 +56,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1204.003
- - T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_ecr_container_upload_unknown_user.yml b/detections/cloud/aws_ecr_container_upload_unknown_user.yml
index bdb09cde4c..345bf6d589 100644
--- a/detections/cloud/aws_ecr_container_upload_unknown_user.yml
+++ b/detections/cloud/aws_ecr_container_upload_unknown_user.yml
@@ -1,7 +1,7 @@
name: AWS ECR Container Upload Unknown User
id: 300688e4-365c-4486-a065-7c884462b31d
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -54,7 +54,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1204.003
- - T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml b/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml
index 58d7a9e5e7..330c094796 100644
--- a/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml
+++ b/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml
@@ -1,7 +1,7 @@
name: AWS High Number Of Failed Authentications From Ip
id: f75b7f1a-b8eb-4975-a214-ff3e0a944757
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: Anomaly
@@ -55,7 +55,6 @@ tags:
- Compromised User Account
asset_type: AWS Account
mitre_attack_id:
- - T1110
- T1110.003
- T1110.004
product:
diff --git a/detections/cloud/aws_iam_successful_group_deletion.yml b/detections/cloud/aws_iam_successful_group_deletion.yml
index 82f8c5e8fb..cc47b126e9 100644
--- a/detections/cloud/aws_iam_successful_group_deletion.yml
+++ b/detections/cloud/aws_iam_successful_group_deletion.yml
@@ -1,7 +1,7 @@
name: AWS IAM Successful Group Deletion
id: e776d06c-9267-11eb-819b-acde48001122
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -36,7 +36,6 @@ tags:
mitre_attack_id:
- T1069.003
- T1098
- - T1069
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_multi_factor_authentication_disabled.yml b/detections/cloud/aws_multi_factor_authentication_disabled.yml
index 827af91c86..6d85bd5101 100644
--- a/detections/cloud/aws_multi_factor_authentication_disabled.yml
+++ b/detections/cloud/aws_multi_factor_authentication_disabled.yml
@@ -1,7 +1,7 @@
name: AWS Multi-Factor Authentication Disabled
id: 374832b1-3603-420c-b456-b373e24d34c0
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -56,11 +56,9 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- - T1586
+ - T1556.006
- T1586.003
- T1621
- - T1556
- - T1556.006
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml b/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml
index 0e087f273c..4f1a8a187f 100644
--- a/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml
+++ b/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml
@@ -1,7 +1,7 @@
name: AWS Multiple Failed MFA Requests For User
id: 1fece617-e614-4329-9e61-3ba228c0f353
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Bhavin Patel
status: production
type: Anomaly
@@ -54,7 +54,6 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- - T1586
- T1586.003
- T1621
product:
diff --git a/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml b/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml
index 7fdb466244..82e904fe15 100644
--- a/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml
+++ b/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml
@@ -1,7 +1,7 @@
name: AWS Multiple Users Failing To Authenticate From Ip
id: 71e1fb89-dd5f-4691-8523-575420de4630
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Bhavin Patel
status: production
type: Anomaly
@@ -57,7 +57,6 @@ tags:
- Compromised User Account
asset_type: AWS Account
mitre_attack_id:
- - T1110
- T1110.003
- T1110.004
product:
diff --git a/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml b/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml
index 9c3254ca93..a392435e99 100644
--- a/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml
+++ b/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml
@@ -1,7 +1,7 @@
name: AWS Network Access Control List Created with All Open Ports
id: ada0f478-84a8-4641-a3f1-d82362d6bd75
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Bhavin Patel, Patrick Bareiss, Splunk
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
asset_type: AWS Instance
mitre_attack_id:
- T1562.007
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_network_access_control_list_deleted.yml b/detections/cloud/aws_network_access_control_list_deleted.yml
index 8499371040..fe044edec0 100644
--- a/detections/cloud/aws_network_access_control_list_deleted.yml
+++ b/detections/cloud/aws_network_access_control_list_deleted.yml
@@ -1,7 +1,7 @@
name: AWS Network Access Control List Deleted
id: ada0f478-84a8-4641-a3f1-d82362d6fd75
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Bhavin Patel, Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -54,7 +54,6 @@ tags:
asset_type: AWS Instance
mitre_attack_id:
- T1562.007
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_new_mfa_method_registered_for_user.yml b/detections/cloud/aws_new_mfa_method_registered_for_user.yml
index 1891036414..50a9b9bc57 100644
--- a/detections/cloud/aws_new_mfa_method_registered_for_user.yml
+++ b/detections/cloud/aws_new_mfa_method_registered_for_user.yml
@@ -1,7 +1,7 @@
name: AWS New MFA Method Registered For User
id: 4e3c26f2-4fb9-4bd7-ab46-1b76ffa2a23b
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -56,7 +56,6 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- - T1556
- T1556.006
product:
- Splunk Enterprise
diff --git a/detections/cloud/aws_setdefaultpolicyversion.yml b/detections/cloud/aws_setdefaultpolicyversion.yml
index b927809aa5..a1fef13c96 100644
--- a/detections/cloud/aws_setdefaultpolicyversion.yml
+++ b/detections/cloud/aws_setdefaultpolicyversion.yml
@@ -1,7 +1,7 @@
name: AWS SetDefaultPolicyVersion
id: 2a9b80d3-6340-4345-11ad-212bf3d0dac4
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1078.004
- - T1078
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_successful_single_factor_authentication.yml b/detections/cloud/aws_successful_single_factor_authentication.yml
index 0e3b986294..86f0eff62a 100644
--- a/detections/cloud/aws_successful_single_factor_authentication.yml
+++ b/detections/cloud/aws_successful_single_factor_authentication.yml
@@ -1,7 +1,7 @@
name: AWS Successful Single-Factor Authentication
id: a520b1fe-cc9e-4f56-b762-18354594c52f
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -56,10 +56,8 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- - T1586
- - T1586.003
- - T1078
- T1078.004
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml b/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml
index 6e86b15927..1ba8b2c8a4 100644
--- a/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml
+++ b/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml
@@ -1,7 +1,7 @@
name: AWS Unusual Number of Failed Authentications From Ip
id: 0b5c9c2b-e2cb-4831-b4f1-af125ceb1386
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: Anomaly
@@ -57,11 +57,9 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- - T1586
- - T1586.003
- - T1110
- T1110.003
- T1110.004
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/aws_updateloginprofile.yml b/detections/cloud/aws_updateloginprofile.yml
index a8ffb62a72..c90f5d742a 100644
--- a/detections/cloud/aws_updateloginprofile.yml
+++ b/detections/cloud/aws_updateloginprofile.yml
@@ -1,7 +1,7 @@
name: AWS UpdateLoginProfile
id: 2a9b80d3-6a40-4115-11ad-212bf3d0d111
-version: 7
-date: '2024-11-14'
+version: 8
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -59,7 +59,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1136.003
- - T1136
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/azure_active_directory_high_risk_sign_in.yml b/detections/cloud/azure_active_directory_high_risk_sign_in.yml
index 0153fff2b2..a7a0c90d5f 100644
--- a/detections/cloud/azure_active_directory_high_risk_sign_in.yml
+++ b/detections/cloud/azure_active_directory_high_risk_sign_in.yml
@@ -1,7 +1,7 @@
name: Azure Active Directory High Risk Sign-in
id: 1ecff169-26d7-4161-9a7b-2ac4c8e61bea
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -58,10 +58,8 @@ tags:
- Azure Active Directory Account Takeover
asset_type: Azure Active Directory
mitre_attack_id:
- - T1586
- - T1586.003
- - T1110
- T1110.003
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/azure_ad_application_administrator_role_assigned.yml b/detections/cloud/azure_ad_application_administrator_role_assigned.yml
index 33eb6d2a8d..6cad0084c7 100644
--- a/detections/cloud/azure_ad_application_administrator_role_assigned.yml
+++ b/detections/cloud/azure_ad_application_administrator_role_assigned.yml
@@ -1,7 +1,7 @@
name: Azure AD Application Administrator Role Assigned
id: eac4de87-7a56-4538-a21b-277897af6d8d
-version: 6
-date: '2024-11-14'
+version: 8
+date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
asset_type: Azure Active Directory
atomic_guid: []
mitre_attack_id:
- - T1098
- T1098.003
product:
- Splunk Enterprise
diff --git a/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml b/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml
index 0ccbb9b85a..85366a53f5 100644
--- a/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml
+++ b/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml
@@ -1,7 +1,7 @@
name: Azure AD Authentication Failed During MFA Challenge
id: e62c9c2e-bf51-4719-906c-3074618fcc1c
-version: 7
-date: '2024-11-14'
+version: 8
+date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk, 0xC0FFEEEE
status: production
type: TTP
@@ -70,10 +70,8 @@ tags:
- Azure Active Directory Account Takeover
asset_type: Azure Active Directory
mitre_attack_id:
- - T1586
- - T1586.003
- - T1078
- T1078.004
+ - T1586.003
- T1621
product:
- Splunk Enterprise
diff --git a/detections/cloud/azure_ad_azurehound_useragent_detected.yml b/detections/cloud/azure_ad_azurehound_useragent_detected.yml
index 12b044f4c3..b81c81b399 100644
--- a/detections/cloud/azure_ad_azurehound_useragent_detected.yml
+++ b/detections/cloud/azure_ad_azurehound_useragent_detected.yml
@@ -1,6 +1,6 @@
name: Azure AD AzureHound UserAgent Detected
id: d62852db-a1f1-40db-a7fc-c3d56fa8bda3
-version: 1
+version: 2
date: '2025-01-06'
author: Dean Luxton
data_source:
diff --git a/detections/cloud/azure_ad_device_code_authentication.yml b/detections/cloud/azure_ad_device_code_authentication.yml
index dbe2c55afe..42e16cab04 100644
--- a/detections/cloud/azure_ad_device_code_authentication.yml
+++ b/detections/cloud/azure_ad_device_code_authentication.yml
@@ -1,7 +1,7 @@
name: Azure AD Device Code Authentication
id: d68d8732-6f7e-4ee5-a6eb-737f2b990b91
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -62,7 +62,6 @@ tags:
asset_type: Azure Tenant
mitre_attack_id:
- T1528
- - T1566
- T1566.002
product:
- Splunk Enterprise
diff --git a/detections/cloud/azure_ad_external_guest_user_invited.yml b/detections/cloud/azure_ad_external_guest_user_invited.yml
index 0a30335c00..b21df736a9 100644
--- a/detections/cloud/azure_ad_external_guest_user_invited.yml
+++ b/detections/cloud/azure_ad_external_guest_user_invited.yml
@@ -1,6 +1,6 @@
name: Azure AD External Guest User Invited
id: c1fb4edb-cab1-4359-9b40-925ffd797fb5
-version: 5
+version: 6
date: '2024-11-14'
author: Gowthamaraj Rajendran, Mauricio Velazco, Splunk
status: production
diff --git a/detections/cloud/azure_ad_high_number_of_failed_authentications_for_user.yml b/detections/cloud/azure_ad_high_number_of_failed_authentications_for_user.yml
index 2ebfe3128c..f095735f34 100644
--- a/detections/cloud/azure_ad_high_number_of_failed_authentications_for_user.yml
+++ b/detections/cloud/azure_ad_high_number_of_failed_authentications_for_user.yml
@@ -1,7 +1,7 @@
name: Azure AD High Number Of Failed Authentications For User
id: 630b1694-210a-48ee-a450-6f79e7679f2c
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
- Azure Active Directory Account Takeover
asset_type: Azure Tenant
mitre_attack_id:
- - T1110
- T1110.001
product:
- Splunk Enterprise
diff --git a/detections/cloud/azure_ad_high_number_of_failed_authentications_from_ip.yml b/detections/cloud/azure_ad_high_number_of_failed_authentications_from_ip.yml
index 9829ad4b7a..27095cce04 100644
--- a/detections/cloud/azure_ad_high_number_of_failed_authentications_from_ip.yml
+++ b/detections/cloud/azure_ad_high_number_of_failed_authentications_from_ip.yml
@@ -1,7 +1,7 @@
name: Azure AD High Number Of Failed Authentications From Ip
id: e5ab41bf-745d-4f72-a393-2611151afd8e
-version: 7
-date: '2024-11-14'
+version: 8
+date: '2025-02-10'
author: Mauricio Velazco, Bhavin Patel, Splunk
status: production
type: TTP
@@ -62,7 +62,6 @@ tags:
- NOBELIUM Group
asset_type: Azure Tenant
mitre_attack_id:
- - T1110
- T1110.001
- T1110.003
product:
diff --git a/detections/cloud/azure_ad_multi_factor_authentication_disabled.yml b/detections/cloud/azure_ad_multi_factor_authentication_disabled.yml
index 9ede5d603b..850e70b076 100644
--- a/detections/cloud/azure_ad_multi_factor_authentication_disabled.yml
+++ b/detections/cloud/azure_ad_multi_factor_authentication_disabled.yml
@@ -1,7 +1,7 @@
name: Azure AD Multi-Factor Authentication Disabled
id: 482dd42a-acfa-486b-a0bb-d6fcda27318e
-version: 5
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -60,10 +60,8 @@ tags:
- Azure Active Directory Account Takeover
asset_type: Azure Active Directory
mitre_attack_id:
- - T1586
- - T1586.003
- - T1556
- T1556.006
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/azure_ad_multi_source_failed_authentications_spike.yml b/detections/cloud/azure_ad_multi_source_failed_authentications_spike.yml
index 01e3e46116..c0d6bedc46 100644
--- a/detections/cloud/azure_ad_multi_source_failed_authentications_spike.yml
+++ b/detections/cloud/azure_ad_multi_source_failed_authentications_spike.yml
@@ -1,7 +1,7 @@
name: Azure AD Multi-Source Failed Authentications Spike
id: 116e11a9-63ea-41eb-a66a-6a13bdc7d2c7
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -53,11 +53,9 @@ tags:
asset_type: Azure Tenant
atomic_guid: []
mitre_attack_id:
- - T1586
- - T1586.003
- - T1110
- T1110.003
- T1110.004
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml b/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml
index c132716d7b..19537e44b7 100644
--- a/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml
+++ b/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml
@@ -1,7 +1,7 @@
name: Azure AD Multiple Failed MFA Requests For User
id: 264ea131-ab1f-41b8-90e0-33ad1a1888ea
-version: 7
-date: '2024-11-14'
+version: 8
+date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -62,11 +62,9 @@ tags:
- Azure Active Directory Account Takeover
asset_type: Azure Active Directory
mitre_attack_id:
- - T1586
+ - T1078.004
- T1586.003
- T1621
- - T1078
- - T1078.004
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml b/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml
index db156f8d6c..6e6a789764 100644
--- a/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml
+++ b/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml
@@ -1,7 +1,7 @@
name: Azure AD Multiple Users Failing To Authenticate From Ip
id: 94481a6a-8f59-4c86-957f-55a71e3612a6
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -60,11 +60,9 @@ tags:
- Azure Active Directory Account Takeover
asset_type: Azure Active Directory
mitre_attack_id:
- - T1586
- - T1586.003
- - T1110
- T1110.003
- T1110.004
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/azure_ad_new_custom_domain_added.yml b/detections/cloud/azure_ad_new_custom_domain_added.yml
index 9e8a4514bd..07d389a8a6 100644
--- a/detections/cloud/azure_ad_new_custom_domain_added.yml
+++ b/detections/cloud/azure_ad_new_custom_domain_added.yml
@@ -1,7 +1,7 @@
name: Azure AD New Custom Domain Added
id: 30c47f45-dd6a-4720-9963-0bca6c8686ef
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
- Azure Active Directory Persistence
asset_type: Azure Active Directory
mitre_attack_id:
- - T1484
- T1484.002
product:
- Splunk Enterprise
diff --git a/detections/cloud/azure_ad_new_federated_domain_added.yml b/detections/cloud/azure_ad_new_federated_domain_added.yml
index 18765ab8c2..0f9a57ccca 100644
--- a/detections/cloud/azure_ad_new_federated_domain_added.yml
+++ b/detections/cloud/azure_ad_new_federated_domain_added.yml
@@ -1,7 +1,7 @@
name: Azure AD New Federated Domain Added
id: a87cd633-076d-4ab2-9047-977751a3c1a0
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
- Azure Active Directory Persistence
asset_type: Azure Active Directory
mitre_attack_id:
- - T1484
- T1484.002
product:
- Splunk Enterprise
diff --git a/detections/cloud/azure_ad_new_mfa_method_registered.yml b/detections/cloud/azure_ad_new_mfa_method_registered.yml
index 548366097d..7519b45a46 100644
--- a/detections/cloud/azure_ad_new_mfa_method_registered.yml
+++ b/detections/cloud/azure_ad_new_mfa_method_registered.yml
@@ -1,7 +1,7 @@
name: Azure AD New MFA Method Registered
id: 0488e814-eb81-42c3-9f1f-b2244973e3a3
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -62,7 +62,6 @@ tags:
- Azure Active Directory Persistence
asset_type: Azure Tenant
mitre_attack_id:
- - T1098
- T1098.005
product:
- Splunk Enterprise
diff --git a/detections/cloud/azure_ad_new_mfa_method_registered_for_user.yml b/detections/cloud/azure_ad_new_mfa_method_registered_for_user.yml
index aa0fd57ecc..5192c93cff 100644
--- a/detections/cloud/azure_ad_new_mfa_method_registered_for_user.yml
+++ b/detections/cloud/azure_ad_new_mfa_method_registered_for_user.yml
@@ -1,7 +1,7 @@
name: Azure AD New MFA Method Registered For User
id: 2628b087-4189-403f-9044-87403f777a1b
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
- Azure Active Directory Account Takeover
asset_type: Azure Active Directory
mitre_attack_id:
- - T1556
- T1556.006
product:
- Splunk Enterprise
diff --git a/detections/cloud/azure_ad_pim_role_assigned.yml b/detections/cloud/azure_ad_pim_role_assigned.yml
index 62cf108b66..51d57975fc 100644
--- a/detections/cloud/azure_ad_pim_role_assigned.yml
+++ b/detections/cloud/azure_ad_pim_role_assigned.yml
@@ -1,7 +1,7 @@
name: Azure AD PIM Role Assigned
id: fcd6dfeb-191c-46a0-a29c-c306382145ab
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
- Azure Active Directory Persistence
asset_type: Azure Active Directory
mitre_attack_id:
- - T1098
- T1098.003
product:
- Splunk Enterprise
diff --git a/detections/cloud/azure_ad_pim_role_assignment_activated.yml b/detections/cloud/azure_ad_pim_role_assignment_activated.yml
index 7904b536f7..08536eba75 100644
--- a/detections/cloud/azure_ad_pim_role_assignment_activated.yml
+++ b/detections/cloud/azure_ad_pim_role_assignment_activated.yml
@@ -1,7 +1,7 @@
name: Azure AD PIM Role Assignment Activated
id: 952e80d0-e343-439b-83f4-808c3e6fbf2e
-version: 7
-date: '2024-11-14'
+version: 8
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
- Azure Active Directory Persistence
asset_type: Azure Active Directory
mitre_attack_id:
- - T1098
- T1098.003
product:
- Splunk Enterprise
diff --git a/detections/cloud/azure_ad_privileged_role_assigned.yml b/detections/cloud/azure_ad_privileged_role_assigned.yml
index e08cfb1eea..c1316e7829 100644
--- a/detections/cloud/azure_ad_privileged_role_assigned.yml
+++ b/detections/cloud/azure_ad_privileged_role_assigned.yml
@@ -1,7 +1,7 @@
name: Azure AD Privileged Role Assigned
id: a28f0bc3-3400-4a6e-a2da-89b9e95f0d2a
-version: 6
-date: '2024-11-14'
+version: 8
+date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -65,7 +65,6 @@ tags:
- NOBELIUM Group
asset_type: Azure Active Directory
mitre_attack_id:
- - T1098
- T1098.003
product:
- Splunk Enterprise
diff --git a/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml b/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml
index 5cc46e6989..e054e3954c 100644
--- a/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml
+++ b/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml
@@ -1,7 +1,7 @@
name: Azure AD Privileged Role Assigned to Service Principal
id: 5dfaa3d3-e2e4-4053-8252-16d9ee528c41
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
- NOBELIUM Group
asset_type: Azure Active Directory
mitre_attack_id:
- - T1098
- T1098.003
product:
- Splunk Enterprise
diff --git a/detections/cloud/azure_ad_service_principal_enumeration.yml b/detections/cloud/azure_ad_service_principal_enumeration.yml
index 67af2a74cc..67efb06d67 100644
--- a/detections/cloud/azure_ad_service_principal_enumeration.yml
+++ b/detections/cloud/azure_ad_service_principal_enumeration.yml
@@ -1,6 +1,6 @@
name: Azure AD Service Principal Enumeration
id: 3f0647ce-add5-4436-8039-cbd1abe74563
-version: 1
+version: 2
date: '2025-01-06'
author: Dean Luxton
data_source:
diff --git a/detections/cloud/azure_ad_service_principal_new_client_credentials.yml b/detections/cloud/azure_ad_service_principal_new_client_credentials.yml
index c737df98b8..d61c4114f4 100644
--- a/detections/cloud/azure_ad_service_principal_new_client_credentials.yml
+++ b/detections/cloud/azure_ad_service_principal_new_client_credentials.yml
@@ -1,7 +1,7 @@
name: Azure AD Service Principal New Client Credentials
id: e3adc0d3-9e4b-4b5d-b662-12cec1adff2a
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -62,7 +62,6 @@ tags:
- NOBELIUM Group
asset_type: Azure Active Directory
mitre_attack_id:
- - T1098
- T1098.001
product:
- Splunk Enterprise
diff --git a/detections/cloud/azure_ad_service_principal_owner_added.yml b/detections/cloud/azure_ad_service_principal_owner_added.yml
index 652d5977ff..70759d0bbc 100644
--- a/detections/cloud/azure_ad_service_principal_owner_added.yml
+++ b/detections/cloud/azure_ad_service_principal_owner_added.yml
@@ -1,6 +1,6 @@
name: Azure AD Service Principal Owner Added
id: 7ddf2084-6cf3-4a44-be83-474f7b73c701
-version: 7
+version: 8
date: '2024-11-14'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
diff --git a/detections/cloud/azure_ad_service_principal_privilege_escalation.yml b/detections/cloud/azure_ad_service_principal_privilege_escalation.yml
index 29720e929f..ea9b383f6a 100644
--- a/detections/cloud/azure_ad_service_principal_privilege_escalation.yml
+++ b/detections/cloud/azure_ad_service_principal_privilege_escalation.yml
@@ -1,24 +1,35 @@
name: Azure AD Service Principal Privilege Escalation
id: 29eb39d3-2bc8-49cc-99b3-35593191a588
-version: 1
-date: '2025-01-06'
+version: 2
+date: '2025-02-10'
author: Dean Luxton
data_source:
- Azure Active Directory Add app role assignment to service principal
type: TTP
status: production
-description: This detection identifies when an Azure Service Principal elevates privileges by adding themself to a new app role assignment.
+description: This detection identifies when an Azure Service Principal elevates privileges
+ by adding themself to a new app role assignment.
search: >-
- `azure_monitor_aad` category=AuditLogs operationName="Add app role assignment to service principal" properties.initiatedBy.app.displayName=* properties.result=Success
- | spath path=properties{}.targetResources{}.modifiedProperties{} output=targetResources
- | stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value")))) as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName")))) as targetServicePrincipal values(eval(mvindex('properties.targetResources{}.displayName',0))) as targetAppContext values(user_agent) as user_agent values(identity) as servicePrincipal values(properties.initiatedBy.app.servicePrincipalId) as servicePrincipalId by operationName tenantId correlationId
+ `azure_monitor_aad` category=AuditLogs operationName="Add app role assignment to
+ service principal" properties.initiatedBy.app.displayName=* properties.result=Success |
+ spath path=properties{}.targetResources{}.modifiedProperties{} output=targetResources
+ | stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value"))))
+ as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName"))))
+ as targetServicePrincipal values(eval(mvindex('properties.targetResources{}.displayName',0)))
+ as targetAppContext values(user_agent) as user_agent values(identity) as servicePrincipal
+ values(properties.initiatedBy.app.servicePrincipalId) as servicePrincipalId by operationName
+ tenantId correlationId
| spath input=appRole path=newValue output=appRole
| spath input=targetServicePrincipal path=newValue output=targetServicePrincipal
- | eval appRole=trim(replace(appRole, "\"", "")), targetServicePrincipal=trim(replace(targetServicePrincipal, "\"", ""))
+ | eval appRole=trim(replace(appRole, "\"", "")), targetServicePrincipal=trim(replace(targetServicePrincipal,
+ "\"", ""))
| where servicePrincipal=targetServicePrincipal
- | table _time operationName servicePrincipal servicePrincipalId appRole targetAppContext user_agent tenantId correlationId
+ | table _time operationName servicePrincipal servicePrincipalId appRole targetAppContext
+ user_agent tenantId correlationId
| `azure_ad_service_principal_privilege_escalation_filter`
-how_to_implement: The Splunk Add-on for Microsoft Cloud Services add-on is required to ingest EntraID audit logs via Azure EventHub. See reference for links for further details on how to onboard this log source.
+how_to_implement: The Splunk Add-on for Microsoft Cloud Services add-on is required
+ to ingest EntraID audit logs via Azure EventHub. See reference for links for further
+ details on how to onboard this log source.
known_false_positives: Unknown
references:
- https://splunkbase.splunk.com/app/3110
@@ -32,11 +43,17 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$servicePrincipal$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$servicePrincipal$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$servicePrincipal$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
-rba:
- message: Service Principal $servicePrincipal$ has elevated privileges by adding themself to app role $appRole$
+rba:
+ message: Service Principal $servicePrincipal$ has elevated privileges by adding
+ themself to app role $appRole$
risk_objects:
- field: servicePrincipal
type: user
@@ -50,7 +67,6 @@ tags:
asset_type: Azure Tenant
mitre_attack_id:
- T1098.003
- - T1098
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -59,6 +75,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/azure_ad_spn_privesc/azure_ad_spn_privesc.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/azure_ad_spn_privesc/azure_ad_spn_privesc.log
sourcetype: azure:monitor:aad
source: Azure AD
diff --git a/detections/cloud/azure_ad_successful_authentication_from_different_ips.yml b/detections/cloud/azure_ad_successful_authentication_from_different_ips.yml
index 84f19bd9f2..a8a8cf0127 100644
--- a/detections/cloud/azure_ad_successful_authentication_from_different_ips.yml
+++ b/detections/cloud/azure_ad_successful_authentication_from_different_ips.yml
@@ -1,7 +1,7 @@
name: Azure AD Successful Authentication From Different Ips
id: be6d868d-33b6-4aaa-912e-724fb555b11a
-version: 7
-date: '2024-11-14'
+version: 8
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
- Azure Active Directory Account Takeover
asset_type: Azure Tenant
mitre_attack_id:
- - T1110
- T1110.001
- T1110.003
product:
diff --git a/detections/cloud/azure_ad_successful_powershell_authentication.yml b/detections/cloud/azure_ad_successful_powershell_authentication.yml
index 40fc93f31e..47cb6d8ad7 100644
--- a/detections/cloud/azure_ad_successful_powershell_authentication.yml
+++ b/detections/cloud/azure_ad_successful_powershell_authentication.yml
@@ -1,7 +1,7 @@
name: Azure AD Successful PowerShell Authentication
id: 62f10052-d7b3-4e48-b57b-56f8e3ac7ceb
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -60,10 +60,8 @@ tags:
- Azure Active Directory Account Takeover
asset_type: Azure Active Directory
mitre_attack_id:
- - T1586
- - T1586.003
- - T1078
- T1078.004
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/azure_ad_successful_single_factor_authentication.yml b/detections/cloud/azure_ad_successful_single_factor_authentication.yml
index 08b55c21be..0df441eb5a 100644
--- a/detections/cloud/azure_ad_successful_single_factor_authentication.yml
+++ b/detections/cloud/azure_ad_successful_single_factor_authentication.yml
@@ -1,7 +1,7 @@
name: Azure AD Successful Single-Factor Authentication
id: a560e7f6-1711-4353-885b-40be53101fcd
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -57,10 +57,8 @@ tags:
- Azure Active Directory Account Takeover
asset_type: Azure Active Directory
mitre_attack_id:
- - T1586
- - T1586.003
- - T1078
- T1078.004
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/azure_ad_tenant_wide_admin_consent_granted.yml b/detections/cloud/azure_ad_tenant_wide_admin_consent_granted.yml
index af3e2f430f..9e187787e0 100644
--- a/detections/cloud/azure_ad_tenant_wide_admin_consent_granted.yml
+++ b/detections/cloud/azure_ad_tenant_wide_admin_consent_granted.yml
@@ -1,7 +1,7 @@
name: Azure AD Tenant Wide Admin Consent Granted
id: dc02c0ee-6ac0-4c7f-87ba-8ce43a4e4418
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -62,7 +62,6 @@ tags:
- NOBELIUM Group
asset_type: Azure Tenant
mitre_attack_id:
- - T1098
- T1098.003
product:
- Splunk Enterprise
diff --git a/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml b/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml
index 24fdfff29f..b8d2b2b680 100644
--- a/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml
+++ b/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml
@@ -1,7 +1,7 @@
name: Azure AD Unusual Number of Failed Authentications From Ip
id: 3d8d3a36-93b8-42d7-8d91-c5f24cec223d
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -62,11 +62,9 @@ tags:
- Azure Active Directory Account Takeover
asset_type: Azure Active Directory
mitre_attack_id:
- - T1586
- - T1586.003
- - T1110
- T1110.003
- T1110.004
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/azure_ad_user_enabled_and_password_reset.yml b/detections/cloud/azure_ad_user_enabled_and_password_reset.yml
index 5cd6090c48..f3601f5b68 100644
--- a/detections/cloud/azure_ad_user_enabled_and_password_reset.yml
+++ b/detections/cloud/azure_ad_user_enabled_and_password_reset.yml
@@ -1,6 +1,6 @@
name: Azure AD User Enabled And Password Reset
id: 1347b9e8-2daa-4a6f-be73-b421d3d9e268
-version: 6
+version: 7
date: '2024-11-14'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
diff --git a/detections/cloud/azure_ad_user_immutableid_attribute_updated.yml b/detections/cloud/azure_ad_user_immutableid_attribute_updated.yml
index 597d44032d..bb46d01420 100644
--- a/detections/cloud/azure_ad_user_immutableid_attribute_updated.yml
+++ b/detections/cloud/azure_ad_user_immutableid_attribute_updated.yml
@@ -1,6 +1,6 @@
name: Azure AD User ImmutableId Attribute Updated
id: 0c0badad-4536-4a84-a561-5ff760f3c00e
-version: 5
+version: 6
date: '2024-11-14'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
diff --git a/detections/cloud/azure_automation_account_created.yml b/detections/cloud/azure_automation_account_created.yml
index 61c90cb7d6..9bbaf90a45 100644
--- a/detections/cloud/azure_automation_account_created.yml
+++ b/detections/cloud/azure_automation_account_created.yml
@@ -1,7 +1,7 @@
name: Azure Automation Account Created
id: 860902fd-2e76-46b3-b050-ba548dab576c
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
- Azure Active Directory Persistence
asset_type: Azure Tenant
mitre_attack_id:
- - T1136
- T1136.003
product:
- Splunk Enterprise
diff --git a/detections/cloud/azure_automation_runbook_created.yml b/detections/cloud/azure_automation_runbook_created.yml
index 30cd14ac36..2188fcc83f 100644
--- a/detections/cloud/azure_automation_runbook_created.yml
+++ b/detections/cloud/azure_automation_runbook_created.yml
@@ -1,7 +1,7 @@
name: Azure Automation Runbook Created
id: 178d696d-6dc6-4ee8-9d25-93fee34eaf5b
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
- Azure Active Directory Persistence
asset_type: Azure Tenant
mitre_attack_id:
- - T1136
- T1136.003
product:
- Splunk Enterprise
diff --git a/detections/cloud/azure_runbook_webhook_created.yml b/detections/cloud/azure_runbook_webhook_created.yml
index f380d8cff2..d53e163981 100644
--- a/detections/cloud/azure_runbook_webhook_created.yml
+++ b/detections/cloud/azure_runbook_webhook_created.yml
@@ -1,7 +1,7 @@
name: Azure Runbook Webhook Created
id: e98944a9-92e4-443c-81b8-a322e33ce75a
-version: 7
-date: '2024-11-14'
+version: 8
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
- Azure Active Directory Persistence
asset_type: Azure Tenant
mitre_attack_id:
- - T1078
- T1078.004
product:
- Splunk Enterprise
diff --git a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml
index 4608e0889a..67198da281 100644
--- a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml
+++ b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml
@@ -1,7 +1,7 @@
name: Cloud Compute Instance Created By Previously Unseen User
id: 37a0ec8d-827e-4d6d-8025-cedf31f3a149
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Rico Valdez, Splunk
status: experimental
type: Anomaly
@@ -46,7 +46,6 @@ tags:
asset_type: Cloud Compute Instance
mitre_attack_id:
- T1078.004
- - T1078
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml b/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml
index d3189b230e..ffe314acbf 100644
--- a/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml
+++ b/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml
@@ -1,7 +1,7 @@
name: Cloud Instance Modified By Previously Unseen User
id: 7fb15084-b14e-405a-bd61-a6de15a40722
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Rico Valdez, Splunk
status: experimental
type: Anomaly
@@ -44,7 +44,6 @@ tags:
asset_type: AWS Instance
mitre_attack_id:
- T1078.004
- - T1078
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/detect_aws_console_login_by_new_user.yml b/detections/cloud/detect_aws_console_login_by_new_user.yml
index ac6587474d..135b7f9126 100644
--- a/detections/cloud/detect_aws_console_login_by_new_user.yml
+++ b/detections/cloud/detect_aws_console_login_by_new_user.yml
@@ -1,7 +1,7 @@
name: Detect AWS Console Login by New User
id: bc91a8cd-35e7-4bb2-6140-e756cc46fd71
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Rico Valdez, Splunk
status: experimental
type: Hunting
@@ -38,9 +38,8 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Instance
mitre_attack_id:
- - T1586
- - T1586.003
- T1552
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml
index 2fea4b9d13..041ef49278 100644
--- a/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml
+++ b/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml
@@ -1,7 +1,7 @@
name: Detect AWS Console Login by User from New City
id: 121b0b11-f8ac-4ed6-a132-3800ca4fc07a
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Bhavin Patel, Eric McGinnis Splunk
status: production
type: Hunting
@@ -45,9 +45,8 @@ tags:
- Compromised User Account
asset_type: AWS Instance
mitre_attack_id:
- - T1586
- - T1586.003
- T1535
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml
index afbc290db7..11effae0f4 100644
--- a/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml
+++ b/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml
@@ -1,7 +1,7 @@
name: Detect AWS Console Login by User from New Country
id: 67bd3def-c41c-4bf6-837b-ae196b4257c6
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Bhavin Patel, Eric McGinnis Splunk
status: production
type: Hunting
@@ -45,9 +45,8 @@ tags:
- Compromised User Account
asset_type: AWS Instance
mitre_attack_id:
- - T1586
- - T1586.003
- T1535
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml
index 8c47e6e6a9..9fc447b49b 100644
--- a/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml
+++ b/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml
@@ -1,7 +1,7 @@
name: Detect AWS Console Login by User from New Region
id: 9f31aa8e-e37c-46bc-bce1-8b3be646d026
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Bhavin Patel, Eric McGinnis Splunk
status: production
type: Hunting
@@ -46,9 +46,8 @@ tags:
- Compromised User Account
asset_type: AWS Instance
mitre_attack_id:
- - T1586
- - T1586.003
- T1535
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml b/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml
index 86cae6e982..be2a129f28 100644
--- a/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml
+++ b/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml
@@ -1,7 +1,7 @@
name: GCP Authentication Failed During MFA Challenge
id: 345f7e1d-a3fe-4158-abd8-e630f9878323
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Bhavin Patel, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -55,10 +55,8 @@ tags:
- GCP Account Takeover
asset_type: Google Cloud Platform tenant
mitre_attack_id:
- - T1586
- - T1586.003
- - T1078
- T1078.004
+ - T1586.003
- T1621
product:
- Splunk Enterprise
diff --git a/detections/cloud/gcp_multi_factor_authentication_disabled.yml b/detections/cloud/gcp_multi_factor_authentication_disabled.yml
index dc6b0479ea..adb0fa638a 100644
--- a/detections/cloud/gcp_multi_factor_authentication_disabled.yml
+++ b/detections/cloud/gcp_multi_factor_authentication_disabled.yml
@@ -1,7 +1,7 @@
name: GCP Multi-Factor Authentication Disabled
id: b9bc5513-6fc1-4821-85a3-e1d81e451c83
-version: 5
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Bhavin Patel, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -58,10 +58,8 @@ tags:
- GCP Account Takeover
asset_type: GCP
mitre_attack_id:
- - T1586
- - T1586.003
- - T1556
- T1556.006
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml b/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml
index 613b536a54..1a8d679b8a 100644
--- a/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml
+++ b/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml
@@ -1,7 +1,7 @@
name: GCP Multiple Failed MFA Requests For User
id: cbb3cb84-c06f-4393-adcc-5cb6195621f1
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -60,11 +60,9 @@ tags:
- GCP Account Takeover
asset_type: Google Cloud Platform tenant
mitre_attack_id:
- - T1586
+ - T1078.004
- T1586.003
- T1621
- - T1078
- - T1078.004
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml b/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml
index e5b02c1c25..3d44e59505 100644
--- a/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml
+++ b/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml
@@ -1,7 +1,7 @@
name: GCP Multiple Users Failing To Authenticate From Ip
id: da20828e-d6fb-4ee5-afb7-d0ac200923d5
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: Anomaly
@@ -61,11 +61,9 @@ tags:
- GCP Account Takeover
asset_type: Google Cloud Platform tenant
mitre_attack_id:
- - T1586
- - T1586.003
- - T1110
- T1110.003
- T1110.004
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/gcp_successful_single_factor_authentication.yml b/detections/cloud/gcp_successful_single_factor_authentication.yml
index 3f13fa8928..8f1d80ddae 100644
--- a/detections/cloud/gcp_successful_single_factor_authentication.yml
+++ b/detections/cloud/gcp_successful_single_factor_authentication.yml
@@ -1,7 +1,7 @@
name: GCP Successful Single-Factor Authentication
id: 40e17d88-87da-414e-b253-8dc1e4f9555b
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Bhavin Patel, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -57,10 +57,8 @@ tags:
- GCP Account Takeover
asset_type: Google Cloud Platform tenant
mitre_attack_id:
- - T1586
- - T1586.003
- - T1078
- T1078.004
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml b/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml
index 7e59b0346a..1ab7a9b099 100644
--- a/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml
+++ b/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml
@@ -1,7 +1,7 @@
name: GCP Unusual Number of Failed Authentications From Ip
id: bd8097ed-958a-4873-87d9-44f2b4d85705
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: Anomaly
@@ -63,11 +63,9 @@ tags:
- GCP Account Takeover
asset_type: Google Cloud Platform tenant
mitre_attack_id:
- - T1586
- - T1586.003
- - T1110
- T1110.003
- T1110.004
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/github_actions_disable_security_workflow.yml b/detections/cloud/github_actions_disable_security_workflow.yml
index 8d8f8d8c2a..e9e0bdb045 100644
--- a/detections/cloud/github_actions_disable_security_workflow.yml
+++ b/detections/cloud/github_actions_disable_security_workflow.yml
@@ -1,7 +1,7 @@
name: GitHub Actions Disable Security Workflow
id: 0459f1a5-c0ac-4987-82d6-65081209f854
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -57,7 +57,6 @@ tags:
asset_type: GitHub
mitre_attack_id:
- T1195.002
- - T1195
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/github_dependabot_alert.yml b/detections/cloud/github_dependabot_alert.yml
index 0e93d69aae..b4e1b2b108 100644
--- a/detections/cloud/github_dependabot_alert.yml
+++ b/detections/cloud/github_dependabot_alert.yml
@@ -1,7 +1,7 @@
name: GitHub Dependabot Alert
id: 05032b04-4469-4034-9df7-05f607d75cba
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -52,7 +52,6 @@ tags:
asset_type: GitHub
mitre_attack_id:
- T1195.001
- - T1195
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/github_pull_request_from_unknown_user.yml b/detections/cloud/github_pull_request_from_unknown_user.yml
index 8cfcb7f5fc..44fcbc501e 100644
--- a/detections/cloud/github_pull_request_from_unknown_user.yml
+++ b/detections/cloud/github_pull_request_from_unknown_user.yml
@@ -1,7 +1,7 @@
name: GitHub Pull Request from Unknown User
id: 9d7b9100-8878-4404-914e-ca5e551a641e
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -53,7 +53,6 @@ tags:
asset_type: GitHub
mitre_attack_id:
- T1195.001
- - T1195
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/gsuite_drive_share_in_external_email.yml b/detections/cloud/gsuite_drive_share_in_external_email.yml
index 469c97577b..0ad1ce1463 100644
--- a/detections/cloud/gsuite_drive_share_in_external_email.yml
+++ b/detections/cloud/gsuite_drive_share_in_external_email.yml
@@ -1,7 +1,7 @@
name: Gsuite Drive Share In External Email
id: f6ee02d6-fea0-11eb-b2c2-acde48001122
-version: 4
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: experimental
type: Anomaly
@@ -49,7 +49,6 @@ tags:
asset_type: GSuite
mitre_attack_id:
- T1567.002
- - T1567
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/gsuite_email_suspicious_attachment.yml b/detections/cloud/gsuite_email_suspicious_attachment.yml
index 7c29d2848b..36963d2120 100644
--- a/detections/cloud/gsuite_email_suspicious_attachment.yml
+++ b/detections/cloud/gsuite_email_suspicious_attachment.yml
@@ -1,7 +1,7 @@
name: GSuite Email Suspicious Attachment
id: 6d663014-fe92-11eb-ab07-acde48001122
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -59,7 +59,6 @@ tags:
asset_type: GSuite
mitre_attack_id:
- T1566.001
- - T1566
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml b/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml
index 9a0e32f6bd..014b621125 100644
--- a/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml
+++ b/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml
@@ -1,7 +1,7 @@
name: Gsuite Email Suspicious Subject With Attachment
id: 8ef3971e-00f2-11ec-b54f-acde48001122
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -64,7 +64,6 @@ tags:
asset_type: GSuite
mitre_attack_id:
- T1566.001
- - T1566
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml b/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml
index cc41adee08..6d4f09108b 100644
--- a/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml
+++ b/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml
@@ -1,7 +1,7 @@
name: Gsuite Email With Known Abuse Web Service Link
id: 8630aa22-042b-11ec-af39-acde48001122
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -58,7 +58,6 @@ tags:
asset_type: GSuite
mitre_attack_id:
- T1566.001
- - T1566
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml b/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml
index e154a605f3..196839b387 100644
--- a/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml
+++ b/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml
@@ -1,7 +1,7 @@
name: Gsuite Outbound Email With Attachment To External Domain
id: dc4dc3a8-ff54-11eb-8bf7-acde48001122
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Stanislav Miskovic, Splunk
status: production
type: Hunting
@@ -37,7 +37,6 @@ tags:
asset_type: GSuite
mitre_attack_id:
- T1048.003
- - T1048
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/gsuite_suspicious_shared_file_name.yml b/detections/cloud/gsuite_suspicious_shared_file_name.yml
index 311f449b7f..a660e05c8c 100644
--- a/detections/cloud/gsuite_suspicious_shared_file_name.yml
+++ b/detections/cloud/gsuite_suspicious_shared_file_name.yml
@@ -1,7 +1,7 @@
name: Gsuite Suspicious Shared File Name
id: 07eed200-03f5-11ec-98fb-acde48001122
-version: 4
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -65,7 +65,6 @@ tags:
asset_type: GSuite
mitre_attack_id:
- T1566.001
- - T1566
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/high_number_of_login_failures_from_a_single_source.yml b/detections/cloud/high_number_of_login_failures_from_a_single_source.yml
index a42e10bb7f..7f6fe588f5 100644
--- a/detections/cloud/high_number_of_login_failures_from_a_single_source.yml
+++ b/detections/cloud/high_number_of_login_failures_from_a_single_source.yml
@@ -1,7 +1,7 @@
name: High Number of Login Failures from a single source
id: 7f398cfb-918d-41f4-8db8-2e2474e02222
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Bhavin Patel, Mauricio Velazco, Splunk
status: production
type: Anomaly
@@ -60,7 +60,6 @@ tags:
asset_type: O365 Tenant
mitre_attack_id:
- T1110.001
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/o365_add_app_role_assignment_grant_user.yml b/detections/cloud/o365_add_app_role_assignment_grant_user.yml
index 40dbc0137d..4137c89c71 100644
--- a/detections/cloud/o365_add_app_role_assignment_grant_user.yml
+++ b/detections/cloud/o365_add_app_role_assignment_grant_user.yml
@@ -1,7 +1,7 @@
name: O365 Add App Role Assignment Grant User
id: b2c81cc6-6040-11eb-ae93-0242ac130002
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Rod Soto, Splunk
status: production
type: TTP
@@ -59,7 +59,6 @@ tags:
asset_type: O365 Tenant
mitre_attack_id:
- T1136.003
- - T1136
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/o365_added_service_principal.yml b/detections/cloud/o365_added_service_principal.yml
index 239d6317b9..ead8633c06 100644
--- a/detections/cloud/o365_added_service_principal.yml
+++ b/detections/cloud/o365_added_service_principal.yml
@@ -1,7 +1,7 @@
name: O365 Added Service Principal
id: 1668812a-6047-11eb-ae93-0242ac130002
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Rod Soto, Splunk
status: production
type: TTP
@@ -59,7 +59,6 @@ tags:
asset_type: O365 Tenant
mitre_attack_id:
- T1136.003
- - T1136
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/o365_advanced_audit_disabled.yml b/detections/cloud/o365_advanced_audit_disabled.yml
index fde6c3a0f8..ac2211f458 100644
--- a/detections/cloud/o365_advanced_audit_disabled.yml
+++ b/detections/cloud/o365_advanced_audit_disabled.yml
@@ -1,7 +1,7 @@
name: O365 Advanced Audit Disabled
id: 49862dd4-9cb2-4c48-a542-8c8a588d9361
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Michael Haag, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
- Office 365 Persistence Mechanisms
asset_type: O365 Tenant
mitre_attack_id:
- - T1562
- T1562.008
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_application_available_to_other_tenants.yml b/detections/cloud/o365_application_available_to_other_tenants.yml
index 0ecc7bab04..1f1a06b147 100644
--- a/detections/cloud/o365_application_available_to_other_tenants.yml
+++ b/detections/cloud/o365_application_available_to_other_tenants.yml
@@ -1,7 +1,7 @@
name: O365 Application Available To Other Tenants
id: 942548a3-0273-47a4-8dbd-e5202437395c
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
asset_type: O365 Tenant
mitre_attack_id:
- T1098.003
- - T1098
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/o365_applicationimpersonation_role_assigned.yml b/detections/cloud/o365_applicationimpersonation_role_assigned.yml
index 777f8755aa..ece9018152 100644
--- a/detections/cloud/o365_applicationimpersonation_role_assigned.yml
+++ b/detections/cloud/o365_applicationimpersonation_role_assigned.yml
@@ -1,7 +1,7 @@
name: O365 ApplicationImpersonation Role Assigned
id: 49cdce75-f814-4d56-a7a4-c64ec3a481f2
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
- NOBELIUM Group
asset_type: O365 Tenant
mitre_attack_id:
- - T1098
- T1098.002
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml b/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml
index 6ad687a266..e0b6f6f7fc 100644
--- a/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml
+++ b/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml
@@ -1,7 +1,7 @@
name: O365 Bypass MFA via Trusted IP
id: c783dd98-c703-4252-9e8a-f19d9f66949e
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Bhavin Patel, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
asset_type: O365 Tenant
mitre_attack_id:
- T1562.007
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/o365_compliance_content_search_exported.yml b/detections/cloud/o365_compliance_content_search_exported.yml
index 74ff0f6355..56cbf61d9c 100644
--- a/detections/cloud/o365_compliance_content_search_exported.yml
+++ b/detections/cloud/o365_compliance_content_search_exported.yml
@@ -1,7 +1,7 @@
name: O365 Compliance Content Search Exported
id: 2ce9f31d-ab4f-4179-b2b7-c77a9652e1d8
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source: []
type: TTP
@@ -53,7 +53,6 @@ tags:
- Office 365 Collection Techniques
asset_type: O365 Tenant
mitre_attack_id:
- - T1114
- T1114.002
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_compliance_content_search_started.yml b/detections/cloud/o365_compliance_content_search_started.yml
index 2b4440c1d1..554aaf4c15 100644
--- a/detections/cloud/o365_compliance_content_search_started.yml
+++ b/detections/cloud/o365_compliance_content_search_started.yml
@@ -1,7 +1,7 @@
name: O365 Compliance Content Search Started
id: f4cabbc7-c19a-4e41-8be5-98daeaccbb50
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source: []
type: TTP
@@ -53,7 +53,6 @@ tags:
- Office 365 Collection Techniques
asset_type: O365 Tenant
mitre_attack_id:
- - T1114
- T1114.002
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_elevated_mailbox_permission_assigned.yml b/detections/cloud/o365_elevated_mailbox_permission_assigned.yml
index 361a0b8cf7..3b9ff5e1f8 100644
--- a/detections/cloud/o365_elevated_mailbox_permission_assigned.yml
+++ b/detections/cloud/o365_elevated_mailbox_permission_assigned.yml
@@ -1,7 +1,7 @@
name: O365 Elevated Mailbox Permission Assigned
id: 2246c142-a678-45f8-8546-aaed7e0efd30
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Patrick Bareiss, Mauricio Velazco, Splunk
data_source: []
type: TTP
@@ -53,7 +53,6 @@ tags:
- Office 365 Collection Techniques
asset_type: O365 Tenant
mitre_attack_id:
- - T1098
- T1098.002
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_email_access_by_security_administrator.yml b/detections/cloud/o365_email_access_by_security_administrator.yml
index 99d7b99204..df598e1fa9 100644
--- a/detections/cloud/o365_email_access_by_security_administrator.yml
+++ b/detections/cloud/o365_email_access_by_security_administrator.yml
@@ -1,7 +1,7 @@
name: O365 Email Access By Security Administrator
id: c6998a30-fef4-4e89-97ac-3bb0123719b4
-version: 3
-date: '2024-11-14'
+version: 4
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -54,9 +54,8 @@ tags:
- Office 365 Account Takeover
asset_type: O365 Tenant
mitre_attack_id:
- - T1567
- - T1114
- T1114.002
+ - T1567
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/o365_email_reported_by_admin_found_malicious.yml b/detections/cloud/o365_email_reported_by_admin_found_malicious.yml
index 0a5d4aa0fa..405e008e80 100644
--- a/detections/cloud/o365_email_reported_by_admin_found_malicious.yml
+++ b/detections/cloud/o365_email_reported_by_admin_found_malicious.yml
@@ -1,7 +1,7 @@
name: O365 Email Reported By Admin Found Malicious
id: 94396c3e-7728-422a-9956-e4b77b53dbdf
-version: 3
-date: '2024-11-14'
+version: 4
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
- Suspicious Emails
asset_type: O365 Tenant
mitre_attack_id:
- - T1566
- T1566.001
- T1566.002
product:
diff --git a/detections/cloud/o365_email_reported_by_user_found_malicious.yml b/detections/cloud/o365_email_reported_by_user_found_malicious.yml
index edbf3a10b7..685ecb2198 100644
--- a/detections/cloud/o365_email_reported_by_user_found_malicious.yml
+++ b/detections/cloud/o365_email_reported_by_user_found_malicious.yml
@@ -1,7 +1,7 @@
name: O365 Email Reported By User Found Malicious
id: 7698b945-238e-4bb9-b172-81f5ca1685a1
-version: 3
-date: '2024-11-14'
+version: 4
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -59,7 +59,6 @@ tags:
- Suspicious Emails
asset_type: O365 Tenant
mitre_attack_id:
- - T1566
- T1566.001
- T1566.002
product:
diff --git a/detections/cloud/o365_email_security_feature_changed.yml b/detections/cloud/o365_email_security_feature_changed.yml
index 9afe560662..983ce4e11a 100644
--- a/detections/cloud/o365_email_security_feature_changed.yml
+++ b/detections/cloud/o365_email_security_feature_changed.yml
@@ -1,7 +1,7 @@
name: O365 Email Security Feature Changed
id: 4d28013d-3a0f-4d65-a33f-4e8009fee0ae
-version: 3
-date: '2024-11-14'
+version: 4
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -51,9 +51,8 @@ tags:
- Office 365 Account Takeover
asset_type: O365 Tenant
mitre_attack_id:
- - T1562
- - T1562.008
- T1562.001
+ - T1562.008
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/o365_email_suspicious_behavior_alert.yml b/detections/cloud/o365_email_suspicious_behavior_alert.yml
index f6770028e1..5714addcec 100644
--- a/detections/cloud/o365_email_suspicious_behavior_alert.yml
+++ b/detections/cloud/o365_email_suspicious_behavior_alert.yml
@@ -1,7 +1,7 @@
name: O365 Email Suspicious Behavior Alert
id: 85c7555a-05af-4322-81aa-76b4ddf52baa
-version: 3
-date: '2024-11-14'
+version: 4
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -54,7 +54,6 @@ tags:
- Office 365 Account Takeover
asset_type: O365 Tenant
mitre_attack_id:
- - T1114
- T1114.003
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_email_transport_rule_changed.yml b/detections/cloud/o365_email_transport_rule_changed.yml
new file mode 100644
index 0000000000..bd7a4f1ee2
--- /dev/null
+++ b/detections/cloud/o365_email_transport_rule_changed.yml
@@ -0,0 +1,67 @@
+name: O365 Email Transport Rule Changed
+id: 11ebb7c2-46bd-41c9-81e1-d0b4b34583a2
+version: 1
+date: '2025-01-15'
+author: Steven Dick
+status: production
+type: Anomaly
+description: The following analytic identifies when a user with sufficient access to Exchange Online alters the mail flow/transport rule configuration of the organization. Transport rules are a set of rules that can be used by attackers to modify or delete emails based on specific conditions, this activity could indicate an attacker hiding or exfiltrated data.
+data_source:
+- Office 365 Universal Audit Log
+search: |-
+ `o365_management_activity` Workload=Exchange AND Operation IN ("Set-*","Disable-*","New-*","Remove-*") AND Operation="*TransportRule"
+ | eval object_name = case('Parameters{}.Name'=="Name",mvindex('Parameters{}.Value',mvfind('Parameters{}.Name',"^Name$")),true(),ObjectId), object_id = case('Parameters{}.Name'=="Identity",mvindex('Parameters{}.Value',mvfind('Parameters{}.Name',"^Identity$")),true(),Id)
+ | stats values(object_name) as object_name, min(_time) as firstTime, max(_time) as lastTime, count by object_id, UserId, Operation
+ | rename UserId as user, Operation as signature
+ | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`
+ | `o365_email_transport_rule_changed_filter`
+how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest Office 365 management activity events.
+known_false_positives: Legitimate administrative changes for business needs.
+references:
+- https://attack.mitre.org/techniques/T1114/003/
+- https://cardinalops.com/blog/cardinalops-contributes-new-mitre-attck-techniques-related-to-abuse-of-mail-transport-rules/
+- https://www.microsoft.com/en-us/security/blog/2022/09/22/malicious-OAuth-applications-used-to-compromise-email-servers-and-spread-spam/
+drilldown_searches:
+- name: View the detection results for - "$user$"
+ search: '%original_detection_search% | search user = "$user$"'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: View risk events for the last 7 days for - "$user$"
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: Investigate changes by $user$
+ search: '`o365_management_activity` Workload=Exchange AND Operation IN ("Set-*","Disable-*","New-*","Remove-*") AND Operation="*Transport*" UserId=$user$'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+rba:
+ message: The user [$user$] altered the exchange transport rule id [$object_name$]
+ risk_objects:
+ - field: user
+ type: user
+ score: 25
+ threat_objects:
+ - field: object_id
+ type: signature
+ - field: object_name
+ type: signature
+tags:
+ analytic_story:
+ - Data Exfiltration
+ - Office 365 Account Takeover
+ asset_type: O365 Tenant
+ mitre_attack_id:
+ - T1114.003
+ - T1564.008
+ product:
+ - Splunk Enterprise
+ - Splunk Enterprise Security
+ - Splunk Cloud
+ security_domain: threat
+tests:
+- name: True Positive Test
+ attack_data:
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114.003/transport_rule_change/transport_rule_change.log
+ source: o365
+ sourcetype: o365:management:activity
diff --git a/detections/cloud/o365_high_number_of_failed_authentications_for_user.yml b/detections/cloud/o365_high_number_of_failed_authentications_for_user.yml
index 41d867d860..259430989e 100644
--- a/detections/cloud/o365_high_number_of_failed_authentications_for_user.yml
+++ b/detections/cloud/o365_high_number_of_failed_authentications_for_user.yml
@@ -1,7 +1,7 @@
name: O365 High Number Of Failed Authentications for User
id: 31641378-2fa9-42b1-948e-25e281cb98f7
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -54,7 +54,6 @@ tags:
- Office 365 Account Takeover
asset_type: O365 Tenant
mitre_attack_id:
- - T1110
- T1110.001
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_high_privilege_role_granted.yml b/detections/cloud/o365_high_privilege_role_granted.yml
index bbe4d281d2..57d53359d0 100644
--- a/detections/cloud/o365_high_privilege_role_granted.yml
+++ b/detections/cloud/o365_high_privilege_role_granted.yml
@@ -1,7 +1,7 @@
name: O365 High Privilege Role Granted
id: e78a1037-4548-4072-bb1b-ad99ae416426
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -56,7 +56,6 @@ tags:
- Office 365 Persistence Mechanisms
asset_type: O365 Tenant
mitre_attack_id:
- - T1098
- T1098.003
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_mailbox_email_forwarding_enabled.yml b/detections/cloud/o365_mailbox_email_forwarding_enabled.yml
index 28c3e91e3f..d4f69f2bd4 100644
--- a/detections/cloud/o365_mailbox_email_forwarding_enabled.yml
+++ b/detections/cloud/o365_mailbox_email_forwarding_enabled.yml
@@ -1,7 +1,7 @@
name: O365 Mailbox Email Forwarding Enabled
id: 0b6bc75c-05d1-4101-9fc3-97e706168f24
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Patrick Bareiss, Mauricio Velazco, Splunk
data_source: []
type: TTP
@@ -54,7 +54,6 @@ tags:
- Office 365 Collection Techniques
asset_type: O365 Tenant
mitre_attack_id:
- - T1114
- T1114.003
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_mailbox_folder_read_permission_assigned.yml b/detections/cloud/o365_mailbox_folder_read_permission_assigned.yml
index e3f85487ae..867df0355e 100644
--- a/detections/cloud/o365_mailbox_folder_read_permission_assigned.yml
+++ b/detections/cloud/o365_mailbox_folder_read_permission_assigned.yml
@@ -1,7 +1,7 @@
name: O365 Mailbox Folder Read Permission Assigned
id: 1435475e-2128-4417-a34f-59770733b0d5
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source: []
type: TTP
@@ -55,7 +55,6 @@ tags:
- Office 365 Collection Techniques
asset_type: O365 Tenant
mitre_attack_id:
- - T1098
- T1098.002
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_mailbox_folder_read_permission_granted.yml b/detections/cloud/o365_mailbox_folder_read_permission_granted.yml
index 6b0939ee72..b6ad3e3269 100644
--- a/detections/cloud/o365_mailbox_folder_read_permission_granted.yml
+++ b/detections/cloud/o365_mailbox_folder_read_permission_granted.yml
@@ -1,7 +1,7 @@
name: O365 Mailbox Folder Read Permission Granted
id: cd15c0a8-470e-4b12-9517-046e4927db30
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source: []
type: TTP
@@ -54,7 +54,6 @@ tags:
- Office 365 Collection Techniques
asset_type: O365 Tenant
mitre_attack_id:
- - T1098
- T1098.002
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_mailbox_inbox_folder_shared_with_all_users.yml b/detections/cloud/o365_mailbox_inbox_folder_shared_with_all_users.yml
index 253de4acee..079ba2b14a 100644
--- a/detections/cloud/o365_mailbox_inbox_folder_shared_with_all_users.yml
+++ b/detections/cloud/o365_mailbox_inbox_folder_shared_with_all_users.yml
@@ -1,7 +1,7 @@
name: O365 Mailbox Inbox Folder Shared with All Users
id: 21421896-a692-4594-9888-5faeb8a53106
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -59,7 +59,6 @@ tags:
- Office 365 Persistence Mechanisms
asset_type: O365 Tenant
mitre_attack_id:
- - T1114
- T1114.002
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_mailbox_read_access_granted_to_application.yml b/detections/cloud/o365_mailbox_read_access_granted_to_application.yml
index 73b115897f..ea65305c88 100644
--- a/detections/cloud/o365_mailbox_read_access_granted_to_application.yml
+++ b/detections/cloud/o365_mailbox_read_access_granted_to_application.yml
@@ -1,7 +1,7 @@
name: O365 Mailbox Read Access Granted to Application
id: 27ab61c5-f08a-438a-b4d3-325e666490b3
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -59,10 +59,8 @@ tags:
- Office 365 Persistence Mechanisms
asset_type: O365 Tenant
mitre_attack_id:
- - T1114.002
- - T1114
- - T1098
- T1098.003
+ - T1114.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/o365_multi_source_failed_authentications_spike.yml b/detections/cloud/o365_multi_source_failed_authentications_spike.yml
index 3c21195c01..275cba424d 100644
--- a/detections/cloud/o365_multi_source_failed_authentications_spike.yml
+++ b/detections/cloud/o365_multi_source_failed_authentications_spike.yml
@@ -1,7 +1,7 @@
name: O365 Multi-Source Failed Authentications Spike
id: ea4e2c41-dbfb-4f5f-a7b6-9ac1b7f104aa
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -45,11 +45,9 @@ tags:
asset_type: O365 Tenant
atomic_guid: []
mitre_attack_id:
- - T1586
- - T1586.003
- - T1110
- T1110.003
- T1110.004
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/o365_multiple_os_vendors_authenticating_from_user.yml b/detections/cloud/o365_multiple_os_vendors_authenticating_from_user.yml
new file mode 100644
index 0000000000..743aca09e9
--- /dev/null
+++ b/detections/cloud/o365_multiple_os_vendors_authenticating_from_user.yml
@@ -0,0 +1,66 @@
+name: O365 Multiple OS Vendors Authenticating From User
+id: 3451e58a-9457-4985-a600-b616b0cbfda1
+version: 1
+date: '2024-12-19'
+author: Steven Dick
+status: production
+type: TTP
+description: The following analytic identifies when multiple operating systems are used to authenticate to Azure/EntraID/Office 365 by the same user account over a short period of time. This activity could be indicative of attackers enumerating various logon capabilities of Azure/EntraID/Office 365 and attempting to discover weaknesses in the organizational MFA or conditional access configurations. Usage of the tools like "MFASweep" will trigger this detection.
+data_source:
+- Office 365 Universal Audit Log
+search: |-
+ `o365_management_activity` Operation IN (UserLoginFailed,UserLoggedIn)
+ | eval -time = _time
+ | bin _time span=15m
+ | stats values(Operation) as signature, values(ErrorNumber) as signature_id, values(OS) as os_name, dc(OS) as os_count, count, min(-time) as firstTime, max(-time) as lastTime by ClientIP, UserId, _time
+ | where os_count >= 4
+ | eval src = ClientIP, user = UserId
+ | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`
+ | `o365_multiple_os_vendors_authenticating_from_user_filter`
+how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest Office 365 management activity events. The thresholds set within the analytic (such as unique OS) are initial guidelines and should be customized based on the organization's user behavior and risk profile. Security teams are encouraged to adjust these thresholds to optimize the balance between detecting genuine threats and minimizing false positives, ensuring the detection is tailored to their specific environment.
+known_false_positives: IP or users where the usage of multiple Operating systems is expected, filter accordingly.
+references:
+- https://attack.mitre.org/techniques/T1110
+- https://www.blackhillsinfosec.com/exploiting-mfa-inconsistencies-on-microsoft-services/
+- https://sra.io/blog/msspray-wait-how-many-endpoints-dont-have-mfa/
+- https://github.com/dafthack/MFASweep/tree/master
+drilldown_searches:
+- name: View the detection results for - "$user$"
+ search: '%original_detection_search% | search user = "$user$"'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: View risk events for the last 7 days for - "$user$"
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: Investigate logons from $user$
+ search: '`o365_management_activity` Operation IN (UserLoginFailed,UserLoggedIn) "$user$"'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+rba:
+ message: The user account $user$ authenticated with $os_count$ unique operating system types over a short period from $src$.
+ risk_objects:
+ - field: user
+ type: user
+ score: 60
+ threat_objects:
+ - field: src
+ type: ip_address
+tags:
+ analytic_story:
+ - Office 365 Account Takeover
+ asset_type: O365 Tenant
+ mitre_attack_id:
+ - T1110
+ product:
+ - Splunk Enterprise
+ - Splunk Enterprise Security
+ - Splunk Cloud
+ security_domain: threat
+tests:
+- name: True Positive Test
+ attack_data:
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110/azure_mfasweep_events/azure_mfasweep_events.log
+ source: o365
+ sourcetype: o365:management:activity
diff --git a/detections/cloud/o365_multiple_users_failing_to_authenticate_from_ip.yml b/detections/cloud/o365_multiple_users_failing_to_authenticate_from_ip.yml
index 24496ddc87..70df08df04 100644
--- a/detections/cloud/o365_multiple_users_failing_to_authenticate_from_ip.yml
+++ b/detections/cloud/o365_multiple_users_failing_to_authenticate_from_ip.yml
@@ -1,7 +1,7 @@
name: O365 Multiple Users Failing To Authenticate From Ip
id: 8d486e2e-3235-4cfe-ac35-0d042e24ecb4
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -58,11 +58,9 @@ tags:
- NOBELIUM Group
asset_type: O365 Tenant
mitre_attack_id:
- - T1586
- - T1586.003
- - T1110
- T1110.003
- T1110.004
+ - T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/o365_new_email_forwarding_rule_created.yml b/detections/cloud/o365_new_email_forwarding_rule_created.yml
index cee90dcbdc..2ec1c2eb73 100644
--- a/detections/cloud/o365_new_email_forwarding_rule_created.yml
+++ b/detections/cloud/o365_new_email_forwarding_rule_created.yml
@@ -1,7 +1,7 @@
name: O365 New Email Forwarding Rule Created
id: 68469fd0-1315-44ba-b7e4-e92847bb76d6
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source: []
type: TTP
@@ -53,7 +53,6 @@ tags:
- Office 365 Collection Techniques
asset_type: O365 Tenant
mitre_attack_id:
- - T1114
- T1114.003
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_new_email_forwarding_rule_enabled.yml b/detections/cloud/o365_new_email_forwarding_rule_enabled.yml
index dcc6b1b909..f6ca3b2785 100644
--- a/detections/cloud/o365_new_email_forwarding_rule_enabled.yml
+++ b/detections/cloud/o365_new_email_forwarding_rule_enabled.yml
@@ -1,7 +1,7 @@
name: O365 New Email Forwarding Rule Enabled
id: ac7c4d0a-06a3-4278-aa59-88a5e537f981
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source: []
type: TTP
@@ -57,7 +57,6 @@ tags:
- Office 365 Collection Techniques
asset_type: O365 Tenant
mitre_attack_id:
- - T1114
- T1114.003
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_new_federated_domain_added.yml b/detections/cloud/o365_new_federated_domain_added.yml
index 6dcebc1fbe..c2cd3a3f0e 100644
--- a/detections/cloud/o365_new_federated_domain_added.yml
+++ b/detections/cloud/o365_new_federated_domain_added.yml
@@ -1,7 +1,7 @@
name: O365 New Federated Domain Added
id: e155876a-6048-11eb-ae93-0242ac130002
-version: 6
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Rod Soto, Mauricio Velazco Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
asset_type: O365 Tenant
mitre_attack_id:
- T1136.003
- - T1136
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/o365_new_mfa_method_registered.yml b/detections/cloud/o365_new_mfa_method_registered.yml
index f5278b8e52..25bcbb5336 100644
--- a/detections/cloud/o365_new_mfa_method_registered.yml
+++ b/detections/cloud/o365_new_mfa_method_registered.yml
@@ -1,7 +1,7 @@
name: O365 New MFA Method Registered
id: 4e12db1f-f7c7-486d-8152-a221cad6ac2b
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
- Office 365 Persistence Mechanisms
asset_type: O365 Tenant
mitre_attack_id:
- - T1098
- T1098.005
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_privileged_role_assigned.yml b/detections/cloud/o365_privileged_role_assigned.yml
index 975cdaa4a0..349eb0ce48 100644
--- a/detections/cloud/o365_privileged_role_assigned.yml
+++ b/detections/cloud/o365_privileged_role_assigned.yml
@@ -1,7 +1,7 @@
name: O365 Privileged Role Assigned
id: db435700-4ddc-4c23-892e-49e7525d7d39
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -62,7 +62,6 @@ tags:
- Azure Active Directory Persistence
asset_type: O365 Tenant
mitre_attack_id:
- - T1098
- T1098.003
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_privileged_role_assigned_to_service_principal.yml b/detections/cloud/o365_privileged_role_assigned_to_service_principal.yml
index f984d8f1de..cc56ca9835 100644
--- a/detections/cloud/o365_privileged_role_assigned_to_service_principal.yml
+++ b/detections/cloud/o365_privileged_role_assigned_to_service_principal.yml
@@ -1,7 +1,7 @@
name: O365 Privileged Role Assigned To Service Principal
id: 80f3fc1b-705f-4080-bf08-f61bf013b900
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -66,7 +66,6 @@ tags:
- Azure Active Directory Privilege Escalation
asset_type: O365 Tenant
mitre_attack_id:
- - T1098
- T1098.003
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_safe_links_detection.yml b/detections/cloud/o365_safe_links_detection.yml
index 1c85c2120c..48f5edc84e 100644
--- a/detections/cloud/o365_safe_links_detection.yml
+++ b/detections/cloud/o365_safe_links_detection.yml
@@ -1,7 +1,7 @@
name: O365 Safe Links Detection
id: 711d9e8c-2cb0-45cf-8813-5f191ecb9b26
-version: 3
-date: '2024-11-14'
+version: 4
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -52,7 +52,6 @@ tags:
- Spearphishing Attachments
asset_type: O365 Tenant
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_security_and_compliance_alert_triggered.yml b/detections/cloud/o365_security_and_compliance_alert_triggered.yml
index f7a2340203..b479777630 100644
--- a/detections/cloud/o365_security_and_compliance_alert_triggered.yml
+++ b/detections/cloud/o365_security_and_compliance_alert_triggered.yml
@@ -1,7 +1,7 @@
name: O365 Security And Compliance Alert Triggered
id: 5b367cdd-8dfc-49ac-a9b7-6406cf27f33e
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source: []
type: TTP
@@ -58,7 +58,6 @@ tags:
- Office 365 Account Takeover
asset_type: O365 Tenant
mitre_attack_id:
- - T1078
- T1078.004
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_service_principal_new_client_credentials.yml b/detections/cloud/o365_service_principal_new_client_credentials.yml
index 702f8ee8f9..fbb1bcb8bd 100644
--- a/detections/cloud/o365_service_principal_new_client_credentials.yml
+++ b/detections/cloud/o365_service_principal_new_client_credentials.yml
@@ -1,7 +1,7 @@
name: O365 Service Principal New Client Credentials
id: a1b229e9-d962-4222-8c62-905a8a010453
-version: 5
-date: '2024-11-14'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
- NOBELIUM Group
asset_type: O365 Tenant
mitre_attack_id:
- - T1098
- T1098.001
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_service_principal_privilege_escalation.yml b/detections/cloud/o365_service_principal_privilege_escalation.yml
index ee93c75401..899a257bb4 100644
--- a/detections/cloud/o365_service_principal_privilege_escalation.yml
+++ b/detections/cloud/o365_service_principal_privilege_escalation.yml
@@ -1,23 +1,32 @@
name: O365 Service Principal Privilege Escalation
id: b686d0bd-cca7-44ca-ae07-87f6465131d9
-version: 1
-date: '2025-01-06'
+version: 2
+date: '2025-02-10'
author: Dean Luxton
data_source:
- O365 Add app role assignment grant to user
type: TTP
status: production
-description: This detection identifies when an Azure Service Principal elevates privileges by adding themself to a new app role assignment.
-search: >-
- `o365_management_activity` Operation="Add app role assignment to service principal." "Actor{}.ID"=ServicePrincipal ResultStatus=Success
+description: This detection identifies when an Azure Service Principal elevates privileges
+ by adding themself to a new app role assignment.
+search: >-
+ `o365_management_activity` Operation="Add app role assignment to service principal."
+ "Actor{}.ID"=ServicePrincipal ResultStatus=Success
| spath path=ModifiedProperties{} output=targetResources
- | stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value")))) as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName")))) as targetServicePrincipal values(object) as targetAppContext values(user_agent) as user_agent values(user) as servicePrincipal values(UserId) as servicePrincipalId by Operation InterSystemsId tenant_id
+ | stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value"))))
+ as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName"))))
+ as targetServicePrincipal values(object) as targetAppContext values(user_agent)
+ as user_agent values(user) as servicePrincipal values(UserId) as servicePrincipalId by
+ Operation InterSystemsId tenant_id
| spath input=appRole path=NewValue output=appRole
| spath input=targetServicePrincipal path=NewValue output=targetServicePrincipal
| where servicePrincipal=targetServicePrincipal
- | table _time Operation servicePrincipal servicePrincipalId appRole targetAppContext user_agent tenant_id InterSystemsId
+ | table _time Operation servicePrincipal servicePrincipalId appRole targetAppContext
+ user_agent tenant_id InterSystemsId
| `o365_service_principal_privilege_escalation_filter`
-how_to_implement: The Splunk Add-on for Microsoft Office 365 add-on is required to ingest EntraID audit logs via the 365 API. See references for links for further details on how to onboard this log source.
+how_to_implement: The Splunk Add-on for Microsoft Office 365 add-on is required to
+ ingest EntraID audit logs via the 365 API. See references for links for further
+ details on how to onboard this log source.
known_false_positives: Unknown
references:
- https://splunkbase.splunk.com/app/4055
@@ -30,11 +39,17 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$servicePrincipal$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$servicePrincipal$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$servicePrincipal$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
- message: Service Principal $servicePrincipal$ has elevated privileges by adding themself to app role $appRole$
+ message: Service Principal $servicePrincipal$ has elevated privileges by adding
+ themself to app role $appRole$
risk_objects:
- field: servicePrincipal
type: user
@@ -49,7 +64,6 @@ tags:
asset_type: Azure Tenant
mitre_attack_id:
- T1098.003
- - T1098
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -58,6 +72,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/o365_spn_privesc/o365_spn_privesc.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/o365_spn_privesc/o365_spn_privesc.log
sourcetype: o365:management:activity
source: Office 365
diff --git a/detections/cloud/o365_sharepoint_malware_detection.yml b/detections/cloud/o365_sharepoint_malware_detection.yml
index a3136a5595..e3ec3d7abc 100644
--- a/detections/cloud/o365_sharepoint_malware_detection.yml
+++ b/detections/cloud/o365_sharepoint_malware_detection.yml
@@ -1,7 +1,7 @@
name: O365 SharePoint Malware Detection
id: 583c5de3-7709-44cb-abfc-0e828d301b59
-version: 3
-date: '2024-11-14'
+version: 4
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -53,7 +53,6 @@ tags:
asset_type: O365 Tenant
mitre_attack_id:
- T1204.002
- - T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml b/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml
new file mode 100644
index 0000000000..52449ed52b
--- /dev/null
+++ b/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml
@@ -0,0 +1,67 @@
+name: O365 SharePoint Suspicious Search Behavior
+id: 6ca919db-52f3-4c95-a4e9-7b189e8a043d
+version: 1
+date: '2025-01-08'
+author: Steven Dick
+status: production
+type: Anomaly
+description: The following analytic identifies when the O365 SharePoint users search for suspicious keywords or have an excessive number of queries within a limited timeframe. This behavior may indicate malicious actor enumeration of SharePoint based data within O365.
+data_source:
+- Office 365 Universal Audit Log
+search: |-
+ `o365_management_activity` Workload=SharePoint Operation="SearchQueryPerformed" SearchQueryText=* EventData=*search*
+ | where NOT (match(SearchQueryText, "\*") OR match(SearchQueryText,"(\*)"))
+ | eval signature_id = CorrelationId, signature=Operation, src = ClientIP, user = UserId, object_name=EventData, command = SearchQueryText, -time = _time
+ | bin _time span=1hr
+ | stats values(object_name) as object_name values(command) as command, values(src) as src, dc(command) as count, min(-time) as firstTime, max(-time) as lastTime by user,signature,_time
+ | where count > 20 OR match(command, "(?i)password|credential|passwd|shadow|active directory|account|username|network|computer|access|MFA|bank|deposit|payroll|EFT|Electonic Funds|routing")
+ | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`
+ | `o365_sharepoint_suspicious_search_behavior_filter`
+how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest Office 365 management activity events. The thresholds and match terms set within the analytic are initial guidelines and should be customized based on the organization's user behavior and risk profile. Security teams are encouraged to adjust these thresholds to optimize the balance between detecting genuine threats and minimizing false positives, ensuring the detection is tailored to their specific environment.
+known_false_positives: Users searching excessively or possible false positives related to matching conditions.
+references:
+- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a
+- https://attack.mitre.org/techniques/T1213/002/
+drilldown_searches:
+- name: View the detection results for - "$user$"
+ search: '%original_detection_search% | search user = "$user$"'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: View risk events for the last 7 days for - "$user$"
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: Investigate search behavior by $user$
+ search: '`o365_management_activity` Workload=SharePoint Operation="SearchQueryPerformed" SearchQueryText=* EventData=*search* AND UserId = "$user$"'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+rba:
+ message: The SharePoint Online was searched suspiciously by $user$
+ risk_objects:
+ - field: user
+ type: user
+ score: 25
+ threat_objects:
+ - field: src
+ type: ip_address
+tags:
+ analytic_story:
+ - Azure Active Directory Persistence
+ - Office 365 Account Takeover
+ - CISA AA22-320A
+ asset_type: O365 Tenant
+ mitre_attack_id:
+ - T1213.002
+ - T1552
+ product:
+ - Splunk Enterprise
+ - Splunk Enterprise Security
+ - Splunk Cloud
+ security_domain: threat
+tests:
+- name: True Positive Test
+ attack_data:
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1213.002/o365_sus_sharepoint_search/o365_sus_sharepoint_search.log
+ source: o365
+ sourcetype: o365:management:activity
diff --git a/detections/cloud/o365_tenant_wide_admin_consent_granted.yml b/detections/cloud/o365_tenant_wide_admin_consent_granted.yml
index 5375087924..9d9a2e8780 100644
--- a/detections/cloud/o365_tenant_wide_admin_consent_granted.yml
+++ b/detections/cloud/o365_tenant_wide_admin_consent_granted.yml
@@ -1,7 +1,7 @@
name: O365 Tenant Wide Admin Consent Granted
id: 50eaabf8-5180-4e86-bfb2-011472c359fc
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
- NOBELIUM Group
asset_type: O365 Tenant
mitre_attack_id:
- - T1098
- T1098.003
product:
- Splunk Enterprise
diff --git a/detections/cloud/o365_threat_intelligence_suspicious_email_delivered.yml b/detections/cloud/o365_threat_intelligence_suspicious_email_delivered.yml
index b2142169f6..80ffe96469 100644
--- a/detections/cloud/o365_threat_intelligence_suspicious_email_delivered.yml
+++ b/detections/cloud/o365_threat_intelligence_suspicious_email_delivered.yml
@@ -1,7 +1,7 @@
name: O365 Threat Intelligence Suspicious Email Delivered
id: 605cc93a-70e4-4ee3-9a3d-1a62e8c9b6c2
-version: 3
-date: '2024-11-14'
+version: 4
+date: '2025-02-10'
author: Steven Dick
status: production
type: Anomaly
@@ -63,7 +63,6 @@ tags:
- Suspicious Emails
asset_type: O365 Tenant
mitre_attack_id:
- - T1566
- T1566.001
- T1566.002
product:
diff --git a/detections/cloud/o365_threat_intelligence_suspicious_file_detected.yml b/detections/cloud/o365_threat_intelligence_suspicious_file_detected.yml
index d7fcb9eb0a..f6313dcc2c 100644
--- a/detections/cloud/o365_threat_intelligence_suspicious_file_detected.yml
+++ b/detections/cloud/o365_threat_intelligence_suspicious_file_detected.yml
@@ -1,7 +1,7 @@
name: O365 Threat Intelligence Suspicious File Detected
id: 00958c7b-35db-4e7a-ad13-31550a7a7c64
-version: 3
-date: '2024-11-14'
+version: 4
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
asset_type: O365 Tenant
mitre_attack_id:
- T1204.002
- - T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/cloud/o365_zap_activity_detection.yml b/detections/cloud/o365_zap_activity_detection.yml
index b16c86afb1..daab34fb89 100644
--- a/detections/cloud/o365_zap_activity_detection.yml
+++ b/detections/cloud/o365_zap_activity_detection.yml
@@ -1,7 +1,7 @@
name: O365 ZAP Activity Detection
id: 4df275fd-a0e5-4246-8b92-d3201edaef7a
-version: 3
-date: '2024-11-14'
+version: 4
+date: '2025-02-10'
author: Steven Dick
status: production
type: Anomaly
@@ -58,7 +58,6 @@ tags:
- Suspicious Emails
asset_type: O365 Tenant
mitre_attack_id:
- - T1566
- T1566.001
- T1566.002
product:
diff --git a/detections/cloud/risk_rule_for_dev_sec_ops_by_repository.yml b/detections/cloud/risk_rule_for_dev_sec_ops_by_repository.yml
index f1555d3ff6..145748eea0 100644
--- a/detections/cloud/risk_rule_for_dev_sec_ops_by_repository.yml
+++ b/detections/cloud/risk_rule_for_dev_sec_ops_by_repository.yml
@@ -1,7 +1,7 @@
name: Risk Rule for Dev Sec Ops by Repository
id: 161bc0ca-4651-4c13-9c27-27770660cf67
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Bhavin Patel
status: production
type: Correlation
@@ -47,7 +47,6 @@ tags:
asset_type: Amazon Elastic Container Registry
mitre_attack_id:
- T1204.003
- - T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/deprecated/account_discovery_with_net_app.yml b/detections/deprecated/account_discovery_with_net_app.yml
index bf2568a3f0..074b4fba7a 100644
--- a/detections/deprecated/account_discovery_with_net_app.yml
+++ b/detections/deprecated/account_discovery_with_net_app.yml
@@ -1,7 +1,7 @@
name: Account Discovery With Net App
id: 339805ce-ac30-11eb-b87d-acde48001122
-version: 8
-date: '2025-01-13'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, TheLawsOfChaos, Github Community
status: deprecated
type: TTP
@@ -72,7 +72,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1087.002
- - T1087
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/deprecated/attempt_to_stop_security_service.yml b/detections/deprecated/attempt_to_stop_security_service.yml
index 09f69ad572..1964d9b110 100644
--- a/detections/deprecated/attempt_to_stop_security_service.yml
+++ b/detections/deprecated/attempt_to_stop_security_service.yml
@@ -1,7 +1,7 @@
name: Attempt To Stop Security Service
id: c8e349c6-b97c-486e-8949-bd7bcd1f3910
-version: 9
-date: '2025-01-24'
+version: 11
+date: '2025-02-10'
author: Rico Valdez, Splunk
status: deprecated
type: TTP
@@ -80,7 +80,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml
index 38fdbf95b5..65c188a991 100644
--- a/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml
+++ b/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml
@@ -1,7 +1,7 @@
name: Attempted Credential Dump From Registry via Reg exe
id: e9fb4a59-c5fb-440a-9f24-191fbc6b2911
-version: 12
-date: '2025-01-15'
+version: 14
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: deprecated
type: TTP
@@ -80,7 +80,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.002
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml
index d59e586b5a..91a576d2f0 100644
--- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml
+++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml
@@ -15,8 +15,8 @@ search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceI
sourceIPAddress | search City=* | stats earliest(_time) as firstTime, latest(_time)
as lastTime by sourceIPAddress, City, Region, Country | inputlookup append=t previously_seen_provisioning_activity_src
| stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress,
- City, Region, Country | outputlookup previously_seen_provisioning_activity_src |
- stats min(firstTime) as firstTime max(lastTime) as lastTime by City | eval newCity=if(firstTime
+ City, Region, Country | outputlookup previously_seen_provisioning_activity_src
+ | stats min(firstTime) as firstTime max(lastTime) as lastTime by City | eval newCity=if(firstTime
>= relative_time(now(), "-70m@m"), 1, 0) | where newCity=1 | table City] | spath
output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time, user,
src_ip, City, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_city_filter`'
diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml
index 05ecc67be0..986a31d1f0 100644
--- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml
+++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml
@@ -14,13 +14,13 @@ search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceI
| search Country=* [search `cloudtrail` (eventName=Run* OR eventName=Create*) |
iplocation sourceIPAddress | search Country=* | stats earliest(_time) as firstTime,
latest(_time) as lastTime by sourceIPAddress, City, Region, Country | inputlookup
- append=t previously_seen_provisioning_activity_src | stats min(firstTime) as firstTime
- max(lastTime) as lastTime by sourceIPAddress, City, Region, Country | outputlookup
- previously_seen_provisioning_activity_src | stats min(firstTime) as firstTime max(lastTime)
- as lastTime by Country | eval newCountry=if(firstTime >= relative_time(now(), "-70m@m"),
- 1, 0) | where newCountry=1 | table Country] | spath output=user userIdentity.arn
- | rename sourceIPAddress as src_ip | table _time, user, src_ip, Country, eventName,
- errorCode | `aws_cloud_provisioning_from_previously_unseen_country_filter`'
+ append=t previously_seen_provisioning_activity_src | stats min(firstTime) as
+ firstTime max(lastTime) as lastTime by sourceIPAddress, City, Region, Country |
+ outputlookup previously_seen_provisioning_activity_src | stats min(firstTime)
+ as firstTime max(lastTime) as lastTime by Country | eval newCountry=if(firstTime
+ >= relative_time(now(), "-70m@m"), 1, 0) | where newCountry=1 | table Country] |
+ spath output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time,
+ user, src_ip, Country, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_country_filter`'
how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later)
and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail
inputs. This search works best when you run the "Previously Seen AWS Provisioning
diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml
index 7adba589db..5efa68a449 100644
--- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml
+++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml
@@ -15,8 +15,8 @@ search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceI
sourceIPAddress | search Region=* | stats earliest(_time) as firstTime, latest(_time)
as lastTime by sourceIPAddress, City, Region, Country | inputlookup append=t previously_seen_provisioning_activity_src
| stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress,
- City, Region, Country | outputlookup previously_seen_provisioning_activity_src |
- stats min(firstTime) as firstTime max(lastTime) as lastTime by Region | eval newRegion=if(firstTime
+ City, Region, Country | outputlookup previously_seen_provisioning_activity_src
+ | stats min(firstTime) as firstTime max(lastTime) as lastTime by Region | eval newRegion=if(firstTime
>= relative_time(now(), "-70m@m"), 1, 0) | where newRegion=1 | table Region] | spath
output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time, user,
src_ip, Region, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_region_filter`'
diff --git a/detections/deprecated/change_default_file_association.yml b/detections/deprecated/change_default_file_association.yml
index b524230015..e5e583848a 100644
--- a/detections/deprecated/change_default_file_association.yml
+++ b/detections/deprecated/change_default_file_association.yml
@@ -1,7 +1,7 @@
name: Change Default File Association
id: 462d17d8-1f71-11ec-ad07-acde48001122
-version: 5
-date: '2025-01-24'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: deprecated
type: TTP
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1546.001
- - T1546
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml b/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml
index 1df440f488..74087020ed 100644
--- a/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml
+++ b/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml
@@ -1,7 +1,7 @@
name: Cmdline Tool Not Executed In CMD Shell
id: 6c3f7dd8-153c-11ec-ac2d-acde48001122
-version: 7
-date: '2025-01-24'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: deprecated
type: TTP
@@ -86,7 +86,6 @@ tags:
- Gozi Malware
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.007
product:
- Splunk Enterprise
diff --git a/detections/deprecated/correlation_by_repository_and_risk.yml b/detections/deprecated/correlation_by_repository_and_risk.yml
index 2629b408ff..681f046bf4 100644
--- a/detections/deprecated/correlation_by_repository_and_risk.yml
+++ b/detections/deprecated/correlation_by_repository_and_risk.yml
@@ -1,7 +1,7 @@
name: Correlation by Repository and Risk
id: 8da9fdd9-6a1b-4ae0-8a34-8c25e6be9687
-version: 3
-date: '2024-11-14'
+version: 4
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: deprecated
type: Correlation
@@ -20,7 +20,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1204.003
- - T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/deprecated/correlation_by_user_and_risk.yml b/detections/deprecated/correlation_by_user_and_risk.yml
index 63d9c738ae..d121453be9 100644
--- a/detections/deprecated/correlation_by_user_and_risk.yml
+++ b/detections/deprecated/correlation_by_user_and_risk.yml
@@ -1,7 +1,7 @@
name: Correlation by User and Risk
id: 610e12dc-b6fa-4541-825e-4a0b3b6f6773
-version: 3
-date: '2024-11-14'
+version: 4
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: deprecated
type: Correlation
@@ -20,7 +20,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1204.003
- - T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/deprecated/create_local_admin_accounts_using_net_exe.yml b/detections/deprecated/create_local_admin_accounts_using_net_exe.yml
index cf89f5b1ac..05bd612ba3 100644
--- a/detections/deprecated/create_local_admin_accounts_using_net_exe.yml
+++ b/detections/deprecated/create_local_admin_accounts_using_net_exe.yml
@@ -1,7 +1,7 @@
name: Create local admin accounts using net exe
id: b89919ed-fe5f-492c-b139-151bb162040e
-version: 15
-date: '2025-01-24'
+version: 17
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: deprecated
type: TTP
@@ -78,7 +78,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1136.001
- - T1136
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/deprecated/deleting_of_net_users.yml b/detections/deprecated/deleting_of_net_users.yml
index cb8dc58817..379264584f 100644
--- a/detections/deprecated/deleting_of_net_users.yml
+++ b/detections/deprecated/deleting_of_net_users.yml
@@ -1,18 +1,18 @@
name: Deleting Of Net Users
id: 1c8c6f66-acce-11eb-aafb-acde48001122
-version: 7
+version: 8
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
type: TTP
-description: The following analytic has been deprecated. The following analytic detects
- the use of net.exe or net1.exe command-line to delete a user account on a system.
- It leverages data from Endpoint Detection and Response (EDR) agents, focusing on
- process and command-line execution logs. This activity is significant as it may
- indicate an attempt to impair user accounts or cover tracks during lateral movement.
- If confirmed malicious, this could lead to unauthorized access removal, disruption
- of legitimate user activities, or concealment of adversarial actions, complicating
- incident response and forensic investigations.
+description: The following analytic has been deprecated.
+ The following analytic detects the use of net.exe or net1.exe command-line
+ to delete a user account on a system. It leverages data from Endpoint Detection
+ and Response (EDR) agents, focusing on process and command-line execution logs.
+ This activity is significant as it may indicate an attempt to impair user accounts
+ or cover tracks during lateral movement. If confirmed malicious, this could lead
+ to unauthorized access removal, disruption of legitimate user activities, or concealment
+ of adversarial actions, complicating incident response and forensic investigations.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml b/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml
index 0c13a55b87..9b6c9aec2c 100644
--- a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml
+++ b/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml
@@ -1,7 +1,7 @@
name: Detect Activity Related to Pass the Hash Attacks
id: f5939373-8054-40ad-8c64-cec478a22a4b
-version: 9
-date: '2024-11-14'
+version: 10
+date: '2025-02-10'
author: Bhavin Patel, Patrick Bareiss, Splunk
status: deprecated
type: Hunting
@@ -29,7 +29,6 @@ tags:
- BlackSuit Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1550
- T1550.002
product:
- Splunk Enterprise
diff --git a/detections/deprecated/detect_critical_alerts_from_security_tools.yml b/detections/deprecated/detect_critical_alerts_from_security_tools.yml
index 75848f931f..79ba56809d 100644
--- a/detections/deprecated/detect_critical_alerts_from_security_tools.yml
+++ b/detections/deprecated/detect_critical_alerts_from_security_tools.yml
@@ -8,40 +8,10 @@ type: TTP
data_source:
- Windows Defender Alerts
- MS365 Defender Incident Alerts
-description: The following analytic has been deprecated in favour of specific and
- dedicated product analytics such as "Microsoft Defender ATP Alerts". The following
- analytic is to detect high and critical alerts from endpoint security tools such
- as Microsoft Defender, Carbon Black, and Crowdstrike. This query aggregates and
- summarizes critical severity alerts from the Alerts data model, providing details
- such as the alert signature, application, description, source, destination, and
- timestamps, while applying custom filters and formatting for enhanced analysis in
- a SIEM environment.This capability allows security teams to efficiently allocate
- resources and maintain a strong security posture, while also supporting compliance
- with regulatory requirements by providing a clear record of critical security events.
- We tested these detections with logs from Microsoft Defender, however this detection
- should work for any security alerts that are ingested into the alerts data model.
- **Note** - We are dynamically creating the risk_score field based on the severity
- of the alert in the SPL and that supersedes the risk score set in the detection.
-search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
- as lastTime values(Alerts.description) as description values(Alerts.mitre_technique_id)
- as annotations.mitre_attack.mitre_technique_id values(Alerts.severity) as severity
- values(Alerts.type) as type values(Alerts.severity_id) as severity_id values(Alerts.signature)
- as signature values(Alerts.signature_id) as signature_id values(Alerts.dest) as
- dest from datamodel=Alerts where Alerts.severity IN ("high","critical") by Alerts.src
- Alerts.user Alerts.id Alerts.vendor sourcetype | `drop_dm_object_name("Alerts")`
- | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | eval
- risk_score=case(severity="informational", 2, severity="low", 5, severity="medium",
- 10, severity="high", 50, severity="critical" , 100) | `detect_critical_alerts_from_security_tools_filter`'
-how_to_implement: In order to properly run this search, you to ingest alerts data
- from other security products such as Crowdstrike, Microsoft Defender, or Carbon
- Black using appropriate TAs for that technology. Once ingested, the fields should
- be mapped to the Alerts data model. Make sure to apply transformation on the data
- if necessary. The risk_score field is used to calculate the risk score for the alerts
- and the mitre_technique_id field is used to map the alerts to the MITRE ATT&CK framework
- is dynamically created by the detection when this is triggered. These fields need
- not be set in the adaptive response actions.
-known_false_positives: False positives may vary by endpoint protection tool; monitor
- and filter out the alerts that are not relevant to your environment.
+description: The following analytic has been deprecated in favour of specific and dedicated product analytics such as "Microsoft Defender ATP Alerts". The following analytic is to detect high and critical alerts from endpoint security tools such as Microsoft Defender, Carbon Black, and Crowdstrike. This query aggregates and summarizes critical severity alerts from the Alerts data model, providing details such as the alert signature, application, description, source, destination, and timestamps, while applying custom filters and formatting for enhanced analysis in a SIEM environment.This capability allows security teams to efficiently allocate resources and maintain a strong security posture, while also supporting compliance with regulatory requirements by providing a clear record of critical security events. We tested these detections with logs from Microsoft Defender, however this detection should work for any security alerts that are ingested into the alerts data model. **Note** - We are dynamically creating the risk_score field based on the severity of the alert in the SPL and that supersedes the risk score set in the detection.
+search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Alerts.description) as description values(Alerts.mitre_technique_id) as annotations.mitre_attack.mitre_technique_id values(Alerts.severity) as severity values(Alerts.type) as type values(Alerts.severity_id) as severity_id values(Alerts.signature) as signature values(Alerts.signature_id) as signature_id values(Alerts.dest) as dest from datamodel=Alerts where Alerts.severity IN ("high","critical") by Alerts.src Alerts.user Alerts.id Alerts.vendor sourcetype | `drop_dm_object_name("Alerts")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | eval risk_score=case(severity="informational", 2, severity="low", 5, severity="medium", 10, severity="high", 50, severity="critical" , 100) | `detect_critical_alerts_from_security_tools_filter`'
+how_to_implement: In order to properly run this search, you to ingest alerts data from other security products such as Crowdstrike, Microsoft Defender, or Carbon Black using appropriate TAs for that technology. Once ingested, the fields should be mapped to the Alerts data model. Make sure to apply transformation on the data if necessary. The risk_score field is used to calculate the risk score for the alerts and the mitre_technique_id field is used to map the alerts to the MITRE ATT&CK framework is dynamically created by the detection when this is triggered. These fields need not be set in the adaptive response actions.
+known_false_positives: False positives may vary by endpoint protection tool; monitor and filter out the alerts that are not relevant to your environment.
references:
- https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/accessing-microsoft-defender-for-cloud-alerts-in-splunk-using/ba-p/938228
- https://docs.splunk.com/Documentation/CIM/5.3.2/User/Alerts
diff --git a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml
index 67c72e7e14..2d4975f3ec 100644
--- a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml
+++ b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml
@@ -31,9 +31,9 @@ how_to_implement: "You need to ingest data from your DNS logs in the Network_Res
add the correct hostname to the \"Phantom Instance\" field in the Adaptive Response
Actions when configuring this detection search, and set the corresponding Playbook
to active.\n(Playbook link:`https://my.phantom.us/4.2/playbook/lets-encrypt-domain-investigate/`)"
-known_false_positives: If a known good domain is not listed in the `legit_domains`
- lookup, then the search could give you false postives. Please update that lookup
- file to filter out DNS requests to legitimate domains.
+known_false_positives: If a known good domain is not listed in the `legit_domains` lookup,
+ then the search could give you false postives. Please update that lookup file
+ to filter out DNS requests to legitimate domains.
references: []
rba:
message: DNS Request for EvilGinx2 Phishing Site
diff --git a/detections/deprecated/detect_mimikatz_using_loaded_images.yml b/detections/deprecated/detect_mimikatz_using_loaded_images.yml
index b002ff2bcc..75e66c0061 100644
--- a/detections/deprecated/detect_mimikatz_using_loaded_images.yml
+++ b/detections/deprecated/detect_mimikatz_using_loaded_images.yml
@@ -1,7 +1,7 @@
name: Detect Mimikatz Using Loaded Images
id: 29e307ba-40af-4ab2-91b2-3c6b392bbba0
-version: 3
-date: '2024-11-14'
+version: 4
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: deprecated
type: TTP
@@ -49,7 +49,6 @@ tags:
asset_type: Windows
mitre_attack_id:
- T1003.001
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/deprecated/detect_new_api_calls_from_user_roles.yml b/detections/deprecated/detect_new_api_calls_from_user_roles.yml
index cc41aecff1..5ed0943c52 100644
--- a/detections/deprecated/detect_new_api_calls_from_user_roles.yml
+++ b/detections/deprecated/detect_new_api_calls_from_user_roles.yml
@@ -12,9 +12,9 @@ search: '`cloudtrail` eventType=AwsApiCall errorCode=success userIdentity.type=A
[search `cloudtrail` eventType=AwsApiCall errorCode=success userIdentity.type=AssumedRole
| stats earliest(_time) as earliest latest(_time) as latest by userName eventName
| inputlookup append=t previously_seen_api_calls_from_user_roles | stats min(earliest)
- as earliest, max(latest) as latest by userName eventName | outputlookup previously_seen_api_calls_from_user_roles
- | eval newApiCallfromUserRole=if(earliest>=relative_time(now(), "-70m@m"), 1, 0)
- | where newApiCallfromUserRole=1 | `security_content_ctime(earliest)` | `security_content_ctime(latest)`
+ as earliest, max(latest) as latest by userName eventName | outputlookup previously_seen_api_calls_from_user_roles |
+ eval newApiCallfromUserRole=if(earliest>=relative_time(now(), "-70m@m"), 1, 0) |
+ where newApiCallfromUserRole=1 | `security_content_ctime(earliest)` | `security_content_ctime(latest)`
| table eventName userName] |rename userName as user| stats values(eventName) earliest(_time)
as earliest latest(_time) as latest by user | `security_content_ctime(earliest)`
| `security_content_ctime(latest)` | `detect_new_api_calls_from_user_roles_filter`'
diff --git a/detections/deprecated/detect_new_user_aws_console_login.yml b/detections/deprecated/detect_new_user_aws_console_login.yml
index 68c62a8d9c..1713d3b52d 100644
--- a/detections/deprecated/detect_new_user_aws_console_login.yml
+++ b/detections/deprecated/detect_new_user_aws_console_login.yml
@@ -13,9 +13,9 @@ description: This search looks for AWS CloudTrail events wherein a console login
data_source: []
search: '`cloudtrail` eventName=ConsoleLogin | rename userIdentity.arn as user | stats
earliest(_time) as firstTime latest(_time) as lastTime by user | inputlookup append=t
- previously_seen_users_console_logins | stats min(firstTime) as firstTime max(lastTime)
- as lastTime by user | eval userStatus=if(firstTime >= relative_time(now(), "-70m@m"),
- "First Time Logging into AWS Console","Previously Seen User") | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`|
+ previously_seen_users_console_logins | stats min(firstTime) as firstTime
+ max(lastTime) as lastTime by user | eval userStatus=if(firstTime >= relative_time(now(),
+ "-70m@m"), "First Time Logging into AWS Console","Previously Seen User") | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`|
where userStatus ="First Time Logging into AWS Console" | `detect_new_user_aws_console_login_filter`'
how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later)
and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail
diff --git a/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml b/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml
index 05f6ff2bd6..d0851935d2 100644
--- a/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml
+++ b/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml
@@ -1,19 +1,20 @@
name: Detect processes used for System Network Configuration Discovery
id: a51bfe1a-94f0-48cc-b1e4-16ae10145893
-version: 7
+version: 8
date: '2025-01-24'
author: Bhavin Patel, Splunk
status: deprecated
type: TTP
-description: The following analytic has been deprecated. The following analytic identifies
- the rapid execution of processes used for system network configuration discovery
- on an endpoint. It leverages data from Endpoint Detection and Response (EDR) agents,
- focusing on process GUIDs, names, parent processes, and command-line executions.
- This activity is significant as it may indicate an attacker attempting to map the
- network, which is a common precursor to lateral movement or further exploitation.
- If confirmed malicious, this behavior could allow an attacker to gain insights into
- the network topology, identify critical systems, and plan subsequent attacks, potentially
- leading to data exfiltration or system compromise.
+description: The following analytic has been deprecated.
+ The following analytic identifies the rapid execution of processes used
+ for system network configuration discovery on an endpoint. It leverages data from
+ Endpoint Detection and Response (EDR) agents, focusing on process GUIDs, names,
+ parent processes, and command-line executions. This activity is significant as it
+ may indicate an attacker attempting to map the network, which is a common precursor
+ to lateral movement or further exploitation. If confirmed malicious, this behavior
+ could allow an attacker to gain insights into the network topology, identify critical
+ systems, and plan subsequent attacks, potentially leading to data exfiltration or
+ system compromise.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/detect_webshell_exploit_behavior.yml b/detections/deprecated/detect_webshell_exploit_behavior.yml
index 5f61b3c0c8..a460946a1a 100644
--- a/detections/deprecated/detect_webshell_exploit_behavior.yml
+++ b/detections/deprecated/detect_webshell_exploit_behavior.yml
@@ -1,7 +1,7 @@
name: Detect Webshell Exploit Behavior
id: 22597426-6dbd-49bd-bcdc-4ec19857192f
-version: 7
-date: '2025-01-24'
+version: 8
+date: '2025-02-10'
author: Steven Dick
status: deprecated
type: TTP
@@ -87,7 +87,6 @@ tags:
- BlackByte Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1505
- T1505.003
product:
- Splunk Enterprise
diff --git a/detections/deprecated/disabling_net_user_account.yml b/detections/deprecated/disabling_net_user_account.yml
index 615c9dea0b..409e89854a 100644
--- a/detections/deprecated/disabling_net_user_account.yml
+++ b/detections/deprecated/disabling_net_user_account.yml
@@ -1,18 +1,18 @@
name: Disabling Net User Account
id: c0325326-acd6-11eb-98c2-acde48001122
-version: 7
+version: 8
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
type: TTP
-description: The following analytic has been deprecated. The following analytic detects
- the use of the `net.exe` utility to disable a user account via the command line.
- It leverages data from Endpoint Detection and Response (EDR) agents, focusing on
- process execution logs and command-line arguments. This activity is significant
- as it may indicate an adversary's attempt to disrupt user availability, potentially
- as a precursor to further malicious actions. If confirmed malicious, this could
- lead to denial of service for legitimate users, aiding the attacker in maintaining
- control or covering their tracks.
+description: The following analytic has been deprecated.
+ The following analytic detects the use of the `net.exe` utility to disable
+ a user account via the command line. It leverages data from Endpoint Detection and
+ Response (EDR) agents, focusing on process execution logs and command-line arguments.
+ This activity is significant as it may indicate an adversary's attempt to disrupt
+ user availability, potentially as a precursor to further malicious actions. If confirmed
+ malicious, this could lead to denial of service for legitimate users, aiding the
+ attacker in maintaining control or covering their tracks.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/domain_account_discovery_with_net_app.yml b/detections/deprecated/domain_account_discovery_with_net_app.yml
index 92ad5bcfa8..a1518a4c1f 100644
--- a/detections/deprecated/domain_account_discovery_with_net_app.yml
+++ b/detections/deprecated/domain_account_discovery_with_net_app.yml
@@ -1,7 +1,7 @@
name: Domain Account Discovery With Net App
id: 98f6a534-04c2-11ec-96b2-acde48001122
-version: 5
-date: '2025-01-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: deprecated
type: TTP
@@ -71,7 +71,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1087.002
- - T1087
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/deprecated/domain_group_discovery_with_net.yml b/detections/deprecated/domain_group_discovery_with_net.yml
index b01c32e127..928dec10e8 100644
--- a/detections/deprecated/domain_group_discovery_with_net.yml
+++ b/detections/deprecated/domain_group_discovery_with_net.yml
@@ -1,7 +1,7 @@
name: Domain Group Discovery With Net
id: f2f14ac7-fa81-471a-80d5-7eb65c3c7349
-version: 6
-date: '2025-01-13'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: deprecated
type: Hunting
@@ -46,7 +46,6 @@ tags:
- Cleo File Transfer Software
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.002
product:
- Splunk Enterprise
diff --git a/detections/deprecated/elevated_group_discovery_with_net.yml b/detections/deprecated/elevated_group_discovery_with_net.yml
index 45c777516b..a941649159 100644
--- a/detections/deprecated/elevated_group_discovery_with_net.yml
+++ b/detections/deprecated/elevated_group_discovery_with_net.yml
@@ -1,7 +1,7 @@
name: Elevated Group Discovery With Net
id: a23a0e20-0b1b-4a07-82e5-ec5f70811e7a
-version: 6
-date: '2025-01-24'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: deprecated
type: TTP
@@ -70,7 +70,6 @@ tags:
- BlackSuit Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.002
product:
- Splunk Enterprise
diff --git a/detections/deprecated/excel_spawning_powershell.yml b/detections/deprecated/excel_spawning_powershell.yml
index 28ca3fa40a..764de86234 100644
--- a/detections/deprecated/excel_spawning_powershell.yml
+++ b/detections/deprecated/excel_spawning_powershell.yml
@@ -1,7 +1,7 @@
name: Excel Spawning PowerShell
id: 42d40a22-9be3-11eb-8f08-acde48001122
-version: 7
-date: '2025-01-13'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: deprecated
type: TTP
@@ -75,7 +75,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.002
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/deprecated/excel_spawning_windows_script_host.yml b/detections/deprecated/excel_spawning_windows_script_host.yml
index 70da2b9f10..40deb89c49 100644
--- a/detections/deprecated/excel_spawning_windows_script_host.yml
+++ b/detections/deprecated/excel_spawning_windows_script_host.yml
@@ -1,12 +1,12 @@
name: Excel Spawning Windows Script Host
id: 57fe880a-9be3-11eb-9bf3-acde48001122
-version: 8
-date: '2025-01-13'
+version: 10
+date: '2025-02-10'
author: Michael Haag, Splunk
status: deprecated
type: TTP
-description: The following analytic has been deprecated in favour of a more generic approach.
- The following analytic identifies instances where Microsoft Excel spawns
+description: The following analytic has been deprecated in favour of a more generic
+ approach. The following analytic identifies instances where Microsoft Excel spawns
Windows Script Host processes (`cscript.exe` or `wscript.exe`). This behavior is
detected using Endpoint Detection and Response (EDR) telemetry, focusing on process
creation events where the parent process is `excel.exe`. This activity is significant
@@ -75,7 +75,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.002
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -84,6 +83,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/deprecated/excessive_service_stop_attempt.yml b/detections/deprecated/excessive_service_stop_attempt.yml
index 9c51626bde..3e27dc456b 100644
--- a/detections/deprecated/excessive_service_stop_attempt.yml
+++ b/detections/deprecated/excessive_service_stop_attempt.yml
@@ -5,14 +5,15 @@ date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
type: Anomaly
-description: The following analytic has been deprecated. The following analytic detects
- multiple attempts to stop or delete services on a system using `net.exe`, `sc.exe`,
- or `net1.exe`. It leverages Endpoint Detection and Response (EDR) telemetry, focusing
- on process names and command-line executions within a one-minute window. This activity
- is significant as it may indicate an adversary attempting to disable security or
- critical services to evade detection and further their objectives. If confirmed
- malicious, this could lead to the attacker gaining persistence, escalating privileges,
- or disrupting essential services, thereby compromising the system's security posture.
+description: The following analytic has been deprecated.
+ The following analytic detects multiple attempts to stop or delete services
+ on a system using `net.exe`, `sc.exe`, or `net1.exe`. It leverages Endpoint Detection
+ and Response (EDR) telemetry, focusing on process names and command-line executions
+ within a one-minute window. This activity is significant as it may indicate an adversary
+ attempting to disable security or critical services to evade detection and further
+ their objectives. If confirmed malicious, this could lead to the attacker gaining
+ persistence, escalating privileges, or disrupting essential services, thereby compromising
+ the system's security posture.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/excessive_usage_of_net_app.yml b/detections/deprecated/excessive_usage_of_net_app.yml
index 050c4047c9..1b3556f57b 100644
--- a/detections/deprecated/excessive_usage_of_net_app.yml
+++ b/detections/deprecated/excessive_usage_of_net_app.yml
@@ -1,18 +1,19 @@
name: Excessive Usage Of Net App
id: 45e52536-ae42-11eb-b5c6-acde48001122
-version: 6
+version: 7
date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
type: Anomaly
-description: The following analytic has been deprecated. The following analytic detects
- excessive usage of `net.exe` or `net1.exe` within a one-minute interval. It leverages
- data from Endpoint Detection and Response (EDR) agents, focusing on process names,
- parent processes, and command-line executions. This behavior is significant as it
- may indicate an adversary attempting to create, delete, or disable multiple user
- accounts rapidly, a tactic observed in Monero mining incidents. If confirmed malicious,
- this activity could lead to unauthorized user account manipulation, potentially
- compromising system integrity and enabling further malicious actions.
+description: The following analytic has been deprecated.
+ The following analytic detects excessive usage of `net.exe` or `net1.exe`
+ within a one-minute interval. It leverages data from Endpoint Detection and Response
+ (EDR) agents, focusing on process names, parent processes, and command-line executions.
+ This behavior is significant as it may indicate an adversary attempting to create,
+ delete, or disable multiple user accounts rapidly, a tactic observed in Monero mining
+ incidents. If confirmed malicious, this activity could lead to unauthorized user
+ account manipulation, potentially compromising system integrity and enabling further
+ malicious actions.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/extraction_of_registry_hives.yml b/detections/deprecated/extraction_of_registry_hives.yml
index 7e1ddbc2bc..ceb5264fa6 100644
--- a/detections/deprecated/extraction_of_registry_hives.yml
+++ b/detections/deprecated/extraction_of_registry_hives.yml
@@ -1,7 +1,7 @@
name: Extraction of Registry Hives
id: 8bbb7d58-b360-11eb-ba21-acde48001122
-version: 6
-date: '2025-01-24'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: deprecated
type: TTP
@@ -77,7 +77,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.002
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/known_services_killed_by_ransomware.yml b/detections/deprecated/known_services_killed_by_ransomware.yml
similarity index 93%
rename from detections/endpoint/known_services_killed_by_ransomware.yml
rename to detections/deprecated/known_services_killed_by_ransomware.yml
index 38760a26ef..5ca93f96d4 100644
--- a/detections/endpoint/known_services_killed_by_ransomware.yml
+++ b/detections/deprecated/known_services_killed_by_ransomware.yml
@@ -1,11 +1,11 @@
name: Known Services Killed by Ransomware
id: 3070f8e0-c528-11eb-b2a0-acde48001122
-version: 7
-date: '2024-12-10'
+version: 8
+date: '2025-02-07'
author: Teoderick Contreras, Splunk
-status: production
+status: deprecated
type: TTP
-description: The following analytic detects the suspicious termination of known services
+description: This analytic has been deprecated in favor of a new analytic - Windows Security And Backup Services Stop. The following analytic detects the suspicious termination of known services
commonly targeted by ransomware before file encryption. It leverages Windows System
Event Logs (EventCode 7036) to identify when critical services such as Volume Shadow
Copy, backup, and antivirus services are stopped. This activity is significant because
@@ -75,4 +75,4 @@ tests:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/known_services_killed_by_ransomware/windows-xml.log
source: XmlWinEventLog:System
- sourcetype: XmlWinEventLog
+ sourcetype: XmlWinEventLog
\ No newline at end of file
diff --git a/detections/deprecated/linux_auditd_find_private_keys.yml b/detections/deprecated/linux_auditd_find_private_keys.yml
index 756073da56..d45b98a890 100644
--- a/detections/deprecated/linux_auditd_find_private_keys.yml
+++ b/detections/deprecated/linux_auditd_find_private_keys.yml
@@ -1,7 +1,7 @@
name: Linux Auditd Find Private Keys
id: 80bb9988-190b-4ee0-a3c3-509545a8f678
-version: 5
-date: '2025-01-24'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: deprecated
type: TTP
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1552.004
- - T1552
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/deprecated/local_account_discovery_with_net.yml b/detections/deprecated/local_account_discovery_with_net.yml
index 8af80acf03..69f3af6598 100644
--- a/detections/deprecated/local_account_discovery_with_net.yml
+++ b/detections/deprecated/local_account_discovery_with_net.yml
@@ -1,7 +1,7 @@
name: Local Account Discovery with Net
id: 5d0d4830-0133-11ec-bae3-acde48001122
-version: 6
-date: '2025-01-24'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: deprecated
type: Hunting
@@ -41,7 +41,6 @@ tags:
- Sandworm Tools
asset_type: Endpoint
mitre_attack_id:
- - T1087
- T1087.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/mshtml_module_load_in_office_product.yml b/detections/deprecated/mshtml_module_load_in_office_product.yml
index 870c4aea9d..833a24a872 100644
--- a/detections/deprecated/mshtml_module_load_in_office_product.yml
+++ b/detections/deprecated/mshtml_module_load_in_office_product.yml
@@ -1,7 +1,7 @@
name: MSHTML Module Load in Office Product
id: 5f1c168e-118b-11ec-84ff-acde48001122
-version: 7
-date: '2025-01-24'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Mauricio Velazco, Splunk
status: deprecated
type: TTP
@@ -64,7 +64,6 @@ tags:
cve:
- CVE-2021-40444
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml b/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml
index 68269b2e43..1ebadf8ebc 100644
--- a/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml
+++ b/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml
@@ -1,7 +1,7 @@
name: Multiple Okta Users With Invalid Credentials From The Same IP
id: 19cba45f-cad3-4032-8911-0c09e0444552
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Mauricio Velazco, Rico Valdez, Splunk
status: deprecated
type: TTP
@@ -41,9 +41,8 @@ tags:
- Suspicious Okta Activity
asset_type: Okta Tenant
mitre_attack_id:
- - T1110.003
- - T1078
- T1078.001
+ - T1110.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/deprecated/net_localgroup_discovery.yml b/detections/deprecated/net_localgroup_discovery.yml
index b3d15becdf..31b775f015 100644
--- a/detections/deprecated/net_localgroup_discovery.yml
+++ b/detections/deprecated/net_localgroup_discovery.yml
@@ -1,7 +1,7 @@
name: Net Localgroup Discovery
id: 54f5201e-155b-11ec-a6e2-acde48001122
-version: 5
-date: '2025-01-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: deprecated
type: Hunting
@@ -52,7 +52,6 @@ tags:
- Rhysida Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/network_connection_discovery_with_net.yml b/detections/deprecated/network_connection_discovery_with_net.yml
index e2caea92c7..0002699f31 100644
--- a/detections/deprecated/network_connection_discovery_with_net.yml
+++ b/detections/deprecated/network_connection_discovery_with_net.yml
@@ -5,15 +5,15 @@ date: '2025-01-24'
author: Mauricio Velazco, Splunk
status: deprecated
type: Hunting
-description: The following analytic has been deprecated. The following analytic identifies
- the execution of `net.exe` or `net1.exe` with command-line arguments used to list
- network connections on a compromised system. It leverages data from Endpoint Detection
- and Response (EDR) agents, focusing on process names and command-line executions.
- This activity is significant as it indicates potential network reconnaissance by
- adversaries or Red Teams, aiming to gather situational awareness and Active Directory
- information. If confirmed malicious, this behavior could allow attackers to map
- the network, identify critical assets, and plan further attacks, potentially leading
- to data exfiltration or lateral movement.
+description: The following analytic has been deprecated.
+ The following analytic identifies the execution of `net.exe` or `net1.exe`
+ with command-line arguments used to list network connections on a compromised system.
+ It leverages data from Endpoint Detection and Response (EDR) agents, focusing on
+ process names and command-line executions. This activity is significant as it indicates
+ potential network reconnaissance by adversaries or Red Teams, aiming to gather situational
+ awareness and Active Directory information. If confirmed malicious, this behavior
+ could allow attackers to map the network, identify critical assets, and plan further
+ attacks, potentially leading to data exfiltration or lateral movement.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/o365_suspicious_admin_email_forwarding.yml b/detections/deprecated/o365_suspicious_admin_email_forwarding.yml
index 13dddb8c18..b706b2d0a8 100644
--- a/detections/deprecated/o365_suspicious_admin_email_forwarding.yml
+++ b/detections/deprecated/o365_suspicious_admin_email_forwarding.yml
@@ -1,7 +1,7 @@
name: O365 Suspicious Admin Email Forwarding
id: 7f398cfb-918d-41f4-8db8-2e2474e02c28
-version: 3
-date: '2024-11-14'
+version: 4
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: deprecated
type: Anomaly
@@ -33,7 +33,6 @@ tags:
asset_type: O365 Tenant
mitre_attack_id:
- T1114.003
- - T1114
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/deprecated/o365_suspicious_rights_delegation.yml b/detections/deprecated/o365_suspicious_rights_delegation.yml
index e9e6543750..716fd6289c 100644
--- a/detections/deprecated/o365_suspicious_rights_delegation.yml
+++ b/detections/deprecated/o365_suspicious_rights_delegation.yml
@@ -1,7 +1,7 @@
name: O365 Suspicious Rights Delegation
id: b25d2973-303e-47c8-bacd-52b61604c6a7
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Patrick Bareiss, Mauricio Velazco, Splunk
status: deprecated
type: TTP
@@ -56,10 +56,8 @@ tags:
- Office 365 Collection Techniques
asset_type: O365 Tenant
mitre_attack_id:
- - T1114.002
- - T1114
- T1098.002
- - T1098
+ - T1114.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/deprecated/o365_suspicious_user_email_forwarding.yml b/detections/deprecated/o365_suspicious_user_email_forwarding.yml
index 1a9c9c5c4c..4ea5ecc88d 100644
--- a/detections/deprecated/o365_suspicious_user_email_forwarding.yml
+++ b/detections/deprecated/o365_suspicious_user_email_forwarding.yml
@@ -1,7 +1,7 @@
name: O365 Suspicious User Email Forwarding
id: f8dfe015-dbb3-4569-ba75-b13787e06aa4
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: deprecated
type: Anomaly
@@ -59,7 +59,6 @@ tags:
asset_type: O365 Tenant
mitre_attack_id:
- T1114.003
- - T1114
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/deprecated/office_application_drop_executable.yml b/detections/deprecated/office_application_drop_executable.yml
index 792556a6d3..c87210ccf6 100644
--- a/detections/deprecated/office_application_drop_executable.yml
+++ b/detections/deprecated/office_application_drop_executable.yml
@@ -1,7 +1,7 @@
name: Office Application Drop Executable
id: 73ce70c4-146d-11ec-9184-acde48001122
-version: 9
-date: '2025-01-24'
+version: 10
+date: '2025-02-10'
author: Teoderick Contreras, Michael Haag, Splunk, TheLawsOfChaos, Github
status: deprecated
type: TTP
@@ -69,7 +69,6 @@ tags:
- PlugX
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/office_application_spawn_regsvr32_process.yml b/detections/deprecated/office_application_spawn_regsvr32_process.yml
index ceec84dba1..8aa07a2de3 100644
--- a/detections/deprecated/office_application_spawn_regsvr32_process.yml
+++ b/detections/deprecated/office_application_spawn_regsvr32_process.yml
@@ -1,7 +1,7 @@
name: Office Application Spawn Regsvr32 process
id: 2d9fc90c-f11f-11eb-9300-acde48001122
-version: 8
-date: '2025-01-13'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: deprecated
type: TTP
@@ -70,7 +70,6 @@ tags:
- Qakbot
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/office_application_spawn_rundll32_process.yml b/detections/deprecated/office_application_spawn_rundll32_process.yml
index 6d10c2b8c8..e648095cc9 100644
--- a/detections/deprecated/office_application_spawn_rundll32_process.yml
+++ b/detections/deprecated/office_application_spawn_rundll32_process.yml
@@ -1,7 +1,7 @@
name: Office Application Spawn rundll32 process
id: 958751e4-9c5f-11eb-b103-acde48001122
-version: 8
-date: '2025-01-13'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: deprecated
type: TTP
@@ -73,7 +73,6 @@ tags:
- Trickbot
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/office_document_creating_schedule_task.yml b/detections/deprecated/office_document_creating_schedule_task.yml
index 1275c00579..ef59131ecc 100644
--- a/detections/deprecated/office_document_creating_schedule_task.yml
+++ b/detections/deprecated/office_document_creating_schedule_task.yml
@@ -1,7 +1,7 @@
name: Office Document Creating Schedule Task
id: cc8b7b74-9d0f-11eb-8342-acde48001122
-version: 10
-date: '2025-01-24'
+version: 11
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: deprecated
type: TTP
@@ -59,7 +59,6 @@ tags:
- Spearphishing Attachments
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/office_document_executing_macro_code.yml b/detections/deprecated/office_document_executing_macro_code.yml
index 9bf6ad3357..8d74ea1aa2 100644
--- a/detections/deprecated/office_document_executing_macro_code.yml
+++ b/detections/deprecated/office_document_executing_macro_code.yml
@@ -1,7 +1,7 @@
name: Office Document Executing Macro Code
id: b12c89bc-9d06-11eb-a592-acde48001122
-version: 9
-date: '2025-01-24'
+version: 10
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: deprecated
type: TTP
@@ -69,7 +69,6 @@ tags:
- NjRAT
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/office_document_spawned_child_process_to_download.yml b/detections/deprecated/office_document_spawned_child_process_to_download.yml
index 73220f4027..2e78ed372c 100644
--- a/detections/deprecated/office_document_spawned_child_process_to_download.yml
+++ b/detections/deprecated/office_document_spawned_child_process_to_download.yml
@@ -1,7 +1,7 @@
name: Office Document Spawned Child Process To Download
id: 6fed27d2-9ec7-11eb-8fe4-aa665a019aa3
-version: 10
-date: '2025-01-24'
+version: 11
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: deprecated
type: TTP
@@ -69,7 +69,6 @@ tags:
- NjRAT
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/office_product_spawn_cmd_process.yml b/detections/deprecated/office_product_spawn_cmd_process.yml
index 4193c23ca8..4893d60d9f 100644
--- a/detections/deprecated/office_product_spawn_cmd_process.yml
+++ b/detections/deprecated/office_product_spawn_cmd_process.yml
@@ -1,7 +1,7 @@
name: Office Product Spawn CMD Process
id: b8b19420-e892-11eb-9244-acde48001122
-version: 8
-date: '2025-01-13'
+version: 10
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: deprecated
type: TTP
@@ -85,7 +85,6 @@ tags:
- NjRAT
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/office_product_spawning_bitsadmin.yml b/detections/deprecated/office_product_spawning_bitsadmin.yml
index 3bda779c35..28ee0cc811 100644
--- a/detections/deprecated/office_product_spawning_bitsadmin.yml
+++ b/detections/deprecated/office_product_spawning_bitsadmin.yml
@@ -1,7 +1,7 @@
name: Office Product Spawning BITSAdmin
id: e8c591f4-a6d7-11eb-8cf7-acde48001122
-version: 9
-date: '2025-01-13'
+version: 10
+date: '2025-02-10'
author: Michael Haag, Splunk
status: deprecated
type: TTP
@@ -71,7 +71,6 @@ tags:
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/office_product_spawning_certutil.yml b/detections/deprecated/office_product_spawning_certutil.yml
index 00bc0797c9..698343c8ae 100644
--- a/detections/deprecated/office_product_spawning_certutil.yml
+++ b/detections/deprecated/office_product_spawning_certutil.yml
@@ -1,7 +1,7 @@
name: Office Product Spawning CertUtil
id: 6925fe72-a6d5-11eb-9e17-acde48001122
-version: 9
-date: '2025-01-13'
+version: 10
+date: '2025-02-10'
author: Michael Haag, Splunk
status: deprecated
type: TTP
@@ -72,7 +72,6 @@ tags:
- CVE-2023-36884 Office and Windows HTML RCE Vulnerability
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/office_product_spawning_mshta.yml b/detections/deprecated/office_product_spawning_mshta.yml
index ef07f76ce2..9c8c8ae1ce 100644
--- a/detections/deprecated/office_product_spawning_mshta.yml
+++ b/detections/deprecated/office_product_spawning_mshta.yml
@@ -1,7 +1,7 @@
name: Office Product Spawning MSHTA
id: 6078fa20-a6d2-11eb-b662-acde48001122
-version: 8
-date: '2025-01-13'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: deprecated
type: TTP
@@ -71,7 +71,6 @@ tags:
- CVE-2023-36884 Office and Windows HTML RCE Vulnerability
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml b/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml
index a74965e373..41f3f9df66 100644
--- a/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml
+++ b/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml
@@ -1,7 +1,7 @@
name: Office Product Spawning Rundll32 with no DLL
id: c661f6be-a38c-11eb-be57-acde48001122
-version: 10
-date: '2025-01-24'
+version: 11
+date: '2025-02-10'
author: Michael Haag, Splunk
status: deprecated
type: TTP
@@ -72,7 +72,6 @@ tags:
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/office_product_spawning_windows_script_host.yml b/detections/deprecated/office_product_spawning_windows_script_host.yml
index 659a4b48ed..b4da3bfa8e 100644
--- a/detections/deprecated/office_product_spawning_windows_script_host.yml
+++ b/detections/deprecated/office_product_spawning_windows_script_host.yml
@@ -1,7 +1,7 @@
name: Office Product Spawning Windows Script Host
id: b3628a5b-8d02-42fa-a891-eebf2351cbe1
-version: 10
-date: '2025-01-13'
+version: 12
+date: '2025-02-10'
author: Michael Haag, Splunk
status: deprecated
type: TTP
@@ -75,7 +75,6 @@ tags:
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/office_product_spawning_wmic.yml b/detections/deprecated/office_product_spawning_wmic.yml
index a06d97a5d7..0e60c6e32f 100644
--- a/detections/deprecated/office_product_spawning_wmic.yml
+++ b/detections/deprecated/office_product_spawning_wmic.yml
@@ -1,7 +1,7 @@
name: Office Product Spawning Wmic
id: ffc236d6-a6c9-11eb-95f1-acde48001122
-version: 10
-date: '2025-01-13'
+version: 11
+date: '2025-02-10'
author: Michael Haag, Splunk
status: deprecated
type: TTP
@@ -72,7 +72,6 @@ tags:
- FIN7
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/office_product_writing_cab_or_inf.yml b/detections/deprecated/office_product_writing_cab_or_inf.yml
index 30adac14d5..9d29d2a888 100644
--- a/detections/deprecated/office_product_writing_cab_or_inf.yml
+++ b/detections/deprecated/office_product_writing_cab_or_inf.yml
@@ -1,7 +1,7 @@
name: Office Product Writing cab or inf
id: f48cd1d4-125a-11ec-a447-acde48001122
-version: 10
-date: '2025-01-24'
+version: 11
+date: '2025-02-10'
author: Michael Haag, Splunk
status: deprecated
type: TTP
@@ -76,7 +76,6 @@ tags:
cve:
- CVE-2021-40444
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/office_spawning_control.yml b/detections/deprecated/office_spawning_control.yml
index 984e8bf0a8..f141b89519 100644
--- a/detections/deprecated/office_spawning_control.yml
+++ b/detections/deprecated/office_spawning_control.yml
@@ -1,7 +1,7 @@
name: Office Spawning Control
id: 053e027c-10c7-11ec-8437-acde48001122
-version: 10
-date: '2025-01-24'
+version: 12
+date: '2025-02-10'
author: Michael Haag, Splunk
status: deprecated
type: TTP
@@ -77,7 +77,6 @@ tags:
cve:
- CVE-2021-40444
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/okta_account_lockout_events.yml b/detections/deprecated/okta_account_lockout_events.yml
index 07f8d09a9d..b2ec1f14ef 100644
--- a/detections/deprecated/okta_account_lockout_events.yml
+++ b/detections/deprecated/okta_account_lockout_events.yml
@@ -1,7 +1,7 @@
name: Okta Account Lockout Events
id: 62b70968-a0a5-4724-8ac4-67871e6f544d
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Rico Valdez, Splunk
status: deprecated
type: Anomaly
@@ -43,7 +43,6 @@ tags:
- Suspicious Okta Activity
asset_type: Infrastructure
mitre_attack_id:
- - T1078
- T1078.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/okta_failed_sso_attempts.yml b/detections/deprecated/okta_failed_sso_attempts.yml
index 6516d32c67..3c1d92c759 100644
--- a/detections/deprecated/okta_failed_sso_attempts.yml
+++ b/detections/deprecated/okta_failed_sso_attempts.yml
@@ -1,7 +1,7 @@
name: Okta Failed SSO Attempts
id: 371a6545-2618-4032-ad84-93386b8698c5
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Rico Valdez, Splunk
status: deprecated
type: Anomaly
@@ -32,7 +32,6 @@ tags:
- Suspicious Okta Activity
asset_type: Infrastructure
mitre_attack_id:
- - T1078
- T1078.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml b/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml
index 1f87cc42bf..00af9d0aa5 100644
--- a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml
+++ b/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml
@@ -1,7 +1,7 @@
name: Okta ThreatInsight Login Failure with High Unknown users
id: 632663b0-4562-4aad-abe9-9f621a049738
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Okta, Inc, Michael Haag, Splunk
type: TTP
status: deprecated
@@ -34,7 +34,6 @@ tags:
- Suspicious Okta Activity
asset_type: Infrastructure
mitre_attack_id:
- - T1078
- T1078.001
- T1110.004
product:
diff --git a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml b/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml
index 478b4895a1..e68cf87729 100644
--- a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml
+++ b/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml
@@ -1,7 +1,7 @@
name: Okta ThreatInsight Suspected PasswordSpray Attack
id: 25dbad05-6682-4dd5-9ce9-8adecf0d9ae2
-version: 4
-date: '2024-11-14'
+version: 5
+date: '2025-02-10'
author: Okta, Inc, Michael Haag, Splunk
type: TTP
status: deprecated
@@ -33,7 +33,6 @@ tags:
- Suspicious Okta Activity
asset_type: Infrastructure
mitre_attack_id:
- - T1078
- T1078.001
- T1110.003
product:
diff --git a/detections/deprecated/osquery_pack___coldroot_detection.yml b/detections/deprecated/osquery_pack___coldroot_detection.yml
index 3ba9866bed..369173b8fd 100644
--- a/detections/deprecated/osquery_pack___coldroot_detection.yml
+++ b/detections/deprecated/osquery_pack___coldroot_detection.yml
@@ -1,6 +1,6 @@
name: Osquery pack - ColdRoot detection
id: a6fffe5e-05c3-4c04-badc-887607fbb8dc
-version: 4
+version: 5
date: '2024-11-14'
author: Rico Valdez, Splunk
status: deprecated
diff --git a/detections/deprecated/password_policy_discovery_with_net.yml b/detections/deprecated/password_policy_discovery_with_net.yml
index 66ef237307..0656e661c8 100644
--- a/detections/deprecated/password_policy_discovery_with_net.yml
+++ b/detections/deprecated/password_policy_discovery_with_net.yml
@@ -5,15 +5,16 @@ date: '2025-01-24'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: deprecated
type: Hunting
-description: The following analytic has been deprecated. The following analytic identifies
- the execution of `net.exe` or `net1.exe` with command line arguments aimed at obtaining
- the domain password policy. It leverages data from Endpoint Detection and Response
- (EDR) agents, focusing on process names and command-line executions. This activity
- is significant as it indicates potential reconnaissance efforts by adversaries to
- gather information about Active Directory password policies. If confirmed malicious,
- this behavior could allow attackers to understand password complexity requirements,
- aiding in brute-force or password-guessing attacks, ultimately compromising user
- accounts and gaining unauthorized access to the network.
+description: The following analytic has been deprecated.
+ The following analytic identifies the execution of `net.exe` or `net1.exe`
+ with command line arguments aimed at obtaining the domain password policy. It leverages
+ data from Endpoint Detection and Response (EDR) agents, focusing on process names
+ and command-line executions. This activity is significant as it indicates potential
+ reconnaissance efforts by adversaries to gather information about Active Directory
+ password policies. If confirmed malicious, this behavior could allow attackers to
+ understand password complexity requirements, aiding in brute-force or password-guessing
+ attacks, ultimately compromising user accounts and gaining unauthorized access to
+ the network.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/remote_desktop_network_bruteforce.yml b/detections/deprecated/remote_desktop_network_bruteforce.yml
new file mode 100644
index 0000000000..400fe691cf
--- /dev/null
+++ b/detections/deprecated/remote_desktop_network_bruteforce.yml
@@ -0,0 +1,58 @@
+name: Remote Desktop Network Bruteforce
+id: a98727cc-286b-4ff2-b898-41df64695923
+version: 7
+date: '2025-01-10'
+author: Jose Hernandez, Bhavin Patel, Splunk
+status: deprecated
+type: TTP
+description: The following analytic has been deprecated in favor of "Windows Remote Desktop Network Bruteforce Attempt". The following analytic identifies potential Remote Desktop Protocol (RDP) brute force attacks by monitoring network traffic for RDP application activity. This query detects potential RDP brute force attacks by identifying source IPs that have made more than 10 successful connection attempts to the same RDP port on a host within a one-hour window. The results are presented in a table that includes the source and destination IPs, destination port, number of attempts, and the times of the first and last connection attempts, helping to prioritize IPs based on the intensity of activity.
+data_source:
+- Sysmon EventID 3
+search: >-
+ | tstats `security_content_summariesonly` count, min(_time) as firstTime, max(_time) as lastTime from datamodel=Network_Traffic where (All_Traffic.app=rdp OR All_Traffic.dest_port=3389) AND All_Traffic.action=allowed by All_Traffic.src, All_Traffic.dest, All_Traffic.dest_port All_Traffic.user All_Traffic.vendor_product
+ | `drop_dm_object_name("All_Traffic")`
+ | eval duration=lastTime-firstTime
+ | where count > 10 AND duration < 3600
+ | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`
+ | `remote_desktop_network_bruteforce_filter`
+how_to_implement: You must ensure that your network traffic data is populating the Network_Traffic data model. Adjust the count and duration thresholds as necessary to tune the sensitivity of your detection.
+known_false_positives: RDP gateways may have unusually high amounts of traffic from all other hosts' RDP applications in the network.Any legitimate RDP traffic using wrong/expired credentials will be also detected as a false positive.
+references:
+- https://www.zscaler.com/blogs/security-research/ransomware-delivered-using-rdp-brute-force-attack
+- https://www.reliaquest.com/blog/rdp-brute-force-attacks/
+drilldown_searches:
+- name: View the detection results for - "$dest$"
+ search: '%original_detection_search% | search dest = "$dest$"'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: View risk events for the last 7 days for - "$dest$"
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+rba:
+ message: RDP brute force attack on $dest$
+ risk_objects:
+ - field: dest
+ type: system
+ score: 25
+ threat_objects: []
+tags:
+ analytic_story:
+ - SamSam Ransomware
+ - Ryuk Ransomware
+ - Compromised User Account
+ asset_type: Endpoint
+ mitre_attack_id:
+ - T1110.001
+ product:
+ - Splunk Enterprise
+ - Splunk Enterprise Security
+ - Splunk Cloud
+ security_domain: network
+tests:
+- name: True Positive Test
+ attack_data:
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.001/rdp_brute_sysmon/sysmon.log
+ source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
+ sourcetype: XmlWinEventLog
diff --git a/detections/deprecated/remote_system_discovery_with_net.yml b/detections/deprecated/remote_system_discovery_with_net.yml
index 6e730569fc..2377264b52 100644
--- a/detections/deprecated/remote_system_discovery_with_net.yml
+++ b/detections/deprecated/remote_system_discovery_with_net.yml
@@ -5,35 +5,13 @@ date: '2025-01-13'
author: Mauricio Velazco, Splunk
status: deprecated
type: Hunting
-description: The following analytic has been deprecated in favour of two dedicated
- analytics "4dc3951f-b3f8-4f46-b412-76a483f72277" and "a23a0e20-0b1b-4a07-82e5-ec5f70811e7a"
- .The following analytic identifies the execution of `net.exe` or `net1.exe` with
- command-line arguments used to discover remote systems, such as `domain computers
- /domain`. This detection leverages data from Endpoint Detection and Response (EDR)
- agents, focusing on process names and command-line arguments. This activity is significant
- as it indicates potential reconnaissance efforts by adversaries or Red Teams to
- map out networked systems and Active Directory structures. If confirmed malicious,
- this behavior could lead to further network exploitation, privilege escalation,
- or lateral movement within the environment.
+description: The following analytic has been deprecated in favour of two dedicated analytics "4dc3951f-b3f8-4f46-b412-76a483f72277" and "a23a0e20-0b1b-4a07-82e5-ec5f70811e7a" .The following analytic identifies the execution of `net.exe` or `net1.exe` with command-line arguments used to discover remote systems, such as `domain computers /domain`. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments. This activity is significant as it indicates potential reconnaissance efforts by adversaries or Red Teams to map out networked systems and Active Directory structures. If confirmed malicious, this behavior could lead to further network exploitation, privilege escalation, or lateral movement within the environment.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
-search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
- as lastTime from datamodel=Endpoint.Processes where `process_net` AND (Processes.process="*domain
- computers*" AND Processes.process=*/do*) OR (Processes.process="*view*" AND Processes.process=*/do*)
- by Processes.dest Processes.user Processes.parent_process Processes.process_name
- Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
- | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `remote_system_discovery_with_net_filter`'
-how_to_implement: The detection is based on data that originates from Endpoint Detection
- and Response (EDR) agents. These agents are designed to provide security-related
- telemetry from the endpoints where the agent is installed. To implement this search,
- you must ingest logs that contain the process GUID, process name, and parent process.
- Additionally, you must ingest complete command-line executions. These logs must
- be processed using the appropriate Splunk Technology Add-ons that are specific to
- the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
- data model. Use the Splunk Common Information Model (CIM) to normalize the field
- names and speed up the data modeling process.
+search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` AND (Processes.process="*domain computers*" AND Processes.process=*/do*) OR (Processes.process="*view*" AND Processes.process=*/do*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `remote_system_discovery_with_net_filter`'
+how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
known_false_positives: Administrators or power users may use this command for troubleshooting.
references:
- https://attack.mitre.org/techniques/T1018/
@@ -53,7 +31,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/suspicious_driver_loaded_path.yml b/detections/deprecated/suspicious_driver_loaded_path.yml
similarity index 93%
rename from detections/endpoint/suspicious_driver_loaded_path.yml
rename to detections/deprecated/suspicious_driver_loaded_path.yml
index 91196704e5..16d121b7b3 100644
--- a/detections/endpoint/suspicious_driver_loaded_path.yml
+++ b/detections/deprecated/suspicious_driver_loaded_path.yml
@@ -1,11 +1,11 @@
name: Suspicious Driver Loaded Path
id: f880acd4-a8f1-11eb-a53b-acde48001122
-version: 4
-date: '2024-11-13'
+version: 6
+date: '2025-02-06'
author: Teoderick Contreras, Splunk
-status: production
+status: deprecated
type: TTP
-description: The following analytic detects the loading of drivers from suspicious
+description: This search has been deprecated in favour of - Windows Suspicious Driver Loaded Path. The following analytic detects the loading of drivers from suspicious
paths, which is a technique often used by malicious software such as coin miners
(e.g., xmrig). It leverages Sysmon EventCode 6 to identify drivers loaded from non-standard
directories. This activity is significant because legitimate drivers typically reside
@@ -61,7 +61,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1543.003
- - T1543
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/suspicious_process_file_path.yml b/detections/deprecated/suspicious_process_file_path.yml
similarity index 95%
rename from detections/endpoint/suspicious_process_file_path.yml
rename to detections/deprecated/suspicious_process_file_path.yml
index 1d636ec76c..d7cd62534f 100644
--- a/detections/endpoint/suspicious_process_file_path.yml
+++ b/detections/deprecated/suspicious_process_file_path.yml
@@ -1,11 +1,11 @@
name: Suspicious Process File Path
id: 9be25988-ad82-11eb-a14f-acde48001122
-version: 6
-date: '2024-12-10'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
-status: production
+status: deprecated
type: TTP
-description: The following analytic identifies processes running from file paths not
+description: This search has been deprecated in favour of - Windows Suspicious Process File Path. The following analytic identifies processes running from file paths not
typically associated with legitimate software. It leverages data from Endpoint Detection
and Response (EDR) agents, focusing on specific process paths within the Endpoint
data model. This activity is significant because adversaries often use unconventional
@@ -117,4 +117,4 @@ tests:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
- sourcetype: XmlWinEventLog
+ sourcetype: XmlWinEventLog
\ No newline at end of file
diff --git a/detections/deprecated/suspicious_rundll32_rename.yml b/detections/deprecated/suspicious_rundll32_rename.yml
index 48fdc6b2d5..eee4228129 100644
--- a/detections/deprecated/suspicious_rundll32_rename.yml
+++ b/detections/deprecated/suspicious_rundll32_rename.yml
@@ -1,7 +1,7 @@
name: Suspicious Rundll32 Rename
id: 7360137f-abad-473e-8189-acbdaa34d114
-version: 7
-date: '2024-11-14'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: deprecated
type: Hunting
@@ -40,10 +40,8 @@ tags:
- Masquerading - Rename System Utilities
asset_type: Endpoint
mitre_attack_id:
- - T1218
- - T1036
- - T1218.011
- T1036.003
+ - T1218.011
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/deprecated/windows_command_shell_fetch_env_variables.yml b/detections/deprecated/windows_command_shell_fetch_env_variables.yml
index 8fcaf15950..90618ba3e5 100644
--- a/detections/deprecated/windows_command_shell_fetch_env_variables.yml
+++ b/detections/deprecated/windows_command_shell_fetch_env_variables.yml
@@ -5,14 +5,15 @@ date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
type: TTP
-description: The following analytic has been deprecated. The following analytic identifies
- a suspicious process command line fetching environment variables with a non-shell
- parent process. It leverages data from Endpoint Detection and Response (EDR) agents,
- focusing on command-line executions and parent process names. This activity is significant
- as it is commonly associated with malware like Qakbot, which uses this technique
- to gather system information. If confirmed malicious, this behavior could indicate
- that the parent process has been compromised, potentially allowing attackers to
- execute arbitrary commands, escalate privileges, or persist within the environment.
+description: The following analytic has been deprecated.
+ The following analytic identifies a suspicious process command line fetching
+ environment variables with a non-shell parent process. It leverages data from Endpoint
+ Detection and Response (EDR) agents, focusing on command-line executions and parent
+ process names. This activity is significant as it is commonly associated with malware
+ like Qakbot, which uses this technique to gather system information. If confirmed
+ malicious, this behavior could indicate that the parent process has been compromised,
+ potentially allowing attackers to execute arbitrary commands, escalate privileges,
+ or persist within the environment.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml b/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml
index 38d777ae9a..6149fc746d 100644
--- a/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml
+++ b/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml
@@ -1,7 +1,7 @@
name: Windows DLL Search Order Hijacking Hunt
id: 79c7d0fc-60c7-41be-a616-ccda752efe89
-version: 5
-date: '2024-11-14'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: deprecated
type: Hunting
@@ -49,7 +49,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1574.001
- - T1574
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/deprecated/windows_lateral_tool_transfer_remcom.yml b/detections/deprecated/windows_lateral_tool_transfer_remcom.yml
index 0611c1c8f6..47789c6b30 100644
--- a/detections/deprecated/windows_lateral_tool_transfer_remcom.yml
+++ b/detections/deprecated/windows_lateral_tool_transfer_remcom.yml
@@ -1,6 +1,6 @@
name: Windows Lateral Tool Transfer RemCom
id: e373a840-5bdc-47ef-b2fd-9cc7aaf387f0
-version: 5
+version: 6
date: '2024-12-10'
author: Michael Haag, Splunk
type: TTP
diff --git a/detections/deprecated/windows_modify_registry_reg_restore.yml b/detections/deprecated/windows_modify_registry_reg_restore.yml
index e1fcad055a..f63d1b0214 100644
--- a/detections/deprecated/windows_modify_registry_reg_restore.yml
+++ b/detections/deprecated/windows_modify_registry_reg_restore.yml
@@ -5,15 +5,15 @@ date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
type: Hunting
-description: The following analytic has been deprecated. The following analytic detects
- the execution of reg.exe with the "restore" parameter, indicating an attempt to
- restore registry backup data on a host. This detection leverages data from Endpoint
- Detection and Response (EDR) agents, focusing on process execution logs and command-line
- arguments. This activity is significant as it may indicate post-exploitation actions,
- such as those performed by tools like winpeas, which use "reg save" and "reg restore"
- to manipulate registry settings. If confirmed malicious, this could allow an attacker
- to revert registry changes, potentially bypassing security controls and maintaining
- persistence.
+description: The following analytic has been deprecated.
+ The following analytic detects the execution of reg.exe with the "restore"
+ parameter, indicating an attempt to restore registry backup data on a host. This
+ detection leverages data from Endpoint Detection and Response (EDR) agents, focusing
+ on process execution logs and command-line arguments. This activity is significant
+ as it may indicate post-exploitation actions, such as those performed by tools like
+ winpeas, which use "reg save" and "reg restore" to manipulate registry settings.
+ If confirmed malicious, this could allow an attacker to revert registry changes,
+ potentially bypassing security controls and maintaining persistence.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/windows_msiexec_with_network_connections.yml b/detections/deprecated/windows_msiexec_with_network_connections.yml
index 39ac9d4465..5c17518468 100644
--- a/detections/deprecated/windows_msiexec_with_network_connections.yml
+++ b/detections/deprecated/windows_msiexec_with_network_connections.yml
@@ -1,18 +1,19 @@
name: Windows MSIExec With Network Connections
id: 827409a1-5393-4d8d-8da4-bbb297c262a7
-version: 6
+version: 7
date: '2025-01-24'
author: Michael Haag, Splunk
status: deprecated
type: TTP
-description: The following analytic has been deprecated. The following analytic detects
- MSIExec making network connections over ports 443 or 80. This behavior is identified
- by correlating process creation events from Endpoint Detection and Response (EDR)
- agents with network traffic logs. Typically, MSIExec does not perform network communication
- to the internet, making this activity unusual and potentially indicative of malicious
- behavior. If confirmed malicious, an attacker could be using MSIExec to download
- or communicate with external servers, potentially leading to data exfiltration,
- command and control (C2) communication, or further malware deployment.
+description: The following analytic has been deprecated.
+ The following analytic detects MSIExec making network connections over
+ ports 443 or 80. This behavior is identified by correlating process creation events
+ from Endpoint Detection and Response (EDR) agents with network traffic logs. Typically,
+ MSIExec does not perform network communication to the internet, making this activity
+ unusual and potentially indicative of malicious behavior. If confirmed malicious,
+ an attacker could be using MSIExec to download or communicate with external servers,
+ potentially leading to data exfiltration, command and control (C2) communication,
+ or further malware deployment.
data_source:
- Sysmon EventID 1 AND Sysmon EventID 3
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
diff --git a/detections/deprecated/windows_network_share_interaction_with_net.yml b/detections/deprecated/windows_network_share_interaction_with_net.yml
index 29047d8992..fea71519c1 100644
--- a/detections/deprecated/windows_network_share_interaction_with_net.yml
+++ b/detections/deprecated/windows_network_share_interaction_with_net.yml
@@ -7,13 +7,13 @@ status: deprecated
type: TTP
data_source:
- Sysmon EventID 1
-description: The following analytic has been deprecated. This analytic detects network
- share discovery and collection activities performed on Windows systems using the
- Net command. Attackers often use network share discovery to identify accessible
- shared resources within a network, which can be a precursor to privilege escalation
- or data exfiltration. By monitoring Windows Event Logs for the usage of the Net
- command to list and interact with network shares, this detection helps identify
- potential reconnaissance and collection activities.
+description: The following analytic has been deprecated.
+ This analytic detects network share discovery and collection activities
+ performed on Windows systems using the Net command. Attackers often use network
+ share discovery to identify accessible shared resources within a network, which
+ can be a precursor to privilege escalation or data exfiltration. By monitoring Windows
+ Event Logs for the usage of the Net command to list and interact with network shares,
+ this detection helps identify potential reconnaissance and collection activities.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime values(Processes.user_category) as user_category values(Processes.user_bunit)
as user_bunit FROM datamodel=Endpoint.Processes WHERE `process_net` BY Processes.user
diff --git a/detections/deprecated/windows_office_product_spawning_msdt.yml b/detections/deprecated/windows_office_product_spawning_msdt.yml
index 88be1f1298..9415352231 100644
--- a/detections/deprecated/windows_office_product_spawning_msdt.yml
+++ b/detections/deprecated/windows_office_product_spawning_msdt.yml
@@ -1,7 +1,7 @@
name: Windows Office Product Spawning MSDT
id: 127eba64-c981-40bf-8589-1830638864a7
-version: 9
-date: '2025-01-24'
+version: 11
+date: '2025-02-10'
author: Michael Haag, Teoderick Contreras, Splunk
status: deprecated
type: TTP
@@ -80,7 +80,6 @@ tags:
cve:
- CVE-2022-30190
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/windows_query_registry_reg_save.yml b/detections/deprecated/windows_query_registry_reg_save.yml
index f44d4b8617..291c0cf7a0 100644
--- a/detections/deprecated/windows_query_registry_reg_save.yml
+++ b/detections/deprecated/windows_query_registry_reg_save.yml
@@ -5,14 +5,14 @@ date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
type: Hunting
-description: The following analytic has been deprecated. The following analytic detects
- the execution of the reg.exe process with the "save" parameter. This detection leverages
- data from Endpoint Detection and Response (EDR) agents, focusing on process execution
- logs and command-line arguments. This activity is significant because threat actors
- often use the "reg save" command to dump credentials or test registry modification
- capabilities on compromised hosts. If confirmed malicious, this behavior could allow
- attackers to escalate privileges, persist in the environment, or access sensitive
- information stored in the registry.
+description: The following analytic has been deprecated.
+ The following analytic detects the execution of the reg.exe process with
+ the "save" parameter. This detection leverages data from Endpoint Detection and
+ Response (EDR) agents, focusing on process execution logs and command-line arguments.
+ This activity is significant because threat actors often use the "reg save" command
+ to dump credentials or test registry modification capabilities on compromised hosts.
+ If confirmed malicious, this behavior could allow attackers to escalate privileges,
+ persist in the environment, or access sensitive information stored in the registry.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/windows_valid_account_with_never_expires_password.yml b/detections/deprecated/windows_valid_account_with_never_expires_password.yml
index 6bd2c46133..01b416d1d5 100644
--- a/detections/deprecated/windows_valid_account_with_never_expires_password.yml
+++ b/detections/deprecated/windows_valid_account_with_never_expires_password.yml
@@ -5,14 +5,15 @@ date: '2025-01-24'
author: Teoderick Contreras, Splunk
status: deprecated
type: TTP
-description: The following analytic has been deprecated. The following analytic detects
- the use of net.exe to update user account policies to set passwords as non-expiring.
- It leverages data from Endpoint Detection and Response (EDR) agents, focusing on
- command-line executions involving "/maxpwage:unlimited". This activity is significant
- as it can indicate an attempt to maintain persistence, escalate privileges, evade
- defenses, or facilitate lateral movement. If confirmed malicious, this behavior
- could allow an attacker to maintain long-term access to compromised accounts, potentially
- leading to further exploitation and unauthorized access to sensitive information.
+description: The following analytic has been deprecated.
+ The following analytic detects the use of net.exe to update user account
+ policies to set passwords as non-expiring. It leverages data from Endpoint Detection
+ and Response (EDR) agents, focusing on command-line executions involving "/maxpwage:unlimited".
+ This activity is significant as it can indicate an attempt to maintain persistence,
+ escalate privileges, evade defenses, or facilitate lateral movement. If confirmed
+ malicious, this behavior could allow an attacker to maintain long-term access to
+ compromised accounts, potentially leading to further exploitation and unauthorized
+ access to sensitive information.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/detections/deprecated/winword_spawning_cmd.yml b/detections/deprecated/winword_spawning_cmd.yml
index f16575033c..2d65e01f22 100644
--- a/detections/deprecated/winword_spawning_cmd.yml
+++ b/detections/deprecated/winword_spawning_cmd.yml
@@ -1,7 +1,7 @@
name: Winword Spawning Cmd
id: 6fcbaedc-a37b-11eb-956b-acde48001122
-version: 7
-date: '2025-01-13'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: deprecated
type: TTP
@@ -73,7 +73,6 @@ tags:
- DarkCrystal RAT
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/winword_spawning_powershell.yml b/detections/deprecated/winword_spawning_powershell.yml
index 50d598f95b..4164d64cf7 100644
--- a/detections/deprecated/winword_spawning_powershell.yml
+++ b/detections/deprecated/winword_spawning_powershell.yml
@@ -1,7 +1,7 @@
name: Winword Spawning PowerShell
id: b2c950b8-9be2-11eb-8658-acde48001122
-version: 7
-date: '2025-01-13'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: deprecated
type: TTP
@@ -76,7 +76,6 @@ tags:
- DarkCrystal RAT
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/deprecated/winword_spawning_windows_script_host.yml b/detections/deprecated/winword_spawning_windows_script_host.yml
index b1d17ca5a5..47feee0635 100644
--- a/detections/deprecated/winword_spawning_windows_script_host.yml
+++ b/detections/deprecated/winword_spawning_windows_script_host.yml
@@ -1,7 +1,7 @@
name: Winword Spawning Windows Script Host
id: 637e1b5c-9be1-11eb-9c32-acde48001122
-version: 6
-date: '2025-01-13'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Splunk
status: deprecated
type: TTP
@@ -70,7 +70,6 @@ tags:
- CVE-2023-21716 Word RTF Heap Corruption
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/7zip_commandline_to_smb_share_path.yml b/detections/endpoint/7zip_commandline_to_smb_share_path.yml
index 01c78be576..052abeb87b 100644
--- a/detections/endpoint/7zip_commandline_to_smb_share_path.yml
+++ b/detections/endpoint/7zip_commandline_to_smb_share_path.yml
@@ -1,7 +1,7 @@
name: 7zip CommandLine To SMB Share Path
id: 01d29b48-ff6f-11eb-b81e-acde48001123
-version: 5
-date: '2025-01-21'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -43,7 +43,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1560.001
- - T1560
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/access_lsass_memory_for_dump_creation.yml b/detections/endpoint/access_lsass_memory_for_dump_creation.yml
index ad6103c9b0..0f261b491b 100644
--- a/detections/endpoint/access_lsass_memory_for_dump_creation.yml
+++ b/detections/endpoint/access_lsass_memory_for_dump_creation.yml
@@ -1,7 +1,7 @@
name: Access LSASS Memory for Dump Creation
id: fb4c31b0-13e8-4155-8aa5-24de4b8d6717
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
asset_type: Windows
mitre_attack_id:
- T1003.001
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/active_setup_registry_autostart.yml b/detections/endpoint/active_setup_registry_autostart.yml
index 6f4e0d1d4d..6ca39da2a4 100644
--- a/detections/endpoint/active_setup_registry_autostart.yml
+++ b/detections/endpoint/active_setup_registry_autostart.yml
@@ -1,7 +1,7 @@
name: Active Setup Registry Autostart
id: f64579c0-203f-11ec-abcc-acde48001122
-version: 8
-date: '2024-12-08'
+version: 9
+date: '2025-02-10'
author: Steven Dick, Teoderick Contreras, Splunk
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1547.014
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/add_defaultuser_and_password_in_registry.yml b/detections/endpoint/add_defaultuser_and_password_in_registry.yml
index cd0c7eb48c..968de4b132 100644
--- a/detections/endpoint/add_defaultuser_and_password_in_registry.yml
+++ b/detections/endpoint/add_defaultuser_and_password_in_registry.yml
@@ -1,7 +1,7 @@
name: Add DefaultUser And Password In Registry
id: d4a3eb62-0f1e-11ec-a971-acde48001122
-version: 8
-date: '2024-12-08'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: Anomaly
@@ -59,7 +59,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1552.002
- - T1552
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/add_or_set_windows_defender_exclusion.yml b/detections/endpoint/add_or_set_windows_defender_exclusion.yml
index cf78828ce7..ca4975ede6 100644
--- a/detections/endpoint/add_or_set_windows_defender_exclusion.yml
+++ b/detections/endpoint/add_or_set_windows_defender_exclusion.yml
@@ -1,7 +1,7 @@
name: Add or Set Windows Defender Exclusion
id: 773b66fe-4dd9-11ec-8289-acde48001122
-version: '6'
-date: '2024-12-17'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -77,7 +77,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/adsisearcher_account_discovery.yml b/detections/endpoint/adsisearcher_account_discovery.yml
index 65286be5b8..67241b0279 100644
--- a/detections/endpoint/adsisearcher_account_discovery.yml
+++ b/detections/endpoint/adsisearcher_account_discovery.yml
@@ -1,7 +1,7 @@
name: AdsiSearcher Account Discovery
id: de7fcadc-04f3-11ec-a241-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -62,7 +62,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1087.002
- - T1087
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml
index 0a86ed9fd9..2e11a3aa86 100644
--- a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml
+++ b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml
@@ -1,7 +1,7 @@
name: Allow File And Printing Sharing In Firewall
id: ce27646e-d411-11eb-8a00-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -70,7 +70,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.007
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml
index 6b7f561f20..8aa114f36a 100644
--- a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml
+++ b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml
@@ -1,7 +1,7 @@
name: Allow Inbound Traffic By Firewall Rule Registry
id: 0a46537c-be02-11eb-92ca-acde48001122
-version: 9
-date: '2024-12-08'
+version: 10
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -66,7 +66,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1021.001
- - T1021
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml b/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml
index 677ec6f051..bf2fda0d4b 100644
--- a/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml
+++ b/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml
@@ -1,7 +1,7 @@
name: Allow Inbound Traffic In Firewall Rule
id: a5d85486-b89c-11eb-8267-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -56,7 +56,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1021.001
- - T1021
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/allow_network_discovery_in_firewall.yml b/detections/endpoint/allow_network_discovery_in_firewall.yml
index 1334af8f48..1163a4d168 100644
--- a/detections/endpoint/allow_network_discovery_in_firewall.yml
+++ b/detections/endpoint/allow_network_discovery_in_firewall.yml
@@ -1,7 +1,7 @@
name: Allow Network Discovery In Firewall
id: ccd6a38c-d40b-11eb-85a5-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -69,7 +69,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.007
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/anomalous_usage_of_7zip.yml b/detections/endpoint/anomalous_usage_of_7zip.yml
index 952bab98c5..32a9f2d25c 100644
--- a/detections/endpoint/anomalous_usage_of_7zip.yml
+++ b/detections/endpoint/anomalous_usage_of_7zip.yml
@@ -1,7 +1,7 @@
name: Anomalous usage of 7zip
id: 9364ee8e-a39a-11eb-8f1d-acde48001122
-version: 6
-date: '2024-11-13'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -77,7 +77,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1560.001
- - T1560
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/any_powershell_downloadfile.yml b/detections/endpoint/any_powershell_downloadfile.yml
index 74049ff9cb..65a6733058 100644
--- a/detections/endpoint/any_powershell_downloadfile.yml
+++ b/detections/endpoint/any_powershell_downloadfile.yml
@@ -1,7 +1,7 @@
name: Any Powershell DownloadFile
id: 1a93b7ea-7af7-11eb-adb5-acde48001122
-version: 9
-date: '2025-01-27'
+version: 11
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -87,7 +87,6 @@ tags:
cve:
- CVE-2021-44228
mitre_attack_id:
- - T1059
- T1059.001
- T1105
product:
@@ -98,6 +97,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/any_powershell_downloadstring.yml b/detections/endpoint/any_powershell_downloadstring.yml
index 3a5fdced6f..7f516361ff 100644
--- a/detections/endpoint/any_powershell_downloadstring.yml
+++ b/detections/endpoint/any_powershell_downloadstring.yml
@@ -1,7 +1,7 @@
name: Any Powershell DownloadString
id: 4d015ef2-7adf-11eb-95da-acde48001122
-version: 7
-date: '2024-11-13'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -83,7 +83,6 @@ tags:
- Phemedrone Stealer
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.001
- T1105
product:
diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml
index 13d06f14d7..a983aeb31d 100644
--- a/detections/endpoint/attacker_tools_on_endpoint.yml
+++ b/detections/endpoint/attacker_tools_on_endpoint.yml
@@ -1,7 +1,7 @@
name: Attacker Tools On Endpoint
id: a51bfe1a-94f0-48cc-b4e4-16a110145893
-version: 7
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -73,9 +73,8 @@ tags:
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- - T1036.005
- - T1036
- T1003
+ - T1036.005
- T1595
product:
- Splunk Enterprise
diff --git a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml
index e23a285c6c..360d6c472d 100644
--- a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml
+++ b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml
@@ -1,7 +1,7 @@
name: Attempt To Add Certificate To Untrusted Store
id: 6bc5243e-ef36-45dc-9b12-f4a6be131159
-version: 11
-date: '2024-11-13'
+version: 13
+date: '2025-02-10'
author: Patrick Bareiss, Rico Valdez, Splunk
status: production
type: TTP
@@ -71,7 +71,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1553.004
- - T1553
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/auto_admin_logon_registry_entry.yml b/detections/endpoint/auto_admin_logon_registry_entry.yml
index ab26897ba0..8161fcdca6 100644
--- a/detections/endpoint/auto_admin_logon_registry_entry.yml
+++ b/detections/endpoint/auto_admin_logon_registry_entry.yml
@@ -1,7 +1,7 @@
name: Auto Admin Logon Registry Entry
id: 1379d2b8-0f18-11ec-8ca3-acde48001122
-version: 8
-date: '2024-12-08'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1552.002
- - T1552
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/batch_file_write_to_system32.yml b/detections/endpoint/batch_file_write_to_system32.yml
index b7fa5f29ff..0d3a9702cd 100644
--- a/detections/endpoint/batch_file_write_to_system32.yml
+++ b/detections/endpoint/batch_file_write_to_system32.yml
@@ -1,7 +1,7 @@
name: Batch File Write to System32
id: 503d17cb-9eab-4cf8-a20e-01d5c6987ae3
-version: 8
-date: '2024-12-10'
+version: 9
+date: '2025-02-10'
author: Steven Dick, Michael Haag, Rico Valdez, Splunk
status: production
type: TTP
@@ -71,7 +71,6 @@ tags:
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- - T1204
- T1204.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/bcdedit_failure_recovery_modification.yml b/detections/endpoint/bcdedit_failure_recovery_modification.yml
index 29bdb7ba33..1425eee424 100644
--- a/detections/endpoint/bcdedit_failure_recovery_modification.yml
+++ b/detections/endpoint/bcdedit_failure_recovery_modification.yml
@@ -1,6 +1,6 @@
name: BCDEdit Failure Recovery Modification
id: 809b31d2-5462-11eb-ae93-0242ac130002
-version: 6
+version: 7
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/bits_job_persistence.yml b/detections/endpoint/bits_job_persistence.yml
index b115098430..eee12eeb44 100644
--- a/detections/endpoint/bits_job_persistence.yml
+++ b/detections/endpoint/bits_job_persistence.yml
@@ -1,6 +1,6 @@
name: BITS Job Persistence
id: e97a5ffe-90bf-11eb-928a-acde48001122
-version: 6
+version: 7
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/bitsadmin_download_file.yml b/detections/endpoint/bitsadmin_download_file.yml
index da8e3522bb..bdab9e207a 100644
--- a/detections/endpoint/bitsadmin_download_file.yml
+++ b/detections/endpoint/bitsadmin_download_file.yml
@@ -1,6 +1,6 @@
name: BITSAdmin Download File
id: 80630ff4-8e4c-11eb-aab5-acde48001122
-version: 7
+version: 8
date: '2024-11-13'
author: Michael Haag, Sittikorn S
status: production
diff --git a/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml b/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml
index 7e3407c516..b6d19b0b39 100644
--- a/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml
+++ b/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml
@@ -1,6 +1,6 @@
name: CertUtil Download With URLCache and Split Arguments
id: 415b4306-8bfb-11eb-85c4-acde48001122
-version: 9
+version: 10
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml b/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml
index 7c6a453b69..97a0c24ba9 100644
--- a/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml
+++ b/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml
@@ -1,6 +1,6 @@
name: CertUtil Download With VerifyCtl and Split Arguments
id: 801ad9e4-8bfb-11eb-8b31-acde48001122
-version: 9
+version: 10
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/certutil_exe_certificate_extraction.yml b/detections/endpoint/certutil_exe_certificate_extraction.yml
index 34b29335c5..6dafec9ff9 100644
--- a/detections/endpoint/certutil_exe_certificate_extraction.yml
+++ b/detections/endpoint/certutil_exe_certificate_extraction.yml
@@ -1,6 +1,6 @@
name: Certutil exe certificate extraction
id: 337a46be-600f-11eb-ae93-0242ac130002
-version: 7
+version: 8
date: '2024-12-10'
author: Rod Soto, Splunk
status: production
diff --git a/detections/endpoint/certutil_with_decode_argument.yml b/detections/endpoint/certutil_with_decode_argument.yml
index 0fc4d9b902..f00b0f4387 100644
--- a/detections/endpoint/certutil_with_decode_argument.yml
+++ b/detections/endpoint/certutil_with_decode_argument.yml
@@ -1,6 +1,6 @@
name: CertUtil With Decode Argument
id: bfe94226-8c10-11eb-a4b3-acde48001122
-version: 6
+version: 7
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/check_elevated_cmd_using_whoami.yml b/detections/endpoint/check_elevated_cmd_using_whoami.yml
index abb19e8ac8..b5f5648875 100644
--- a/detections/endpoint/check_elevated_cmd_using_whoami.yml
+++ b/detections/endpoint/check_elevated_cmd_using_whoami.yml
@@ -1,6 +1,6 @@
name: Check Elevated CMD using whoami
id: a9079b18-1633-11ec-859c-acde48001122
-version: 4
+version: 5
date: '2024-11-13'
author: Teoderick Contreras, Splunk
status: production
diff --git a/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml b/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml
index ee6d5594e2..82a73a420c 100644
--- a/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml
+++ b/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml
@@ -1,7 +1,7 @@
name: Clear Unallocated Sector Using Cipher App
id: cd80a6ac-c9d9-11eb-8839-acde48001122
-version: 6
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -72,7 +72,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1070.004
- - T1070
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/clop_common_exec_parameter.yml b/detections/endpoint/clop_common_exec_parameter.yml
index 0be756484b..3618dec57d 100644
--- a/detections/endpoint/clop_common_exec_parameter.yml
+++ b/detections/endpoint/clop_common_exec_parameter.yml
@@ -1,6 +1,6 @@
name: Clop Common Exec Parameter
id: 5a8a2a72-8322-11eb-9ee9-acde48001122
-version: 7
+version: 8
date: '2024-12-10'
author: Teoderick Contreras, Splunk
status: production
diff --git a/detections/endpoint/cmd_carry_out_string_command_parameter.yml b/detections/endpoint/cmd_carry_out_string_command_parameter.yml
index ead8c6acad..f2545358d1 100644
--- a/detections/endpoint/cmd_carry_out_string_command_parameter.yml
+++ b/detections/endpoint/cmd_carry_out_string_command_parameter.yml
@@ -1,7 +1,7 @@
name: CMD Carry Out String Command Parameter
id: 54a6ed00-3256-11ec-b031-acde48001122
-version: 7
-date: '2024-11-13'
+version: 8
+date: '2025-02-10'
author: Teoderick Contreras, Bhavin Patel, Splunk
status: production
type: Hunting
@@ -64,7 +64,6 @@ tags:
- CVE-2021-44228
mitre_attack_id:
- T1059.003
- - T1059
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/cmd_echo_pipe___escalation.yml b/detections/endpoint/cmd_echo_pipe___escalation.yml
index 618a7f1670..c1b77e4c5b 100644
--- a/detections/endpoint/cmd_echo_pipe___escalation.yml
+++ b/detections/endpoint/cmd_echo_pipe___escalation.yml
@@ -1,7 +1,7 @@
name: CMD Echo Pipe - Escalation
id: eb277ba0-b96b-11eb-b00e-acde48001122
-version: 7
-date: '2024-12-10'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -75,10 +75,8 @@ tags:
- BlackByte Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.003
- T1543.003
- - T1543
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml b/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml
index d71bc60a38..deb0daab75 100644
--- a/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml
+++ b/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml
@@ -1,7 +1,7 @@
name: CMLUA Or CMSTPLUA UAC Bypass
id: f87b5062-b405-11eb-a889-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
- ValleyRAT
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/common_ransomware_extensions.yml b/detections/endpoint/common_ransomware_extensions.yml
index 281a998ed1..b7dbef7eb3 100644
--- a/detections/endpoint/common_ransomware_extensions.yml
+++ b/detections/endpoint/common_ransomware_extensions.yml
@@ -1,6 +1,6 @@
name: Common Ransomware Extensions
id: a9e5c5db-db11-43ca-86a8-c852d1b2c0ec
-version: 10
+version: 11
date: '2025-01-07'
author: David Dorsey, Michael Haag, Splunk, Steven Dick
status: production
diff --git a/detections/endpoint/conti_common_exec_parameter.yml b/detections/endpoint/conti_common_exec_parameter.yml
index fe3227dd29..68ddb073f8 100644
--- a/detections/endpoint/conti_common_exec_parameter.yml
+++ b/detections/endpoint/conti_common_exec_parameter.yml
@@ -1,6 +1,6 @@
name: Conti Common Exec parameter
id: 624919bc-c382-11eb-adcc-acde48001122
-version: 6
+version: 7
date: '2024-12-10'
author: Teoderick Contreras, Splunk
status: production
diff --git a/detections/endpoint/control_loading_from_world_writable_directory.yml b/detections/endpoint/control_loading_from_world_writable_directory.yml
index 0b02258a47..34c0fe2491 100644
--- a/detections/endpoint/control_loading_from_world_writable_directory.yml
+++ b/detections/endpoint/control_loading_from_world_writable_directory.yml
@@ -1,7 +1,7 @@
name: Control Loading from World Writable Directory
id: 10423ac4-10c9-11ec-8dc4-acde48001122
-version: 6
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -80,7 +80,6 @@ tags:
cve:
- CVE-2021-40444
mitre_attack_id:
- - T1218
- T1218.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml
index c90a12c6e9..43cc11f1f7 100644
--- a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml
+++ b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml
@@ -1,7 +1,7 @@
name: Create or delete windows shares using net exe
id: 743a322c-9a68-4a0f-9c17-85d9cce2a27c
-version: 10
-date: '2024-12-12'
+version: 12
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -76,7 +76,6 @@ tags:
- DarkGate Malware
asset_type: Endpoint
mitre_attack_id:
- - T1070
- T1070.005
product:
- Splunk Enterprise
diff --git a/detections/endpoint/create_remote_thread_into_lsass.yml b/detections/endpoint/create_remote_thread_into_lsass.yml
index daf76493ed..fbc0310759 100644
--- a/detections/endpoint/create_remote_thread_into_lsass.yml
+++ b/detections/endpoint/create_remote_thread_into_lsass.yml
@@ -1,7 +1,7 @@
name: Create Remote Thread into LSASS
id: 67d4dbef-9564-4699-8da8-03a151529edc
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
@@ -59,7 +59,6 @@ tags:
asset_type: Windows
mitre_attack_id:
- T1003.001
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml b/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml
index ee0bb861f3..dcd2a4391c 100644
--- a/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml
+++ b/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml
@@ -1,7 +1,7 @@
name: Creation of lsass Dump with Taskmgr
id: b2fbe95a-9c62-4c12-8a29-24b97e84c0cd
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -59,7 +59,6 @@ tags:
asset_type: Windows
mitre_attack_id:
- T1003.001
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/creation_of_shadow_copy.yml b/detections/endpoint/creation_of_shadow_copy.yml
index 49b3059565..ce5b148d77 100644
--- a/detections/endpoint/creation_of_shadow_copy.yml
+++ b/detections/endpoint/creation_of_shadow_copy.yml
@@ -1,7 +1,7 @@
name: Creation of Shadow Copy
id: eb120f5f-b879-4a63-97c1-93352b5df844
-version: 6
-date: '2024-12-10'
+version: 7
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
@@ -74,7 +74,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.003
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml
index 9571ea9236..78b7c0d9dd 100644
--- a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml
+++ b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml
@@ -1,7 +1,7 @@
name: Creation of Shadow Copy with wmic and powershell
id: 2ed8b538-d284-449a-be1d-82ad1dbd186b
-version: 8
-date: '2024-12-10'
+version: 9
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
@@ -71,7 +71,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.003
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml
index 69aa5fe62b..a443947f7e 100644
--- a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml
+++ b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml
@@ -1,7 +1,7 @@
name: Credential Dumping via Copy Command from Shadow Copy
id: d8c406fe-23d2-45f3-a983-1abe7b83ff3b
-version: 6
-date: '2024-12-10'
+version: 7
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
@@ -70,7 +70,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.003
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml
index ed7082bfee..ac524c6b29 100644
--- a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml
+++ b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml
@@ -1,7 +1,7 @@
name: Credential Dumping via Symlink to Shadow Copy
id: c5eac648-fae0-4263-91a6-773df1f4c903
-version: 6
-date: '2024-12-10'
+version: 7
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
@@ -69,7 +69,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.003
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/csc_net_on_the_fly_compilation.yml b/detections/endpoint/csc_net_on_the_fly_compilation.yml
index 523efe64be..39211a947c 100644
--- a/detections/endpoint/csc_net_on_the_fly_compilation.yml
+++ b/detections/endpoint/csc_net_on_the_fly_compilation.yml
@@ -1,7 +1,7 @@
name: CSC Net On The Fly Compilation
id: ea73128a-43ab-11ec-9753-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -45,7 +45,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1027.004
- - T1027
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/deleting_shadow_copies.yml b/detections/endpoint/deleting_shadow_copies.yml
index 43b2d363b6..89b5ebed9b 100644
--- a/detections/endpoint/deleting_shadow_copies.yml
+++ b/detections/endpoint/deleting_shadow_copies.yml
@@ -1,6 +1,6 @@
name: Deleting Shadow Copies
id: b89919ed-ee5f-492c-b139-95dbb162039e
-version: 9
+version: 10
date: '2024-12-10'
author: David Dorsey, Splunk
status: production
diff --git a/detections/endpoint/detect_azurehound_command_line_arguments.yml b/detections/endpoint/detect_azurehound_command_line_arguments.yml
index a20929459c..df661b9c10 100644
--- a/detections/endpoint/detect_azurehound_command_line_arguments.yml
+++ b/detections/endpoint/detect_azurehound_command_line_arguments.yml
@@ -1,7 +1,7 @@
name: Detect AzureHound Command-Line Arguments
id: 26f02e96-c300-11eb-b611-acde48001122
-version: 7
-date: '2024-12-10'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -72,13 +72,11 @@ tags:
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- - T1087.002
- T1069.001
- - T1482
- - T1087.001
- - T1087
- T1069.002
- - T1069
+ - T1087.001
+ - T1087.002
+ - T1482
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/detect_azurehound_file_modifications.yml b/detections/endpoint/detect_azurehound_file_modifications.yml
index 71aee3b142..af89e009cd 100644
--- a/detections/endpoint/detect_azurehound_file_modifications.yml
+++ b/detections/endpoint/detect_azurehound_file_modifications.yml
@@ -1,7 +1,7 @@
name: Detect AzureHound File Modifications
id: 1c34549e-c31b-11eb-996b-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -62,13 +62,11 @@ tags:
- Windows Discovery Techniques
asset_type: Endpoint
mitre_attack_id:
- - T1087.002
- T1069.001
- - T1482
- - T1087.001
- - T1087
- T1069.002
- - T1069
+ - T1087.001
+ - T1087.002
+ - T1482
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/detect_certify_with_powershell_script_block_logging.yml b/detections/endpoint/detect_certify_with_powershell_script_block_logging.yml
index 38e25e1fcc..5b22224e3d 100644
--- a/detections/endpoint/detect_certify_with_powershell_script_block_logging.yml
+++ b/detections/endpoint/detect_certify_with_powershell_script_block_logging.yml
@@ -1,7 +1,7 @@
name: Detect Certify With PowerShell Script Block Logging
id: f533ca6c-9440-4686-80cb-7f294c07812a
-version: 4
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -62,9 +62,8 @@ tags:
- Malicious PowerShell
asset_type: Endpoint
mitre_attack_id:
- - T1649
- - T1059
- T1059.001
+ - T1649
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/detect_certipy_file_modifications.yml b/detections/endpoint/detect_certipy_file_modifications.yml
index 932c36dce7..48a6a3129b 100644
--- a/detections/endpoint/detect_certipy_file_modifications.yml
+++ b/detections/endpoint/detect_certipy_file_modifications.yml
@@ -1,6 +1,6 @@
name: Detect Certipy File Modifications
id: 7e3df743-b1d8-4631-8fa8-bd5819688876
-version: 4
+version: 5
date: '2024-11-13'
author: Steven Dick
status: production
diff --git a/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml b/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml
index 9f13d8ec5e..5ba7b43a6d 100644
--- a/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml
+++ b/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml
@@ -1,7 +1,7 @@
name: Detect Copy of ShadowCopy with Script Block Logging
id: 9251299c-ea5b-11eb-a8de-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
- CVE-2021-36934
mitre_attack_id:
- T1003.002
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/detect_credential_dumping_through_lsass_access.yml b/detections/endpoint/detect_credential_dumping_through_lsass_access.yml
index cbca225e2f..d407bbd637 100644
--- a/detections/endpoint/detect_credential_dumping_through_lsass_access.yml
+++ b/detections/endpoint/detect_credential_dumping_through_lsass_access.yml
@@ -1,7 +1,7 @@
name: Detect Credential Dumping through LSASS access
id: 2c365e57-4414-4540-8dc0-73ab10729996
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
asset_type: Windows
mitre_attack_id:
- T1003.001
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml b/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml
index 7e5e09b90a..4c5e71523a 100644
--- a/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml
+++ b/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml
@@ -1,7 +1,7 @@
name: Detect Empire with PowerShell Script Block Logging
id: bc1dc6b8-c954-11eb-bade-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -65,7 +65,6 @@ tags:
- Data Destruction
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml b/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml
index c159f44c23..e81a797125 100644
--- a/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml
+++ b/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml
@@ -1,7 +1,7 @@
name: Detect Excessive Account Lockouts From Endpoint
id: c026e3dd-7e18-4abb-8f41-929e836efe74
-version: 11
-date: '2024-11-13'
+version: 12
+date: '2025-02-10'
author: David Dorsey, Splunk
status: production
type: Anomaly
@@ -66,7 +66,6 @@ tags:
- Active Directory Password Spraying
asset_type: Windows
mitre_attack_id:
- - T1078
- T1078.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_excessive_user_account_lockouts.yml b/detections/endpoint/detect_excessive_user_account_lockouts.yml
index e80d4200a3..6eab6eb5d8 100644
--- a/detections/endpoint/detect_excessive_user_account_lockouts.yml
+++ b/detections/endpoint/detect_excessive_user_account_lockouts.yml
@@ -1,7 +1,7 @@
name: Detect Excessive User Account Lockouts
id: 95a7f9a5-6096-437e-a19e-86f42ac609bd
-version: 8
-date: '2024-11-13'
+version: 9
+date: '2025-02-10'
author: David Dorsey, Splunk
status: production
type: Anomaly
@@ -51,7 +51,6 @@ tags:
- Active Directory Password Spraying
asset_type: Windows
mitre_attack_id:
- - T1078
- T1078.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_exchange_web_shell.yml b/detections/endpoint/detect_exchange_web_shell.yml
index 6301bf3efc..11b24212d0 100644
--- a/detections/endpoint/detect_exchange_web_shell.yml
+++ b/detections/endpoint/detect_exchange_web_shell.yml
@@ -1,7 +1,7 @@
name: Detect Exchange Web Shell
id: 8c14eeee-2af1-4a4b-bda8-228da0f4862a
-version: 9
-date: '2024-12-12'
+version: 10
+date: '2025-02-10'
author: Michael Haag, Shannon Davis, David Dorsey, Splunk
status: production
type: TTP
@@ -16,18 +16,16 @@ description: The following analytic identifies the creation of suspicious .aspx
data_source:
- Sysmon EventID 1 AND Sysmon EventID 11
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
- where Processes.process_name=System by _time span=1h Processes.process_guid Processes.process_name Processes.process
- Processes.dest Processes.user
-| `drop_dm_object_name(Processes)`
-| join process_guid, _time
- [| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
- as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\HttpProxy\\owa\\auth\\*",
- "*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*") Filesystem.file_name
- IN( "*.aspx", "*.ashx") by _time span=1h Filesystem.process_guid Filesystem.user Filesystem.dest Filesystem.file_create_time
- Filesystem.file_name Filesystem.file_path
- | `drop_dm_object_name(Filesystem)` ]
- | dedup file_create_time
- | table _time dest user file_create_time file_name file_path process_name process process_guid | `detect_exchange_web_shell_filter`'
+ where Processes.process_name=System by _time span=1h Processes.process_guid Processes.process_name
+ Processes.process Processes.dest Processes.user | `drop_dm_object_name(Processes)`
+ | join process_guid, _time [| tstats `security_content_summariesonly` count min(_time)
+ as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path
+ IN ("*\\HttpProxy\\owa\\auth\\*", "*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*")
+ Filesystem.file_name IN( "*.aspx", "*.ashx") by _time span=1h Filesystem.process_guid
+ Filesystem.user Filesystem.dest Filesystem.file_create_time Filesystem.file_name
+ Filesystem.file_path | `drop_dm_object_name(Filesystem)` ] | dedup file_create_time
+ | table _time dest user file_create_time file_name file_path process_name process
+ process_guid | `detect_exchange_web_shell_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem`
@@ -78,10 +76,9 @@ tags:
- BlackByte Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1505
- - T1505.003
- - T1190
- T1133
+ - T1190
+ - T1505.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/detect_html_help_renamed.yml b/detections/endpoint/detect_html_help_renamed.yml
index 5ad0885f0f..a772c50bad 100644
--- a/detections/endpoint/detect_html_help_renamed.yml
+++ b/detections/endpoint/detect_html_help_renamed.yml
@@ -1,7 +1,7 @@
name: Detect HTML Help Renamed
id: 62fed254-513b-460e-953d-79771493a9f3
-version: 8
-date: '2024-11-13'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -44,7 +44,6 @@ tags:
- Living Off The Land
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_html_help_spawn_child_process.yml b/detections/endpoint/detect_html_help_spawn_child_process.yml
index 05aed6328e..e4cf5469a5 100644
--- a/detections/endpoint/detect_html_help_spawn_child_process.yml
+++ b/detections/endpoint/detect_html_help_spawn_child_process.yml
@@ -1,7 +1,7 @@
name: Detect HTML Help Spawn Child Process
id: 723716de-ee55-4cd4-9759-c44e7e55ba4b
-version: 7
-date: '2024-12-10'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -78,7 +78,6 @@ tags:
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_html_help_url_in_command_line.yml b/detections/endpoint/detect_html_help_url_in_command_line.yml
index d72c7f64a1..4e07b994f9 100644
--- a/detections/endpoint/detect_html_help_url_in_command_line.yml
+++ b/detections/endpoint/detect_html_help_url_in_command_line.yml
@@ -1,7 +1,7 @@
name: Detect HTML Help URL in Command Line
id: 8c5835b9-39d9-438b-817c-95f14c69a31e
-version: 7
-date: '2024-12-10'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -77,7 +77,6 @@ tags:
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml b/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml
index 335817cd7b..3ab1a666ab 100644
--- a/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml
+++ b/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml
@@ -1,7 +1,7 @@
name: Detect HTML Help Using InfoTech Storage Handlers
id: 0b2eefa5-5508-450d-b970-3dd2fb761aec
-version: 7
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -75,7 +75,6 @@ tags:
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml b/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml
index 0960910cc8..d3616fae42 100644
--- a/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml
+++ b/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml
@@ -1,6 +1,6 @@
name: Detect Mimikatz With PowerShell Script Block Logging
id: 8148c29c-c952-11eb-9255-acde48001122
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/detect_mshta_inline_hta_execution.yml b/detections/endpoint/detect_mshta_inline_hta_execution.yml
index 09c4f17867..cc64c91a1d 100644
--- a/detections/endpoint/detect_mshta_inline_hta_execution.yml
+++ b/detections/endpoint/detect_mshta_inline_hta_execution.yml
@@ -1,7 +1,7 @@
name: Detect mshta inline hta execution
id: a0873b32-5b68-11eb-ae93-0242ac130002
-version: 12
-date: '2024-12-10'
+version: 14
+date: '2025-02-10'
author: Bhavin Patel, Michael Haag, Splunk
status: production
type: TTP
@@ -77,7 +77,6 @@ tags:
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.005
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_mshta_renamed.yml b/detections/endpoint/detect_mshta_renamed.yml
index 229050f266..8edd8c5256 100644
--- a/detections/endpoint/detect_mshta_renamed.yml
+++ b/detections/endpoint/detect_mshta_renamed.yml
@@ -1,7 +1,7 @@
name: Detect mshta renamed
id: 8f45fcf0-5b68-11eb-ae93-0242ac130002
-version: 7
-date: '2024-11-13'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -42,7 +42,6 @@ tags:
- Living Off The Land
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.005
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_mshta_url_in_command_line.yml b/detections/endpoint/detect_mshta_url_in_command_line.yml
index 7a9bc24261..c33a2bd047 100644
--- a/detections/endpoint/detect_mshta_url_in_command_line.yml
+++ b/detections/endpoint/detect_mshta_url_in_command_line.yml
@@ -1,7 +1,7 @@
name: Detect MSHTA Url in Command Line
id: 9b3af1e6-5b68-11eb-ae93-0242ac130002
-version: 8
-date: '2024-12-10'
+version: 10
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -77,7 +77,6 @@ tags:
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.005
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_new_local_admin_account.yml b/detections/endpoint/detect_new_local_admin_account.yml
index f70320bd1c..e17eed841e 100644
--- a/detections/endpoint/detect_new_local_admin_account.yml
+++ b/detections/endpoint/detect_new_local_admin_account.yml
@@ -1,7 +1,7 @@
name: Detect New Local Admin account
id: b25f6f62-0712-43c1-b203-083231ffd97d
-version: 6
-date: '2024-12-12'
+version: 7
+date: '2025-02-10'
author: David Dorsey, Splunk
status: production
type: TTP
@@ -62,7 +62,6 @@ tags:
asset_type: Windows
mitre_attack_id:
- T1136.001
- - T1136
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml b/detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml
index 4e6934e5fc..95d80c9749 100644
--- a/detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml
+++ b/detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml
@@ -1,7 +1,7 @@
name: Detect Outlook exe writing a zip file
id: a51bfe1a-94f0-4822-b1e4-16ae10145893
-version: 9
-date: '2024-12-10'
+version: 10
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: experimental
type: TTP
@@ -55,7 +55,6 @@ tags:
- Meduza Stealer
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_password_spray_attack_behavior_from_source.yml b/detections/endpoint/detect_password_spray_attack_behavior_from_source.yml
index a3a18311fa..474fcdd7d7 100644
--- a/detections/endpoint/detect_password_spray_attack_behavior_from_source.yml
+++ b/detections/endpoint/detect_password_spray_attack_behavior_from_source.yml
@@ -1,7 +1,7 @@
name: Detect Password Spray Attack Behavior From Source
id: b6391b15-e913-4c2c-8949-9eecc06efacc
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -68,7 +68,6 @@ tags:
asset_type: Account
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/detect_password_spray_attack_behavior_on_user.yml b/detections/endpoint/detect_password_spray_attack_behavior_on_user.yml
index bd82127859..c584c6dae0 100644
--- a/detections/endpoint/detect_password_spray_attack_behavior_on_user.yml
+++ b/detections/endpoint/detect_password_spray_attack_behavior_on_user.yml
@@ -1,7 +1,7 @@
name: Detect Password Spray Attack Behavior On User
id: a7539705-7183-4a12-9b6a-b6eef645a6d7
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -69,7 +69,6 @@ tags:
asset_type: Account
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml
index f6f07579ae..7996dfb15e 100644
--- a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml
+++ b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml
@@ -1,7 +1,7 @@
name: Detect Path Interception By Creation Of program exe
id: cbef820c-e1ff-407f-887f-0a9240a2d477
-version: 9
-date: '2024-11-13'
+version: 11
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
@@ -72,7 +72,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1574.009
- - T1574
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml
index 08ebbb0515..1b9df60d0d 100644
--- a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml
+++ b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml
@@ -1,7 +1,7 @@
name: Detect Prohibited Applications Spawning cmd exe
id: dcfd6b40-42f9-469d-a433-2e53f7486664
-version: 10
-date: '2024-11-13'
+version: 11
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: Hunting
@@ -44,7 +44,6 @@ tags:
- NOBELIUM Group
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_psexec_with_accepteula_flag.yml b/detections/endpoint/detect_psexec_with_accepteula_flag.yml
index 6004101254..f1974ad052 100644
--- a/detections/endpoint/detect_psexec_with_accepteula_flag.yml
+++ b/detections/endpoint/detect_psexec_with_accepteula_flag.yml
@@ -1,7 +1,7 @@
name: Detect PsExec With accepteula Flag
id: 27c3a83d-cada-47c6-9042-67baf19d2574
-version: 8
-date: '2024-11-13'
+version: 10
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -83,7 +83,6 @@ tags:
- Rhysida Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1021
- T1021.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_rclone_command_line_usage.yml b/detections/endpoint/detect_rclone_command_line_usage.yml
index 31e5bc6329..a36e49cace 100644
--- a/detections/endpoint/detect_rclone_command_line_usage.yml
+++ b/detections/endpoint/detect_rclone_command_line_usage.yml
@@ -1,6 +1,6 @@
name: Detect RClone Command-Line Usage
id: 32e0baea-b3f1-11eb-a2ce-acde48001122
-version: 6
+version: 7
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/detect_regasm_spawning_a_process.yml b/detections/endpoint/detect_regasm_spawning_a_process.yml
index edd0e0652f..adc6c5a181 100644
--- a/detections/endpoint/detect_regasm_spawning_a_process.yml
+++ b/detections/endpoint/detect_regasm_spawning_a_process.yml
@@ -1,7 +1,7 @@
name: Detect Regasm Spawning a Process
id: 72170ec5-f7d2-42f5-aefb-2b8be6aad15f
-version: 8
-date: '2024-12-10'
+version: 10
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -81,7 +81,6 @@ tags:
- Snake Keylogger
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.009
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_regasm_with_network_connection.yml b/detections/endpoint/detect_regasm_with_network_connection.yml
index 9b010fad35..803e1d2cc8 100644
--- a/detections/endpoint/detect_regasm_with_network_connection.yml
+++ b/detections/endpoint/detect_regasm_with_network_connection.yml
@@ -1,7 +1,7 @@
name: Detect Regasm with Network Connection
id: 07921114-6db4-4e2e-ae58-3ea8a52ae93f
-version: 7
-date: '2024-11-13'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
- Handala Wiper
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.009
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml b/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml
index 3431b74b40..a04e5c72a0 100644
--- a/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml
+++ b/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml
@@ -1,7 +1,7 @@
name: Detect Regasm with no Command Line Arguments
id: c3bc1430-04e7-4178-835f-047d8e6e97df
-version: 7
-date: '2024-11-13'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -75,7 +75,6 @@ tags:
- Handala Wiper
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.009
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_regsvcs_spawning_a_process.yml b/detections/endpoint/detect_regsvcs_spawning_a_process.yml
index 369fa49db9..72541a45bc 100644
--- a/detections/endpoint/detect_regsvcs_spawning_a_process.yml
+++ b/detections/endpoint/detect_regsvcs_spawning_a_process.yml
@@ -1,7 +1,7 @@
name: Detect Regsvcs Spawning a Process
id: bc477b57-5c21-4ab6-9c33-668772e7f114
-version: 7
-date: '2024-12-10'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -76,7 +76,6 @@ tags:
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.009
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_regsvcs_with_network_connection.yml b/detections/endpoint/detect_regsvcs_with_network_connection.yml
index 43d8cd8f6f..160e0aad1e 100644
--- a/detections/endpoint/detect_regsvcs_with_network_connection.yml
+++ b/detections/endpoint/detect_regsvcs_with_network_connection.yml
@@ -1,7 +1,7 @@
name: Detect Regsvcs with Network Connection
id: e3e7a1c0-f2b9-445c-8493-f30a63522d1a
-version: 8
-date: '2024-11-13'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
- Living Off The Land
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.009
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml b/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml
index c8dfa3767d..79f0ca5b7e 100644
--- a/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml
+++ b/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml
@@ -1,7 +1,7 @@
name: Detect Regsvcs with No Command Line Arguments
id: 6b74d578-a02e-4e94-a0d1-39440d0bf254
-version: 7
-date: '2024-11-13'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -73,7 +73,6 @@ tags:
- Living Off The Land
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.009
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_regsvr32_application_control_bypass.yml b/detections/endpoint/detect_regsvr32_application_control_bypass.yml
index e2130893c1..a3df354b36 100644
--- a/detections/endpoint/detect_regsvr32_application_control_bypass.yml
+++ b/detections/endpoint/detect_regsvr32_application_control_bypass.yml
@@ -1,7 +1,7 @@
name: Detect Regsvr32 Application Control Bypass
id: 070e9b80-6252-11eb-ae93-0242ac130002
-version: 7
-date: '2024-12-10'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -79,7 +79,6 @@ tags:
- BlackByte Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.010
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_remote_access_software_usage_file.yml b/detections/endpoint/detect_remote_access_software_usage_file.yml
index a9d1005364..25292e24c2 100644
--- a/detections/endpoint/detect_remote_access_software_usage_file.yml
+++ b/detections/endpoint/detect_remote_access_software_usage_file.yml
@@ -1,6 +1,6 @@
name: Detect Remote Access Software Usage File
id: 3bf5541a-6a45-4fdc-b01d-59b899fff961
-version: 5
+version: 6
date: '2024-11-13'
author: Steven Dick
status: production
@@ -54,6 +54,10 @@ drilldown_searches:
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
+- name: Investigate files on $dest$
+ search: '| from datamodel:Endpoint.Filesystem | search dest=$dest$ file_name=$file_name$'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
rba:
message: A file for known a remote access software [$file_name$] was created on
$dest$ by $user$.
@@ -67,6 +71,8 @@ rba:
threat_objects:
- field: file_name
type: file_name
+ - field: signature
+ type: signature
tags:
analytic_story:
- Insider Threat
@@ -74,6 +80,7 @@ tags:
- Ransomware
- Gozi Malware
- CISA AA24-241A
+ - Remote Monitoring and Management Software
asset_type: Endpoint
mitre_attack_id:
- T1219
diff --git a/detections/endpoint/detect_remote_access_software_usage_fileinfo.yml b/detections/endpoint/detect_remote_access_software_usage_fileinfo.yml
index 8286572d72..b1a9ef4f84 100644
--- a/detections/endpoint/detect_remote_access_software_usage_fileinfo.yml
+++ b/detections/endpoint/detect_remote_access_software_usage_fileinfo.yml
@@ -1,6 +1,6 @@
name: Detect Remote Access Software Usage FileInfo
id: ccad96d7-a48c-4f13-8b9c-9f6a31cba454
-version: 5
+version: 6
date: '2024-11-13'
author: Steven Dick
status: production
@@ -47,6 +47,10 @@ drilldown_searches:
| `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
+- name: Investigate processes on $dest$
+ search: '| from datamodel:Endpoint.Processes| search dest=$dest$ process_name=$process_name$'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
rba:
message: A file attributes for known a remote access software [$process_name$] was
detected on $dest$
@@ -54,15 +58,21 @@ rba:
- field: dest
type: system
score: 25
+ - field: user
+ type: user
+ score: 25
threat_objects:
- field: process_name
type: process_name
+ - field: signature
+ type: signature
tags:
analytic_story:
- Insider Threat
- Command And Control
- Ransomware
- Gozi Malware
+ - Remote Monitoring and Management Software
asset_type: Endpoint
mitre_attack_id:
- T1219
diff --git a/detections/endpoint/detect_remote_access_software_usage_process.yml b/detections/endpoint/detect_remote_access_software_usage_process.yml
index 8a5dfd6d64..e0417a4071 100644
--- a/detections/endpoint/detect_remote_access_software_usage_process.yml
+++ b/detections/endpoint/detect_remote_access_software_usage_process.yml
@@ -1,6 +1,6 @@
name: Detect Remote Access Software Usage Process
id: ffd5e001-2e34-48f4-97a2-26dc4bb08178
-version: 5
+version: 6
date: '2024-11-13'
author: Steven Dick
status: production
@@ -59,6 +59,10 @@ drilldown_searches:
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
+- name: Investigate processes on $dest$
+ search: '| from datamodel:Endpoint.Processes| search dest=$dest$ process_name=$process_name$'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
rba:
message: A process for a known remote access software $process_name$ was identified
on $dest$.
@@ -72,6 +76,8 @@ rba:
threat_objects:
- field: process_name
type: process_name
+ - field: signature
+ type: signature
tags:
analytic_story:
- Insider Threat
@@ -79,6 +85,7 @@ tags:
- Ransomware
- Gozi Malware
- CISA AA24-241A
+ - Remote Monitoring and Management Software
asset_type: Endpoint
mitre_attack_id:
- T1219
diff --git a/detections/endpoint/detect_remote_access_software_usage_registry.yml b/detections/endpoint/detect_remote_access_software_usage_registry.yml
index 93e927f108..a757b157c9 100644
--- a/detections/endpoint/detect_remote_access_software_usage_registry.yml
+++ b/detections/endpoint/detect_remote_access_software_usage_registry.yml
@@ -1,6 +1,6 @@
name: Detect Remote Access Software Usage Registry
id: 33804986-25dd-43cf-bb6b-dc14956c7cbc
-version: 2
+version: 3
date: '2025-01-10'
author: Steven Dick
status: production
@@ -60,6 +60,7 @@ tags:
- Ransomware
- Gozi Malware
- CISA AA24-241A
+ - Remote Monitoring and Management Software
asset_type: Endpoint
mitre_attack_id:
- T1219
diff --git a/detections/endpoint/detect_renamed_7_zip.yml b/detections/endpoint/detect_renamed_7_zip.yml
index e2a994e020..62309db2ab 100644
--- a/detections/endpoint/detect_renamed_7_zip.yml
+++ b/detections/endpoint/detect_renamed_7_zip.yml
@@ -1,7 +1,7 @@
name: Detect Renamed 7-Zip
id: 4057291a-b8cf-11eb-95fe-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -43,7 +43,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1560.001
- - T1560
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/detect_renamed_psexec.yml b/detections/endpoint/detect_renamed_psexec.yml
index 3b2380accc..27479f9d15 100644
--- a/detections/endpoint/detect_renamed_psexec.yml
+++ b/detections/endpoint/detect_renamed_psexec.yml
@@ -1,7 +1,7 @@
name: Detect Renamed PSExec
id: 683e6196-b8e8-11eb-9a79-acde48001122
-version: 10
-date: '2025-01-27'
+version: 11
+date: '2025-02-10'
author: Michael Haag, Splunk, Alex Oberkircher, Github Community
status: production
type: Hunting
@@ -53,7 +53,6 @@ tags:
- Rhysida Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1569
- T1569.002
product:
- Splunk Enterprise
@@ -63,6 +62,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/atomic_red_team/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/detect_renamed_winrar.yml b/detections/endpoint/detect_renamed_winrar.yml
index 43af74579c..5c146b775f 100644
--- a/detections/endpoint/detect_renamed_winrar.yml
+++ b/detections/endpoint/detect_renamed_winrar.yml
@@ -1,7 +1,7 @@
name: Detect Renamed WinRAR
id: 1b7bfb2c-b8e6-11eb-99ac-acde48001122
-version: 8
-date: '2025-01-27'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -45,7 +45,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1560.001
- - T1560
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -54,6 +53,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/detect_rtlo_in_file_name.yml b/detections/endpoint/detect_rtlo_in_file_name.yml
index 0754140915..5e65a0dda2 100644
--- a/detections/endpoint/detect_rtlo_in_file_name.yml
+++ b/detections/endpoint/detect_rtlo_in_file_name.yml
@@ -1,7 +1,7 @@
name: Detect RTLO In File Name
id: 468b7e11-d362-43b8-b6ec-7a2d3b246678
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -65,7 +65,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1036.002
- - T1036
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/detect_rtlo_in_process.yml b/detections/endpoint/detect_rtlo_in_process.yml
index f9af08e747..c9ee16ee83 100644
--- a/detections/endpoint/detect_rtlo_in_process.yml
+++ b/detections/endpoint/detect_rtlo_in_process.yml
@@ -1,7 +1,7 @@
name: Detect RTLO In Process
id: 22ac27b4-7189-4a4f-9375-b9017c9620d7
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -72,7 +72,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1036.002
- - T1036
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml b/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml
index 8774c0b8e9..710a02181c 100644
--- a/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml
+++ b/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml
@@ -1,7 +1,7 @@
name: Detect Rundll32 Application Control Bypass - advpack
id: 4aefadfe-9abd-4bf8-b3fd-867e9ef95bf8
-version: 7
-date: '2024-12-10'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -77,7 +77,6 @@ tags:
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.011
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml b/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml
index 5870f0e87b..2ee5451c0e 100644
--- a/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml
+++ b/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml
@@ -1,7 +1,7 @@
name: Detect Rundll32 Application Control Bypass - setupapi
id: 61e7b44a-6088-4f26-b788-9a96ba13b37a
-version: 7
-date: '2024-12-10'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -77,7 +77,6 @@ tags:
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.011
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml b/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml
index cab866b351..86662d958f 100644
--- a/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml
+++ b/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml
@@ -1,7 +1,7 @@
name: Detect Rundll32 Application Control Bypass - syssetup
id: 71b9bf37-cde1-45fb-b899-1b0aa6fa1183
-version: 7
-date: '2024-12-10'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -77,7 +77,6 @@ tags:
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.011
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_rundll32_inline_hta_execution.yml b/detections/endpoint/detect_rundll32_inline_hta_execution.yml
index 310dee62f4..3a1a84e20a 100644
--- a/detections/endpoint/detect_rundll32_inline_hta_execution.yml
+++ b/detections/endpoint/detect_rundll32_inline_hta_execution.yml
@@ -1,7 +1,7 @@
name: Detect Rundll32 Inline HTA Execution
id: 91c79f14-5b41-11eb-ae93-0242ac130002
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -66,7 +66,6 @@ tags:
- Living Off The Land
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.005
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_sharphound_command_line_arguments.yml b/detections/endpoint/detect_sharphound_command_line_arguments.yml
index 25d0f48916..f1763e793c 100644
--- a/detections/endpoint/detect_sharphound_command_line_arguments.yml
+++ b/detections/endpoint/detect_sharphound_command_line_arguments.yml
@@ -1,7 +1,7 @@
name: Detect SharpHound Command-Line Arguments
id: a0bdd2f6-c2ff-11eb-b918-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -67,13 +67,11 @@ tags:
- BlackSuit Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1087.002
- T1069.001
- - T1482
- - T1087.001
- - T1087
- T1069.002
- - T1069
+ - T1087.001
+ - T1087.002
+ - T1482
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/detect_sharphound_file_modifications.yml b/detections/endpoint/detect_sharphound_file_modifications.yml
index 6d6d2d57ee..9054f588ce 100644
--- a/detections/endpoint/detect_sharphound_file_modifications.yml
+++ b/detections/endpoint/detect_sharphound_file_modifications.yml
@@ -1,7 +1,7 @@
name: Detect SharpHound File Modifications
id: 42b4b438-beed-11eb-ba1d-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -64,13 +64,11 @@ tags:
- BlackSuit Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1087.002
- T1069.001
- - T1482
- - T1087.001
- - T1087
- T1069.002
- - T1069
+ - T1087.001
+ - T1087.002
+ - T1482
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/detect_sharphound_usage.yml b/detections/endpoint/detect_sharphound_usage.yml
index 8f75b08dfe..ce759de968 100644
--- a/detections/endpoint/detect_sharphound_usage.yml
+++ b/detections/endpoint/detect_sharphound_usage.yml
@@ -1,7 +1,7 @@
name: Detect SharpHound Usage
id: dd04b29a-beed-11eb-87bc-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -67,13 +67,11 @@ tags:
- Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1087.002
- T1069.001
- - T1482
- - T1087.001
- - T1087
- T1069.002
- - T1069
+ - T1087.001
+ - T1087.002
+ - T1482
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/detect_suspicious_processnames_using_pretrained_model_in_dsdl.yml b/detections/endpoint/detect_suspicious_processnames_using_pretrained_model_in_dsdl.yml
index 6fa1b4cdd0..93af7b9881 100644
--- a/detections/endpoint/detect_suspicious_processnames_using_pretrained_model_in_dsdl.yml
+++ b/detections/endpoint/detect_suspicious_processnames_using_pretrained_model_in_dsdl.yml
@@ -1,6 +1,6 @@
name: Detect suspicious processnames using pretrained model in DSDL
id: a15f8977-ad7d-4669-92ef-b59b97219bf5
-version: 4
+version: 5
date: '2024-11-13'
author: Abhinav Mishra, Kumar Sharad and Namratha Sreekanta, Splunk
type: Anomaly
diff --git a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml
index eb1159dade..307509b731 100644
--- a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml
+++ b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml
@@ -1,7 +1,7 @@
name: Detect Use of cmd exe to Launch Script Interpreters
id: b89919ed-fe5f-492c-b139-95dbb162039e
-version: 8
-date: '2024-11-13'
+version: 9
+date: '2025-02-10'
author: Bhavin Patel, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -65,7 +65,6 @@ tags:
- Azorult
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/detect_wmi_event_subscription_persistence.yml b/detections/endpoint/detect_wmi_event_subscription_persistence.yml
index 4ed7920815..5aff76c6d1 100644
--- a/detections/endpoint/detect_wmi_event_subscription_persistence.yml
+++ b/detections/endpoint/detect_wmi_event_subscription_persistence.yml
@@ -1,7 +1,7 @@
name: Detect WMI Event Subscription Persistence
id: 01d9a0c2-cece-11eb-ab46-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1546.003
- - T1546
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disable_amsi_through_registry.yml b/detections/endpoint/disable_amsi_through_registry.yml
index 4f526be68b..a0ee63d1be 100644
--- a/detections/endpoint/disable_amsi_through_registry.yml
+++ b/detections/endpoint/disable_amsi_through_registry.yml
@@ -1,7 +1,7 @@
name: Disable AMSI Through Registry
id: 9c27ec42-d338-11eb-9044-acde48001122
-version: 8
-date: '2024-12-08'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -62,7 +62,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disable_defender_antivirus_registry.yml b/detections/endpoint/disable_defender_antivirus_registry.yml
index b73157c4ce..fdd91cef44 100644
--- a/detections/endpoint/disable_defender_antivirus_registry.yml
+++ b/detections/endpoint/disable_defender_antivirus_registry.yml
@@ -1,7 +1,7 @@
name: Disable Defender AntiVirus Registry
id: aa4f695a-3024-11ec-9987-acde48001122
-version: 8
-date: '2024-12-08'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disable_defender_blockatfirstseen_feature.yml b/detections/endpoint/disable_defender_blockatfirstseen_feature.yml
index d092f50138..f1289e60a2 100644
--- a/detections/endpoint/disable_defender_blockatfirstseen_feature.yml
+++ b/detections/endpoint/disable_defender_blockatfirstseen_feature.yml
@@ -1,7 +1,7 @@
name: Disable Defender BlockAtFirstSeen Feature
id: 2dd719ac-3021-11ec-97b4-acde48001122
-version: 8
-date: '2024-12-08'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disable_defender_enhanced_notification.yml b/detections/endpoint/disable_defender_enhanced_notification.yml
index 55022f84b4..6475fe086a 100644
--- a/detections/endpoint/disable_defender_enhanced_notification.yml
+++ b/detections/endpoint/disable_defender_enhanced_notification.yml
@@ -1,7 +1,7 @@
name: Disable Defender Enhanced Notification
id: dc65678c-301f-11ec-8e30-acde48001122
-version: 7
-date: '2025-01-21'
+version: 8
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -75,7 +75,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disable_defender_mpengine_registry.yml b/detections/endpoint/disable_defender_mpengine_registry.yml
index e7472c30b0..ce5b547c15 100644
--- a/detections/endpoint/disable_defender_mpengine_registry.yml
+++ b/detections/endpoint/disable_defender_mpengine_registry.yml
@@ -1,7 +1,7 @@
name: Disable Defender MpEngine Registry
id: cc391750-3024-11ec-955a-acde48001122
-version: 9
-date: '2024-12-16'
+version: 10
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disable_defender_spynet_reporting.yml b/detections/endpoint/disable_defender_spynet_reporting.yml
index 4c5bffe004..f670dce6cc 100644
--- a/detections/endpoint/disable_defender_spynet_reporting.yml
+++ b/detections/endpoint/disable_defender_spynet_reporting.yml
@@ -1,7 +1,7 @@
name: Disable Defender Spynet Reporting
id: 898debf4-3021-11ec-ba7c-acde48001122
-version: 8
-date: '2024-12-08'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disable_defender_submit_samples_consent_feature.yml b/detections/endpoint/disable_defender_submit_samples_consent_feature.yml
index e7286d3d79..3ee864c99c 100644
--- a/detections/endpoint/disable_defender_submit_samples_consent_feature.yml
+++ b/detections/endpoint/disable_defender_submit_samples_consent_feature.yml
@@ -1,7 +1,7 @@
name: Disable Defender Submit Samples Consent Feature
id: 73922ff8-3022-11ec-bf5e-acde48001122
-version: 8
-date: '2024-12-16'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disable_etw_through_registry.yml b/detections/endpoint/disable_etw_through_registry.yml
index cae93c999b..6aeb854d3b 100644
--- a/detections/endpoint/disable_etw_through_registry.yml
+++ b/detections/endpoint/disable_etw_through_registry.yml
@@ -1,7 +1,7 @@
name: Disable ETW Through Registry
id: f0eacfa4-d33f-11eb-8f9d-acde48001122
-version: 8
-date: '2024-12-08'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -59,7 +59,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disable_logs_using_wevtutil.yml b/detections/endpoint/disable_logs_using_wevtutil.yml
index 33e17afd7d..434b6452ec 100644
--- a/detections/endpoint/disable_logs_using_wevtutil.yml
+++ b/detections/endpoint/disable_logs_using_wevtutil.yml
@@ -1,7 +1,7 @@
name: Disable Logs Using WevtUtil
id: 236e7c8e-c9d9-11eb-a824-acde48001122
-version: 6
-date: '2024-12-10'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
- Rhysida Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1070
- T1070.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/disable_registry_tool.yml b/detections/endpoint/disable_registry_tool.yml
index b75eca4b3c..ce3b191378 100644
--- a/detections/endpoint/disable_registry_tool.yml
+++ b/detections/endpoint/disable_registry_tool.yml
@@ -1,7 +1,7 @@
name: Disable Registry Tool
id: cd2cf33c-9201-11eb-a10a-acde48001122
-version: 9
-date: '2024-12-08'
+version: 10
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -58,9 +58,8 @@ tags:
- NjRAT
asset_type: Endpoint
mitre_attack_id:
- - T1562.001
- - T1562
- T1112
+ - T1562.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disable_schedule_task.yml b/detections/endpoint/disable_schedule_task.yml
index 4474a3fc1d..43abf6fe4d 100644
--- a/detections/endpoint/disable_schedule_task.yml
+++ b/detections/endpoint/disable_schedule_task.yml
@@ -1,7 +1,7 @@
name: Disable Schedule Task
id: db596056-3019-11ec-a9ff-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disable_show_hidden_files.yml b/detections/endpoint/disable_show_hidden_files.yml
index 8cf133efe2..f2851fcdf0 100644
--- a/detections/endpoint/disable_show_hidden_files.yml
+++ b/detections/endpoint/disable_show_hidden_files.yml
@@ -1,7 +1,7 @@
name: Disable Show Hidden Files
id: 6f3ccfa2-91fe-11eb-8f9b-acde48001122
-version: 9
-date: '2024-12-08'
+version: 10
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: Anomaly
@@ -58,11 +58,9 @@ tags:
- Azorult
asset_type: Endpoint
mitre_attack_id:
- - T1564.001
- - T1562.001
- - T1564
- - T1562
- T1112
+ - T1562.001
+ - T1564.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disable_uac_remote_restriction.yml b/detections/endpoint/disable_uac_remote_restriction.yml
index 9ca80568c7..5f4ae2f4db 100644
--- a/detections/endpoint/disable_uac_remote_restriction.yml
+++ b/detections/endpoint/disable_uac_remote_restriction.yml
@@ -1,7 +1,7 @@
name: Disable UAC Remote Restriction
id: 9928b732-210e-11ec-b65e-acde48001122
-version: 8
-date: '2024-12-08'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.002
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disable_windows_app_hotkeys.yml b/detections/endpoint/disable_windows_app_hotkeys.yml
index 0edb9bc907..61d89307c0 100644
--- a/detections/endpoint/disable_windows_app_hotkeys.yml
+++ b/detections/endpoint/disable_windows_app_hotkeys.yml
@@ -1,7 +1,7 @@
name: Disable Windows App Hotkeys
id: 1490f224-ad8b-11eb-8c4f-acde48001122
-version: 8
-date: '2024-12-08'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -57,9 +57,8 @@ tags:
- Windows Registry Abuse
asset_type: Endpoint
mitre_attack_id:
- - T1562.001
- - T1562
- T1112
+ - T1562.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disable_windows_behavior_monitoring.yml b/detections/endpoint/disable_windows_behavior_monitoring.yml
index 07d891b9b9..ff1af8433e 100644
--- a/detections/endpoint/disable_windows_behavior_monitoring.yml
+++ b/detections/endpoint/disable_windows_behavior_monitoring.yml
@@ -1,7 +1,7 @@
name: Disable Windows Behavior Monitoring
id: 79439cae-9200-11eb-a4d3-acde48001122
-version: 10
-date: '2024-12-08'
+version: 11
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -69,7 +69,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disable_windows_smartscreen_protection.yml b/detections/endpoint/disable_windows_smartscreen_protection.yml
index 88d052f10e..d804b2c8d0 100644
--- a/detections/endpoint/disable_windows_smartscreen_protection.yml
+++ b/detections/endpoint/disable_windows_smartscreen_protection.yml
@@ -1,7 +1,7 @@
name: Disable Windows SmartScreen Protection
id: 664f0fd0-91ff-11eb-a56f-acde48001122
-version: 9
-date: '2024-12-08'
+version: 10
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_get_aduser.yml b/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_get_aduser.yml
index 1606e574da..2aeb701771 100644
--- a/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_get_aduser.yml
+++ b/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_get_aduser.yml
@@ -1,7 +1,7 @@
name: Disabled Kerberos Pre-Authentication Discovery With Get-ADUser
id: 114c6bfe-9406-11ec-bcce-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -56,7 +56,6 @@ tags:
- BlackSuit Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1558
- T1558.004
product:
- Splunk Enterprise
diff --git a/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_powerview.yml b/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_powerview.yml
index e5ac20f37f..b5464753fe 100644
--- a/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_powerview.yml
+++ b/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_powerview.yml
@@ -1,7 +1,7 @@
name: Disabled Kerberos Pre-Authentication Discovery With PowerView
id: b0b34e2c-90de-11ec-baeb-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -53,7 +53,6 @@ tags:
- Active Directory Kerberos Attacks
asset_type: Endpoint
mitre_attack_id:
- - T1558
- T1558.004
product:
- Splunk Enterprise
diff --git a/detections/endpoint/disabling_cmd_application.yml b/detections/endpoint/disabling_cmd_application.yml
index d35acced16..2a96b3b449 100644
--- a/detections/endpoint/disabling_cmd_application.yml
+++ b/detections/endpoint/disabling_cmd_application.yml
@@ -1,7 +1,7 @@
name: Disabling CMD Application
id: ff86077c-9212-11eb-a1e6-acde48001122
-version: 9
-date: '2024-12-08'
+version: 10
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -60,9 +60,8 @@ tags:
- NjRAT
asset_type: Endpoint
mitre_attack_id:
- - T1562.001
- - T1562
- T1112
+ - T1562.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disabling_controlpanel.yml b/detections/endpoint/disabling_controlpanel.yml
index c6428e5197..7225cef46f 100644
--- a/detections/endpoint/disabling_controlpanel.yml
+++ b/detections/endpoint/disabling_controlpanel.yml
@@ -1,7 +1,7 @@
name: Disabling ControlPanel
id: 6ae0148e-9215-11eb-a94a-acde48001122
-version: 9
-date: '2024-12-08'
+version: 10
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -60,9 +60,8 @@ tags:
- Windows Registry Abuse
asset_type: Endpoint
mitre_attack_id:
- - T1562.001
- - T1562
- T1112
+ - T1562.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disabling_defender_services.yml b/detections/endpoint/disabling_defender_services.yml
index d9432952f5..c8fc943b34 100644
--- a/detections/endpoint/disabling_defender_services.yml
+++ b/detections/endpoint/disabling_defender_services.yml
@@ -1,7 +1,7 @@
name: Disabling Defender Services
id: 911eacdc-317f-11ec-ad30-acde48001122
-version: 8
-date: '2024-12-08'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disabling_firewall_with_netsh.yml b/detections/endpoint/disabling_firewall_with_netsh.yml
index d2cf8713d8..c5d95d266a 100644
--- a/detections/endpoint/disabling_firewall_with_netsh.yml
+++ b/detections/endpoint/disabling_firewall_with_netsh.yml
@@ -1,7 +1,7 @@
name: Disabling Firewall with Netsh
id: 6860a62c-9203-11eb-9e05-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disabling_folderoptions_windows_feature.yml b/detections/endpoint/disabling_folderoptions_windows_feature.yml
index 1025506d70..572e1550d2 100644
--- a/detections/endpoint/disabling_folderoptions_windows_feature.yml
+++ b/detections/endpoint/disabling_folderoptions_windows_feature.yml
@@ -1,7 +1,7 @@
name: Disabling FolderOptions Windows Feature
id: 83776de4-921a-11eb-868a-acde48001122
-version: 9
-date: '2024-12-08'
+version: 10
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -62,7 +62,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disabling_norun_windows_app.yml b/detections/endpoint/disabling_norun_windows_app.yml
index 793a6f7540..28ad2e6afa 100644
--- a/detections/endpoint/disabling_norun_windows_app.yml
+++ b/detections/endpoint/disabling_norun_windows_app.yml
@@ -1,7 +1,7 @@
name: Disabling NoRun Windows App
id: de81bc46-9213-11eb-adc9-acde48001122
-version: 9
-date: '2024-12-08'
+version: 10
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -60,9 +60,8 @@ tags:
- Windows Registry Abuse
asset_type: Endpoint
mitre_attack_id:
- - T1562.001
- - T1562
- T1112
+ - T1562.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disabling_remote_user_account_control.yml b/detections/endpoint/disabling_remote_user_account_control.yml
index cac14cea20..e1729e4fee 100644
--- a/detections/endpoint/disabling_remote_user_account_control.yml
+++ b/detections/endpoint/disabling_remote_user_account_control.yml
@@ -1,7 +1,7 @@
name: Disabling Remote User Account Control
id: bbc644bc-37df-4e1a-9c88-ec9a53e2038c
-version: 8
-date: '2024-12-16'
+version: 9
+date: '2025-02-10'
author: David Dorsey, Patrick Bareiss, Splunk
status: production
type: TTP
@@ -66,7 +66,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.002
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/disabling_task_manager.yml b/detections/endpoint/disabling_task_manager.yml
index 218bab32c0..0cd9db8bc1 100644
--- a/detections/endpoint/disabling_task_manager.yml
+++ b/detections/endpoint/disabling_task_manager.yml
@@ -1,7 +1,7 @@
name: Disabling Task Manager
id: dac279bc-9202-11eb-b7fb-acde48001122
-version: 9
-date: '2024-12-08'
+version: 10
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -62,7 +62,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/dns_exfiltration_using_nslookup_app.yml b/detections/endpoint/dns_exfiltration_using_nslookup_app.yml
index a244b2a733..9e42a31685 100644
--- a/detections/endpoint/dns_exfiltration_using_nslookup_app.yml
+++ b/detections/endpoint/dns_exfiltration_using_nslookup_app.yml
@@ -1,6 +1,6 @@
name: DNS Exfiltration Using Nslookup App
id: 2452e632-9e0d-11eb-bacd-acde48001122
-version: 7
+version: 8
date: '2024-12-10'
author: Teoderick Contreras, Splunk, Wouter Jansen
status: production
diff --git a/detections/endpoint/domain_account_discovery_with_dsquery.yml b/detections/endpoint/domain_account_discovery_with_dsquery.yml
index cde94f4d78..73c4f00bf2 100644
--- a/detections/endpoint/domain_account_discovery_with_dsquery.yml
+++ b/detections/endpoint/domain_account_discovery_with_dsquery.yml
@@ -1,7 +1,7 @@
name: Domain Account Discovery with Dsquery
id: b1a8ce04-04c2-11ec-bea7-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -42,7 +42,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1087.002
- - T1087
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/domain_account_discovery_with_wmic.yml b/detections/endpoint/domain_account_discovery_with_wmic.yml
index d374d2851a..5997c315cc 100644
--- a/detections/endpoint/domain_account_discovery_with_wmic.yml
+++ b/detections/endpoint/domain_account_discovery_with_wmic.yml
@@ -1,7 +1,7 @@
name: Domain Account Discovery with Wmic
id: 383572e0-04c5-11ec-bdcc-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -68,7 +68,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1087.002
- - T1087
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/domain_group_discovery_with_adsisearcher.yml b/detections/endpoint/domain_group_discovery_with_adsisearcher.yml
index e1abeaa0b5..7e402f9632 100644
--- a/detections/endpoint/domain_group_discovery_with_adsisearcher.yml
+++ b/detections/endpoint/domain_group_discovery_with_adsisearcher.yml
@@ -1,7 +1,7 @@
name: Domain Group Discovery with Adsisearcher
id: 089c862f-5f83-49b5-b1c8-7e4ff66560c7
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -53,7 +53,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/domain_group_discovery_with_dsquery.yml b/detections/endpoint/domain_group_discovery_with_dsquery.yml
index 1ab2a63c77..3c80940d89 100644
--- a/detections/endpoint/domain_group_discovery_with_dsquery.yml
+++ b/detections/endpoint/domain_group_discovery_with_dsquery.yml
@@ -1,7 +1,7 @@
name: Domain Group Discovery With Dsquery
id: f0c9d62f-a232-4edd-b17e-bc409fb133d4
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -40,7 +40,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/domain_group_discovery_with_wmic.yml b/detections/endpoint/domain_group_discovery_with_wmic.yml
index 77e3b1886c..0ea13c9e66 100644
--- a/detections/endpoint/domain_group_discovery_with_wmic.yml
+++ b/detections/endpoint/domain_group_discovery_with_wmic.yml
@@ -1,7 +1,7 @@
name: Domain Group Discovery With Wmic
id: a87736a6-95cd-4728-8689-3c64d5026b3e
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -40,7 +40,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/drop_icedid_license_dat.yml b/detections/endpoint/drop_icedid_license_dat.yml
index 12460ee148..c5232b8655 100644
--- a/detections/endpoint/drop_icedid_license_dat.yml
+++ b/detections/endpoint/drop_icedid_license_dat.yml
@@ -1,7 +1,7 @@
name: Drop IcedID License dat
id: b7a045fc-f14a-11eb-8e79-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -31,7 +31,6 @@ tags:
- IcedID
asset_type: Endpoint
mitre_attack_id:
- - T1204
- T1204.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/dsquery_domain_discovery.yml b/detections/endpoint/dsquery_domain_discovery.yml
index 3ee0399230..72e21dfb8e 100644
--- a/detections/endpoint/dsquery_domain_discovery.yml
+++ b/detections/endpoint/dsquery_domain_discovery.yml
@@ -1,6 +1,6 @@
name: DSQuery Domain Discovery
id: cc316032-924a-11eb-91a2-acde48001122
-version: 6
+version: 7
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml
index ea6d606030..7199fc7352 100644
--- a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml
+++ b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml
@@ -1,7 +1,7 @@
name: Dump LSASS via comsvcs DLL
id: 8943b567-f14d-4ee8-a0bb-2121d4ce3184
-version: 7
-date: '2024-12-10'
+version: 9
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
@@ -84,7 +84,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.001
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/dump_lsass_via_procdump.yml b/detections/endpoint/dump_lsass_via_procdump.yml
index 56b38267ec..18d9cc1aa4 100644
--- a/detections/endpoint/dump_lsass_via_procdump.yml
+++ b/detections/endpoint/dump_lsass_via_procdump.yml
@@ -1,7 +1,7 @@
name: Dump LSASS via procdump
id: 3742ebfe-64c2-11eb-ae93-0242ac130002
-version: 8
-date: '2024-12-10'
+version: 10
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -76,7 +76,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.001
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/elevated_group_discovery_with_powerview.yml b/detections/endpoint/elevated_group_discovery_with_powerview.yml
index 1493676285..6b8427834e 100644
--- a/detections/endpoint/elevated_group_discovery_with_powerview.yml
+++ b/detections/endpoint/elevated_group_discovery_with_powerview.yml
@@ -1,7 +1,7 @@
name: Elevated Group Discovery with PowerView
id: 10d62950-0de5-4199-a710-cff9ea79b413
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -35,7 +35,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/elevated_group_discovery_with_wmic.yml b/detections/endpoint/elevated_group_discovery_with_wmic.yml
index 3c74c3e9ca..d06e82db3f 100644
--- a/detections/endpoint/elevated_group_discovery_with_wmic.yml
+++ b/detections/endpoint/elevated_group_discovery_with_wmic.yml
@@ -1,7 +1,7 @@
name: Elevated Group Discovery With Wmic
id: 3f6bbf22-093e-4cb4-9641-83f47b8444b6
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -66,7 +66,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/esentutl_sam_copy.yml b/detections/endpoint/esentutl_sam_copy.yml
index cf7ea2b703..b4f247be75 100644
--- a/detections/endpoint/esentutl_sam_copy.yml
+++ b/detections/endpoint/esentutl_sam_copy.yml
@@ -1,7 +1,7 @@
name: Esentutl SAM Copy
id: d372f928-ce4f-11eb-a762-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -43,7 +43,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.002
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/etw_registry_disabled.yml b/detections/endpoint/etw_registry_disabled.yml
index e001bbdc5b..c2be3b0a81 100644
--- a/detections/endpoint/etw_registry_disabled.yml
+++ b/detections/endpoint/etw_registry_disabled.yml
@@ -1,7 +1,7 @@
name: ETW Registry Disabled
id: 8ed523ac-276b-11ec-ac39-acde48001122
-version: 9
-date: '2024-12-16'
+version: 11
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -64,9 +64,8 @@ tags:
- Data Destruction
asset_type: Endpoint
mitre_attack_id:
- - T1562.006
- T1127
- - T1562
+ - T1562.006
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/eventvwr_uac_bypass.yml b/detections/endpoint/eventvwr_uac_bypass.yml
index d86cc12b72..87c438a3b5 100644
--- a/detections/endpoint/eventvwr_uac_bypass.yml
+++ b/detections/endpoint/eventvwr_uac_bypass.yml
@@ -1,7 +1,7 @@
name: Eventvwr UAC Bypass
id: 9cf8fe08-7ad8-11eb-9819-acde48001122
-version: 7
-date: '2024-11-13'
+version: 8
+date: '2025-02-10'
author: Steven Dick, Michael Haag, Splunk
status: production
type: TTP
@@ -78,7 +78,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.002
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml
index 87384b30be..8e55318d13 100644
--- a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml
+++ b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml
@@ -1,7 +1,7 @@
name: Excessive number of service control start as disabled
id: 77592bec-d5cc-11eb-9e60-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Hart, Splunk
status: production
type: Anomaly
@@ -70,7 +70,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/excessive_usage_of_sc_service_utility.yml b/detections/endpoint/excessive_usage_of_sc_service_utility.yml
index bf447f6818..a7cbd28e9d 100644
--- a/detections/endpoint/excessive_usage_of_sc_service_utility.yml
+++ b/detections/endpoint/excessive_usage_of_sc_service_utility.yml
@@ -1,7 +1,7 @@
name: Excessive Usage Of SC Service Utility
id: cb6b339e-d4c6-11eb-a026-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -59,7 +59,6 @@ tags:
- Crypto Stealer
asset_type: Endpoint
mitre_attack_id:
- - T1569
- T1569.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/excessive_usage_of_taskkill.yml b/detections/endpoint/excessive_usage_of_taskkill.yml
index 14669e1cab..58c6c1d2c6 100644
--- a/detections/endpoint/excessive_usage_of_taskkill.yml
+++ b/detections/endpoint/excessive_usage_of_taskkill.yml
@@ -1,7 +1,7 @@
name: Excessive Usage Of Taskkill
id: fe5bca48-accb-11eb-a67c-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -72,7 +72,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/exchange_powershell_module_usage.yml b/detections/endpoint/exchange_powershell_module_usage.yml
index 0f67e57eea..a4a976b447 100644
--- a/detections/endpoint/exchange_powershell_module_usage.yml
+++ b/detections/endpoint/exchange_powershell_module_usage.yml
@@ -1,7 +1,7 @@
name: Exchange PowerShell Module Usage
id: 2d10095e-05ae-11ec-8fdf-acde48001122
-version: 8
-date: '2024-11-13'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -66,7 +66,6 @@ tags:
- CISA AA22-264A
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/executable_file_written_in_administrative_smb_share.yml b/detections/endpoint/executable_file_written_in_administrative_smb_share.yml
index b86556c3ad..17986ee585 100644
--- a/detections/endpoint/executable_file_written_in_administrative_smb_share.yml
+++ b/detections/endpoint/executable_file_written_in_administrative_smb_share.yml
@@ -1,7 +1,7 @@
name: Executable File Written in Administrative SMB Share
id: f63c34fe-a435-11eb-935a-acde48001122
-version: 7
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -68,7 +68,6 @@ tags:
- Trickbot
asset_type: Endpoint
mitre_attack_id:
- - T1021
- T1021.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml b/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml
index d389a1626f..7099216131 100644
--- a/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml
+++ b/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml
@@ -1,7 +1,7 @@
name: Execute Javascript With Jscript COM CLSID
id: dc64d064-d346-11eb-8588-acde48001122
-version: 4
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -68,7 +68,6 @@ tags:
- Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.005
product:
- Splunk Enterprise
diff --git a/detections/endpoint/execution_of_file_with_multiple_extensions.yml b/detections/endpoint/execution_of_file_with_multiple_extensions.yml
index 306a367e2b..c7c46d2a00 100644
--- a/detections/endpoint/execution_of_file_with_multiple_extensions.yml
+++ b/detections/endpoint/execution_of_file_with_multiple_extensions.yml
@@ -1,7 +1,7 @@
name: Execution of File with Multiple Extensions
id: b06a555e-dce0-417d-a2eb-28a5d8d66ef7
-version: 7
-date: '2024-11-13'
+version: 9
+date: '2025-02-10'
author: Rico Valdez, Teoderick Contreras, Splunk
status: production
type: TTP
@@ -71,7 +71,6 @@ tags:
- DarkGate Malware
asset_type: Endpoint
mitre_attack_id:
- - T1036
- T1036.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/file_with_samsam_extension.yml b/detections/endpoint/file_with_samsam_extension.yml
index 0d86b46dcd..f09d658da1 100644
--- a/detections/endpoint/file_with_samsam_extension.yml
+++ b/detections/endpoint/file_with_samsam_extension.yml
@@ -1,6 +1,6 @@
name: File with Samsam Extension
id: 02c6cfc2-ae66-4735-bfc7-6291da834cbf
-version: 5
+version: 6
date: '2024-11-13'
author: Rico Valdez, Splunk
status: production
diff --git a/detections/endpoint/firewall_allowed_program_enable.yml b/detections/endpoint/firewall_allowed_program_enable.yml
index 39966aac74..11f599d75e 100644
--- a/detections/endpoint/firewall_allowed_program_enable.yml
+++ b/detections/endpoint/firewall_allowed_program_enable.yml
@@ -1,7 +1,7 @@
name: Firewall Allowed Program Enable
id: 9a8f63a8-43ac-11ec-904c-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -70,7 +70,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.004
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/first_time_seen_running_windows_service.yml b/detections/endpoint/first_time_seen_running_windows_service.yml
index 8576de1a20..70ca621bf7 100644
--- a/detections/endpoint/first_time_seen_running_windows_service.yml
+++ b/detections/endpoint/first_time_seen_running_windows_service.yml
@@ -1,7 +1,7 @@
name: First Time Seen Running Windows Service
id: 823136f2-d755-4b6d-ae04-372b486a5808
-version: 7
-date: '2024-11-13'
+version: 8
+date: '2025-02-10'
author: David Dorsey, Splunk
status: experimental
type: Anomaly
@@ -46,7 +46,6 @@ tags:
- NOBELIUM Group
asset_type: Endpoint
mitre_attack_id:
- - T1569
- T1569.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/fodhelper_uac_bypass.yml b/detections/endpoint/fodhelper_uac_bypass.yml
index b1be122909..643bf866c4 100644
--- a/detections/endpoint/fodhelper_uac_bypass.yml
+++ b/detections/endpoint/fodhelper_uac_bypass.yml
@@ -1,7 +1,7 @@
name: FodHelper UAC Bypass
id: 909f8fd8-7ac8-11eb-a1f3-acde48001122
-version: 7
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -75,7 +75,6 @@ tags:
mitre_attack_id:
- T1112
- T1548.002
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/get_aduser_with_powershell.yml b/detections/endpoint/get_aduser_with_powershell.yml
index 1c21e48521..19c5c4c847 100644
--- a/detections/endpoint/get_aduser_with_powershell.yml
+++ b/detections/endpoint/get_aduser_with_powershell.yml
@@ -1,7 +1,7 @@
name: Get ADUser with PowerShell
id: 0b6ee3f4-04e3-11ec-a87d-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -45,7 +45,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1087.002
- - T1087
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/get_aduser_with_powershell_script_block.yml b/detections/endpoint/get_aduser_with_powershell_script_block.yml
index ecdc645ace..4ea837065c 100644
--- a/detections/endpoint/get_aduser_with_powershell_script_block.yml
+++ b/detections/endpoint/get_aduser_with_powershell_script_block.yml
@@ -1,7 +1,7 @@
name: Get ADUser with PowerShell Script Block
id: 21432e40-04f4-11ec-b7e6-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -34,7 +34,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1087.002
- - T1087
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/get_domainuser_with_powershell.yml b/detections/endpoint/get_domainuser_with_powershell.yml
index f6f9362eb3..b7844e4976 100644
--- a/detections/endpoint/get_domainuser_with_powershell.yml
+++ b/detections/endpoint/get_domainuser_with_powershell.yml
@@ -1,7 +1,7 @@
name: Get DomainUser with PowerShell
id: 9a5a41d6-04e7-11ec-923c-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -70,7 +70,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1087.002
- - T1087
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/get_domainuser_with_powershell_script_block.yml b/detections/endpoint/get_domainuser_with_powershell_script_block.yml
index 8b3e401a5a..9fb765be7e 100644
--- a/detections/endpoint/get_domainuser_with_powershell_script_block.yml
+++ b/detections/endpoint/get_domainuser_with_powershell_script_block.yml
@@ -1,7 +1,7 @@
name: Get DomainUser with PowerShell Script Block
id: 61994268-04f4-11ec-865c-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1087.002
- - T1087
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/get_wmiobject_group_discovery.yml b/detections/endpoint/get_wmiobject_group_discovery.yml
index ca6601298b..eb0c67807c 100644
--- a/detections/endpoint/get_wmiobject_group_discovery.yml
+++ b/detections/endpoint/get_wmiobject_group_discovery.yml
@@ -1,7 +1,7 @@
name: Get WMIObject Group Discovery
id: 5434f670-155d-11ec-8cca-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -41,7 +41,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml b/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml
index 04fa251a96..b6b6ec3604 100644
--- a/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml
+++ b/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml
@@ -1,7 +1,7 @@
name: Get WMIObject Group Discovery with Script Block Logging
id: 69df7f7c-155d-11ec-a055-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -34,7 +34,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/getadgroup_with_powershell.yml b/detections/endpoint/getadgroup_with_powershell.yml
index d381b71e36..8f87c04925 100644
--- a/detections/endpoint/getadgroup_with_powershell.yml
+++ b/detections/endpoint/getadgroup_with_powershell.yml
@@ -1,7 +1,7 @@
name: GetAdGroup with PowerShell
id: 872e3063-0fc4-4e68-b2f3-f2b99184a708
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -41,7 +41,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/getadgroup_with_powershell_script_block.yml b/detections/endpoint/getadgroup_with_powershell_script_block.yml
index 0e2b7f09ef..5f765ba70b 100644
--- a/detections/endpoint/getadgroup_with_powershell_script_block.yml
+++ b/detections/endpoint/getadgroup_with_powershell_script_block.yml
@@ -1,7 +1,7 @@
name: GetAdGroup with PowerShell Script Block
id: e4c73d68-794b-468d-b4d0-dac1772bbae7
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -31,7 +31,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/getdomaingroup_with_powershell.yml b/detections/endpoint/getdomaingroup_with_powershell.yml
index 85f7f11b3e..8c01054c4b 100644
--- a/detections/endpoint/getdomaingroup_with_powershell.yml
+++ b/detections/endpoint/getdomaingroup_with_powershell.yml
@@ -1,7 +1,7 @@
name: GetDomainGroup with PowerShell
id: 93c94be3-bead-4a60-860f-77ca3fe59903
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/getdomaingroup_with_powershell_script_block.yml b/detections/endpoint/getdomaingroup_with_powershell_script_block.yml
index 913dbacb5e..bad857a4c9 100644
--- a/detections/endpoint/getdomaingroup_with_powershell_script_block.yml
+++ b/detections/endpoint/getdomaingroup_with_powershell_script_block.yml
@@ -1,7 +1,7 @@
name: GetDomainGroup with PowerShell Script Block
id: 09725404-a44f-4ed3-9efa-8ed5d69e4c53
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -52,7 +52,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/getlocaluser_with_powershell.yml b/detections/endpoint/getlocaluser_with_powershell.yml
index 690b834301..7819e2520b 100644
--- a/detections/endpoint/getlocaluser_with_powershell.yml
+++ b/detections/endpoint/getlocaluser_with_powershell.yml
@@ -1,7 +1,7 @@
name: GetLocalUser with PowerShell
id: 85fae8fa-0427-11ec-8b78-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -41,7 +41,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1087
- T1087.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/getlocaluser_with_powershell_script_block.yml b/detections/endpoint/getlocaluser_with_powershell_script_block.yml
index 754d2cadae..5e8423446f 100644
--- a/detections/endpoint/getlocaluser_with_powershell_script_block.yml
+++ b/detections/endpoint/getlocaluser_with_powershell_script_block.yml
@@ -1,7 +1,7 @@
name: GetLocalUser with PowerShell Script Block
id: 2e891cbe-0426-11ec-9c9c-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -33,9 +33,8 @@ tags:
- Malicious PowerShell
asset_type: Endpoint
mitre_attack_id:
- - T1087
- - T1087.001
- T1059.001
+ - T1087.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/getwmiobject_ds_group_with_powershell.yml b/detections/endpoint/getwmiobject_ds_group_with_powershell.yml
index 11b144c48c..f0dc6262b2 100644
--- a/detections/endpoint/getwmiobject_ds_group_with_powershell.yml
+++ b/detections/endpoint/getwmiobject_ds_group_with_powershell.yml
@@ -1,7 +1,7 @@
name: GetWmiObject Ds Group with PowerShell
id: df275a44-4527-443b-b884-7600e066e3eb
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml b/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml
index 5dcd4326a6..36a64083ac 100644
--- a/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml
+++ b/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml
@@ -1,7 +1,7 @@
name: GetWmiObject Ds Group with PowerShell Script Block
id: 67740bd3-1506-469c-b91d-effc322cc6e5
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -53,7 +53,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml
index 5cd432dcaa..eeb6e39b17 100644
--- a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml
+++ b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml
@@ -1,7 +1,7 @@
name: GetWmiObject DS User with PowerShell
id: 22d3b118-04df-11ec-8fa3-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -69,7 +69,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1087.002
- - T1087
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml
index ac5f12c52e..ab9fdb89c4 100644
--- a/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml
+++ b/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml
@@ -1,7 +1,7 @@
name: GetWmiObject DS User with PowerShell Script Block
id: fabd364e-04f3-11ec-b34b-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1087.002
- - T1087
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/getwmiobject_user_account_with_powershell.yml b/detections/endpoint/getwmiobject_user_account_with_powershell.yml
index 0c6134ae47..8733ba54ea 100644
--- a/detections/endpoint/getwmiobject_user_account_with_powershell.yml
+++ b/detections/endpoint/getwmiobject_user_account_with_powershell.yml
@@ -1,7 +1,7 @@
name: GetWmiObject User Account with PowerShell
id: b44f6ac6-0429-11ec-87e9-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -42,7 +42,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1087
- T1087.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml b/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml
index 1a5ed182ed..8677fb28ab 100644
--- a/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml
+++ b/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml
@@ -1,7 +1,7 @@
name: GetWmiObject User Account with PowerShell Script Block
id: 640b0eda-0429-11ec-accd-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -32,9 +32,8 @@ tags:
- Malicious PowerShell
asset_type: Endpoint
mitre_attack_id:
- - T1087
- - T1087.001
- T1059.001
+ - T1087.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml b/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml
index c60512b788..46ab4b2a2e 100644
--- a/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml
+++ b/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml
@@ -1,6 +1,6 @@
name: GPUpdate with no Command Line Arguments with Network
id: 2c853856-a140-11eb-a5b5-acde48001122
-version: 7
+version: 8
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/headless_browser_mockbin_or_mocky_request.yml b/detections/endpoint/headless_browser_mockbin_or_mocky_request.yml
index a5a0e59b2d..6d6557e0ab 100644
--- a/detections/endpoint/headless_browser_mockbin_or_mocky_request.yml
+++ b/detections/endpoint/headless_browser_mockbin_or_mocky_request.yml
@@ -1,6 +1,6 @@
name: Headless Browser Mockbin or Mocky Request
id: 94fc85a1-e55b-4265-95e1-4b66730e05c0
-version: 4
+version: 5
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/hide_user_account_from_sign_in_screen.yml b/detections/endpoint/hide_user_account_from_sign_in_screen.yml
index 8d27a673ad..1a4035b651 100644
--- a/detections/endpoint/hide_user_account_from_sign_in_screen.yml
+++ b/detections/endpoint/hide_user_account_from_sign_in_screen.yml
@@ -1,7 +1,7 @@
name: Hide User Account From Sign-In Screen
id: 834ba832-ad89-11eb-937d-acde48001122
-version: 8
-date: '2024-12-08'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml
index c95af49a98..9e314746a6 100644
--- a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml
+++ b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml
@@ -1,7 +1,7 @@
name: Hiding Files And Directories With Attrib exe
id: 6e5a3ae4-90a3-462d-9aa6-0119f638c0f1
-version: 9
-date: '2024-12-10'
+version: 10
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -67,7 +67,6 @@ tags:
- Crypto Stealer
asset_type: Endpoint
mitre_attack_id:
- - T1222
- T1222.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml b/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml
index d0965e6ffb..2a4a093612 100644
--- a/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml
+++ b/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml
@@ -1,7 +1,7 @@
name: IcedID Exfiltrated Archived File Creation
id: 0db4da70-f14b-11eb-8043-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -34,7 +34,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1560.001
- - T1560
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml
index 67d36cf818..7325419b34 100644
--- a/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml
+++ b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml
@@ -1,7 +1,7 @@
name: Impacket Lateral Movement Commandline Parameters
id: 8ce07472-496f-11ec-ab3b-3e22fbd008af
-version: 7
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -82,7 +82,6 @@ tags:
- CISA AA22-277A
asset_type: Endpoint
mitre_attack_id:
- - T1021
- T1021.002
- T1021.003
- T1047
diff --git a/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml
index b48dcbbc37..5bc432054e 100644
--- a/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml
+++ b/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml
@@ -1,7 +1,7 @@
name: Impacket Lateral Movement smbexec CommandLine Parameters
id: bb3c1bac-6bdf-4aa0-8dc9-068b8b712a76
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -83,7 +83,6 @@ tags:
asset_type: Endpoint
atomic_guid: []
mitre_attack_id:
- - T1021
- T1021.002
- T1021.003
- T1047
diff --git a/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml
index 7965e0f409..9e48d7ea19 100644
--- a/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml
+++ b/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml
@@ -1,7 +1,7 @@
name: Impacket Lateral Movement WMIExec Commandline Parameters
id: d6e464e4-5c6a-474e-82d2-aed616a3a492
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -83,7 +83,6 @@ tags:
asset_type: Endpoint
atomic_guid: []
mitre_attack_id:
- - T1021
- T1021.002
- T1021.003
- T1047
diff --git a/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml b/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml
index a096091412..4e56391427 100644
--- a/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml
+++ b/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml
@@ -1,7 +1,7 @@
name: Interactive Session on Remote Endpoint with PowerShell
id: a4e8f3a4-48b2-11ec-bcfc-3e22fbd008af
-version: 7
-date: '2024-11-13'
+version: 8
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -55,7 +55,6 @@ tags:
- Active Directory Lateral Movement
asset_type: Endpoint
mitre_attack_id:
- - T1021
- T1021.006
product:
- Splunk Enterprise
diff --git a/detections/endpoint/jscript_execution_using_cscript_app.yml b/detections/endpoint/jscript_execution_using_cscript_app.yml
index a88bd5debd..94f26c5e5f 100644
--- a/detections/endpoint/jscript_execution_using_cscript_app.yml
+++ b/detections/endpoint/jscript_execution_using_cscript_app.yml
@@ -1,7 +1,7 @@
name: Jscript Execution Using Cscript App
id: 002f1e24-146e-11ec-a470-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -67,7 +67,6 @@ tags:
- Remcos
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.007
product:
- Splunk Enterprise
diff --git a/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml b/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml
index 948d171659..57f2076b4c 100644
--- a/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml
+++ b/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml
@@ -1,7 +1,7 @@
name: Kerberoasting spn request with RC4 encryption
id: 5cc67381-44fa-4111-8a37-7a230943f027
-version: 9
-date: '2024-12-10'
+version: 10
+date: '2025-02-10'
author: Jose Hernandez, Patrick Bareiss, Mauricio Velazco, Dean Luxton, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
- Hermetic Wiper
asset_type: Endpoint
mitre_attack_id:
- - T1558
- T1558.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/kerberos_pre_authentication_flag_disabled_in_useraccountcontrol.yml b/detections/endpoint/kerberos_pre_authentication_flag_disabled_in_useraccountcontrol.yml
index f5d8ed8cf8..748fef94bf 100644
--- a/detections/endpoint/kerberos_pre_authentication_flag_disabled_in_useraccountcontrol.yml
+++ b/detections/endpoint/kerberos_pre_authentication_flag_disabled_in_useraccountcontrol.yml
@@ -1,7 +1,7 @@
name: Kerberos Pre-Authentication Flag Disabled in UserAccountControl
id: 0cb847ee-9423-11ec-b2df-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -16,7 +16,8 @@ description: The following analytic detects when the Kerberos Pre-Authentication
data_source:
- Windows Event Log Security 4738
search: >
- `wineventlog_security` EventCode=4738 MSADChangedAttributes="*\'Don\'t Require Preauth\' - Enabled*" |rename Account_Name as user | table EventCode, user, dest, Security_ID,
+ `wineventlog_security` EventCode=4738 MSADChangedAttributes="*\'Don\'t Require Preauth\'
+ - Enabled*" |rename Account_Name as user | table EventCode, user, dest, Security_ID,
MSADChangedAttributes | `kerberos_pre_authentication_flag_disabled_in_useraccountcontrol_filter`
how_to_implement: To successfully implement this search, you need to be ingesting
Domain Controller events. The Advanced Security Audit policy setting `User Account
@@ -53,7 +54,6 @@ tags:
- BlackSuit Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1558
- T1558.004
product:
- Splunk Enterprise
diff --git a/detections/endpoint/kerberos_pre_authentication_flag_disabled_with_powershell.yml b/detections/endpoint/kerberos_pre_authentication_flag_disabled_with_powershell.yml
index bc3d94ee68..67814fc234 100644
--- a/detections/endpoint/kerberos_pre_authentication_flag_disabled_with_powershell.yml
+++ b/detections/endpoint/kerberos_pre_authentication_flag_disabled_with_powershell.yml
@@ -1,7 +1,7 @@
name: Kerberos Pre-Authentication Flag Disabled with PowerShell
id: 59b51620-94c9-11ec-b3d5-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -55,7 +55,6 @@ tags:
- Active Directory Kerberos Attacks
asset_type: Endpoint
mitre_attack_id:
- - T1558
- T1558.004
product:
- Splunk Enterprise
diff --git a/detections/endpoint/kerberos_service_ticket_request_using_rc4_encryption.yml b/detections/endpoint/kerberos_service_ticket_request_using_rc4_encryption.yml
index d667d529f4..768d5fe2e6 100644
--- a/detections/endpoint/kerberos_service_ticket_request_using_rc4_encryption.yml
+++ b/detections/endpoint/kerberos_service_ticket_request_using_rc4_encryption.yml
@@ -1,7 +1,7 @@
name: Kerberos Service Ticket Request Using RC4 Encryption
id: 7d90f334-a482-11ec-908c-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -62,7 +62,6 @@ tags:
- Active Directory Privilege Escalation
asset_type: Endpoint
mitre_attack_id:
- - T1558
- T1558.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/kerberos_user_enumeration.yml b/detections/endpoint/kerberos_user_enumeration.yml
index 570a014a73..e5b80a4cea 100644
--- a/detections/endpoint/kerberos_user_enumeration.yml
+++ b/detections/endpoint/kerberos_user_enumeration.yml
@@ -1,7 +1,7 @@
name: Kerberos User Enumeration
id: d82d4af4-a0bd-11ec-9445-3e22fbd008af
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: Anomaly
@@ -55,7 +55,6 @@ tags:
- Active Directory Kerberos Attacks
asset_type: Endpoint
mitre_attack_id:
- - T1589
- T1589.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/linux_account_manipulation_of_ssh_config_and_keys.yml b/detections/endpoint/linux_account_manipulation_of_ssh_config_and_keys.yml
index 70069801ef..8728599618 100644
--- a/detections/endpoint/linux_account_manipulation_of_ssh_config_and_keys.yml
+++ b/detections/endpoint/linux_account_manipulation_of_ssh_config_and_keys.yml
@@ -1,7 +1,7 @@
name: Linux Account Manipulation Of SSH Config and Keys
id: 73a56508-1cf5-4df7-b8d9-5737fbdc27d2
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -55,9 +55,8 @@ tags:
- AcidRain
asset_type: Endpoint
mitre_attack_id:
- - T1485
- T1070.004
- - T1070
+ - T1485
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_add_files_in_known_crontab_directories.yml b/detections/endpoint/linux_add_files_in_known_crontab_directories.yml
index 5ac49389a5..7c5f666cd9 100644
--- a/detections/endpoint/linux_add_files_in_known_crontab_directories.yml
+++ b/detections/endpoint/linux_add_files_in_known_crontab_directories.yml
@@ -1,7 +1,7 @@
name: Linux Add Files In Known Crontab Directories
id: 023f3452-5f27-11ec-bf00-acde48001122
-version: 5
-date: '2024-12-19'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -59,7 +59,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.003
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_add_user_account.yml b/detections/endpoint/linux_add_user_account.yml
index 3685c49b94..3c798ae4cb 100644
--- a/detections/endpoint/linux_add_user_account.yml
+++ b/detections/endpoint/linux_add_user_account.yml
@@ -1,7 +1,7 @@
name: Linux Add User Account
id: 51fbcaf2-6259-11ec-b0f3-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -40,7 +40,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1136.001
- - T1136
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_adding_crontab_using_list_parameter.yml b/detections/endpoint/linux_adding_crontab_using_list_parameter.yml
index 8bdc8a8822..7f05ba1ab8 100644
--- a/detections/endpoint/linux_adding_crontab_using_list_parameter.yml
+++ b/detections/endpoint/linux_adding_crontab_using_list_parameter.yml
@@ -1,7 +1,7 @@
name: Linux Adding Crontab Using List Parameter
id: 52f6d751-1fd4-4c74-a4c9-777ecfeb5c58
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -47,7 +47,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.003
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_apt_get_privilege_escalation.yml b/detections/endpoint/linux_apt_get_privilege_escalation.yml
index 7924c146e3..0dd8a1971a 100644
--- a/detections/endpoint/linux_apt_get_privilege_escalation.yml
+++ b/detections/endpoint/linux_apt_get_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux apt-get Privilege Escalation
id: d870ce3b-e796-402f-b2af-cab4da1223f2
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -68,7 +68,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_apt_privilege_escalation.yml b/detections/endpoint/linux_apt_privilege_escalation.yml
index 7f6804cbfb..b663f74c24 100644
--- a/detections/endpoint/linux_apt_privilege_escalation.yml
+++ b/detections/endpoint/linux_apt_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux APT Privilege Escalation
id: 4d5a05fa-77d9-4fd0-af9c-05704f9f9a88
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -68,7 +68,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_at_allow_config_file_creation.yml b/detections/endpoint/linux_at_allow_config_file_creation.yml
index 732c20f5b7..ae556ae740 100644
--- a/detections/endpoint/linux_at_allow_config_file_creation.yml
+++ b/detections/endpoint/linux_at_allow_config_file_creation.yml
@@ -1,7 +1,7 @@
name: Linux At Allow Config File Creation
id: 977b3082-5f3d-11ec-b954-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -58,7 +58,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.003
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_at_application_execution.yml b/detections/endpoint/linux_at_application_execution.yml
index 3cd126c6ca..6666181369 100644
--- a/detections/endpoint/linux_at_application_execution.yml
+++ b/detections/endpoint/linux_at_application_execution.yml
@@ -1,7 +1,7 @@
name: Linux At Application Execution
id: bf0a378e-5f3c-11ec-a6de-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -66,7 +66,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.002
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_auditd_add_user_account.yml b/detections/endpoint/linux_auditd_add_user_account.yml
index 900f4b6a4e..c29d67571e 100644
--- a/detections/endpoint/linux_auditd_add_user_account.yml
+++ b/detections/endpoint/linux_auditd_add_user_account.yml
@@ -1,7 +1,7 @@
name: Linux Auditd Add User Account
id: aae66dc0-74b4-4807-b480-b35f8027abb4
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -61,7 +61,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1136.001
- - T1136
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_auditd_add_user_account_type.yml b/detections/endpoint/linux_auditd_add_user_account_type.yml
index 929dd08741..7bf00799da 100644
--- a/detections/endpoint/linux_auditd_add_user_account_type.yml
+++ b/detections/endpoint/linux_auditd_add_user_account_type.yml
@@ -1,7 +1,7 @@
name: Linux Auditd Add User Account Type
id: f8c325ea-506e-4105-8ccf-da1492e90115
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -59,7 +59,6 @@ tags:
- Compromised Linux Host
asset_type: Endpoint
mitre_attack_id:
- - T1136
- T1136.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/linux_auditd_at_application_execution.yml b/detections/endpoint/linux_auditd_at_application_execution.yml
index da29fe7c02..e9c76689ff 100644
--- a/detections/endpoint/linux_auditd_at_application_execution.yml
+++ b/detections/endpoint/linux_auditd_at_application_execution.yml
@@ -1,7 +1,7 @@
name: Linux Auditd At Application Execution
id: 9f306e0a-1c36-469e-8892-968ca12470dd
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -66,7 +66,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.002
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_auditd_change_file_owner_to_root.yml b/detections/endpoint/linux_auditd_change_file_owner_to_root.yml
index a45a65d0f8..b4733004c9 100644
--- a/detections/endpoint/linux_auditd_change_file_owner_to_root.yml
+++ b/detections/endpoint/linux_auditd_change_file_owner_to_root.yml
@@ -1,16 +1,35 @@
name: Linux Auditd Change File Owner To Root
id: 7b87c556-0ca4-47e0-b84c-6cd62a0a3e90
-version: 4
-date: '2025-01-20'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
-description: The following analytic detects the use of the 'chown' command to change a file owner to 'root' on a Linux system. It leverages Linux Auditd telemetry, specifically monitoring command-line executions and process details. This activity is significant as it may indicate an attempt to escalate privileges by adversaries, malware, or red teamers. If confirmed malicious, this action could allow an attacker to gain root-level access, leading to full control over the compromised host and potential persistence within the environment.
+description: The following analytic detects the use of the 'chown' command to change
+ a file owner to 'root' on a Linux system. It leverages Linux Auditd telemetry, specifically
+ monitoring command-line executions and process details. This activity is significant
+ as it may indicate an attempt to escalate privileges by adversaries, malware, or
+ red teamers. If confirmed malicious, this action could allow an attacker to gain
+ root-level access, leading to full control over the compromised host and potential
+ persistence within the environment.
data_source:
- Linux Auditd Proctitle
-search: '`linux_auditd` `linux_auditd_normalized_proctitle_process`| rename host as dest | where LIKE (process_exec, "%chown %root%") | stats count min(_time) as firstTime max(_time) as lastTime by process_exec proctitle normalized_proctitle_delimiter dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_change_file_owner_to_root_filter`'
-how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed
-known_false_positives: Administrator or network operator can execute this command. Please update the filter macros to remove false positives.
+search: '`linux_auditd` `linux_auditd_normalized_proctitle_process`| rename host as
+ dest | where LIKE (process_exec, "%chown %root%") | stats count min(_time) as firstTime
+ max(_time) as lastTime by process_exec proctitle normalized_proctitle_delimiter
+ dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|
+ `linux_auditd_change_file_owner_to_root_filter`'
+how_to_implement: To implement this detection, the process begins by ingesting auditd
+ data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures
+ command-line executions and process details on Unix/Linux systems. These logs should
+ be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833),
+ which is essential for correctly parsing and categorizing the data. The next step
+ involves normalizing the field names to match the field names set by the Splunk
+ Common Information Model (CIM) to ensure consistency across different data sources
+ and enhance the efficiency of data modeling. This approach enables effective monitoring
+ and detection of linux endpoints where auditd is deployed
+known_false_positives: Administrator or network operator can execute this command.
+ Please update the filter macros to remove false positives.
references:
- https://unix.stackexchange.com/questions/101073/how-to-change-permissions-from-root-user-to-all-users
- https://askubuntu.com/questions/617850/changing-from-user-to-superuser
@@ -20,7 +39,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -40,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1222.002
- - T1222
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -49,6 +72,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.002/linux_auditd_chown_root/linux_auditd_chown_root.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.002/linux_auditd_chown_root/linux_auditd_chown_root.log
source: /var/log/audit/audit.log
sourcetype: linux:audit
diff --git a/detections/endpoint/linux_auditd_disable_or_modify_system_firewall.yml b/detections/endpoint/linux_auditd_disable_or_modify_system_firewall.yml
index 5dfd17febc..a825c4c9fe 100644
--- a/detections/endpoint/linux_auditd_disable_or_modify_system_firewall.yml
+++ b/detections/endpoint/linux_auditd_disable_or_modify_system_firewall.yml
@@ -1,7 +1,7 @@
name: Linux Auditd Disable Or Modify System Firewall
id: 07052556-d4b5-4bae-89aa-cbdc1bb11250
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -62,7 +62,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.004
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_auditd_doas_conf_file_creation.yml b/detections/endpoint/linux_auditd_doas_conf_file_creation.yml
index 6eea3f2bdf..ce27362871 100644
--- a/detections/endpoint/linux_auditd_doas_conf_file_creation.yml
+++ b/detections/endpoint/linux_auditd_doas_conf_file_creation.yml
@@ -1,7 +1,7 @@
name: Linux Auditd Doas Conf File Creation
id: 61059783-574b-40d2-ac2f-69b898afd6b4
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_auditd_doas_tool_execution.yml b/detections/endpoint/linux_auditd_doas_tool_execution.yml
index 14483461ca..d955c86264 100644
--- a/detections/endpoint/linux_auditd_doas_tool_execution.yml
+++ b/detections/endpoint/linux_auditd_doas_tool_execution.yml
@@ -1,7 +1,7 @@
name: Linux Auditd Doas Tool Execution
id: 91b8ca78-f205-4826-a3ef-cd8d6b24e97b
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -62,7 +62,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_auditd_edit_cron_table_parameter.yml b/detections/endpoint/linux_auditd_edit_cron_table_parameter.yml
index abcf36a2c5..e3a2452cda 100644
--- a/detections/endpoint/linux_auditd_edit_cron_table_parameter.yml
+++ b/detections/endpoint/linux_auditd_edit_cron_table_parameter.yml
@@ -1,7 +1,7 @@
name: Linux Auditd Edit Cron Table Parameter
id: f4bb7321-7e64-4d1e-b1aa-21f8b019a91f
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.003
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_auditd_file_permission_modification_via_chmod.yml b/detections/endpoint/linux_auditd_file_permission_modification_via_chmod.yml
index f33b95fed5..7ce6b582fc 100644
--- a/detections/endpoint/linux_auditd_file_permission_modification_via_chmod.yml
+++ b/detections/endpoint/linux_auditd_file_permission_modification_via_chmod.yml
@@ -1,8 +1,8 @@
name: Linux Auditd File Permission Modification Via Chmod
id: 5f1d2ea7-eec0-4790-8b24-6875312ad492
-version: 6
-date: '2025-01-27'
-author: "Teoderick Contreras, Splunk, Ivar Nyg\xE5rd"
+version: 7
+date: '2025-02-10'
+author: Teoderick Contreras, Splunk, Ivar Nygård
status: production
type: Anomaly
description: The following analytic detects suspicious file permission modifications
@@ -68,7 +68,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1222.002
- - T1222
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -77,6 +76,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.002/linux_auditd_chmod_exec_attrib/linux_auditd_chmod_exec_attrib.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.002/linux_auditd_chmod_exec_attrib/linux_auditd_chmod_exec_attrib.log
source: /var/log/audit/audit.log
sourcetype: linux:audit
diff --git a/detections/endpoint/linux_auditd_file_permissions_modification_via_chattr.yml b/detections/endpoint/linux_auditd_file_permissions_modification_via_chattr.yml
index 84bb8beef4..de8a0c8bc8 100644
--- a/detections/endpoint/linux_auditd_file_permissions_modification_via_chattr.yml
+++ b/detections/endpoint/linux_auditd_file_permissions_modification_via_chattr.yml
@@ -1,16 +1,30 @@
name: Linux Auditd File Permissions Modification Via Chattr
id: f2d1110d-b01c-4a58-9975-90a9edeb083a
-version: 3
-date: '2025-01-16'
+version: 4
+date: '2025-02-03'
author: Teoderick Contreras, Splunk
status: production
-type: TTP
+type: Anomaly
description: The following analytic detects suspicious file permissions modifications using the chattr command, which may indicate an attacker attempting to manipulate file attributes to evade detection or prevent alteration. The chattr command can be used to make files immutable or restrict deletion, which can be leveraged to protect malicious files or disrupt system operations. By monitoring for unusual or unauthorized chattr usage, this analytic helps identify potential tampering with critical files, enabling security teams to quickly respond to and mitigate threats associated with unauthorized file attribute changes.
data_source:
- Linux Auditd Execve
-search: '`linux_auditd` `linux_auditd_normalized_proctitle_process` | rename host as dest | rename comm as process_name | rename exe as process | where LIKE(process_exec, "%chattr %") AND LIKE(process_exec, "% -i%") | stats count min(_time) as firstTime max(_time) as lastTime by process_exec proctitle normalized_proctitle_delimiter dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_file_permissions_modification_via_chattr_filter`'
-how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed
-known_false_positives: Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives.
+search: '`linux_auditd` `linux_auditd_normalized_proctitle_process` | rename host
+ as dest | rename comm as process_name | rename exe as process | where LIKE(process_exec,
+ "%chattr %") AND LIKE(process_exec, "% -i%") | stats count min(_time) as firstTime
+ max(_time) as lastTime by process_exec proctitle normalized_proctitle_delimiter
+ dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|
+ `linux_auditd_file_permissions_modification_via_chattr_filter`'
+how_to_implement: To implement this detection, the process begins by ingesting auditd
+ data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures
+ command-line executions and process details on Unix/Linux systems. These logs should
+ be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833),
+ which is essential for correctly parsing and categorizing the data. The next step
+ involves normalizing the field names to match the field names set by the Splunk
+ Common Information Model (CIM) to ensure consistency across different data sources
+ and enhance the efficiency of data modeling. This approach enables effective monitoring
+ and detection of linux endpoints where auditd is deployed
+known_false_positives: Administrator or network operator can use this application
+ for automation purposes. Please update the filter macros to remove false positives.
references:
- https://www.splunk.com/en_us/blog/security/deep-dive-on-persistence-privilege-escalation-technique-and-detection-in-linux-platform.html
drilldown_searches:
@@ -19,7 +33,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -28,7 +47,7 @@ rba:
risk_objects:
- field: dest
type: system
- score: 49
+ score: 30
threat_objects: []
tags:
analytic_story:
@@ -39,7 +58,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1222.002
- - T1222
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -48,6 +66,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.002/linux_auditd_chattr_i/linux_auditd_chattr_i.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.002/linux_auditd_chattr_i/linux_auditd_chattr_i.log
source: /var/log/audit/audit.log
sourcetype: linux:audit
diff --git a/detections/endpoint/linux_auditd_find_credentials_from_password_managers.yml b/detections/endpoint/linux_auditd_find_credentials_from_password_managers.yml
index f42a173862..91a4468484 100644
--- a/detections/endpoint/linux_auditd_find_credentials_from_password_managers.yml
+++ b/detections/endpoint/linux_auditd_find_credentials_from_password_managers.yml
@@ -1,14 +1,21 @@
name: Linux Auditd Find Credentials From Password Managers
id: 784241aa-85a5-4782-a503-d071bd3446f9
-version: 3
-date: '2025-01-16'
+version: 4
+date: '2025-02-03'
author: Teoderick Contreras, Splunk
status: production
type: TTP
-description: The following analytic detects suspicious attempts to find credentials stored in password managers, which may indicate an attacker's effort to retrieve sensitive login information. Password managers are often targeted by adversaries seeking to access stored passwords for further compromise or lateral movement within a network. By monitoring for unusual or unauthorized access to password manager files or processes, this analytic helps identify potential credential theft attempts, enabling security teams to respond quickly to protect critical accounts and prevent further unauthorized access.
+description: The following analytic detects suspicious attempts to find credentials
+ stored in password managers, which may indicate an attacker's effort to retrieve
+ sensitive login information. Password managers are often targeted by adversaries
+ seeking to access stored passwords for further compromise or lateral movement within
+ a network. By monitoring for unusual or unauthorized access to password manager
+ files or processes, this analytic helps identify potential credential theft attempts,
+ enabling security teams to respond quickly to protect critical accounts and prevent
+ further unauthorized access.
data_source:
- Linux Auditd Execve
-search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%.kdbx%") OR LIKE (process_exec, "%KeePass%") OR LIKE (process_exec, "%KeePass\.enforced%") OR LIKE (process_exec, "%.lpdb%")OR LIKE (process_exec, "%.opvault%")OR LIKE (process_exec, "%.agilekeychain%")OR LIKE (process_exec, "%.dashlane%")OR LIKE (process_exec, "%.rfx%")OR LIKE (process_exec, "%passbolt%")OR LIKE (process_exec, "%.spdb%")OR LIKE (process_exec, "%StickyPassword%")OR LIKE (process_exec, "%.walletx%")OR LIKE (process_exec, "%enpass%")OR LIKE (process_exec, "%vault%")OR LIKE (process_exec, "%.kdb%")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_find_credentials_from_password_managers_filter`'
+search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%.kdbx%") OR LIKE (process_exec, "%KeePass%") OR LIKE (process_exec, "%.enforced%") OR LIKE (process_exec, "%.lpdb%")OR LIKE (process_exec, "%.opvault%")OR LIKE (process_exec, "%.agilekeychain%")OR LIKE (process_exec, "%.dashlane%")OR LIKE (process_exec, "%.rfx%")OR LIKE (process_exec, "%passbolt%")OR LIKE (process_exec, "%.spdb%")OR LIKE (process_exec, "%StickyPassword%")OR LIKE (process_exec, "%.walletx%")OR LIKE (process_exec, "%enpass%")OR LIKE (process_exec, "%vault%")OR LIKE (process_exec, "%.kdb%")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_find_credentials_from_password_managers_filter`'
how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed
known_false_positives: Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives.
references:
@@ -20,7 +27,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -40,7 +52,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1555.005
- - T1555
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -49,6 +60,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555.005/linux_auditd_find_password_db/linux_auditd_find_password_db.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555.005/linux_auditd_find_password_db/linux_auditd_find_password_db.log
source: /var/log/audit/audit.log
sourcetype: linux:audit
diff --git a/detections/endpoint/linux_auditd_find_credentials_from_password_stores.yml b/detections/endpoint/linux_auditd_find_credentials_from_password_stores.yml
index 6332592a94..9ae67754ae 100644
--- a/detections/endpoint/linux_auditd_find_credentials_from_password_stores.yml
+++ b/detections/endpoint/linux_auditd_find_credentials_from_password_stores.yml
@@ -1,16 +1,38 @@
name: Linux Auditd Find Credentials From Password Stores
id: 4de73044-9a1d-4a51-a1c2-85267d8dcab3
-version: 3
-date: '2025-01-16'
+version: 4
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
-description: The following analytic detects suspicious attempts to find credentials stored in password stores, indicating a potential attacker's effort to access sensitive login information. Password stores are critical repositories that contain valuable credentials, and unauthorized access to them can lead to significant security breaches. By monitoring for unusual or unauthorized activities related to password store access, this analytic helps identify potential credential theft attempts, allowing security teams to respond promptly and prevent unauthorized access to critical systems and data.
+description: The following analytic detects suspicious attempts to find credentials
+ stored in password stores, indicating a potential attacker's effort to access sensitive
+ login information. Password stores are critical repositories that contain valuable
+ credentials, and unauthorized access to them can lead to significant security breaches.
+ By monitoring for unusual or unauthorized activities related to password store access,
+ this analytic helps identify potential credential theft attempts, allowing security
+ teams to respond promptly and prevent unauthorized access to critical systems and
+ data.
data_source:
- Linux Auditd Execve
-search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%password%") OR LIKE (process_exec, "%pass %") OR LIKE (process_exec, "%credential%")OR LIKE (process_exec, "%creds%")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_find_credentials_from_password_stores_filter`'
-how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed
-known_false_positives: Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives.
+search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as
+ dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec,
+ "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%password%")
+ OR LIKE (process_exec, "%pass %") OR LIKE (process_exec, "%credential%")OR LIKE
+ (process_exec, "%creds%")) | stats count min(_time) as firstTime max(_time) as lastTime
+ by argc process_exec dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|
+ `linux_auditd_find_credentials_from_password_stores_filter`'
+how_to_implement: To implement this detection, the process begins by ingesting auditd
+ data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures
+ command-line executions and process details on Unix/Linux systems. These logs should
+ be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833),
+ which is essential for correctly parsing and categorizing the data. The next step
+ involves normalizing the field names to match the field names set by the Splunk
+ Common Information Model (CIM) to ensure consistency across different data sources
+ and enhance the efficiency of data modeling. This approach enables effective monitoring
+ and detection of linux endpoints where auditd is deployed
+known_false_positives: Administrator or network operator can use this application
+ for automation purposes. Please update the filter macros to remove false positives.
references:
- https://www.splunk.com/en_us/blog/security/deep-dive-on-persistence-privilege-escalation-technique-and-detection-in-linux-platform.html
- https://github.com/peass-ng/PEASS-ng/tree/master/linPEAS
@@ -20,7 +42,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -40,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1555.005
- - T1555
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -49,6 +75,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555.005/linux_auditd_find_credentials/linux_auditd_find_credentials.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555.005/linux_auditd_find_credentials/linux_auditd_find_credentials.log
source: /var/log/audit/audit.log
sourcetype: linux:audit
diff --git a/detections/endpoint/linux_auditd_find_ssh_private_keys.yml b/detections/endpoint/linux_auditd_find_ssh_private_keys.yml
index 8788828cc2..96e7d7d952 100644
--- a/detections/endpoint/linux_auditd_find_ssh_private_keys.yml
+++ b/detections/endpoint/linux_auditd_find_ssh_private_keys.yml
@@ -1,16 +1,38 @@
name: Linux Auditd Find Ssh Private Keys
id: e2d2bd10-dcd1-4b2f-8a76-0198eab32ba5
-version: 3
-date: '2025-01-16'
+version: 4
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
-description: The following analytic detects suspicious attempts to find SSH private keys, which may indicate an attacker's effort to compromise secure access to systems. SSH private keys are essential for secure authentication, and unauthorized access to these keys can enable attackers to gain unauthorized access to servers and other critical infrastructure. By monitoring for unusual or unauthorized searches for SSH private keys, this analytic helps identify potential threats to network security, allowing security teams to quickly respond and safeguard against unauthorized access and potential breaches.
+description: The following analytic detects suspicious attempts to find SSH private
+ keys, which may indicate an attacker's effort to compromise secure access to systems.
+ SSH private keys are essential for secure authentication, and unauthorized access
+ to these keys can enable attackers to gain unauthorized access to servers and other
+ critical infrastructure. By monitoring for unusual or unauthorized searches for
+ SSH private keys, this analytic helps identify potential threats to network security,
+ allowing security teams to quickly respond and safeguard against unauthorized access
+ and potential breaches.
data_source:
- Linux Auditd Execve
-search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%id_rsa%") OR LIKE (process_exec, "%id_dsa%")OR LIKE (process_exec, "%.key%") OR LIKE (process_exec, "%ssh_key%")OR LIKE (process_exec, "%authorized_keys%")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_find_ssh_private_keys_filter`'
-how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed
-known_false_positives: Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives.
+search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as
+ dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec,
+ "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%id_rsa%")
+ OR LIKE (process_exec, "%id_dsa%")OR LIKE (process_exec, "%.key%") OR LIKE (process_exec,
+ "%ssh_key%")OR LIKE (process_exec, "%authorized_keys%")) | stats count min(_time)
+ as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`| `linux_auditd_find_ssh_private_keys_filter`'
+how_to_implement: To implement this detection, the process begins by ingesting auditd
+ data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures
+ command-line executions and process details on Unix/Linux systems. These logs should
+ be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833),
+ which is essential for correctly parsing and categorizing the data. The next step
+ involves normalizing the field names to match the field names set by the Splunk
+ Common Information Model (CIM) to ensure consistency across different data sources
+ and enhance the efficiency of data modeling. This approach enables effective monitoring
+ and detection of linux endpoints where auditd is deployed
+known_false_positives: Administrator or network operator can use this application
+ for automation purposes. Please update the filter macros to remove false positives.
references:
- https://www.splunk.com/en_us/blog/security/deep-dive-on-persistence-privilege-escalation-technique-and-detection-in-linux-platform.html
- https://github.com/peass-ng/PEASS-ng/tree/master/linPEAS
@@ -20,7 +42,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -40,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1552.004
- - T1552
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -49,6 +75,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.004/linux_auditd_find_ssh_files/linux_auditd_find_ssh_files.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.004/linux_auditd_find_ssh_files/linux_auditd_find_ssh_files.log
source: /var/log/audit/audit.log
sourcetype: linux:audit
diff --git a/detections/endpoint/linux_auditd_hidden_files_and_directories_creation.yml b/detections/endpoint/linux_auditd_hidden_files_and_directories_creation.yml
index f888933bba..483150c621 100644
--- a/detections/endpoint/linux_auditd_hidden_files_and_directories_creation.yml
+++ b/detections/endpoint/linux_auditd_hidden_files_and_directories_creation.yml
@@ -1,10 +1,10 @@
name: Linux Auditd Hidden Files And Directories Creation
id: 555cc358-bf16-4e05-9b3a-0f89c73b7261
-version: 4
-date: '2025-01-16'
+version: 5
+date: '2025-02-03'
author: Teoderick Contreras, Splunk
status: production
-type: TTP
+type: Anomaly
description: The following analytic detects suspicious creation of hidden files and directories, which may indicate an attacker's attempt to conceal malicious activities or unauthorized data. Hidden files and directories are often used to evade detection by security tools and administrators, providing a stealthy means for storing malware, logs, or sensitive information. By monitoring for unusual or unauthorized creation of hidden files and directories, this analytic helps identify potential attempts to hide or unauthorized creation of hidden files and directories, this analytic helps identify potential attempts to hide malicious operations, enabling security teams to uncover and address hidden threats effectively.
data_source:
- Linux Auditd Execve
@@ -28,7 +28,7 @@ rba:
risk_objects:
- field: dest
type: system
- score: 64
+ score: 30
threat_objects: []
tags:
analytic_story:
diff --git a/detections/endpoint/linux_auditd_insert_kernel_module_using_insmod_utility.yml b/detections/endpoint/linux_auditd_insert_kernel_module_using_insmod_utility.yml
index 10a1cc21ad..0b168373bc 100644
--- a/detections/endpoint/linux_auditd_insert_kernel_module_using_insmod_utility.yml
+++ b/detections/endpoint/linux_auditd_insert_kernel_module_using_insmod_utility.yml
@@ -1,7 +1,7 @@
name: Linux Auditd Insert Kernel Module Using Insmod Utility
id: bc0ca53f-dea6-4906-9b12-09c396fdf1d3
-version: 4
-date: '2024-12-19'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -19,9 +19,9 @@ search: '`linux_auditd` type=SYSCALL comm=insmod | rename host as dest | stats c
success dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|
`linux_auditd_insert_kernel_module_using_insmod_utility_filter`'
how_to_implement: To implement this detection, the process begins by ingesting auditd
- data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line
- executions and process details on Unix/Linux systems. These logs should be ingested
- and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833),
+ data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures
+ command-line executions and process details on Unix/Linux systems. These logs should
+ be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833),
which is essential for correctly parsing and categorizing the data. The next step
involves normalizing the field names to match the field names set by the Splunk
Common Information Model (CIM) to ensure consistency across different data sources
@@ -65,7 +65,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1547.006
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_auditd_install_kernel_module_using_modprobe_utility.yml b/detections/endpoint/linux_auditd_install_kernel_module_using_modprobe_utility.yml
index 29a1db8488..a57cd34a93 100644
--- a/detections/endpoint/linux_auditd_install_kernel_module_using_modprobe_utility.yml
+++ b/detections/endpoint/linux_auditd_install_kernel_module_using_modprobe_utility.yml
@@ -1,16 +1,34 @@
name: Linux Auditd Install Kernel Module Using Modprobe Utility
id: 95165985-ace5-4d42-9c42-93a89a5af901
-version: 3
-date: '2025-01-20'
+version: 4
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
-description: The following analytic detects the installation of a Linux kernel module using the modprobe utility. It leverages data from Linux Auditd, focusing on process names and command-line executions. This activity is significant because installing a kernel module can indicate an attempt to deploy a rootkit or other malicious kernel-level code, potentially leading to elevated privileges and bypassing security detections. If confirmed malicious, this could allow an attacker to gain persistent, high-level access to the system, compromising its integrity and security.
+description: The following analytic detects the installation of a Linux kernel module
+ using the modprobe utility. It leverages data from Linux Auditd, focusing on process
+ names and command-line executions. This activity is significant because installing
+ a kernel module can indicate an attempt to deploy a rootkit or other malicious kernel-level
+ code, potentially leading to elevated privileges and bypassing security detections.
+ If confirmed malicious, this could allow an attacker to gain persistent, high-level
+ access to the system, compromising its integrity and security.
data_source:
- Linux Auditd Syscall
-search: '`linux_auditd` type=SYSCALL comm=modprobe | rename host as dest | stats count min(_time) as firstTime max(_time) as lastTime by comm exe SYSCALL UID ppid pid success dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `linux_auditd_install_kernel_module_using_modprobe_utility_filter`'
-how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed
-known_false_positives: Administrator or network operator can execute this command. Please update the filter macros to remove false positives.
+search: '`linux_auditd` type=SYSCALL comm=modprobe | rename host as dest | stats count
+ min(_time) as firstTime max(_time) as lastTime by comm exe SYSCALL UID ppid pid
+ success dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
+ `linux_auditd_install_kernel_module_using_modprobe_utility_filter`'
+how_to_implement: To implement this detection, the process begins by ingesting auditd
+ data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures
+ command-line executions and process details on Unix/Linux systems. These logs should
+ be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833),
+ which is essential for correctly parsing and categorizing the data. The next step
+ involves normalizing the field names to match the field names set by the Splunk
+ Common Information Model (CIM) to ensure consistency across different data sources
+ and enhance the efficiency of data modeling. This approach enables effective monitoring
+ and detection of linux endpoints where auditd is deployed
+known_false_positives: Administrator or network operator can execute this command.
+ Please update the filter macros to remove false positives.
references:
- https://docs.fedoraproject.org/en-US/fedora/rawhide/system-administrators-guide/kernel-module-driver-configuration/Working_with_Kernel_Modules/
- https://security.stackexchange.com/questions/175953/how-to-load-a-malicious-lkm-at-startup
@@ -21,7 +39,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -41,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1547.006
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -50,6 +72,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.006/linux_auditd_modprobe/linux_auditd_modprobe.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.006/linux_auditd_modprobe/linux_auditd_modprobe.log
source: /var/log/audit/audit.log
sourcetype: linux:audit
diff --git a/detections/endpoint/linux_auditd_kernel_module_using_rmmod_utility.yml b/detections/endpoint/linux_auditd_kernel_module_using_rmmod_utility.yml
index 85736a7952..0d437219d2 100644
--- a/detections/endpoint/linux_auditd_kernel_module_using_rmmod_utility.yml
+++ b/detections/endpoint/linux_auditd_kernel_module_using_rmmod_utility.yml
@@ -1,7 +1,7 @@
name: Linux Auditd Kernel Module Using Rmmod Utility
id: 31810b7a-0abe-42be-a210-0dec8106afee
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1547.006
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_auditd_nopasswd_entry_in_sudoers_file.yml b/detections/endpoint/linux_auditd_nopasswd_entry_in_sudoers_file.yml
index b0d9f8aa6c..2470ddfe8f 100644
--- a/detections/endpoint/linux_auditd_nopasswd_entry_in_sudoers_file.yml
+++ b/detections/endpoint/linux_auditd_nopasswd_entry_in_sudoers_file.yml
@@ -1,7 +1,7 @@
name: Linux Auditd Nopasswd Entry In Sudoers File
id: 651df959-ad17-4b73-a323-90cb96d5fa1b
-version: 4
-date: '2025-01-27'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -65,7 +65,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -74,6 +73,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_nopasswd/linux_auditd_nopasswd.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_nopasswd/linux_auditd_nopasswd.log
source: /var/log/audit/audit.log
sourcetype: linux:audit
diff --git a/detections/endpoint/linux_auditd_possible_access_or_modification_of_sshd_config_file.yml b/detections/endpoint/linux_auditd_possible_access_or_modification_of_sshd_config_file.yml
index 965112d606..a9323c6d19 100644
--- a/detections/endpoint/linux_auditd_possible_access_or_modification_of_sshd_config_file.yml
+++ b/detections/endpoint/linux_auditd_possible_access_or_modification_of_sshd_config_file.yml
@@ -1,7 +1,7 @@
name: Linux Auditd Possible Access Or Modification Of Sshd Config File
id: acb3ea33-70f7-47aa-b335-643b3aebcb2f
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1098.004
- - T1098
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_auditd_possible_access_to_credential_files.yml b/detections/endpoint/linux_auditd_possible_access_to_credential_files.yml
index 499e0a23bb..62158c07f3 100644
--- a/detections/endpoint/linux_auditd_possible_access_to_credential_files.yml
+++ b/detections/endpoint/linux_auditd_possible_access_to_credential_files.yml
@@ -1,7 +1,7 @@
name: Linux Auditd Possible Access To Credential Files
id: 0419cb7a-57ea-467b-974f-77c303dfe2a3
-version: 4
-date: '2025-01-27'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.008
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -76,6 +75,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/linux_auditd_access_credential/linux_auditd_access_credential.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/linux_auditd_access_credential/linux_auditd_access_credential.log
source: /var/log/audit/audit.log
sourcetype: linux:audit
diff --git a/detections/endpoint/linux_auditd_possible_access_to_sudoers_file.yml b/detections/endpoint/linux_auditd_possible_access_to_sudoers_file.yml
index 8dda7e5e89..ce58e5dae8 100644
--- a/detections/endpoint/linux_auditd_possible_access_to_sudoers_file.yml
+++ b/detections/endpoint/linux_auditd_possible_access_to_sudoers_file.yml
@@ -1,7 +1,7 @@
name: Linux Auditd Possible Access To Sudoers File
id: 8be88f46-f7e8-4ae6-b15e-cf1b13392834
-version: 4
-date: '2025-01-27'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -73,6 +72,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_sudoers_access/linux_auditd_sudoers_access.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_sudoers_access/linux_auditd_sudoers_access.log
source: /var/log/audit/audit.log
sourcetype: linux:audit
diff --git a/detections/endpoint/linux_auditd_possible_append_cronjob_entry_on_existing_cronjob_file.yml b/detections/endpoint/linux_auditd_possible_append_cronjob_entry_on_existing_cronjob_file.yml
index d80e3059c5..7fac278e2a 100644
--- a/detections/endpoint/linux_auditd_possible_append_cronjob_entry_on_existing_cronjob_file.yml
+++ b/detections/endpoint/linux_auditd_possible_append_cronjob_entry_on_existing_cronjob_file.yml
@@ -1,7 +1,7 @@
name: Linux Auditd Possible Append Cronjob Entry On Existing Cronjob File
id: fea71cf0-fa10-4ef6-9202-9682b2e0c477
-version: 4
-date: '2025-01-20'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -19,9 +19,9 @@ search: '`linux_auditd` type=PATH name IN("*/etc/cron*", "*/var/spool/cron/*", "
by name nametype OGID dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
`linux_auditd_possible_append_cronjob_entry_on_existing_cronjob_file_filter`'
how_to_implement: To implement this detection, the process begins by ingesting auditd
- data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line
- executions and process details on Unix/Linux systems. These logs should be ingested
- and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833),
+ data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures
+ command-line executions and process details on Unix/Linux systems. These logs should
+ be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833),
which is essential for correctly parsing and categorizing the data. The next step
involves normalizing the field names to match the field names set by the Splunk
Common Information Model (CIM) to ensure consistency across different data sources
@@ -45,7 +45,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.003
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_auditd_preload_hijack_library_calls.yml b/detections/endpoint/linux_auditd_preload_hijack_library_calls.yml
index fdfa38e184..8eb1a95ce2 100644
--- a/detections/endpoint/linux_auditd_preload_hijack_library_calls.yml
+++ b/detections/endpoint/linux_auditd_preload_hijack_library_calls.yml
@@ -1,7 +1,7 @@
name: Linux Auditd Preload Hijack Library Calls
id: 35c50572-a70b-452f-afa9-bebdf3c3ce36
-version: 4
-date: '2025-01-27'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -65,7 +65,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1574.006
- - T1574
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -74,6 +73,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/linux_auditd_ldpreload/linux_auditd_ldpreload.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/linux_auditd_ldpreload/linux_auditd_ldpreload.log
source: /var/log/audit/audit.log
sourcetype: linux:audit
diff --git a/detections/endpoint/linux_auditd_preload_hijack_via_preload_file.yml b/detections/endpoint/linux_auditd_preload_hijack_via_preload_file.yml
index 2d5b8c3d5e..d850271d2d 100644
--- a/detections/endpoint/linux_auditd_preload_hijack_via_preload_file.yml
+++ b/detections/endpoint/linux_auditd_preload_hijack_via_preload_file.yml
@@ -1,7 +1,7 @@
name: Linux Auditd Preload Hijack Via Preload File
id: c1b7abca-55cb-4a39-bdfb-e28c1c12745f
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -47,7 +47,8 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
- message: A [$type$] event has occurred on host - [$dest$] to modify the preload file.
+ message: A [$type$] event has occurred on host - [$dest$] to modify the preload
+ file.
risk_objects:
- field: dest
type: system
@@ -62,7 +63,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1574.006
- - T1574
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_auditd_private_keys_and_certificate_enumeration.yml b/detections/endpoint/linux_auditd_private_keys_and_certificate_enumeration.yml
index 29d3189d49..3734df8760 100644
--- a/detections/endpoint/linux_auditd_private_keys_and_certificate_enumeration.yml
+++ b/detections/endpoint/linux_auditd_private_keys_and_certificate_enumeration.yml
@@ -1,16 +1,40 @@
name: Linux Auditd Private Keys and Certificate Enumeration
id: 892eb674-3344-4143-8e52-4775b1daf3f1
-version: 1
-date: '2025-01-15'
+version: 2
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
-description: The following analytic detects suspicious attempts to find private keys, which may indicate an attacker's effort to access sensitive cryptographic information. Private keys are crucial for securing encrypted communications and data, and unauthorized access to them can lead to severe security breaches, including data decryption and identity theft. By monitoring for unusual or unauthorized searches for private keys, this analytic helps identify potential threats to cryptographic security, enabling security teams to take swift action to protect the integrity and confidentiality of encrypted information.
+description: The following analytic detects suspicious attempts to find private keys,
+ which may indicate an attacker's effort to access sensitive cryptographic information.
+ Private keys are crucial for securing encrypted communications and data, and unauthorized
+ access to them can lead to severe security breaches, including data decryption and
+ identity theft. By monitoring for unusual or unauthorized searches for private keys,
+ this analytic helps identify potential threats to cryptographic security, enabling
+ security teams to take swift action to protect the integrity and confidentiality
+ of encrypted information.
data_source:
- Linux Auditd Execve
-search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%.pem%") OR LIKE (process_exec, "%.cer%") OR LIKE (process_exec, "%.crt%") OR LIKE (process_exec, "%.pgp%") OR LIKE (process_exec, "%.key%") OR LIKE (process_exec, "%.gpg%")OR LIKE (process_exec, "%.ppk%") OR LIKE (process_exec, "%.p12%") OR LIKE (process_exec, "%.pfx%")OR LIKE (process_exec, "%.p7b%")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_private_keys_and_certificate_enumeration_filter`'
-how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed
-known_false_positives: Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives.
+search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as
+ dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec,
+ "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%.pem%") OR
+ LIKE (process_exec, "%.cer%") OR LIKE (process_exec, "%.crt%") OR LIKE (process_exec,
+ "%.pgp%") OR LIKE (process_exec, "%.key%") OR LIKE (process_exec, "%.gpg%")OR LIKE
+ (process_exec, "%.ppk%") OR LIKE (process_exec, "%.p12%") OR LIKE (process_exec,
+ "%.pfx%")OR LIKE (process_exec, "%.p7b%")) | stats count min(_time) as firstTime
+ max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`| `linux_auditd_private_keys_and_certificate_enumeration_filter`'
+how_to_implement: To implement this detection, the process begins by ingesting auditd
+ data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures
+ command-line executions and process details on Unix/Linux systems. These logs should
+ be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833),
+ which is essential for correctly parsing and categorizing the data. The next step
+ involves normalizing the field names to match the field names set by the Splunk
+ Common Information Model (CIM) to ensure consistency across different data sources
+ and enhance the efficiency of data modeling. This approach enables effective monitoring
+ and detection of linux endpoints where auditd is deployed
+known_false_positives: Administrator or network operator can use this application
+ for automation purposes. Please update the filter macros to remove false positives.
references:
- https://www.splunk.com/en_us/blog/security/deep-dive-on-persistence-privilege-escalation-technique-and-detection-in-linux-platform.html
- https://github.com/peass-ng/PEASS-ng/tree/master/linPEAS
@@ -20,7 +44,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -39,7 +68,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1552.004
- - T1552
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -48,6 +76,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.004/linux_auditd_find_gpg/linux_auditd_find_gpg.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.004/linux_auditd_find_gpg/linux_auditd_find_gpg.log
source: /var/log/audit/audit.log
sourcetype: linux:audit
diff --git a/detections/endpoint/linux_auditd_service_restarted.yml b/detections/endpoint/linux_auditd_service_restarted.yml
index a619b94f79..63fbdd633c 100644
--- a/detections/endpoint/linux_auditd_service_restarted.yml
+++ b/detections/endpoint/linux_auditd_service_restarted.yml
@@ -1,7 +1,7 @@
name: Linux Auditd Service Restarted
id: 8eb3e858-18d3-44a4-a514-52cfa39f154a
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -68,7 +68,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.006
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_auditd_service_started.yml b/detections/endpoint/linux_auditd_service_started.yml
index 2e878c1779..d157eebc41 100644
--- a/detections/endpoint/linux_auditd_service_started.yml
+++ b/detections/endpoint/linux_auditd_service_started.yml
@@ -1,10 +1,10 @@
name: Linux Auditd Service Started
id: b5eed06d-5c97-4092-a3a1-fa4b7e77c71a
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-03'
author: Teoderick Contreras, Splunk
status: production
-type: TTP
+type: Anomaly
description: The following analytic detects the suspicious service started. This behavior
is critical for a SOC to monitor because it may indicate attempts to gain unauthorized
access or maintain control over a system. Such actions could be signs of malicious
@@ -53,7 +53,7 @@ rba:
risk_objects:
- field: dest
type: system
- score: 64
+ score: 40
threat_objects: []
tags:
analytic_story:
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1569.002
- - T1569
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_auditd_setuid_using_chmod_utility.yml b/detections/endpoint/linux_auditd_setuid_using_chmod_utility.yml
index 7c32e22160..db1157d54e 100644
--- a/detections/endpoint/linux_auditd_setuid_using_chmod_utility.yml
+++ b/detections/endpoint/linux_auditd_setuid_using_chmod_utility.yml
@@ -1,7 +1,7 @@
name: Linux Auditd Setuid Using Chmod Utility
id: 8230c407-1b47-4d95-ac2e-718bd6381386
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.001
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_auditd_setuid_using_setcap_utility.yml b/detections/endpoint/linux_auditd_setuid_using_setcap_utility.yml
index df8cc3f4ae..08a69f6ca0 100644
--- a/detections/endpoint/linux_auditd_setuid_using_setcap_utility.yml
+++ b/detections/endpoint/linux_auditd_setuid_using_setcap_utility.yml
@@ -1,16 +1,38 @@
name: Linux Auditd Setuid Using Setcap Utility
id: 1474459a-302b-4255-8add-d82f96d14cd9
-version: 3
-date: '2025-01-16'
+version: 4
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
-description: The following analytic detects the execution of the 'setcap' utility to enable the SUID bit on Linux systems. It leverages Linux Auditd data, focusing on process names and command-line arguments that indicate the use of 'setcap' with specific capabilities. This activity is significant because setting the SUID bit allows a user to temporarily gain root access, posing a substantial security risk. If confirmed malicious, an attacker could escalate privileges, execute arbitrary commands with elevated permissions, and potentially compromise the entire system.
+description: The following analytic detects the execution of the 'setcap' utility
+ to enable the SUID bit on Linux systems. It leverages Linux Auditd data, focusing
+ on process names and command-line arguments that indicate the use of 'setcap' with
+ specific capabilities. This activity is significant because setting the SUID bit
+ allows a user to temporarily gain root access, posing a substantial security risk.
+ If confirmed malicious, an attacker could escalate privileges, execute arbitrary
+ commands with elevated permissions, and potentially compromise the entire system.
data_source:
- Linux Auditd Execve
-search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where LIKE (process_exec, "%setcap %") AND (LIKE (process_exec, "% cap_setuid+ep %") OR LIKE (process_exec, "% cap_setuid=ep %") OR LIKE (process_exec, "% cap_net_bind_service+p %") OR LIKE (process_exec, "% cap_net_raw+ep %") OR LIKE (process_exec, "% cap_dac_read_search+ep %")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `linux_auditd_setuid_using_setcap_utility_filter`'
-how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed
-known_false_positives: Administrator or network operator can execute this command. Please update the filter macros to remove false positives.
+search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as
+ dest | rename comm as process_name | rename exe as process | where LIKE (process_exec,
+ "%setcap %") AND (LIKE (process_exec, "% cap_setuid+ep %") OR LIKE (process_exec,
+ "% cap_setuid=ep %") OR LIKE (process_exec, "% cap_net_bind_service+p %") OR LIKE
+ (process_exec, "% cap_net_raw+ep %") OR LIKE (process_exec, "% cap_dac_read_search+ep
+ %")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec
+ dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
+ `linux_auditd_setuid_using_setcap_utility_filter`'
+how_to_implement: To implement this detection, the process begins by ingesting auditd
+ data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures
+ command-line executions and process details on Unix/Linux systems. These logs should
+ be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833),
+ which is essential for correctly parsing and categorizing the data. The next step
+ involves normalizing the field names to match the field names set by the Splunk
+ Common Information Model (CIM) to ensure consistency across different data sources
+ and enhance the efficiency of data modeling. This approach enables effective monitoring
+ and detection of linux endpoints where auditd is deployed
+known_false_positives: Administrator or network operator can execute this command.
+ Please update the filter macros to remove false positives.
references:
- https://www.hackingarticles.in/linux-privilege-escalation-using-capabilities/
drilldown_searches:
@@ -19,7 +41,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -38,7 +65,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.001
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -47,6 +73,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/linux_auditd_setuid/linux_auditd_setcap_priv.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/linux_auditd_setuid/linux_auditd_setcap_priv.log
source: /var/log/audit/audit.log
sourcetype: linux:audit
diff --git a/detections/endpoint/linux_auditd_sudo_or_su_execution.yml b/detections/endpoint/linux_auditd_sudo_or_su_execution.yml
index b53ed7ef6c..ebf46c26c5 100644
--- a/detections/endpoint/linux_auditd_sudo_or_su_execution.yml
+++ b/detections/endpoint/linux_auditd_sudo_or_su_execution.yml
@@ -1,16 +1,35 @@
name: Linux Auditd Sudo Or Su Execution
id: 817a5c89-5b92-4818-a22d-aa35e1361afe
-version: 3
-date: '2025-01-20'
+version: 4
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
-description: The following analytic detects the execution of the "sudo" or "su" command on a Linux operating system. It leverages data from Linux Auditd, focusing on process names and parent process names. This activity is significant because "sudo" and "su" commands are commonly used by adversaries to elevate privileges, potentially leading to unauthorized access or control over the system. If confirmed malicious, this activity could allow attackers to execute commands with root privileges, leading to severe security breaches, data exfiltration, or further system compromise.
+description: The following analytic detects the execution of the "sudo" or "su" command
+ on a Linux operating system. It leverages data from Linux Auditd, focusing on process
+ names and parent process names. This activity is significant because "sudo" and
+ "su" commands are commonly used by adversaries to elevate privileges, potentially
+ leading to unauthorized access or control over the system. If confirmed malicious,
+ this activity could allow attackers to execute commands with root privileges, leading
+ to severe security breaches, data exfiltration, or further system compromise.
data_source:
- Linux Auditd Proctitle
-search: '`linux_auditd` `linux_auditd_normalized_proctitle_process` | rename host as dest | where LIKE(process_exec, "%sudo %") OR LIKE(process_exec, "%su %") | stats count min(_time) as firstTime max(_time) as lastTime by process_exec proctitle normalized_proctitle_delimiter dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_sudo_or_su_execution_filter`'
-how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed
-known_false_positives: Administrator or network operator can execute this command. Please update the filter macros to remove false positives.
+search: '`linux_auditd` `linux_auditd_normalized_proctitle_process` | rename host
+ as dest | where LIKE(process_exec, "%sudo %") OR LIKE(process_exec, "%su %") | stats
+ count min(_time) as firstTime max(_time) as lastTime by process_exec proctitle normalized_proctitle_delimiter
+ dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|
+ `linux_auditd_sudo_or_su_execution_filter`'
+how_to_implement: To implement this detection, the process begins by ingesting auditd
+ data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures
+ command-line executions and process details on Unix/Linux systems. These logs should
+ be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833),
+ which is essential for correctly parsing and categorizing the data. The next step
+ involves normalizing the field names to match the field names set by the Splunk
+ Common Information Model (CIM) to ensure consistency across different data sources
+ and enhance the efficiency of data modeling. This approach enables effective monitoring
+ and detection of linux endpoints where auditd is deployed
+known_false_positives: Administrator or network operator can execute this command.
+ Please update the filter macros to remove false positives.
references:
- https://attack.mitre.org/techniques/T1548/003/
drilldown_searches:
@@ -19,7 +38,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -38,7 +62,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -47,6 +70,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_sudo_su/linux_auditd_sudo_su.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_sudo_su/linux_auditd_sudo_su.log
source: /var/log/audit/audit.log
sourcetype: linux:audit
diff --git a/detections/endpoint/linux_auditd_unix_shell_configuration_modification.yml b/detections/endpoint/linux_auditd_unix_shell_configuration_modification.yml
index 50d90725bc..664416e29d 100644
--- a/detections/endpoint/linux_auditd_unix_shell_configuration_modification.yml
+++ b/detections/endpoint/linux_auditd_unix_shell_configuration_modification.yml
@@ -1,7 +1,7 @@
name: Linux Auditd Unix Shell Configuration Modification
id: 66f737c6-3f7f-46ed-8e9b-cc0e5bf01f04
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -69,7 +69,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1546.004
- - T1546
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_auditd_unload_module_via_modprobe.yml b/detections/endpoint/linux_auditd_unload_module_via_modprobe.yml
index d3f5d76e2e..cdd0c0c95c 100644
--- a/detections/endpoint/linux_auditd_unload_module_via_modprobe.yml
+++ b/detections/endpoint/linux_auditd_unload_module_via_modprobe.yml
@@ -1,16 +1,36 @@
name: Linux Auditd Unload Module Via Modprobe
id: 90964d6a-4b5f-409a-85bd-95e261e03fe9
-version: 3
-date: '2025-01-16'
+version: 4
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
-description: The following analytic detects suspicious use of the `modprobe` command to unload kernel modules, which may indicate an attempt to disable critical system components or evade detection. The `modprobe` utility manages kernel modules, and unauthorized unloading of modules can disrupt system security features, remove logging capabilities, or conceal malicious activities. By monitoring for unusual or unauthorized `modprobe` operations involving module unloading, this analytic helps identify potential tampering with kernel functionality, enabling security teams to investigate and address possible threats to system integrity.
+description: The following analytic detects suspicious use of the `modprobe` command
+ to unload kernel modules, which may indicate an attempt to disable critical system
+ components or evade detection. The `modprobe` utility manages kernel modules, and
+ unauthorized unloading of modules can disrupt system security features, remove logging
+ capabilities, or conceal malicious activities. By monitoring for unusual or unauthorized
+ `modprobe` operations involving module unloading, this analytic helps identify potential
+ tampering with kernel functionality, enabling security teams to investigate and
+ address possible threats to system integrity.
data_source:
- Linux Auditd Execve
-search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where LIKE (process_exec, "%modprobe%") AND LIKE (process_exec, "%-r %") | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `linux_auditd_unload_module_via_modprobe_filter`'
-how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed
-known_false_positives: Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives.
+search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as
+ dest | rename comm as process_name | rename exe as process | where LIKE (process_exec,
+ "%modprobe%") AND LIKE (process_exec, "%-r %") | stats count min(_time) as firstTime
+ max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)`|
+ `security_content_ctime(lastTime)`| `linux_auditd_unload_module_via_modprobe_filter`'
+how_to_implement: To implement this detection, the process begins by ingesting auditd
+ data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures
+ command-line executions and process details on Unix/Linux systems. These logs should
+ be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833),
+ which is essential for correctly parsing and categorizing the data. The next step
+ involves normalizing the field names to match the field names set by the Splunk
+ Common Information Model (CIM) to ensure consistency across different data sources
+ and enhance the efficiency of data modeling. This approach enables effective monitoring
+ and detection of linux endpoints where auditd is deployed
+known_false_positives: Administrator or network operator can use this application
+ for automation purposes. Please update the filter macros to remove false positives.
references:
- https://www.splunk.com/en_us/blog/security/deep-dive-on-persistence-privilege-escalation-technique-and-detection-in-linux-platform.html
drilldown_searches:
@@ -19,7 +39,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -39,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1547.006
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -48,6 +72,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.006/linux_auditd_modprobe_unload_module/linux_auditd_modprobe_unload_module.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.006/linux_auditd_modprobe_unload_module/linux_auditd_modprobe_unload_module.log
source: /var/log/audit/audit.log
sourcetype: linux:audit
diff --git a/detections/endpoint/linux_awk_privilege_escalation.yml b/detections/endpoint/linux_awk_privilege_escalation.yml
index 1036c94106..412b476eef 100644
--- a/detections/endpoint/linux_awk_privilege_escalation.yml
+++ b/detections/endpoint/linux_awk_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux AWK Privilege Escalation
id: 4510cae0-96a2-4840-9919-91d262db210a
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_busybox_privilege_escalation.yml b/detections/endpoint/linux_busybox_privilege_escalation.yml
index f6bbd0bde7..74ea49e117 100644
--- a/detections/endpoint/linux_busybox_privilege_escalation.yml
+++ b/detections/endpoint/linux_busybox_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux Busybox Privilege Escalation
id: 387c4e78-f4a4-413d-ad44-e9f7bc4642c9
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_c89_privilege_escalation.yml b/detections/endpoint/linux_c89_privilege_escalation.yml
index 3919b610e8..229db8dfc8 100644
--- a/detections/endpoint/linux_c89_privilege_escalation.yml
+++ b/detections/endpoint/linux_c89_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux c89 Privilege Escalation
id: 54c95f4d-3e5d-44be-9521-ea19ba62f7a8
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_c99_privilege_escalation.yml b/detections/endpoint/linux_c99_privilege_escalation.yml
index 9e76c91bfe..6456f1654a 100644
--- a/detections/endpoint/linux_c99_privilege_escalation.yml
+++ b/detections/endpoint/linux_c99_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux c99 Privilege Escalation
id: e1c6dec5-2249-442d-a1f9-99a4bd228183
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_change_file_owner_to_root.yml b/detections/endpoint/linux_change_file_owner_to_root.yml
index 89b8695a26..0135aa468d 100644
--- a/detections/endpoint/linux_change_file_owner_to_root.yml
+++ b/detections/endpoint/linux_change_file_owner_to_root.yml
@@ -1,7 +1,7 @@
name: Linux Change File Owner To Root
id: c1400ea2-6257-11ec-ad49-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -63,7 +63,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1222.002
- - T1222
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_common_process_for_elevation_control.yml b/detections/endpoint/linux_common_process_for_elevation_control.yml
index 9bcb78b36d..221f4c30c6 100644
--- a/detections/endpoint/linux_common_process_for_elevation_control.yml
+++ b/detections/endpoint/linux_common_process_for_elevation_control.yml
@@ -1,7 +1,7 @@
name: Linux Common Process For Elevation Control
id: 66ab15c0-63d0-11ec-9e70-acde48001122
-version: 5
-date: '2025-01-27'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -52,7 +52,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.001
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -61,6 +60,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/chmod_uid/sysmon_linux.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/chmod_uid/sysmon_linux.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon:linux
diff --git a/detections/endpoint/linux_composer_privilege_escalation.yml b/detections/endpoint/linux_composer_privilege_escalation.yml
index 4128c46843..d3303e4046 100644
--- a/detections/endpoint/linux_composer_privilege_escalation.yml
+++ b/detections/endpoint/linux_composer_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux Composer Privilege Escalation
id: a3bddf71-6ba3-42ab-a6b2-396929b16d92
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -68,7 +68,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_cpulimit_privilege_escalation.yml b/detections/endpoint/linux_cpulimit_privilege_escalation.yml
index 2d565e6a8b..42c898b210 100644
--- a/detections/endpoint/linux_cpulimit_privilege_escalation.yml
+++ b/detections/endpoint/linux_cpulimit_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux Cpulimit Privilege Escalation
id: d4e40b7e-aad3-4a7d-aac8-550ea5222be5
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_csvtool_privilege_escalation.yml b/detections/endpoint/linux_csvtool_privilege_escalation.yml
index 0b4a4ed4b6..4c17cce459 100644
--- a/detections/endpoint/linux_csvtool_privilege_escalation.yml
+++ b/detections/endpoint/linux_csvtool_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux Csvtool Privilege Escalation
id: f8384f9e-1a5c-4c3a-96d6-8a7e5a38a8b8
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -66,7 +66,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_data_destruction_command.yml b/detections/endpoint/linux_data_destruction_command.yml
index 0ed0562b5d..d995933ae4 100644
--- a/detections/endpoint/linux_data_destruction_command.yml
+++ b/detections/endpoint/linux_data_destruction_command.yml
@@ -1,6 +1,6 @@
name: Linux Data Destruction Command
id: b11d3979-b2f7-411b-bb1a-bd00e642173b
-version: 4
+version: 5
date: '2024-11-13'
author: Teoderick Contreras, Splunk
status: production
diff --git a/detections/endpoint/linux_decode_base64_to_shell.yml b/detections/endpoint/linux_decode_base64_to_shell.yml
index a60cd9db88..a332d7535a 100644
--- a/detections/endpoint/linux_decode_base64_to_shell.yml
+++ b/detections/endpoint/linux_decode_base64_to_shell.yml
@@ -1,6 +1,6 @@
name: Linux Decode Base64 to Shell
id: 637b603e-1799-40fd-bf87-47ecbd551b66
-version: 6
+version: 7
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/linux_deletion_of_cron_jobs.yml b/detections/endpoint/linux_deletion_of_cron_jobs.yml
index 6c57aa65d9..0e75efa4a7 100644
--- a/detections/endpoint/linux_deletion_of_cron_jobs.yml
+++ b/detections/endpoint/linux_deletion_of_cron_jobs.yml
@@ -1,7 +1,7 @@
name: Linux Deletion Of Cron Jobs
id: 3b132a71-9335-4f33-9932-00bb4f6ac7e8
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -57,9 +57,8 @@ tags:
- AcidPour
asset_type: Endpoint
mitre_attack_id:
- - T1485
- T1070.004
- - T1070
+ - T1485
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_deletion_of_init_daemon_script.yml b/detections/endpoint/linux_deletion_of_init_daemon_script.yml
index 98d166fbbf..339d58c50b 100644
--- a/detections/endpoint/linux_deletion_of_init_daemon_script.yml
+++ b/detections/endpoint/linux_deletion_of_init_daemon_script.yml
@@ -1,7 +1,7 @@
name: Linux Deletion Of Init Daemon Script
id: 729aab57-d26f-4156-b97f-ab8dda8f44b1
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -57,9 +57,8 @@ tags:
- AcidPour
asset_type: Endpoint
mitre_attack_id:
- - T1485
- T1070.004
- - T1070
+ - T1485
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_deletion_of_services.yml b/detections/endpoint/linux_deletion_of_services.yml
index 0105dcf5c9..2d27e43f5b 100644
--- a/detections/endpoint/linux_deletion_of_services.yml
+++ b/detections/endpoint/linux_deletion_of_services.yml
@@ -1,7 +1,7 @@
name: Linux Deletion Of Services
id: b509bbd3-0331-4aaa-8e4a-d2affe100af6
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -62,9 +62,8 @@ tags:
- AcidPour
asset_type: Endpoint
mitre_attack_id:
- - T1485
- T1070.004
- - T1070
+ - T1485
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_deletion_of_ssl_certificate.yml b/detections/endpoint/linux_deletion_of_ssl_certificate.yml
index 3742f9eeed..94765cb179 100644
--- a/detections/endpoint/linux_deletion_of_ssl_certificate.yml
+++ b/detections/endpoint/linux_deletion_of_ssl_certificate.yml
@@ -1,7 +1,7 @@
name: Linux Deletion of SSL Certificate
id: 839ab790-a60a-4f81-bfb3-02567063f615
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -58,9 +58,8 @@ tags:
- AcidPour
asset_type: Endpoint
mitre_attack_id:
- - T1485
- T1070.004
- - T1070
+ - T1485
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_doas_conf_file_creation.yml b/detections/endpoint/linux_doas_conf_file_creation.yml
index 5acb1dff95..8dfac80ecc 100644
--- a/detections/endpoint/linux_doas_conf_file_creation.yml
+++ b/detections/endpoint/linux_doas_conf_file_creation.yml
@@ -1,7 +1,7 @@
name: Linux Doas Conf File Creation
id: f6343e86-6e09-11ec-9376-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -56,7 +56,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_doas_tool_execution.yml b/detections/endpoint/linux_doas_tool_execution.yml
index 3c242194f3..24876440f0 100644
--- a/detections/endpoint/linux_doas_tool_execution.yml
+++ b/detections/endpoint/linux_doas_tool_execution.yml
@@ -1,7 +1,7 @@
name: Linux Doas Tool Execution
id: d5a62490-6e09-11ec-884e-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -62,7 +62,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_docker_privilege_escalation.yml b/detections/endpoint/linux_docker_privilege_escalation.yml
index a6c8d07606..6a3293283f 100644
--- a/detections/endpoint/linux_docker_privilege_escalation.yml
+++ b/detections/endpoint/linux_docker_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux Docker Privilege Escalation
id: 2e7bfb78-85f6-47b5-bc2f-15813a4ef2b3
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_edit_cron_table_parameter.yml b/detections/endpoint/linux_edit_cron_table_parameter.yml
index 9283c0bbfb..6da604bda5 100644
--- a/detections/endpoint/linux_edit_cron_table_parameter.yml
+++ b/detections/endpoint/linux_edit_cron_table_parameter.yml
@@ -1,7 +1,7 @@
name: Linux Edit Cron Table Parameter
id: 0d370304-5f26-11ec-a4bb-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -42,7 +42,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.003
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_emacs_privilege_escalation.yml b/detections/endpoint/linux_emacs_privilege_escalation.yml
index 2e3b916845..3e44cdc17f 100644
--- a/detections/endpoint/linux_emacs_privilege_escalation.yml
+++ b/detections/endpoint/linux_emacs_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux Emacs Privilege Escalation
id: 92033cab-1871-483d-a03b-a7ce98665cfc
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml b/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml
index 2b4da8e0f3..1335c47856 100644
--- a/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml
+++ b/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml
@@ -1,7 +1,7 @@
name: Linux File Created In Kernel Driver Directory
id: b85bbeec-6326-11ec-9311-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -56,7 +56,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1547.006
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_file_creation_in_init_boot_directory.yml b/detections/endpoint/linux_file_creation_in_init_boot_directory.yml
index 810914e4f3..05900fd9fa 100644
--- a/detections/endpoint/linux_file_creation_in_init_boot_directory.yml
+++ b/detections/endpoint/linux_file_creation_in_init_boot_directory.yml
@@ -1,7 +1,7 @@
name: Linux File Creation In Init Boot Directory
id: 97d9cfb2-61ad-11ec-bb2d-acde48001122
-version: 6
-date: '2025-01-27'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -57,7 +57,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1037.004
- - T1037
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -66,6 +65,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.004/linux_init_profile/sysmon_linux.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.004/linux_init_profile/sysmon_linux.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon:linux
diff --git a/detections/endpoint/linux_file_creation_in_profile_directory.yml b/detections/endpoint/linux_file_creation_in_profile_directory.yml
index c35c743ea6..d42712cf76 100644
--- a/detections/endpoint/linux_file_creation_in_profile_directory.yml
+++ b/detections/endpoint/linux_file_creation_in_profile_directory.yml
@@ -1,7 +1,7 @@
name: Linux File Creation In Profile Directory
id: 46ba0082-61af-11ec-9826-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -56,7 +56,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1546.004
- - T1546
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_find_privilege_escalation.yml b/detections/endpoint/linux_find_privilege_escalation.yml
index faeeb076e0..6f3280fbc7 100644
--- a/detections/endpoint/linux_find_privilege_escalation.yml
+++ b/detections/endpoint/linux_find_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux Find Privilege Escalation
id: 2ff4e0c2-8256-4143-9c07-1e39c7231111
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -68,7 +68,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_gdb_privilege_escalation.yml b/detections/endpoint/linux_gdb_privilege_escalation.yml
index fd91250e3a..ac12b85551 100644
--- a/detections/endpoint/linux_gdb_privilege_escalation.yml
+++ b/detections/endpoint/linux_gdb_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux GDB Privilege Escalation
id: 310b7da2-ab52-437f-b1bf-0bd458674308
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -66,7 +66,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_gem_privilege_escalation.yml b/detections/endpoint/linux_gem_privilege_escalation.yml
index 7976f81781..ad933d3de7 100644
--- a/detections/endpoint/linux_gem_privilege_escalation.yml
+++ b/detections/endpoint/linux_gem_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux Gem Privilege Escalation
id: 0115482a-5dcb-4bb0-bcca-5d095d224236
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_gnu_awk_privilege_escalation.yml b/detections/endpoint/linux_gnu_awk_privilege_escalation.yml
index 818ca801e4..2b34220074 100644
--- a/detections/endpoint/linux_gnu_awk_privilege_escalation.yml
+++ b/detections/endpoint/linux_gnu_awk_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux GNU Awk Privilege Escalation
id: 0dcf43b9-50d8-42a6-acd9-d1c9201fe6ae
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -66,7 +66,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml b/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml
index 49948ef473..cdde6977e4 100644
--- a/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml
+++ b/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml
@@ -1,7 +1,7 @@
name: Linux High Frequency Of File Deletion In Boot Folder
id: e27fbc5d-0445-4c4a-bc39-87f060d5c602
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -58,9 +58,8 @@ tags:
- AcidPour
asset_type: Endpoint
mitre_attack_id:
- - T1485
- T1070.004
- - T1070
+ - T1485
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml b/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml
index c783597e9c..ae5aa85d0d 100644
--- a/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml
+++ b/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml
@@ -1,7 +1,7 @@
name: Linux High Frequency Of File Deletion In Etc Folder
id: 9d867448-2aff-4d07-876c-89409a752ff8
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -56,9 +56,8 @@ tags:
- Data Destruction
asset_type: Endpoint
mitre_attack_id:
- - T1485
- T1070.004
- - T1070
+ - T1485
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_impair_defenses_process_kill.yml b/detections/endpoint/linux_impair_defenses_process_kill.yml
index 095729c786..6662f54760 100644
--- a/detections/endpoint/linux_impair_defenses_process_kill.yml
+++ b/detections/endpoint/linux_impair_defenses_process_kill.yml
@@ -1,7 +1,7 @@
name: Linux Impair Defenses Process Kill
id: 435c6b33-adf9-47fe-be87-8e29fd6654f5
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -42,7 +42,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_indicator_removal_service_file_deletion.yml b/detections/endpoint/linux_indicator_removal_service_file_deletion.yml
index 917a6f8fb6..de2d2e6acb 100644
--- a/detections/endpoint/linux_indicator_removal_service_file_deletion.yml
+++ b/detections/endpoint/linux_indicator_removal_service_file_deletion.yml
@@ -1,7 +1,7 @@
name: Linux Indicator Removal Service File Deletion
id: 6c077f81-2a83-4537-afbc-0e62e3215d55
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1070.004
- - T1070
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml b/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml
index cb4fd7b694..fc543070b2 100644
--- a/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml
+++ b/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml
@@ -1,7 +1,7 @@
name: Linux Insert Kernel Module Using Insmod Utility
id: 18b5a1a0-6326-11ec-943a-acde48001122
-version: 5
-date: '2024-12-17'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -66,7 +66,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1547.006
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml b/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml
index 7668cca286..32b16133a8 100644
--- a/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml
+++ b/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml
@@ -1,7 +1,7 @@
name: Linux Install Kernel Module Using Modprobe Utility
id: 387b278a-6326-11ec-aa2c-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -65,7 +65,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1547.006
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_iptables_firewall_modification.yml b/detections/endpoint/linux_iptables_firewall_modification.yml
index 3107d907e2..395f7c7c45 100644
--- a/detections/endpoint/linux_iptables_firewall_modification.yml
+++ b/detections/endpoint/linux_iptables_firewall_modification.yml
@@ -1,7 +1,7 @@
name: Linux Iptables Firewall Modification
id: 309d59dc-1e1b-49b2-9800-7cf18d12f7b7
-version: 7
-date: '2025-01-27'
+version: 8
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -73,7 +73,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.004
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -82,6 +81,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/cyclopsblink/sysmon_linux.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/cyclopsblink/sysmon_linux.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon:linux
diff --git a/detections/endpoint/linux_java_spawning_shell.yml b/detections/endpoint/linux_java_spawning_shell.yml
index 4625c20fb7..a13f0d306e 100644
--- a/detections/endpoint/linux_java_spawning_shell.yml
+++ b/detections/endpoint/linux_java_spawning_shell.yml
@@ -1,6 +1,6 @@
name: Linux Java Spawning Shell
id: 7b09db8a-5c20-11ec-9945-acde48001122
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/linux_kernel_module_enumeration.yml b/detections/endpoint/linux_kernel_module_enumeration.yml
index 9939c3de7c..157f255449 100644
--- a/detections/endpoint/linux_kernel_module_enumeration.yml
+++ b/detections/endpoint/linux_kernel_module_enumeration.yml
@@ -1,6 +1,6 @@
name: Linux Kernel Module Enumeration
id: 6df99886-0e04-4c11-8b88-325747419278
-version: 6
+version: 7
date: '2024-11-17'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/linux_kworker_process_in_writable_process_path.yml b/detections/endpoint/linux_kworker_process_in_writable_process_path.yml
index 0672ad7b93..6f189c9c75 100644
--- a/detections/endpoint/linux_kworker_process_in_writable_process_path.yml
+++ b/detections/endpoint/linux_kworker_process_in_writable_process_path.yml
@@ -1,7 +1,7 @@
name: Linux Kworker Process In Writable Process Path
id: 1cefb270-74a5-4e27-aa0c-2b6fa7c5b4ed
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -43,7 +43,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1036.004
- - T1036
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_make_privilege_escalation.yml b/detections/endpoint/linux_make_privilege_escalation.yml
index a8e87a9bf6..8167787558 100644
--- a/detections/endpoint/linux_make_privilege_escalation.yml
+++ b/detections/endpoint/linux_make_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux Make Privilege Escalation
id: 80b22836-5091-4944-80ee-f733ac443f4f
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -66,7 +66,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_mysql_privilege_escalation.yml b/detections/endpoint/linux_mysql_privilege_escalation.yml
index 370c6cc5e1..4fc1ec1c2a 100644
--- a/detections/endpoint/linux_mysql_privilege_escalation.yml
+++ b/detections/endpoint/linux_mysql_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux MySQL Privilege Escalation
id: c0d810f4-230c-44ea-b703-989da02ff145
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_ngrok_reverse_proxy_usage.yml b/detections/endpoint/linux_ngrok_reverse_proxy_usage.yml
index eeaf7de9e4..ace58aa7ad 100644
--- a/detections/endpoint/linux_ngrok_reverse_proxy_usage.yml
+++ b/detections/endpoint/linux_ngrok_reverse_proxy_usage.yml
@@ -1,6 +1,6 @@
name: Linux Ngrok Reverse Proxy Usage
id: bc84d574-708c-467d-b78a-4c1e20171f97
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/linux_node_privilege_escalation.yml b/detections/endpoint/linux_node_privilege_escalation.yml
index 5e26a21d55..de6c9fa5c1 100644
--- a/detections/endpoint/linux_node_privilege_escalation.yml
+++ b/detections/endpoint/linux_node_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux Node Privilege Escalation
id: 2e58a4ff-398f-42f4-8fd0-e01ebfe2a8ce
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -69,7 +69,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml b/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml
index 15ca07070f..42d8d99f84 100644
--- a/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml
+++ b/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml
@@ -1,7 +1,7 @@
name: Linux NOPASSWD Entry In Sudoers File
id: ab1e0d52-624a-11ec-8e0b-acde48001122
-version: 5
-date: '2025-01-27'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -65,7 +65,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -74,6 +73,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/nopasswd_sudoers/sysmon_linux.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/nopasswd_sudoers/sysmon_linux.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon:linux
diff --git a/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml b/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml
index 033284562b..eeb2fe21ba 100644
--- a/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml
+++ b/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml
@@ -1,6 +1,6 @@
name: Linux Obfuscated Files or Information Base64 Decode
id: 303b38b2-c03f-44e2-8f41-4594606fcfc7
-version: 6
+version: 7
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/linux_octave_privilege_escalation.yml b/detections/endpoint/linux_octave_privilege_escalation.yml
index 37839dd3cb..ac9ee41409 100644
--- a/detections/endpoint/linux_octave_privilege_escalation.yml
+++ b/detections/endpoint/linux_octave_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux Octave Privilege Escalation
id: 78f7487d-42ce-4f7f-8685-2159b25fb477
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -68,7 +68,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_openvpn_privilege_escalation.yml b/detections/endpoint/linux_openvpn_privilege_escalation.yml
index 452799d717..721061b734 100644
--- a/detections/endpoint/linux_openvpn_privilege_escalation.yml
+++ b/detections/endpoint/linux_openvpn_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux OpenVPN Privilege Escalation
id: d25feebe-fa1c-4754-8a1e-afb03bedc0f2
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -68,7 +68,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_php_privilege_escalation.yml b/detections/endpoint/linux_php_privilege_escalation.yml
index 521ece7f21..d65dc8062b 100644
--- a/detections/endpoint/linux_php_privilege_escalation.yml
+++ b/detections/endpoint/linux_php_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux PHP Privilege Escalation
id: 4fc4c031-e5be-4cc0-8cf9-49f9f507bcb5
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_pkexec_privilege_escalation.yml b/detections/endpoint/linux_pkexec_privilege_escalation.yml
index e4fa7129d7..81844e155e 100644
--- a/detections/endpoint/linux_pkexec_privilege_escalation.yml
+++ b/detections/endpoint/linux_pkexec_privilege_escalation.yml
@@ -1,6 +1,6 @@
name: Linux pkexec Privilege Escalation
id: 03e22c1c-8086-11ec-ac2e-acde48001122
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml b/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml
index a7f1ec3741..99ccd2b813 100644
--- a/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml
+++ b/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml
@@ -1,7 +1,7 @@
name: Linux Possible Access Or Modification Of sshd Config File
id: 7a85eb24-72da-11ec-ac76-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1098.004
- - T1098
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_possible_access_to_credential_files.yml b/detections/endpoint/linux_possible_access_to_credential_files.yml
index e5f2c33dce..9bbbe61f67 100644
--- a/detections/endpoint/linux_possible_access_to_credential_files.yml
+++ b/detections/endpoint/linux_possible_access_to_credential_files.yml
@@ -1,7 +1,7 @@
name: Linux Possible Access To Credential Files
id: 16107e0e-71fc-11ec-b862-acde48001122
-version: 6
-date: '2025-01-27'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -65,7 +65,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.008
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -74,6 +73,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/copy_file_stdoutpipe/sysmon_linux.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/copy_file_stdoutpipe/sysmon_linux.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon:linux
diff --git a/detections/endpoint/linux_possible_access_to_sudoers_file.yml b/detections/endpoint/linux_possible_access_to_sudoers_file.yml
index 2be5685254..92ff1b6f97 100644
--- a/detections/endpoint/linux_possible_access_to_sudoers_file.yml
+++ b/detections/endpoint/linux_possible_access_to_sudoers_file.yml
@@ -1,7 +1,7 @@
name: Linux Possible Access To Sudoers File
id: 4479539c-71fc-11ec-b2e2-acde48001122
-version: 5
-date: '2025-01-27'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -73,6 +72,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/copy_file_stdoutpipe/sysmon_linux.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/copy_file_stdoutpipe/sysmon_linux.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon:linux
diff --git a/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml b/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml
index 928b9536fa..484cd366c6 100644
--- a/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml
+++ b/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml
@@ -1,7 +1,7 @@
name: Linux Possible Append Command To At Allow Config File
id: 7bc20606-5f40-11ec-a586-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.002
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml b/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml
index bf67c01e6a..d003d753b3 100644
--- a/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml
+++ b/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml
@@ -1,7 +1,7 @@
name: Linux Possible Append Command To Profile Config File
id: 9c94732a-61af-11ec-91e3-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1546.004
- - T1546
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file.yml b/detections/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file.yml
index 5dc3a73b3b..419ae58634 100644
--- a/detections/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file.yml
+++ b/detections/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file.yml
@@ -1,7 +1,7 @@
name: Linux Possible Append Cronjob Entry on Existing Cronjob File
id: b5b91200-5f27-11ec-bb4e-acde48001122
-version: 5
-date: '2024-12-19'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -47,7 +47,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.003
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_possible_cronjob_modification_with_editor.yml b/detections/endpoint/linux_possible_cronjob_modification_with_editor.yml
index 859463e22c..2b2ebb78dc 100644
--- a/detections/endpoint/linux_possible_cronjob_modification_with_editor.yml
+++ b/detections/endpoint/linux_possible_cronjob_modification_with_editor.yml
@@ -1,7 +1,7 @@
name: Linux Possible Cronjob Modification With Editor
id: dcc89bde-5f24-11ec-87ca-acde48001122
-version: 5
-date: '2024-12-19'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -44,7 +44,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.003
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_possible_ssh_key_file_creation.yml b/detections/endpoint/linux_possible_ssh_key_file_creation.yml
index a67d49a356..63df17e210 100644
--- a/detections/endpoint/linux_possible_ssh_key_file_creation.yml
+++ b/detections/endpoint/linux_possible_ssh_key_file_creation.yml
@@ -1,7 +1,7 @@
name: Linux Possible Ssh Key File Creation
id: c04ef40c-72da-11ec-8eac-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -56,7 +56,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1098.004
- - T1098
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_preload_hijack_library_calls.yml b/detections/endpoint/linux_preload_hijack_library_calls.yml
index 9ad2401c00..051c3c042d 100644
--- a/detections/endpoint/linux_preload_hijack_library_calls.yml
+++ b/detections/endpoint/linux_preload_hijack_library_calls.yml
@@ -1,7 +1,7 @@
name: Linux Preload Hijack Library Calls
id: cbe2ca30-631e-11ec-8670-acde48001122
-version: 5
-date: '2025-01-27'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1574.006
- - T1574
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -73,6 +72,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/lib_hijack/sysmon_linux.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/lib_hijack/sysmon_linux.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon:linux
diff --git a/detections/endpoint/linux_proxy_socks_curl.yml b/detections/endpoint/linux_proxy_socks_curl.yml
index 1093bc6413..2501295d79 100644
--- a/detections/endpoint/linux_proxy_socks_curl.yml
+++ b/detections/endpoint/linux_proxy_socks_curl.yml
@@ -1,6 +1,6 @@
name: Linux Proxy Socks Curl
id: bd596c22-ad1e-44fc-b242-817253ce8b08
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/linux_puppet_privilege_escalation.yml b/detections/endpoint/linux_puppet_privilege_escalation.yml
index 05c7c3d735..b6a4422129 100644
--- a/detections/endpoint/linux_puppet_privilege_escalation.yml
+++ b/detections/endpoint/linux_puppet_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux Puppet Privilege Escalation
id: 1d19037f-466e-4d56-8d87-36fafd9aa3ce
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -68,7 +68,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_rpm_privilege_escalation.yml b/detections/endpoint/linux_rpm_privilege_escalation.yml
index 612f08ab5f..8f3021760f 100644
--- a/detections/endpoint/linux_rpm_privilege_escalation.yml
+++ b/detections/endpoint/linux_rpm_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux RPM Privilege Escalation
id: f8e58a23-cecd-495f-9c65-6c76b4cb9774
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -68,7 +68,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_ruby_privilege_escalation.yml b/detections/endpoint/linux_ruby_privilege_escalation.yml
index b004b42783..42301ecd19 100644
--- a/detections/endpoint/linux_ruby_privilege_escalation.yml
+++ b/detections/endpoint/linux_ruby_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux Ruby Privilege Escalation
id: 097b28b5-7004-4d40-a715-7e390501788b
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -66,7 +66,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_service_file_created_in_systemd_directory.yml b/detections/endpoint/linux_service_file_created_in_systemd_directory.yml
index 5d09d54a8e..84f9f74176 100644
--- a/detections/endpoint/linux_service_file_created_in_systemd_directory.yml
+++ b/detections/endpoint/linux_service_file_created_in_systemd_directory.yml
@@ -1,7 +1,7 @@
name: Linux Service File Created In Systemd Directory
id: c7495048-61b6-11ec-9a37-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -66,7 +66,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.006
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_service_restarted.yml b/detections/endpoint/linux_service_restarted.yml
index b51395a490..e38b12f9c0 100644
--- a/detections/endpoint/linux_service_restarted.yml
+++ b/detections/endpoint/linux_service_restarted.yml
@@ -1,7 +1,7 @@
name: Linux Service Restarted
id: 084275ba-61b8-11ec-8d64-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -68,7 +68,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.006
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_service_started_or_enabled.yml b/detections/endpoint/linux_service_started_or_enabled.yml
index ca91f33339..c5ee30eed0 100644
--- a/detections/endpoint/linux_service_started_or_enabled.yml
+++ b/detections/endpoint/linux_service_started_or_enabled.yml
@@ -1,7 +1,7 @@
name: Linux Service Started Or Enabled
id: e0428212-61b7-11ec-88a3-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.006
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_setuid_using_chmod_utility.yml b/detections/endpoint/linux_setuid_using_chmod_utility.yml
index 4355cf7209..91fc08356f 100644
--- a/detections/endpoint/linux_setuid_using_chmod_utility.yml
+++ b/detections/endpoint/linux_setuid_using_chmod_utility.yml
@@ -1,7 +1,7 @@
name: Linux Setuid Using Chmod Utility
id: bf0304b6-6250-11ec-9d7c-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.001
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_setuid_using_setcap_utility.yml b/detections/endpoint/linux_setuid_using_setcap_utility.yml
index 7092cc2521..55265c8fdf 100644
--- a/detections/endpoint/linux_setuid_using_setcap_utility.yml
+++ b/detections/endpoint/linux_setuid_using_setcap_utility.yml
@@ -1,7 +1,7 @@
name: Linux Setuid Using Setcap Utility
id: 9d96022e-6250-11ec-9a19-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.001
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_sqlite3_privilege_escalation.yml b/detections/endpoint/linux_sqlite3_privilege_escalation.yml
index 60c9288b4e..276443066d 100644
--- a/detections/endpoint/linux_sqlite3_privilege_escalation.yml
+++ b/detections/endpoint/linux_sqlite3_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Linux Sqlite3 Privilege Escalation
id: ab75dbb7-c3ba-4689-9c1b-8d2717bdcba1
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_ssh_authorized_keys_modification.yml b/detections/endpoint/linux_ssh_authorized_keys_modification.yml
index a2a4c09110..d513ccb7c5 100644
--- a/detections/endpoint/linux_ssh_authorized_keys_modification.yml
+++ b/detections/endpoint/linux_ssh_authorized_keys_modification.yml
@@ -1,6 +1,6 @@
name: Linux SSH Authorized Keys Modification
id: f5ab595e-28e5-4327-8077-5008ba97c850
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/linux_ssh_remote_services_script_execute.yml b/detections/endpoint/linux_ssh_remote_services_script_execute.yml
index 6fcbed4dcd..cddd81fa59 100644
--- a/detections/endpoint/linux_ssh_remote_services_script_execute.yml
+++ b/detections/endpoint/linux_ssh_remote_services_script_execute.yml
@@ -1,6 +1,6 @@
name: Linux SSH Remote Services Script Execute
id: aa1748dd-4a5c-457a-9cf6-ca7b4eb711b3
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml b/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml
index ce2ed01432..07665db54f 100644
--- a/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml
+++ b/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml
@@ -1,7 +1,7 @@
name: Linux Stdout Redirection To Dev Null File
id: de62b809-a04d-46b5-9a15-8298d330f0c8
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: experimental
type: Anomaly
@@ -49,7 +49,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.004
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_sudo_or_su_execution.yml b/detections/endpoint/linux_sudo_or_su_execution.yml
index 4d09a93bfb..da149584d5 100644
--- a/detections/endpoint/linux_sudo_or_su_execution.yml
+++ b/detections/endpoint/linux_sudo_or_su_execution.yml
@@ -1,7 +1,7 @@
name: Linux Sudo OR Su Execution
id: 4b00f134-6d6a-11ec-a90c-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -41,7 +41,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_sudoers_tmp_file_creation.yml b/detections/endpoint/linux_sudoers_tmp_file_creation.yml
index 838f432cab..cd67ed8058 100644
--- a/detections/endpoint/linux_sudoers_tmp_file_creation.yml
+++ b/detections/endpoint/linux_sudoers_tmp_file_creation.yml
@@ -1,7 +1,7 @@
name: Linux Sudoers Tmp File Creation
id: be254a5c-63e7-11ec-89da-acde48001122
-version: 5
-date: '2025-01-27'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -58,7 +58,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -67,6 +66,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/sudoers_temp/sysmon_linux.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/sudoers_temp/sysmon_linux.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon:linux
diff --git a/detections/endpoint/linux_unix_shell_enable_all_sysrq_functions.yml b/detections/endpoint/linux_unix_shell_enable_all_sysrq_functions.yml
index e6fab0a962..d183c538ae 100644
--- a/detections/endpoint/linux_unix_shell_enable_all_sysrq_functions.yml
+++ b/detections/endpoint/linux_unix_shell_enable_all_sysrq_functions.yml
@@ -1,7 +1,7 @@
name: Linux Unix Shell Enable All SysRq Functions
id: e7a96937-3b58-4962-8dce-538e4763cf15
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1059.004
- - T1059
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/linux_visudo_utility_execution.yml b/detections/endpoint/linux_visudo_utility_execution.yml
index 93adeaf905..596d9a84c3 100644
--- a/detections/endpoint/linux_visudo_utility_execution.yml
+++ b/detections/endpoint/linux_visudo_utility_execution.yml
@@ -1,7 +1,7 @@
name: Linux Visudo Utility Execution
id: 08c41040-624c-11ec-a71f-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -62,7 +62,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.003
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/loading_of_dynwrapx_module.yml b/detections/endpoint/loading_of_dynwrapx_module.yml
index 4b57f8a939..b84f0b040e 100644
--- a/detections/endpoint/loading_of_dynwrapx_module.yml
+++ b/detections/endpoint/loading_of_dynwrapx_module.yml
@@ -1,7 +1,7 @@
name: Loading Of Dynwrapx Module
id: eac5e8ba-4857-11ec-9371-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
- AsyncRAT
asset_type: Endpoint
mitre_attack_id:
- - T1055
- T1055.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/local_account_discovery_with_wmic.yml b/detections/endpoint/local_account_discovery_with_wmic.yml
index 7a5da713bb..85b07244d2 100644
--- a/detections/endpoint/local_account_discovery_with_wmic.yml
+++ b/detections/endpoint/local_account_discovery_with_wmic.yml
@@ -1,7 +1,7 @@
name: Local Account Discovery With Wmic
id: 4902d7aa-0134-11ec-9d65-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -39,7 +39,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1087
- T1087.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/logon_script_event_trigger_execution.yml b/detections/endpoint/logon_script_event_trigger_execution.yml
index 78ab8e9852..b27836b375 100644
--- a/detections/endpoint/logon_script_event_trigger_execution.yml
+++ b/detections/endpoint/logon_script_event_trigger_execution.yml
@@ -1,7 +1,7 @@
name: Logon Script Event Trigger Execution
id: 4c38c264-1f74-11ec-b5fa-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
- Windows Persistence Techniques
asset_type: Endpoint
mitre_attack_id:
- - T1037
- T1037.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/macos_lolbin.yml b/detections/endpoint/macos_lolbin.yml
index 57a2ca77ce..364826a00d 100644
--- a/detections/endpoint/macos_lolbin.yml
+++ b/detections/endpoint/macos_lolbin.yml
@@ -1,7 +1,7 @@
name: MacOS LOLbin
id: 58d270fb-5b39-418e-a855-4b8ac046805e
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1059.004
- - T1059
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/mailsniper_invoke_functions.yml b/detections/endpoint/mailsniper_invoke_functions.yml
index c61b356b5d..63412c881e 100644
--- a/detections/endpoint/mailsniper_invoke_functions.yml
+++ b/detections/endpoint/mailsniper_invoke_functions.yml
@@ -1,7 +1,7 @@
name: Mailsniper Invoke functions
id: a36972c8-b894-11eb-9f78-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -56,7 +56,6 @@ tags:
- Data Exfiltration
asset_type: Endpoint
mitre_attack_id:
- - T1114
- T1114.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/malicious_powershell_executed_as_a_service.yml b/detections/endpoint/malicious_powershell_executed_as_a_service.yml
index a846b2b6d5..9ce1a87d91 100644
--- a/detections/endpoint/malicious_powershell_executed_as_a_service.yml
+++ b/detections/endpoint/malicious_powershell_executed_as_a_service.yml
@@ -1,7 +1,7 @@
name: Malicious Powershell Executed As A Service
id: 8e204dfd-cae0-4ea8-a61d-e972a1ff2ff8
-version: 7
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Ryan Becwar
status: production
type: TTP
@@ -62,7 +62,6 @@ tags:
- Malicious PowerShell
asset_type: Endpoint
mitre_attack_id:
- - T1569
- T1569.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml
index 228765bed3..ecc670ddcd 100644
--- a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml
+++ b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml
@@ -1,7 +1,7 @@
name: Malicious PowerShell Process - Execution Policy Bypass
id: 9be56c82-b1cc-4318-87eb-d138afaaca39
-version: 9
-date: '2025-01-27'
+version: 10
+date: '2025-02-10'
author: Rico Valdez, Mauricio Velazco, Splunk
status: production
type: Anomaly
@@ -69,7 +69,6 @@ tags:
- Volt Typhoon
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.001
product:
- Splunk Enterprise
@@ -79,6 +78,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/encoded_powershell/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/encoded_powershell/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml b/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml
index 4e23a604b3..eb1e0f4e3a 100644
--- a/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml
+++ b/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml
@@ -1,7 +1,7 @@
name: Malicious PowerShell Process With Obfuscation Techniques
id: cde75cf6-3c7a-4dd6-af01-27cdb4511fd4
-version: 9
-date: '2024-11-13'
+version: 10
+date: '2025-02-10'
author: David Dorsey, Splunk
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
- Data Destruction
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/microsoft_defender_atp_alerts.yml b/detections/endpoint/microsoft_defender_atp_alerts.yml
index e18398545b..eba3aaecd3 100644
--- a/detections/endpoint/microsoft_defender_atp_alerts.yml
+++ b/detections/endpoint/microsoft_defender_atp_alerts.yml
@@ -1,6 +1,6 @@
name: Microsoft Defender ATP Alerts
id: 38f034ed-1598-46c8-95e8-14edf05fdf5d
-version: 2
+version: 3
date: '2025-01-20'
author: Bryan Pluta, Bhavin Patel, Splunk
status: production
diff --git a/detections/endpoint/microsoft_defender_incident_alerts.yml b/detections/endpoint/microsoft_defender_incident_alerts.yml
index 2133ecae98..4cae1ede0f 100644
--- a/detections/endpoint/microsoft_defender_incident_alerts.yml
+++ b/detections/endpoint/microsoft_defender_incident_alerts.yml
@@ -1,6 +1,6 @@
name: Microsoft Defender Incident Alerts
id: 13435b55-afd8-46d4-9045-7d5457f430a5
-version: 2
+version: 3
date: '2025-01-20'
author: Bryan Pluta, Bhavin Patel, Splunk
status: production
diff --git a/detections/endpoint/mimikatz_passtheticket_commandline_parameters.yml b/detections/endpoint/mimikatz_passtheticket_commandline_parameters.yml
index 5a6def368f..5757d7a98d 100644
--- a/detections/endpoint/mimikatz_passtheticket_commandline_parameters.yml
+++ b/detections/endpoint/mimikatz_passtheticket_commandline_parameters.yml
@@ -1,7 +1,7 @@
name: Mimikatz PassTheTicket CommandLine Parameters
id: 13bbd574-83ac-11ec-99d4-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -72,7 +72,6 @@ tags:
- Active Directory Kerberos Attacks
asset_type: Endpoint
mitre_attack_id:
- - T1550
- T1550.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/mmc_lolbas_execution_process_spawn.yml b/detections/endpoint/mmc_lolbas_execution_process_spawn.yml
index a3e11e7507..a2db5e0210 100644
--- a/detections/endpoint/mmc_lolbas_execution_process_spawn.yml
+++ b/detections/endpoint/mmc_lolbas_execution_process_spawn.yml
@@ -1,7 +1,7 @@
name: Mmc LOLBAS Execution Process Spawn
id: f6601940-4c74-11ec-b9b7-3e22fbd008af
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -75,7 +75,6 @@ tags:
- Living Off The Land
asset_type: Endpoint
mitre_attack_id:
- - T1021
- T1021.003
- T1218.014
product:
diff --git a/detections/endpoint/monitor_registry_keys_for_print_monitors.yml b/detections/endpoint/monitor_registry_keys_for_print_monitors.yml
index d40890a563..51119f9f76 100644
--- a/detections/endpoint/monitor_registry_keys_for_print_monitors.yml
+++ b/detections/endpoint/monitor_registry_keys_for_print_monitors.yml
@@ -1,7 +1,7 @@
name: Monitor Registry Keys for Print Monitors
id: f5f6af30-7ba7-4295-bfe9-07de87c01bbc
-version: 9
-date: '2024-12-08'
+version: 10
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick, Bhavin Patel
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1547.010
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml b/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml
index df154acdcd..dff28e7dd0 100644
--- a/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml
+++ b/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml
@@ -1,7 +1,7 @@
name: MS Exchange Mailbox Replication service writing Active Server Pages
id: 985f322c-57a5-11ec-b9ac-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: experimental
type: TTP
@@ -56,10 +56,9 @@ tags:
- BlackByte Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1505
- - T1505.003
- - T1190
- T1133
+ - T1190
+ - T1505.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/ms_scripting_process_loading_ldap_module.yml b/detections/endpoint/ms_scripting_process_loading_ldap_module.yml
index f6c51367ef..eb406c8ba5 100644
--- a/detections/endpoint/ms_scripting_process_loading_ldap_module.yml
+++ b/detections/endpoint/ms_scripting_process_loading_ldap_module.yml
@@ -1,7 +1,7 @@
name: MS Scripting Process Loading Ldap Module
id: 0b0c40dc-14a6-11ec-b267-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -54,7 +54,6 @@ tags:
- FIN7
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.007
product:
- Splunk Enterprise
diff --git a/detections/endpoint/ms_scripting_process_loading_wmi_module.yml b/detections/endpoint/ms_scripting_process_loading_wmi_module.yml
index 58ecca447c..bfe6fe971f 100644
--- a/detections/endpoint/ms_scripting_process_loading_wmi_module.yml
+++ b/detections/endpoint/ms_scripting_process_loading_wmi_module.yml
@@ -1,7 +1,7 @@
name: MS Scripting Process Loading WMI Module
id: 2eba3d36-14a6-11ec-a682-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -56,7 +56,6 @@ tags:
- FIN7
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.007
product:
- Splunk Enterprise
diff --git a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml b/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml
index 05fa46f331..2163163ec3 100644
--- a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml
+++ b/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml
@@ -1,7 +1,7 @@
name: MSBuild Suspicious Spawned By Script Process
id: 213b3148-24ea-11ec-93a2-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -69,7 +69,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1127.001
- - T1127
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml b/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml
index 904d7c0ff7..15849b0340 100644
--- a/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml
+++ b/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml
@@ -1,7 +1,7 @@
name: Mshta spawning Rundll32 OR Regsvr32 Process
id: 4aa5d062-e893-11eb-9eb2-acde48001122
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -67,7 +67,6 @@ tags:
- Living Off The Land
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.005
product:
- Splunk Enterprise
diff --git a/detections/endpoint/msi_module_loaded_by_non_system_binary.yml b/detections/endpoint/msi_module_loaded_by_non_system_binary.yml
index 22fa5c3e01..2c944989d3 100644
--- a/detections/endpoint/msi_module_loaded_by_non_system_binary.yml
+++ b/detections/endpoint/msi_module_loaded_by_non_system_binary.yml
@@ -1,7 +1,7 @@
name: MSI Module Loaded by Non-System Binary
id: ccb98a66-5851-11ec-b91c-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -37,7 +37,6 @@ tags:
- CVE-2021-41379
mitre_attack_id:
- T1574.002
- - T1574
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/msmpeng_application_dll_side_loading.yml b/detections/endpoint/msmpeng_application_dll_side_loading.yml
index c6a910d2c8..70f151f1ee 100644
--- a/detections/endpoint/msmpeng_application_dll_side_loading.yml
+++ b/detections/endpoint/msmpeng_application_dll_side_loading.yml
@@ -1,7 +1,7 @@
name: Msmpeng Application DLL Side Loading
id: 8bb3f280-dd9b-11eb-84d5-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Sanjay Govind
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1574.002
- - T1574
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/net_profiler_uac_bypass.yml b/detections/endpoint/net_profiler_uac_bypass.yml
index 4a11fbd77f..66a59db29f 100644
--- a/detections/endpoint/net_profiler_uac_bypass.yml
+++ b/detections/endpoint/net_profiler_uac_bypass.yml
@@ -1,7 +1,7 @@
name: NET Profiler UAC bypass
id: 0252ca80-e30d-11eb-8aa3-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.002
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/network_discovery_using_route_windows_app.yml b/detections/endpoint/network_discovery_using_route_windows_app.yml
index cf9e62d47b..acea9bdc52 100644
--- a/detections/endpoint/network_discovery_using_route_windows_app.yml
+++ b/detections/endpoint/network_discovery_using_route_windows_app.yml
@@ -1,7 +1,7 @@
name: Network Discovery Using Route Windows App
id: dd83407e-439f-11ec-ab8e-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -45,7 +45,6 @@ tags:
- Prestige Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1016
- T1016.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/network_traffic_to_active_directory_web_services_protocol.yml b/detections/endpoint/network_traffic_to_active_directory_web_services_protocol.yml
index 5a05f52cd4..96fc75806e 100644
--- a/detections/endpoint/network_traffic_to_active_directory_web_services_protocol.yml
+++ b/detections/endpoint/network_traffic_to_active_directory_web_services_protocol.yml
@@ -1,7 +1,7 @@
name: Network Traffic to Active Directory Web Services Protocol
id: 68a0056c-34cb-455f-b03d-df935ea62c4f
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -37,13 +37,11 @@ tags:
asset_type: Network
atomic_guid: []
mitre_attack_id:
- - T1087.002
- T1069.001
- - T1482
- - T1087.001
- - T1087
- T1069.002
- - T1069
+ - T1087.001
+ - T1087.002
+ - T1482
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/nishang_powershelltcponeline.yml b/detections/endpoint/nishang_powershelltcponeline.yml
index 3bca3b340a..676364635a 100644
--- a/detections/endpoint/nishang_powershelltcponeline.yml
+++ b/detections/endpoint/nishang_powershelltcponeline.yml
@@ -1,7 +1,7 @@
name: Nishang PowershellTCPOneLine
id: 1a382c6c-7c2e-11eb-ac69-acde48001122
-version: 6
-date: '2024-12-16'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -65,7 +65,6 @@ tags:
- Cleo File Transfer Software
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml b/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml
index fa4c8d036a..3a3b1fe2b8 100644
--- a/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml
+++ b/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml
@@ -1,7 +1,7 @@
name: Non Chrome Process Accessing Chrome Default Dir
id: 81263de4-160a-11ec-944f-acde48001122
-version: 6
-date: '2025-01-27'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -64,7 +64,6 @@ tags:
- RedLine Stealer
asset_type: Endpoint
mitre_attack_id:
- - T1555
- T1555.003
product:
- Splunk Enterprise
@@ -74,6 +73,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/non_chrome_process_accessing_chrome_default_dir/windows-xml.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/non_chrome_process_accessing_chrome_default_dir/windows-xml.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml b/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml
index abc2b0fc09..8ba8350c73 100644
--- a/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml
+++ b/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml
@@ -1,7 +1,7 @@
name: Non Firefox Process Access Firefox Profile Dir
id: e6fc13b0-1609-11ec-b533-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -62,7 +62,6 @@ tags:
- Snake Keylogger
asset_type: Endpoint
mitre_attack_id:
- - T1555
- T1555.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/notepad_with_no_command_line_arguments.yml b/detections/endpoint/notepad_with_no_command_line_arguments.yml
index 1b8e50b748..9598488359 100644
--- a/detections/endpoint/notepad_with_no_command_line_arguments.yml
+++ b/detections/endpoint/notepad_with_no_command_line_arguments.yml
@@ -1,6 +1,6 @@
name: Notepad with no Command Line Arguments
id: 5adbc5f1-9a2f-41c1-a810-f37e015f8179
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
type: TTP
diff --git a/detections/endpoint/ntdsutil_export_ntds.yml b/detections/endpoint/ntdsutil_export_ntds.yml
index fee86a72ef..6272375790 100644
--- a/detections/endpoint/ntdsutil_export_ntds.yml
+++ b/detections/endpoint/ntdsutil_export_ntds.yml
@@ -1,7 +1,7 @@
name: Ntdsutil Export NTDS
id: da63bc76-61ae-11eb-ae93-0242ac130002
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Patrick Bareiss, Splunk
status: production
type: TTP
@@ -71,7 +71,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.003
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/overwriting_accessibility_binaries.yml b/detections/endpoint/overwriting_accessibility_binaries.yml
index cf10053592..a81a27d1ef 100644
--- a/detections/endpoint/overwriting_accessibility_binaries.yml
+++ b/detections/endpoint/overwriting_accessibility_binaries.yml
@@ -1,7 +1,7 @@
name: Overwriting Accessibility Binaries
id: 13c2f6c3-10c5-4deb-9ba1-7c4460ebe4ae
-version: 7
-date: '2024-11-13'
+version: 8
+date: '2025-02-10'
author: David Dorsey, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
- Flax Typhoon
asset_type: Endpoint
mitre_attack_id:
- - T1546
- T1546.008
product:
- Splunk Enterprise
diff --git a/detections/endpoint/permission_modification_using_takeown_app.yml b/detections/endpoint/permission_modification_using_takeown_app.yml
index 8beee2753c..cb60ecf027 100644
--- a/detections/endpoint/permission_modification_using_takeown_app.yml
+++ b/detections/endpoint/permission_modification_using_takeown_app.yml
@@ -1,10 +1,10 @@
name: Permission Modification using Takeown App
id: fa7ca5c6-c9d8-11eb-bce9-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-01-27'
author: Teoderick Contreras, Splunk
status: production
-type: TTP
+type: Anomaly
description: The following analytic detects the modification of file or directory
permissions using the takeown.exe Windows application. It leverages data from Endpoint
Detection and Response (EDR) agents, focusing on process execution logs that include
@@ -56,7 +56,7 @@ rba:
risk_objects:
- field: dest
type: system
- score: 56
+ score: 30
threat_objects:
- field: process_name
type: process_name
diff --git a/detections/endpoint/ping_sleep_batch_command.yml b/detections/endpoint/ping_sleep_batch_command.yml
index 0b164dcc22..3123e4654a 100644
--- a/detections/endpoint/ping_sleep_batch_command.yml
+++ b/detections/endpoint/ping_sleep_batch_command.yml
@@ -1,7 +1,7 @@
name: Ping Sleep Batch Command
id: ce058d6c-79f2-11ec-b476-acde48001122
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -71,7 +71,6 @@ tags:
- Meduza Stealer
asset_type: Endpoint
mitre_attack_id:
- - T1497
- T1497.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/possible_browser_pass_view_parameter.yml b/detections/endpoint/possible_browser_pass_view_parameter.yml
index 5a2fdbcd71..65339f563a 100644
--- a/detections/endpoint/possible_browser_pass_view_parameter.yml
+++ b/detections/endpoint/possible_browser_pass_view_parameter.yml
@@ -1,7 +1,7 @@
name: Possible Browser Pass View Parameter
id: 8ba484e8-4b97-11ec-b19a-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -46,7 +46,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1555.003
- - T1555
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/possible_lateral_movement_powershell_spawn.yml b/detections/endpoint/possible_lateral_movement_powershell_spawn.yml
index a5e4e662a0..0829ca7479 100644
--- a/detections/endpoint/possible_lateral_movement_powershell_spawn.yml
+++ b/detections/endpoint/possible_lateral_movement_powershell_spawn.yml
@@ -1,7 +1,7 @@
name: Possible Lateral Movement PowerShell Spawn
id: cb909b3e-512b-11ec-aa31-3e22fbd008af
-version: 8
-date: '2024-11-13'
+version: 9
+date: '2025-02-10'
author: Mauricio Velazco, Michael Haag, Splunk
status: production
type: TTP
@@ -76,14 +76,13 @@ tags:
- CISA AA24-241A
asset_type: Endpoint
mitre_attack_id:
- - T1021
- T1021.003
- T1021.006
- T1047
- T1053.005
- - T1543.003
- T1059.001
- T1218.014
+ - T1543.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/potential_system_network_configuration_discovery_activity.yml b/detections/endpoint/potential_system_network_configuration_discovery_activity.yml
index 593947e09e..7939bcde78 100644
--- a/detections/endpoint/potential_system_network_configuration_discovery_activity.yml
+++ b/detections/endpoint/potential_system_network_configuration_discovery_activity.yml
@@ -1,6 +1,6 @@
name: Potential System Network Configuration Discovery Activity
id: 3f0b95e3-3195-46ac-bea3-84fb59e7fac5
-version: 1
+version: 2
date: '2025-01-20'
author: Bhavin Patel, Splunk
status: production
diff --git a/detections/endpoint/powershell_4104_hunting.yml b/detections/endpoint/powershell_4104_hunting.yml
index bdf4328edc..e4c1ddafe7 100644
--- a/detections/endpoint/powershell_4104_hunting.yml
+++ b/detections/endpoint/powershell_4104_hunting.yml
@@ -1,7 +1,7 @@
name: PowerShell 4104 Hunting
id: d6f2b006-0041-11ec-8885-acde48001122
-version: 10
-date: '2025-01-27'
+version: 11
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -74,7 +74,6 @@ tags:
- CISA AA24-241A
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.001
product:
- Splunk Enterprise
@@ -84,6 +83,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log
source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml b/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml
index 4448706801..d69d9be400 100644
--- a/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml
+++ b/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml
@@ -1,7 +1,7 @@
name: PowerShell - Connect To Internet With Hidden Window
id: ee18ed37-0802-4268-9435-b3b91aaa18db
-version: 11
-date: '2024-11-13'
+version: 12
+date: '2025-02-10'
author: David Dorsey, Michael Haag Splunk
status: production
type: Hunting
@@ -55,7 +55,6 @@ tags:
- CVE-2021-44228
mitre_attack_id:
- T1059.001
- - T1059
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/powershell_com_hijacking_inprocserver32_modification.yml b/detections/endpoint/powershell_com_hijacking_inprocserver32_modification.yml
index 568bb5677c..2999af89df 100644
--- a/detections/endpoint/powershell_com_hijacking_inprocserver32_modification.yml
+++ b/detections/endpoint/powershell_com_hijacking_inprocserver32_modification.yml
@@ -1,7 +1,7 @@
name: Powershell COM Hijacking InprocServer32 Modification
id: ea61e291-af05-4716-932a-67faddb6ae6f
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -56,9 +56,8 @@ tags:
- Malicious PowerShell
asset_type: Endpoint
mitre_attack_id:
- - T1546.015
- - T1059
- T1059.001
+ - T1546.015
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/powershell_creating_thread_mutex.yml b/detections/endpoint/powershell_creating_thread_mutex.yml
index 636784f5f6..17dc9e26a6 100644
--- a/detections/endpoint/powershell_creating_thread_mutex.yml
+++ b/detections/endpoint/powershell_creating_thread_mutex.yml
@@ -1,7 +1,7 @@
name: Powershell Creating Thread Mutex
id: 637557ec-ca08-11eb-bd0a-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -59,7 +59,6 @@ tags:
- Malicious PowerShell
asset_type: Endpoint
mitre_attack_id:
- - T1027
- T1027.005
- T1059.001
product:
diff --git a/detections/endpoint/powershell_disable_security_monitoring.yml b/detections/endpoint/powershell_disable_security_monitoring.yml
index acf1715048..1564ed0507 100644
--- a/detections/endpoint/powershell_disable_security_monitoring.yml
+++ b/detections/endpoint/powershell_disable_security_monitoring.yml
@@ -1,7 +1,7 @@
name: Powershell Disable Security Monitoring
id: c148a894-dd93-11eb-bf2a-acde48001122
-version: 7
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/powershell_domain_enumeration.yml b/detections/endpoint/powershell_domain_enumeration.yml
index f0d3a6b92e..b5d57545c4 100644
--- a/detections/endpoint/powershell_domain_enumeration.yml
+++ b/detections/endpoint/powershell_domain_enumeration.yml
@@ -1,7 +1,7 @@
name: PowerShell Domain Enumeration
id: e1866ce2-ca22-11eb-8e44-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
- Data Destruction
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/powershell_enable_powershell_remoting.yml b/detections/endpoint/powershell_enable_powershell_remoting.yml
index 8cfdb6a12c..412a67fcd6 100644
--- a/detections/endpoint/powershell_enable_powershell_remoting.yml
+++ b/detections/endpoint/powershell_enable_powershell_remoting.yml
@@ -1,7 +1,7 @@
name: PowerShell Enable PowerShell Remoting
id: 40e3b299-19a5-4460-96e9-e1467f714f8e
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
type: Anomaly
status: production
@@ -53,7 +53,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1059.001
- - T1059
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/powershell_enable_smb1protocol_feature.yml b/detections/endpoint/powershell_enable_smb1protocol_feature.yml
index 5778e667c4..4027bd9cbf 100644
--- a/detections/endpoint/powershell_enable_smb1protocol_feature.yml
+++ b/detections/endpoint/powershell_enable_smb1protocol_feature.yml
@@ -1,7 +1,7 @@
name: Powershell Enable SMB1Protocol Feature
id: afed80b2-d34b-11eb-a952-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -54,7 +54,6 @@ tags:
- Data Destruction
asset_type: Endpoint
mitre_attack_id:
- - T1027
- T1027.005
product:
- Splunk Enterprise
diff --git a/detections/endpoint/powershell_execute_com_object.yml b/detections/endpoint/powershell_execute_com_object.yml
index afa898ec22..0829d8c7a5 100644
--- a/detections/endpoint/powershell_execute_com_object.yml
+++ b/detections/endpoint/powershell_execute_com_object.yml
@@ -1,7 +1,7 @@
name: Powershell Execute COM Object
id: 65711630-f9bf-11eb-8d72-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -55,9 +55,8 @@ tags:
- Data Destruction
asset_type: Endpoint
mitre_attack_id:
- - T1546.015
- - T1546
- T1059.001
+ - T1546.015
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml b/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml
index d57deb4a84..be8d0a5b04 100644
--- a/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml
+++ b/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml
@@ -1,7 +1,7 @@
name: Powershell Fileless Process Injection via GetProcAddress
id: a26d9db4-c883-11eb-9d75-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
- Data Destruction
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1055
- T1059.001
product:
diff --git a/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml b/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml
index 220cb14ad7..c6cf407c05 100644
--- a/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml
+++ b/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml
@@ -1,7 +1,7 @@
name: Powershell Fileless Script Contains Base64 Encoded Content
id: 8acbc04c-c882-11eb-b060-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
- IcedID
- NjRAT
mitre_attack_id:
- - T1059
- T1027
- T1059.001
product:
diff --git a/detections/endpoint/powershell_get_localgroup_discovery.yml b/detections/endpoint/powershell_get_localgroup_discovery.yml
index cf5e6ada50..95170cb2f8 100644
--- a/detections/endpoint/powershell_get_localgroup_discovery.yml
+++ b/detections/endpoint/powershell_get_localgroup_discovery.yml
@@ -1,7 +1,7 @@
name: PowerShell Get LocalGroup Discovery
id: b71adfcc-155b-11ec-9413-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -41,7 +41,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml b/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml
index 09e77be336..633fbc71a1 100644
--- a/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml
+++ b/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml
@@ -1,7 +1,7 @@
name: Powershell Get LocalGroup Discovery with Script Block Logging
id: d7c6ad22-155c-11ec-bb64-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -35,7 +35,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/powershell_load_module_in_meterpreter.yml b/detections/endpoint/powershell_load_module_in_meterpreter.yml
index de6090bb3f..48f13d3839 100644
--- a/detections/endpoint/powershell_load_module_in_meterpreter.yml
+++ b/detections/endpoint/powershell_load_module_in_meterpreter.yml
@@ -1,7 +1,7 @@
name: Powershell Load Module in Meterpreter
id: d5905da5-d050-48db-9259-018d8f034fcf
-version: 4
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
- MetaSploit
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml b/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml
index d848c784db..d7d526e11e 100644
--- a/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml
+++ b/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml
@@ -1,16 +1,31 @@
name: PowerShell Loading DotNET into Memory via Reflection
id: 85bc3f30-ca28-11eb-bd21-acde48001122
-version: 6
-date: '2025-01-16'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Anomaly
data_source:
- Powershell Script Block Logging 4104
-description: The following analytic detects the use of PowerShell scripts to load .NET assemblies into memory via reflection, a technique often used in malicious activities such as those by Empire and Cobalt Strike. It leverages PowerShell Script Block Logging (EventCode=4104) to capture and analyze the full command executed. This behavior is significant as it can indicate advanced attack techniques aiming to execute code in memory, bypassing traditional defenses. If confirmed malicious, this activity could lead to unauthorized code execution, privilege escalation, and persistent access within the environment.
-search: '`powershell` EventCode=4104 ScriptBlockText IN ("*Reflection.Assembly]::Load*", "*Reflection.Assembly.Load*", "*UnsafeLoadFrom*", "*.LoadFrom(*", "*.LoadModule(*", "*.LoadWithPartialName*", "*ReflectionOnlyLoad*") | stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText | rename Computer as dest, UserID as user| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `powershell_loading_dotnet_into_memory_via_reflection_filter`'
-how_to_implement: To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.
-known_false_positives: False positives should be limited as day to day scripts do not use this method.
+description: The following analytic detects the use of PowerShell scripts to load
+ .NET assemblies into memory via reflection, a technique often used in malicious
+ activities such as those by Empire and Cobalt Strike. It leverages PowerShell Script
+ Block Logging (EventCode=4104) to capture and analyze the full command executed.
+ This behavior is significant as it can indicate advanced attack techniques aiming
+ to execute code in memory, bypassing traditional defenses. If confirmed malicious,
+ this activity could lead to unauthorized code execution, privilege escalation, and
+ persistent access within the environment.
+search: '`powershell` EventCode=4104 ScriptBlockText IN ("*Reflection.Assembly]::Load*",
+ "*Reflection.Assembly.Load*", "*UnsafeLoadFrom*", "*.LoadFrom(*", "*.LoadModule(*",
+ "*.LoadWithPartialName*", "*ReflectionOnlyLoad*") | stats count min(_time) as firstTime
+ max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText | rename
+ Computer as dest, UserID as user| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
+ | `powershell_loading_dotnet_into_memory_via_reflection_filter`'
+how_to_implement: To successfully implement this analytic, you will need to enable
+ PowerShell Script Block Logging on some or all endpoints. Additional setup here
+ https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.
+known_false_positives: False positives should be limited as day to day scripts do
+ not use this method.
references:
- https://docs.microsoft.com/en-us/dotnet/api/system.reflection.assembly?view=net-5.0
- https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.
@@ -23,7 +38,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$" and "$user$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$$", "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$$",
+ "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
+ as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
+ Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
+ as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
+ by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -48,7 +68,6 @@ tags:
- Data Destruction
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.001
product:
- Splunk Enterprise
@@ -58,6 +77,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/reflection.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/reflection.log
source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
- sourcetype: XmlWinEventLog
\ No newline at end of file
+ sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/powershell_processing_stream_of_data.yml b/detections/endpoint/powershell_processing_stream_of_data.yml
index 24967a1f8b..76d78cf424 100644
--- a/detections/endpoint/powershell_processing_stream_of_data.yml
+++ b/detections/endpoint/powershell_processing_stream_of_data.yml
@@ -1,7 +1,7 @@
name: Powershell Processing Stream Of Data
id: 0d718b52-c9f1-11eb-bc61-acde48001122
-version: 6
-date: '2024-11-22'
+version: 8
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -69,7 +69,6 @@ tags:
- PXA Stealer
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/powershell_remote_services_add_trustedhost.yml b/detections/endpoint/powershell_remote_services_add_trustedhost.yml
index f8535f004f..7a96343fb7 100644
--- a/detections/endpoint/powershell_remote_services_add_trustedhost.yml
+++ b/detections/endpoint/powershell_remote_services_add_trustedhost.yml
@@ -1,7 +1,7 @@
name: Powershell Remote Services Add TrustedHost
id: bef21d24-297e-45e3-9b9a-c6ac45450474
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1021.006
- - T1021
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/powershell_remove_windows_defender_directory.yml b/detections/endpoint/powershell_remove_windows_defender_directory.yml
index 6f0ea6b1e1..8b6f9c3a6d 100644
--- a/detections/endpoint/powershell_remove_windows_defender_directory.yml
+++ b/detections/endpoint/powershell_remove_windows_defender_directory.yml
@@ -1,7 +1,7 @@
name: Powershell Remove Windows Defender Directory
id: adf47620-79fa-11ec-b248-acde48001122
-version: 6
-date: '2024-11-13'
+version: 8
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -56,7 +56,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/powershell_start_bitstransfer.yml b/detections/endpoint/powershell_start_bitstransfer.yml
index 104e8afe41..6b50ec5b4f 100644
--- a/detections/endpoint/powershell_start_bitstransfer.yml
+++ b/detections/endpoint/powershell_start_bitstransfer.yml
@@ -1,6 +1,6 @@
name: PowerShell Start-BitsTransfer
id: 39e2605a-90d8-11eb-899e-acde48001122
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/powershell_using_memory_as_backing_store.yml b/detections/endpoint/powershell_using_memory_as_backing_store.yml
index a57cf47628..e33e455cd2 100644
--- a/detections/endpoint/powershell_using_memory_as_backing_store.yml
+++ b/detections/endpoint/powershell_using_memory_as_backing_store.yml
@@ -1,7 +1,7 @@
name: Powershell Using memory As Backing Store
id: c396a0c4-c9f2-11eb-b4f5-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -66,7 +66,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1059.001
- - T1059
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/powershell_windows_defender_exclusion_commands.yml b/detections/endpoint/powershell_windows_defender_exclusion_commands.yml
index 7e80adf439..04e6fb422d 100644
--- a/detections/endpoint/powershell_windows_defender_exclusion_commands.yml
+++ b/detections/endpoint/powershell_windows_defender_exclusion_commands.yml
@@ -1,7 +1,7 @@
name: Powershell Windows Defender Exclusion Commands
id: 907ac95c-4dd9-11ec-ba2c-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml b/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml
index 0bac5ac032..06ea69848f 100644
--- a/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml
+++ b/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml
@@ -1,6 +1,6 @@
name: Prevent Automatic Repair Mode using Bcdedit
id: 7742aa92-c9d9-11eb-bbfc-acde48001122
-version: 4
+version: 5
date: '2024-11-13'
author: Teoderick Contreras, Splunk
status: production
diff --git a/detections/endpoint/print_processor_registry_autostart.yml b/detections/endpoint/print_processor_registry_autostart.yml
index e162953369..04f8f2a5d4 100644
--- a/detections/endpoint/print_processor_registry_autostart.yml
+++ b/detections/endpoint/print_processor_registry_autostart.yml
@@ -1,7 +1,7 @@
name: Print Processor Registry Autostart
id: 1f5b68aa-2037-11ec-898e-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: experimental
type: TTP
@@ -51,7 +51,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1547.012
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/print_spooler_adding_a_printer_driver.yml b/detections/endpoint/print_spooler_adding_a_printer_driver.yml
index 1c47ffd8df..8afd39363a 100644
--- a/detections/endpoint/print_spooler_adding_a_printer_driver.yml
+++ b/detections/endpoint/print_spooler_adding_a_printer_driver.yml
@@ -1,7 +1,7 @@
name: Print Spooler Adding A Printer Driver
id: 313681a2-da8e-11eb-adad-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
- CVE-2021-1675
mitre_attack_id:
- T1547.012
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml b/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml
index 5e37c7894e..7ad22f6b32 100644
--- a/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml
+++ b/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml
@@ -1,7 +1,7 @@
name: Print Spooler Failed to Load a Plug-in
id: 1adc9548-da7c-11eb-8f13-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Michael Haag, Splunk
status: production
type: TTP
@@ -59,7 +59,6 @@ tags:
- CVE-2021-1675
mitre_attack_id:
- T1547.012
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml
index 4cf346c8fa..820170d6e4 100644
--- a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml
+++ b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml
@@ -1,7 +1,7 @@
name: Process Creating LNK file in Suspicious Location
id: 5d814af1-1041-47b5-a9ac-d754e82e9a26
-version: 9
-date: '2024-11-13'
+version: 10
+date: '2025-02-10'
author: Jose Hernandez, Michael Haag, Splunk
status: production
type: TTP
@@ -70,7 +70,6 @@ tags:
- Gozi Malware
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/process_kill_base_on_file_path.yml b/detections/endpoint/process_kill_base_on_file_path.yml
index 22d03dda5e..1ec53796f1 100644
--- a/detections/endpoint/process_kill_base_on_file_path.yml
+++ b/detections/endpoint/process_kill_base_on_file_path.yml
@@ -1,7 +1,7 @@
name: Process Kill Base On File Path
id: 5ffaa42c-acdb-11eb-9ad3-acde48001122
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/processes_launching_netsh.yml b/detections/endpoint/processes_launching_netsh.yml
index e719a57984..212cf0f860 100644
--- a/detections/endpoint/processes_launching_netsh.yml
+++ b/detections/endpoint/processes_launching_netsh.yml
@@ -1,7 +1,7 @@
name: Processes launching netsh
id: b89919ed-fe5f-492c-b139-95dbb162040e
-version: 7
-date: '2024-11-13'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Josef Kuepker, Splunk
status: production
type: Anomaly
@@ -74,7 +74,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.004
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/randomly_generated_scheduled_task_name.yml b/detections/endpoint/randomly_generated_scheduled_task_name.yml
index ddca4c00e3..d54a781091 100644
--- a/detections/endpoint/randomly_generated_scheduled_task_name.yml
+++ b/detections/endpoint/randomly_generated_scheduled_task_name.yml
@@ -1,7 +1,7 @@
name: Randomly Generated Scheduled Task Name
id: 9d22a780-5165-11ec-ad4f-3e22fbd008af
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: experimental
type: Hunting
@@ -33,7 +33,6 @@ tags:
- Scheduled Tasks
asset_type: Endpoint
mitre_attack_id:
- - T1053
- T1053.005
product:
- Splunk Enterprise
diff --git a/detections/endpoint/randomly_generated_windows_service_name.yml b/detections/endpoint/randomly_generated_windows_service_name.yml
index da693af615..eac52741ca 100644
--- a/detections/endpoint/randomly_generated_windows_service_name.yml
+++ b/detections/endpoint/randomly_generated_windows_service_name.yml
@@ -1,7 +1,7 @@
name: Randomly Generated Windows Service Name
id: 2032a95a-5165-11ec-a2c3-3e22fbd008af
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: experimental
type: Hunting
@@ -30,7 +30,6 @@ tags:
- BlackSuit Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1543
- T1543.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml b/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml
index 15539d184d..b217c5d2a0 100644
--- a/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml
+++ b/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml
@@ -1,6 +1,6 @@
name: Recon AVProduct Through Pwh or WMI
id: 28077620-c9f6-11eb-8785-acde48001122
-version: 5
+version: 6
date: '2024-11-13'
author: Teoderick Contreras, Splunk
status: production
diff --git a/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml b/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml
index 3ba5e16d48..89aa7cb4e4 100644
--- a/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml
+++ b/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml
@@ -1,7 +1,7 @@
name: Recursive Delete of Directory In Batch CMD
id: ba570b3a-d356-11eb-8358-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1070.004
- - T1070
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml
index f11cc03166..096acf7bf7 100644
--- a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml
+++ b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml
@@ -1,7 +1,7 @@
name: Reg exe Manipulating Windows Services Registry Keys
id: 8470d755-0c13-45b3-bd63-387a373c10cf
-version: 8
-date: '2024-11-13'
+version: 10
+date: '2025-02-10'
author: Rico Valdez, Splunk
status: production
type: TTP
@@ -69,7 +69,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1574.011
- - T1574
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/registry_keys_for_creating_shim_databases.yml b/detections/endpoint/registry_keys_for_creating_shim_databases.yml
index 7d20f02115..aeec02af3e 100644
--- a/detections/endpoint/registry_keys_for_creating_shim_databases.yml
+++ b/detections/endpoint/registry_keys_for_creating_shim_databases.yml
@@ -1,7 +1,7 @@
name: Registry Keys for Creating SHIM Databases
id: f5f6af30-7aa7-4295-bfe9-07fe87c01bbb
-version: 10
-date: '2024-12-08'
+version: 12
+date: '2025-02-10'
author: Patrick Bareiss, Teoderick Contreras, Splunk, Steven Dick, Bhavin Patel
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1546.011
- - T1546
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml
index 9f542cbcf2..841571bdaf 100644
--- a/detections/endpoint/registry_keys_used_for_persistence.yml
+++ b/detections/endpoint/registry_keys_used_for_persistence.yml
@@ -1,7 +1,7 @@
name: Registry Keys Used For Persistence
id: f5f6af30-7aa7-4295-bfe9-07fe87c01a4b
-version: 15
-date: '2025-01-27'
+version: 16
+date: '2025-02-10'
author: Jose Hernandez, David Dorsey, Teoderick Contreras, Rod Soto, Splunk
status: production
type: TTP
@@ -109,7 +109,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1547.001
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -118,6 +117,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml
index 37f1c77d98..fe8be39dd9 100644
--- a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml
+++ b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml
@@ -1,7 +1,7 @@
name: Registry Keys Used For Privilege Escalation
id: c9f4b923-f8af-4155-b697-1354f5bcbc5e
-version: 11
-date: '2024-12-08'
+version: 12
+date: '2025-02-10'
author: David Dorsey, Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1546.012
- - T1546
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml b/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml
index fa6a03e4f6..89f088a05b 100644
--- a/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml
+++ b/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml
@@ -1,7 +1,7 @@
name: Regsvr32 Silent and Install Param Dll Loading
id: f421c250-24e7-11ec-bc43-acde48001122
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -76,7 +76,6 @@ tags:
- Suspicious Regsvr32 Activity
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.010
product:
- Splunk Enterprise
diff --git a/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml b/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml
index 624108b462..43b74c27f5 100644
--- a/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml
+++ b/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml
@@ -1,7 +1,7 @@
name: Regsvr32 with Known Silent Switch Cmdline
id: c9ef7dc4-eeaf-11eb-b2b6-acde48001122
-version: 6
-date: '2024-11-13'
+version: 8
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -76,7 +76,6 @@ tags:
- AsyncRAT
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.010
product:
- Splunk Enterprise
diff --git a/detections/endpoint/remote_desktop_process_running_on_system.yml b/detections/endpoint/remote_desktop_process_running_on_system.yml
index 98b7d2a398..90532d273c 100644
--- a/detections/endpoint/remote_desktop_process_running_on_system.yml
+++ b/detections/endpoint/remote_desktop_process_running_on_system.yml
@@ -1,7 +1,7 @@
name: Remote Desktop Process Running On System
id: f5939373-8054-40ad-8c64-cec478a22a4a
-version: 8
-date: '2024-11-13'
+version: 9
+date: '2025-02-10'
author: David Dorsey, Splunk
status: experimental
type: Hunting
@@ -40,7 +40,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1021.001
- - T1021
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml
index 538d923090..c9b9804885 100644
--- a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml
+++ b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml
@@ -1,7 +1,7 @@
name: Remote Process Instantiation via DCOM and PowerShell
id: d4f42098-4680-11ec-ad07-3e22fbd008af
-version: 6
-date: '2024-12-10'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -66,7 +66,6 @@ tags:
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- - T1021
- T1021.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml
index 4f4648445b..2b3c8abaab 100644
--- a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml
+++ b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml
@@ -1,7 +1,7 @@
name: Remote Process Instantiation via DCOM and PowerShell Script Block
id: fa1c3040-4680-11ec-a618-3e22fbd008af
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -54,7 +54,6 @@ tags:
- Active Directory Lateral Movement
asset_type: Endpoint
mitre_attack_id:
- - T1021
- T1021.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml
index 8b574d9bb7..fc7a0db67d 100644
--- a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml
+++ b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml
@@ -1,7 +1,7 @@
name: Remote Process Instantiation via WinRM and PowerShell
id: ba24cda8-4716-11ec-8009-3e22fbd008af
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -65,7 +65,6 @@ tags:
- Active Directory Lateral Movement
asset_type: Endpoint
mitre_attack_id:
- - T1021
- T1021.006
product:
- Splunk Enterprise
diff --git a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml
index d2cff18278..63c06643c1 100644
--- a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml
+++ b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml
@@ -1,7 +1,7 @@
name: Remote Process Instantiation via WinRM and PowerShell Script Block
id: 7d4c618e-4716-11ec-951c-3e22fbd008af
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -56,7 +56,6 @@ tags:
- Active Directory Lateral Movement
asset_type: Endpoint
mitre_attack_id:
- - T1021
- T1021.006
product:
- Splunk Enterprise
diff --git a/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml b/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml
index 4d5ae43729..f2d3dcf4d5 100644
--- a/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml
+++ b/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml
@@ -1,7 +1,7 @@
name: Remote Process Instantiation via WinRM and Winrs
id: 0dd296a2-4338-11ec-ba02-3e22fbd008af
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
- Active Directory Lateral Movement
asset_type: Endpoint
mitre_attack_id:
- - T1021
- T1021.006
product:
- Splunk Enterprise
diff --git a/detections/endpoint/rubeus_command_line_parameters.yml b/detections/endpoint/rubeus_command_line_parameters.yml
index 9a0fe4997a..8d0e78f4ef 100644
--- a/detections/endpoint/rubeus_command_line_parameters.yml
+++ b/detections/endpoint/rubeus_command_line_parameters.yml
@@ -1,7 +1,7 @@
name: Rubeus Command Line Parameters
id: cca37478-8377-11ec-b59a-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -78,9 +78,7 @@ tags:
- BlackSuit Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1550
- T1550.003
- - T1558
- T1558.003
- T1558.004
product:
diff --git a/detections/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access.yml b/detections/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access.yml
index e9200fe464..5950c1ca67 100644
--- a/detections/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access.yml
+++ b/detections/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access.yml
@@ -1,7 +1,7 @@
name: Rubeus Kerberos Ticket Exports Through Winlogon Access
id: 5ed8c50a-8869-11ec-876f-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
- BlackSuit Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1550
- T1550.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/runas_execution_in_commandline.yml b/detections/endpoint/runas_execution_in_commandline.yml
index dd66057bfe..0ed47331a5 100644
--- a/detections/endpoint/runas_execution_in_commandline.yml
+++ b/detections/endpoint/runas_execution_in_commandline.yml
@@ -1,7 +1,7 @@
name: Runas Execution in CommandLine
id: 4807e716-43a4-11ec-a0e7-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -44,7 +44,6 @@ tags:
- Windows Privilege Escalation
asset_type: Endpoint
mitre_attack_id:
- - T1134
- T1134.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/rundll32_control_rundll_hunt.yml b/detections/endpoint/rundll32_control_rundll_hunt.yml
index dc0beb376a..b1ad8f7ef5 100644
--- a/detections/endpoint/rundll32_control_rundll_hunt.yml
+++ b/detections/endpoint/rundll32_control_rundll_hunt.yml
@@ -1,7 +1,7 @@
name: Rundll32 Control RunDLL Hunt
id: c8e7ced0-10c5-11ec-8b03-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -50,7 +50,6 @@ tags:
cve:
- CVE-2021-40444
mitre_attack_id:
- - T1218
- T1218.011
product:
- Splunk Enterprise
diff --git a/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml b/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml
index aa845361b4..1d2585be25 100644
--- a/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml
+++ b/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml
@@ -1,7 +1,7 @@
name: Rundll32 Control RunDLL World Writable Directory
id: 1adffe86-10c3-11ec-8ce6-acde48001122
-version: 6
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -81,7 +81,6 @@ tags:
cve:
- CVE-2021-40444
mitre_attack_id:
- - T1218
- T1218.011
product:
- Splunk Enterprise
diff --git a/detections/endpoint/rundll32_dnsquery.yml b/detections/endpoint/rundll32_dnsquery.yml
index f72c6c3ba3..398448fbaf 100644
--- a/detections/endpoint/rundll32_dnsquery.yml
+++ b/detections/endpoint/rundll32_dnsquery.yml
@@ -1,7 +1,7 @@
name: Rundll32 DNSQuery
id: f1483f5e-ee29-11eb-9d23-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
- Living Off The Land
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.011
product:
- Splunk Enterprise
diff --git a/detections/endpoint/rundll32_lockworkstation.yml b/detections/endpoint/rundll32_lockworkstation.yml
index b3a0ca0968..4f3f8a2188 100644
--- a/detections/endpoint/rundll32_lockworkstation.yml
+++ b/detections/endpoint/rundll32_lockworkstation.yml
@@ -1,7 +1,7 @@
name: Rundll32 LockWorkStation
id: fa90f372-f91d-11eb-816c-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -62,7 +62,6 @@ tags:
- Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.011
product:
- Splunk Enterprise
diff --git a/detections/endpoint/rundll32_process_creating_exe_dll_files.yml b/detections/endpoint/rundll32_process_creating_exe_dll_files.yml
index 7381fd77d0..b3203c8ad4 100644
--- a/detections/endpoint/rundll32_process_creating_exe_dll_files.yml
+++ b/detections/endpoint/rundll32_process_creating_exe_dll_files.yml
@@ -1,7 +1,7 @@
name: Rundll32 Process Creating Exe Dll Files
id: 6338266a-ee2a-11eb-bf68-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -54,7 +54,6 @@ tags:
- Living Off The Land
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.011
product:
- Splunk Enterprise
diff --git a/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml b/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml
index b668edd1ef..23f1723414 100644
--- a/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml
+++ b/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml
@@ -1,7 +1,7 @@
name: Rundll32 with no Command Line Arguments with Network
id: 35307032-a12d-11eb-835f-acde48001122
-version: 8
-date: '2024-12-10'
+version: 9
+date: '2025-02-10'
author: Steven Dick, Michael Haag, Splunk
status: production
type: TTP
@@ -78,7 +78,6 @@ tags:
cve:
- CVE-2021-34527
mitre_attack_id:
- - T1218
- T1218.011
product:
- Splunk Enterprise
diff --git a/detections/endpoint/rundll_loading_dll_by_ordinal.yml b/detections/endpoint/rundll_loading_dll_by_ordinal.yml
index b8fccdd6c4..fc41b88df5 100644
--- a/detections/endpoint/rundll_loading_dll_by_ordinal.yml
+++ b/detections/endpoint/rundll_loading_dll_by_ordinal.yml
@@ -1,7 +1,7 @@
name: RunDLL Loading DLL By Ordinal
id: 6c135f8d-5e60-454e-80b7-c56eed739833
-version: 9
-date: '2024-11-13'
+version: 10
+date: '2025-02-10'
author: Michael Haag, David Dorsey, Splunk
status: production
type: TTP
@@ -72,7 +72,6 @@ tags:
- IcedID
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.011
product:
- Splunk Enterprise
diff --git a/detections/endpoint/ryuk_wake_on_lan_command.yml b/detections/endpoint/ryuk_wake_on_lan_command.yml
index e7f88ed5c7..4bfc808d08 100644
--- a/detections/endpoint/ryuk_wake_on_lan_command.yml
+++ b/detections/endpoint/ryuk_wake_on_lan_command.yml
@@ -1,7 +1,7 @@
name: Ryuk Wake on LAN Command
id: 538d0152-7aaa-11eb-beaa-acde48001122
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -68,7 +68,6 @@ tags:
- Ryuk Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/sam_database_file_access_attempt.yml b/detections/endpoint/sam_database_file_access_attempt.yml
index e76cbb1396..2ce1ddaa93 100644
--- a/detections/endpoint/sam_database_file_access_attempt.yml
+++ b/detections/endpoint/sam_database_file_access_attempt.yml
@@ -1,7 +1,7 @@
name: SAM Database File Access Attempt
id: 57551656-ebdb-11eb-afdf-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -42,7 +42,6 @@ tags:
- CVE-2021-36934
mitre_attack_id:
- T1003.002
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/sc_exe_manipulating_windows_services.yml b/detections/endpoint/sc_exe_manipulating_windows_services.yml
index ab462622b5..d08cad9a5b 100644
--- a/detections/endpoint/sc_exe_manipulating_windows_services.yml
+++ b/detections/endpoint/sc_exe_manipulating_windows_services.yml
@@ -1,7 +1,7 @@
name: Sc exe Manipulating Windows Services
id: f0c693d8-2a89-4ce7-80b4-98fea4c3ea6d
-version: 7
-date: '2024-11-13'
+version: 9
+date: '2025-02-10'
author: Rico Valdez, Splunk
status: production
type: TTP
@@ -76,7 +76,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1543.003
- - T1543
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml b/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml
index fff2339458..1d84e7384b 100644
--- a/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml
+++ b/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml
@@ -1,7 +1,7 @@
name: SchCache Change By App Connect And Create ADSI Object
id: 991eb510-0fc6-11ec-82d3-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -56,7 +56,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1087.002
- - T1087
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml b/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml
index 7732be5bf9..f23eb706b0 100644
--- a/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml
+++ b/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml
@@ -1,7 +1,7 @@
name: Scheduled Task Creation on Remote Endpoint using At
id: 4be54858-432f-11ec-8209-3e22fbd008af
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -65,7 +65,6 @@ tags:
- Scheduled Tasks
asset_type: Endpoint
mitre_attack_id:
- - T1053
- T1053.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml
index 3b47886f19..5090e71991 100644
--- a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml
+++ b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml
@@ -1,7 +1,7 @@
name: Scheduled Task Deleted Or Created via CMD
id: d5af132c-7c17-439c-9d31-13d55340f36c
-version: 10
-date: '2025-01-27'
+version: 12
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -95,7 +95,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.005
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -104,6 +103,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml b/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml
index 80d3a28e57..d44dbd1f24 100644
--- a/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml
+++ b/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml
@@ -1,7 +1,7 @@
name: Scheduled Task Initiation on Remote Endpoint
id: 95cf4608-4302-11ec-8194-3e22fbd008af
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk, Badoodish, Github Community
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
- Scheduled Tasks
asset_type: Endpoint
mitre_attack_id:
- - T1053
- T1053.005
product:
- Splunk Enterprise
diff --git a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml
index a32d7dca97..48b5d1fa98 100644
--- a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml
+++ b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml
@@ -1,7 +1,7 @@
name: Schtasks scheduling job on remote system
id: 1297fb80-f42a-4b4a-9c8a-88c066237cf6
-version: 11
-date: '2024-12-10'
+version: 12
+date: '2025-02-10'
author: David Dorsey, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -76,7 +76,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.005
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml
index 72e8073ffc..ff5ff09caa 100644
--- a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml
+++ b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml
@@ -1,7 +1,7 @@
name: Schtasks used for forcing a reboot
id: 1297fb80-f42a-4b4a-9c8a-88c066437cf6
-version: 7
-date: '2024-11-13'
+version: 9
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -69,7 +69,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.005
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/screensaver_event_trigger_execution.yml b/detections/endpoint/screensaver_event_trigger_execution.yml
index 1b68e6996f..b7668b1a51 100644
--- a/detections/endpoint/screensaver_event_trigger_execution.yml
+++ b/detections/endpoint/screensaver_event_trigger_execution.yml
@@ -1,7 +1,7 @@
name: Screensaver Event Trigger Execution
id: 58cea3ec-1f6d-11ec-8560-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
- Data Destruction
asset_type: Endpoint
mitre_attack_id:
- - T1546
- T1546.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/sdclt_uac_bypass.yml b/detections/endpoint/sdclt_uac_bypass.yml
index 4efac5ec1b..c6c89c02b0 100644
--- a/detections/endpoint/sdclt_uac_bypass.yml
+++ b/detections/endpoint/sdclt_uac_bypass.yml
@@ -1,7 +1,7 @@
name: Sdclt UAC Bypass
id: d71efbf6-da63-11eb-8c6e-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Steven Dick, Teoderick Contreras, Splunk
status: production
type: TTP
@@ -75,7 +75,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.002
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/sdelete_application_execution.yml b/detections/endpoint/sdelete_application_execution.yml
index 30f375f28a..10aefc21a4 100644
--- a/detections/endpoint/sdelete_application_execution.yml
+++ b/detections/endpoint/sdelete_application_execution.yml
@@ -1,7 +1,7 @@
name: Sdelete Application Execution
id: 31702fc0-2682-11ec-85c3-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -65,9 +65,8 @@ tags:
- Masquerading - Rename System Utilities
asset_type: Endpoint
mitre_attack_id:
- - T1485
- T1070.004
- - T1070
+ - T1485
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml
index f973ba81b6..fb76934525 100644
--- a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml
+++ b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml
@@ -1,7 +1,7 @@
name: SecretDumps Offline NTDS Dumping Tool
id: 5672819c-be09-11eb-bbfb-acde48001122
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -71,7 +71,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.003
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml b/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml
index 735ed9149a..1abd21eb3c 100644
--- a/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml
+++ b/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml
@@ -1,6 +1,6 @@
name: ServicePrincipalNames Discovery with SetSPN
id: ae8b3efc-2d2e-11ec-8b57-acde48001122
-version: 6
+version: 7
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/services_lolbas_execution_process_spawn.yml b/detections/endpoint/services_lolbas_execution_process_spawn.yml
index 7d8de9c979..50ab6ea4fd 100644
--- a/detections/endpoint/services_lolbas_execution_process_spawn.yml
+++ b/detections/endpoint/services_lolbas_execution_process_spawn.yml
@@ -1,7 +1,7 @@
name: Services LOLBAS Execution Process Spawn
id: ba9e1954-4c04-11ec-8b74-3e22fbd008af
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -77,7 +77,6 @@ tags:
- CISA AA23-347A
asset_type: Endpoint
mitre_attack_id:
- - T1543
- T1543.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml
index edfccceae6..00822bc0c3 100644
--- a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml
+++ b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml
@@ -1,7 +1,7 @@
name: Set Default PowerShell Execution Policy To Unrestricted or Bypass
id: c2590137-0b08-4985-9ec5-6ae23d92f63d
-version: 12
-date: '2024-11-13'
+version: 13
+date: '2025-02-10'
author: Steven Dick, Patrick Bareiss, Splunk
status: production
type: TTP
@@ -79,7 +79,6 @@ tags:
- DarkGate Malware
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/shim_database_file_creation.yml b/detections/endpoint/shim_database_file_creation.yml
index 21a14c236b..21bd64b76b 100644
--- a/detections/endpoint/shim_database_file_creation.yml
+++ b/detections/endpoint/shim_database_file_creation.yml
@@ -1,7 +1,7 @@
name: Shim Database File Creation
id: 6e4c4588-ba2f-42fa-97e6-9f6f548eaa33
-version: 7
-date: '2024-11-13'
+version: 8
+date: '2025-02-10'
author: David Dorsey, Splunk
status: production
type: TTP
@@ -56,7 +56,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1546.011
- - T1546
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml
index 9e30f471ff..37302453aa 100644
--- a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml
+++ b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml
@@ -1,7 +1,7 @@
name: Shim Database Installation With Suspicious Parameters
id: 404620de-46d8-48b6-90cc-8a8d7b0876a3
-version: 8
-date: '2024-12-16'
+version: 9
+date: '2025-02-10'
author: David Dorsey, Splunk
status: production
type: TTP
@@ -17,8 +17,21 @@ data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
-search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = sdbinst.exe NOT Processes.process IN ("\"C:\\Windows\\System32\\sdbinst.exe\"", "C:\\Windows\\System32\\sdbinst.exe", "*-mm", "*-?", "*-m -bg") by Processes.process_name Processes.parent_process_name Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `shim_database_installation_with_suspicious_parameters_filter`'
-how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
+search: '| tstats `security_content_summariesonly` values(Processes.process) as process
+ min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
+ where Processes.process_name = sdbinst.exe NOT Processes.process IN ("\"C:\\Windows\\System32\\sdbinst.exe\"",
+ "C:\\Windows\\System32\\sdbinst.exe", "*-mm", "*-?", "*-m -bg") by Processes.process_name
+ Processes.parent_process_name Processes.dest Processes.user | `drop_dm_object_name(Processes)`
+ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `shim_database_installation_with_suspicious_parameters_filter`'
+how_to_implement: The detection is based on data that originates from Endpoint Detection
+ and Response (EDR) agents. These agents are designed to provide security-related
+ telemetry from the endpoints where the agent is installed. To implement this search,
+ you must ingest logs that contain the process GUID, process name, and parent process.
+ Additionally, you must ingest complete command-line executions. These logs must
+ be processed using the appropriate Splunk Technology Add-ons that are specific to
+ the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
+ data model. Use the Splunk Common Information Model (CIM) to normalize the field
+ names and speed up the data modeling process.
known_false_positives: None identified
references: []
drilldown_searches:
@@ -53,7 +66,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1546.011
- - T1546
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -62,6 +74,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.011/atomic_red_team/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.011/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/short_lived_windows_accounts.yml b/detections/endpoint/short_lived_windows_accounts.yml
index 528b8e0280..2004bdfab1 100644
--- a/detections/endpoint/short_lived_windows_accounts.yml
+++ b/detections/endpoint/short_lived_windows_accounts.yml
@@ -1,7 +1,7 @@
name: Short Lived Windows Accounts
id: b25f6f62-0782-43c1-b403-083231ffd97d
-version: 7
-date: '2024-11-22'
+version: 8
+date: '2025-02-10'
author: David Dorsey, Bhavin Patel, Splunk
status: production
type: TTP
@@ -64,9 +64,8 @@ tags:
- Active Directory Lateral Movement
asset_type: Windows
mitre_attack_id:
- - T1136.001
- - T1136
- T1078.003
+ - T1136.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/silentcleanup_uac_bypass.yml b/detections/endpoint/silentcleanup_uac_bypass.yml
index 9c6c70c9c5..a18bda03a1 100644
--- a/detections/endpoint/silentcleanup_uac_bypass.yml
+++ b/detections/endpoint/silentcleanup_uac_bypass.yml
@@ -1,7 +1,7 @@
name: SilentCleanup UAC Bypass
id: 56d7cfcc-da63-11eb-92d4-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Steven Dick, Teoderick Contreras, Splunk
status: production
type: TTP
@@ -74,7 +74,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.002
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/single_letter_process_on_endpoint.yml b/detections/endpoint/single_letter_process_on_endpoint.yml
index 29bfc12c8d..8c6caa9566 100644
--- a/detections/endpoint/single_letter_process_on_endpoint.yml
+++ b/detections/endpoint/single_letter_process_on_endpoint.yml
@@ -1,7 +1,7 @@
name: Single Letter Process On Endpoint
id: a4214f0b-e01c-41bc-8cc4-d2b71e3056b4
-version: 7
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: David Dorsey, Splunk
status: production
type: TTP
@@ -67,7 +67,6 @@ tags:
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- - T1204
- T1204.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/slui_runas_elevated.yml b/detections/endpoint/slui_runas_elevated.yml
index 02cbd1a2ae..fccaeca2c1 100644
--- a/detections/endpoint/slui_runas_elevated.yml
+++ b/detections/endpoint/slui_runas_elevated.yml
@@ -1,7 +1,7 @@
name: SLUI RunAs Elevated
id: 8d124810-b3e4-11eb-96c7-acde48001122
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -73,7 +73,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.002
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/slui_spawning_a_process.yml b/detections/endpoint/slui_spawning_a_process.yml
index a9b5887f11..118a53b0ef 100644
--- a/detections/endpoint/slui_spawning_a_process.yml
+++ b/detections/endpoint/slui_spawning_a_process.yml
@@ -1,7 +1,7 @@
name: SLUI Spawning a Process
id: 879c4330-b3e0-11eb-b1b1-acde48001122
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -71,7 +71,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.002
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/spoolsv_spawning_rundll32.yml b/detections/endpoint/spoolsv_spawning_rundll32.yml
index 04f2ce636b..70da48f52e 100644
--- a/detections/endpoint/spoolsv_spawning_rundll32.yml
+++ b/detections/endpoint/spoolsv_spawning_rundll32.yml
@@ -1,7 +1,7 @@
name: Spoolsv Spawning Rundll32
id: 15d905f6-da6b-11eb-ab82-acde48001122
-version: 6
-date: '2024-12-10'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Michael Haag, Splunk
status: production
type: TTP
@@ -72,7 +72,6 @@ tags:
- CVE-2021-34527
mitre_attack_id:
- T1547.012
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/spoolsv_suspicious_loaded_modules.yml b/detections/endpoint/spoolsv_suspicious_loaded_modules.yml
index eda8f672d8..07a521d03e 100644
--- a/detections/endpoint/spoolsv_suspicious_loaded_modules.yml
+++ b/detections/endpoint/spoolsv_suspicious_loaded_modules.yml
@@ -1,7 +1,7 @@
name: Spoolsv Suspicious Loaded Modules
id: a5e451f8-da81-11eb-b245-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk
status: production
type: TTP
@@ -55,7 +55,6 @@ tags:
- CVE-2021-34527
mitre_attack_id:
- T1547.012
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/spoolsv_suspicious_process_access.yml b/detections/endpoint/spoolsv_suspicious_process_access.yml
index ee46ef235d..a41111a7b1 100644
--- a/detections/endpoint/spoolsv_suspicious_process_access.yml
+++ b/detections/endpoint/spoolsv_suspicious_process_access.yml
@@ -1,6 +1,6 @@
name: Spoolsv Suspicious Process Access
id: 799b606e-da81-11eb-93f8-acde48001122
-version: 5
+version: 6
date: '2024-11-13'
author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk
status: production
diff --git a/detections/endpoint/spoolsv_writing_a_dll.yml b/detections/endpoint/spoolsv_writing_a_dll.yml
index e4665434d5..3111e77d23 100644
--- a/detections/endpoint/spoolsv_writing_a_dll.yml
+++ b/detections/endpoint/spoolsv_writing_a_dll.yml
@@ -1,7 +1,7 @@
name: Spoolsv Writing a DLL
id: d5bf5cf2-da71-11eb-92c2-acde48001122
-version: 6
-date: '2024-12-10'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Michael Haag, Splunk
status: production
type: TTP
@@ -70,7 +70,6 @@ tags:
- CVE-2021-34527
mitre_attack_id:
- T1547.012
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml b/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml
index 255480b538..de8fec23dd 100644
--- a/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml
+++ b/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml
@@ -1,7 +1,7 @@
name: Spoolsv Writing a DLL - Sysmon
id: 347fd388-da87-11eb-836d-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Michael Haag, Splunk
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
- CVE-2021-34527
mitre_attack_id:
- T1547.012
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/suspicious_computer_account_name_change.yml b/detections/endpoint/suspicious_computer_account_name_change.yml
index 25a57db4be..e7aaee43b7 100644
--- a/detections/endpoint/suspicious_computer_account_name_change.yml
+++ b/detections/endpoint/suspicious_computer_account_name_change.yml
@@ -1,7 +1,7 @@
name: Suspicious Computer Account Name Change
id: 35a61ed8-61c4-11ec-bc1e-acde48001122
-version: 6
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
- CVE-2021-42287
- CVE-2021-42278
mitre_attack_id:
- - T1078
- T1078.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/suspicious_copy_on_system32.yml b/detections/endpoint/suspicious_copy_on_system32.yml
index 552376e126..74724bd7d7 100644
--- a/detections/endpoint/suspicious_copy_on_system32.yml
+++ b/detections/endpoint/suspicious_copy_on_system32.yml
@@ -1,7 +1,7 @@
name: Suspicious Copy on System32
id: ce633e56-25b2-11ec-9e76-acde48001122
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -76,7 +76,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1036.003
- - T1036
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/suspicious_event_log_service_behavior.yml b/detections/endpoint/suspicious_event_log_service_behavior.yml
index bac4d7f013..6900ba2b70 100644
--- a/detections/endpoint/suspicious_event_log_service_behavior.yml
+++ b/detections/endpoint/suspicious_event_log_service_behavior.yml
@@ -1,7 +1,7 @@
name: Suspicious Event Log Service Behavior
id: 2b85aa3d-f5f6-4c2e-a081-a09f6e1c2e40
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -33,7 +33,6 @@ tags:
- Clop Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1070
- T1070.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml b/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml
index f966afa7c3..0af0bc7214 100644
--- a/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml
+++ b/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml
@@ -1,7 +1,7 @@
name: Suspicious IcedID Rundll32 Cmdline
id: bed761f8-ee29-11eb-8bf3-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
- Living Off The Land
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.011
product:
- Splunk Enterprise
diff --git a/detections/endpoint/suspicious_kerberos_service_ticket_request.yml b/detections/endpoint/suspicious_kerberos_service_ticket_request.yml
index b8c5f71cac..2f08209956 100644
--- a/detections/endpoint/suspicious_kerberos_service_ticket_request.yml
+++ b/detections/endpoint/suspicious_kerberos_service_ticket_request.yml
@@ -1,7 +1,7 @@
name: Suspicious Kerberos Service Ticket Request
id: 8b1297bc-6204-11ec-b7c4-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
- CVE-2021-42287
- CVE-2021-42278
mitre_attack_id:
- - T1078
- T1078.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml
index 31415533bd..4484fb6321 100644
--- a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml
+++ b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml
@@ -1,7 +1,7 @@
name: Suspicious microsoft workflow compiler rename
id: f0db4464-55d9-11eb-ae93-0242ac130002
-version: 8
-date: '2024-11-13'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -47,9 +47,8 @@ tags:
- Graceful Wipe Out Attack
asset_type: Endpoint
mitre_attack_id:
- - T1036
- - T1127
- T1036.003
+ - T1127
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/suspicious_msbuild_path.yml b/detections/endpoint/suspicious_msbuild_path.yml
index 1ee9e409d7..fc2f44999f 100644
--- a/detections/endpoint/suspicious_msbuild_path.yml
+++ b/detections/endpoint/suspicious_msbuild_path.yml
@@ -1,7 +1,7 @@
name: Suspicious msbuild path
id: f5198224-551c-11eb-ae93-0242ac130002
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -72,8 +72,6 @@ tags:
- Graceful Wipe Out Attack
asset_type: Endpoint
mitre_attack_id:
- - T1036
- - T1127
- T1036.003
- T1127.001
product:
diff --git a/detections/endpoint/suspicious_msbuild_rename.yml b/detections/endpoint/suspicious_msbuild_rename.yml
index 438fcdeb92..f9bd30e77d 100644
--- a/detections/endpoint/suspicious_msbuild_rename.yml
+++ b/detections/endpoint/suspicious_msbuild_rename.yml
@@ -1,7 +1,7 @@
name: Suspicious MSBuild Rename
id: 4006adac-5937-11eb-ae93-0242ac130002
-version: 7
-date: '2024-11-13'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -48,8 +48,6 @@ tags:
- Graceful Wipe Out Attack
asset_type: Endpoint
mitre_attack_id:
- - T1036
- - T1127
- T1036.003
- T1127.001
product:
diff --git a/detections/endpoint/suspicious_msbuild_spawn.yml b/detections/endpoint/suspicious_msbuild_spawn.yml
index 1c23444d24..897b1fd22e 100644
--- a/detections/endpoint/suspicious_msbuild_spawn.yml
+++ b/detections/endpoint/suspicious_msbuild_spawn.yml
@@ -1,7 +1,7 @@
name: Suspicious MSBuild Spawn
id: a115fba6-5514-11eb-ae93-0242ac130002
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -67,7 +67,6 @@ tags:
- Living Off The Land
asset_type: Endpoint
mitre_attack_id:
- - T1127
- T1127.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/suspicious_mshta_child_process.yml b/detections/endpoint/suspicious_mshta_child_process.yml
index 55035b8d46..7e5a50e44b 100644
--- a/detections/endpoint/suspicious_mshta_child_process.yml
+++ b/detections/endpoint/suspicious_mshta_child_process.yml
@@ -1,7 +1,7 @@
name: Suspicious mshta child process
id: 60023bb6-5500-11eb-ae93-0242ac130002
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -74,7 +74,6 @@ tags:
- Lumma Stealer
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.005
product:
- Splunk Enterprise
diff --git a/detections/endpoint/suspicious_mshta_spawn.yml b/detections/endpoint/suspicious_mshta_spawn.yml
index 95a3c39c82..bffd402f2c 100644
--- a/detections/endpoint/suspicious_mshta_spawn.yml
+++ b/detections/endpoint/suspicious_mshta_spawn.yml
@@ -1,7 +1,7 @@
name: Suspicious mshta spawn
id: 4d33a488-5b5f-11eb-ae93-0242ac130002
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -65,7 +65,6 @@ tags:
- Living Off The Land
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.005
product:
- Splunk Enterprise
diff --git a/detections/endpoint/suspicious_plistbuddy_usage.yml b/detections/endpoint/suspicious_plistbuddy_usage.yml
index 76c97f45ec..f3dc262cfd 100644
--- a/detections/endpoint/suspicious_plistbuddy_usage.yml
+++ b/detections/endpoint/suspicious_plistbuddy_usage.yml
@@ -1,7 +1,7 @@
name: Suspicious PlistBuddy Usage
id: c3194009-e0eb-4f84-87a9-4070f8688f00
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: experimental
type: TTP
@@ -53,7 +53,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1543.001
- - T1543
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/suspicious_plistbuddy_usage_via_osquery.yml b/detections/endpoint/suspicious_plistbuddy_usage_via_osquery.yml
index 6bb4e11150..ec7ee9dc78 100644
--- a/detections/endpoint/suspicious_plistbuddy_usage_via_osquery.yml
+++ b/detections/endpoint/suspicious_plistbuddy_usage_via_osquery.yml
@@ -1,7 +1,7 @@
name: Suspicious PlistBuddy Usage via OSquery
id: 20ba6c32-c733-4a32-b64e-2688cf231399
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: experimental
type: TTP
@@ -37,7 +37,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1543.001
- - T1543
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml b/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml
index 1bce9c0f7d..d239401dda 100644
--- a/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml
+++ b/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml
@@ -1,7 +1,7 @@
name: Suspicious Process DNS Query Known Abuse Web Services
id: 3cf0dc36-484d-11ec-a6bc-acde48001122
-version: 8
-date: '2024-12-10'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1059.005
- - T1059
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/suspicious_process_with_discord_dns_query.yml b/detections/endpoint/suspicious_process_with_discord_dns_query.yml
index 29366f73c9..4dd954857d 100644
--- a/detections/endpoint/suspicious_process_with_discord_dns_query.yml
+++ b/detections/endpoint/suspicious_process_with_discord_dns_query.yml
@@ -1,7 +1,7 @@
name: Suspicious Process With Discord DNS Query
id: 4d4332ae-792c-11ec-89c1-acde48001122
-version: 6
-date: '2024-11-22'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: production
type: Anomaly
@@ -58,7 +58,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1059.005
- - T1059
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/suspicious_reg_exe_process.yml b/detections/endpoint/suspicious_reg_exe_process.yml
index 1d7dfc280a..0add6178bb 100644
--- a/detections/endpoint/suspicious_reg_exe_process.yml
+++ b/detections/endpoint/suspicious_reg_exe_process.yml
@@ -1,6 +1,6 @@
name: Suspicious Reg exe Process
id: a6b3ab4e-dd77-4213-95fa-fc94701995e0
-version: 8
+version: 9
date: '2024-11-13'
author: David Dorsey, Splunk
status: production
diff --git a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml
index 65c6989495..598771f5eb 100644
--- a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml
+++ b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml
@@ -1,7 +1,7 @@
name: Suspicious Regsvr32 Register Suspicious Path
id: 62732736-6250-11eb-ae93-0242ac130002
-version: 10
-date: '2025-01-27'
+version: 12
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -82,7 +82,6 @@ tags:
- Living Off The Land
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.010
product:
- Splunk Enterprise
@@ -92,6 +91,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.010/atomic_red_team/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.010/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml
index 31ca3d198e..3a91a79903 100644
--- a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml
+++ b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml
@@ -1,7 +1,7 @@
name: Suspicious Rundll32 dllregisterserver
id: 8c00a385-9b86-4ac0-8932-c9ec3713b159
-version: 6
-date: '2024-11-13'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -78,7 +78,6 @@ tags:
- IcedID
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.011
product:
- Splunk Enterprise
diff --git a/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml b/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml
index 519b5bc050..a409f211ca 100644
--- a/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml
+++ b/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml
@@ -1,7 +1,7 @@
name: Suspicious Rundll32 no Command Line Arguments
id: e451bd16-e4c5-4109-8eb1-c4c6ecf048b4
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -74,7 +74,6 @@ tags:
cve:
- CVE-2021-34527
mitre_attack_id:
- - T1218
- T1218.011
product:
- Splunk Enterprise
diff --git a/detections/endpoint/suspicious_rundll32_plugininit.yml b/detections/endpoint/suspicious_rundll32_plugininit.yml
index ab0d1c31be..1d83ad1012 100644
--- a/detections/endpoint/suspicious_rundll32_plugininit.yml
+++ b/detections/endpoint/suspicious_rundll32_plugininit.yml
@@ -1,7 +1,7 @@
name: Suspicious Rundll32 PluginInit
id: 92d51712-ee29-11eb-b1ae-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
- IcedID
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.011
product:
- Splunk Enterprise
diff --git a/detections/endpoint/suspicious_rundll32_startw.yml b/detections/endpoint/suspicious_rundll32_startw.yml
index 2c39e6dec8..734b077b09 100644
--- a/detections/endpoint/suspicious_rundll32_startw.yml
+++ b/detections/endpoint/suspicious_rundll32_startw.yml
@@ -1,7 +1,7 @@
name: Suspicious Rundll32 StartW
id: 9319dda5-73f2-4d43-a85a-67ce961bddb7
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -73,7 +73,6 @@ tags:
- Graceful Wipe Out Attack
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.011
product:
- Splunk Enterprise
diff --git a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml
index 7fce587c31..8e78c248d6 100644
--- a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml
+++ b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml
@@ -1,7 +1,7 @@
name: Suspicious Scheduled Task from Public Directory
id: 7feb7972-7ac3-11eb-bac8-acde48001122
-version: 5
-date: '2025-01-27'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Anomaly
@@ -81,7 +81,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.005
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -90,6 +89,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/schtasks/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/schtasks/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/suspicious_ticket_granting_ticket_request.yml b/detections/endpoint/suspicious_ticket_granting_ticket_request.yml
index 069de0c8e2..e51bfe28b4 100644
--- a/detections/endpoint/suspicious_ticket_granting_ticket_request.yml
+++ b/detections/endpoint/suspicious_ticket_granting_ticket_request.yml
@@ -1,7 +1,7 @@
name: Suspicious Ticket Granting Ticket Request
id: d77d349e-6269-11ec-9cfe-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -39,7 +39,6 @@ tags:
- Active Directory Privilege Escalation
asset_type: Endpoint
mitre_attack_id:
- - T1078
- T1078.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/suspicious_wevtutil_usage.yml b/detections/endpoint/suspicious_wevtutil_usage.yml
index 321027b633..39b6278f58 100644
--- a/detections/endpoint/suspicious_wevtutil_usage.yml
+++ b/detections/endpoint/suspicious_wevtutil_usage.yml
@@ -1,7 +1,7 @@
name: Suspicious wevtutil Usage
id: 2827c0fd-e1be-4868-ae25-59d28e0f9d4f
-version: 8
-date: '2024-11-13'
+version: 10
+date: '2025-02-10'
author: David Dorsey, Michael Haag, Teoderick Contreras, Splunk
status: production
type: TTP
@@ -73,7 +73,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1070.001
- - T1070
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/svchost_lolbas_execution_process_spawn.yml b/detections/endpoint/svchost_lolbas_execution_process_spawn.yml
index 256c4e7869..ef195b0980 100644
--- a/detections/endpoint/svchost_lolbas_execution_process_spawn.yml
+++ b/detections/endpoint/svchost_lolbas_execution_process_spawn.yml
@@ -1,7 +1,7 @@
name: Svchost LOLBAS Execution Process Spawn
id: 09e5c72a-4c0d-11ec-aa29-3e22fbd008af
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -75,7 +75,6 @@ tags:
- Scheduled Tasks
asset_type: Endpoint
mitre_attack_id:
- - T1053
- T1053.005
product:
- Splunk Enterprise
diff --git a/detections/endpoint/system_processes_run_from_unexpected_locations.yml b/detections/endpoint/system_processes_run_from_unexpected_locations.yml
index 689b31f757..4821dfd05e 100644
--- a/detections/endpoint/system_processes_run_from_unexpected_locations.yml
+++ b/detections/endpoint/system_processes_run_from_unexpected_locations.yml
@@ -1,7 +1,7 @@
name: System Processes Run From Unexpected Locations
id: a34aae96-ccf8-4aef-952c-3ea21444444d
-version: 9
-date: '2024-11-13'
+version: 10
+date: '2025-02-10'
author: David Dorsey, Michael Haag, Splunk
status: production
type: Anomaly
@@ -72,7 +72,6 @@ tags:
- DarkGate Malware
asset_type: Endpoint
mitre_attack_id:
- - T1036
- T1036.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/system_user_discovery_with_query.yml b/detections/endpoint/system_user_discovery_with_query.yml
index 249c62b457..cd0788aeb9 100644
--- a/detections/endpoint/system_user_discovery_with_query.yml
+++ b/detections/endpoint/system_user_discovery_with_query.yml
@@ -1,7 +1,7 @@
name: System User Discovery With Query
id: ad03bfcf-8a91-4bc2-a500-112993deba87
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-05'
author: Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -17,9 +17,8 @@ data_source:
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
- as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="query.exe")
- (Processes.process=*user*) by Processes.dest Processes.user Processes.parent_process
- Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
+ as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="query.exe" OR Processes.original_file_name="query.exe")
+ AND Processes.process="*user*" AND ((NOT Processes.process="*/server*") OR Processes.process IN ("*/server:localhost*", "*/server:127.0.0.1*")) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `system_user_discovery_with_query_filter`'
how_to_implement: The detection is based on data that originates from Endpoint Detection
diff --git a/detections/endpoint/time_provider_persistence_registry.yml b/detections/endpoint/time_provider_persistence_registry.yml
index 98a2391ac9..9ebc6d728f 100644
--- a/detections/endpoint/time_provider_persistence_registry.yml
+++ b/detections/endpoint/time_provider_persistence_registry.yml
@@ -1,7 +1,7 @@
name: Time Provider Persistence Registry
id: 5ba382c4-2105-11ec-8d8f-acde48001122
-version: 8
-date: '2024-12-08'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1547.003
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml b/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml
index 669ef87e2e..03661c70d7 100644
--- a/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml
+++ b/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml
@@ -1,7 +1,7 @@
name: UAC Bypass MMC Load Unsigned Dll
id: 7f04349c-e30d-11eb-bc7f-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -55,9 +55,8 @@ tags:
- Windows Defense Evasion Tactics
asset_type: Endpoint
mitre_attack_id:
- - T1548.002
- - T1548
- T1218.014
+ - T1548.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/uac_bypass_with_colorui_com_object.yml b/detections/endpoint/uac_bypass_with_colorui_com_object.yml
index c93938fb95..3b5ec1cdb6 100644
--- a/detections/endpoint/uac_bypass_with_colorui_com_object.yml
+++ b/detections/endpoint/uac_bypass_with_colorui_com_object.yml
@@ -1,7 +1,7 @@
name: UAC Bypass With Colorui COM Object
id: 2bcccd20-fc2b-11eb-8d22-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -54,7 +54,6 @@ tags:
- LockBit Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/uninstall_app_using_msiexec.yml b/detections/endpoint/uninstall_app_using_msiexec.yml
index 95e609aade..06248d5f3b 100644
--- a/detections/endpoint/uninstall_app_using_msiexec.yml
+++ b/detections/endpoint/uninstall_app_using_msiexec.yml
@@ -1,7 +1,7 @@
name: Uninstall App Using MsiExec
id: 1fca2b28-f922-11eb-b2dd-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1218.007
- - T1218
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/unload_sysmon_filter_driver.yml b/detections/endpoint/unload_sysmon_filter_driver.yml
index 93302c30ba..74f3715365 100644
--- a/detections/endpoint/unload_sysmon_filter_driver.yml
+++ b/detections/endpoint/unload_sysmon_filter_driver.yml
@@ -1,7 +1,7 @@
name: Unload Sysmon Filter Driver
id: e5928ff3-23eb-4d8b-b8a4-dcbc844fdfbe
-version: 7
-date: '2024-11-13'
+version: 8
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/unloading_amsi_via_reflection.yml b/detections/endpoint/unloading_amsi_via_reflection.yml
index 3fba97f093..63a2cee57d 100644
--- a/detections/endpoint/unloading_amsi_via_reflection.yml
+++ b/detections/endpoint/unloading_amsi_via_reflection.yml
@@ -1,7 +1,7 @@
name: Unloading AMSI via Reflection
id: a21e3484-c94d-11eb-b55b-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -57,9 +57,8 @@ tags:
- Data Destruction
asset_type: Endpoint
mitre_attack_id:
- - T1562
- T1059.001
- - T1059
+ - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/unusual_number_of_kerberos_service_tickets_requested.yml b/detections/endpoint/unusual_number_of_kerberos_service_tickets_requested.yml
index 7735319ec4..58affd514e 100644
--- a/detections/endpoint/unusual_number_of_kerberos_service_tickets_requested.yml
+++ b/detections/endpoint/unusual_number_of_kerberos_service_tickets_requested.yml
@@ -1,7 +1,7 @@
name: Unusual Number of Kerberos Service Tickets Requested
id: eb3e6702-8936-11ec-98fe-acde48001122
-version: 6
-date: '2024-11-13'
+version: 8
+date: '2025-02-10'
author: Mauricio Velazco, Dean Luxton, Splunk
status: production
type: Anomaly
@@ -64,7 +64,6 @@ tags:
- Active Directory Kerberos Attacks
asset_type: Endpoint
mitre_attack_id:
- - T1558
- T1558.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/vbscript_execution_using_wscript_app.yml b/detections/endpoint/vbscript_execution_using_wscript_app.yml
index e9fd89ca8c..a7a87ba473 100644
--- a/detections/endpoint/vbscript_execution_using_wscript_app.yml
+++ b/detections/endpoint/vbscript_execution_using_wscript_app.yml
@@ -1,7 +1,7 @@
name: Vbscript Execution Using Wscript App
id: 35159940-228f-11ec-8a49-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -69,7 +69,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1059.005
- - T1059
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/verclsid_clsid_execution.yml b/detections/endpoint/verclsid_clsid_execution.yml
index fa5b44a719..f45344915b 100644
--- a/detections/endpoint/verclsid_clsid_execution.yml
+++ b/detections/endpoint/verclsid_clsid_execution.yml
@@ -1,7 +1,7 @@
name: Verclsid CLSID Execution
id: 61e9a56a-20fa-11ec-8ba3-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -45,7 +45,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1218.012
- - T1218
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/w3wp_spawning_shell.yml b/detections/endpoint/w3wp_spawning_shell.yml
index 30d7cd3caa..21d2e3fb4f 100644
--- a/detections/endpoint/w3wp_spawning_shell.yml
+++ b/detections/endpoint/w3wp_spawning_shell.yml
@@ -1,7 +1,7 @@
name: W3WP Spawning Shell
id: 0f03423c-7c6a-11eb-bc47-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -79,7 +79,6 @@ tags:
- CVE-2021-34523
- CVE-2021-31207
mitre_attack_id:
- - T1505
- T1505.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/wbemprox_com_object_execution.yml b/detections/endpoint/wbemprox_com_object_execution.yml
index 6e770d7563..3a63ebc37c 100644
--- a/detections/endpoint/wbemprox_com_object_execution.yml
+++ b/detections/endpoint/wbemprox_com_object_execution.yml
@@ -1,7 +1,7 @@
name: Wbemprox COM Object Execution
id: 9d911ce0-c3be-11eb-b177-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
- LockBit Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml b/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml
index fe60773917..5a0d5637a2 100644
--- a/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml
+++ b/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml
@@ -1,7 +1,7 @@
name: Wermgr Process Connecting To IP Check Web Services
id: ed313326-a0f9-11eb-a89c-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -56,7 +56,6 @@ tags:
- Trickbot
asset_type: Endpoint
mitre_attack_id:
- - T1590
- T1590.005
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml b/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml
index 9f00ab5ca2..66a85dd28f 100644
--- a/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml
+++ b/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml
@@ -1,7 +1,7 @@
name: Windows Access Token Manipulation SeDebugPrivilege
id: 6ece9ed0-5f92-4315-889d-48560472b188
-version: 10
-date: '2025-01-27'
+version: 11
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -70,7 +70,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1134.002
- - T1134
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -79,6 +78,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/brute_ratel/sedebugprivilege_token/security-xml.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/brute_ratel/sedebugprivilege_token/security-xml.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_access_token_manipulation_winlogon_duplicate_token_handle.yml b/detections/endpoint/windows_access_token_manipulation_winlogon_duplicate_token_handle.yml
index 4dbd423a92..dd647d1112 100644
--- a/detections/endpoint/windows_access_token_manipulation_winlogon_duplicate_token_handle.yml
+++ b/detections/endpoint/windows_access_token_manipulation_winlogon_duplicate_token_handle.yml
@@ -1,7 +1,7 @@
name: Windows Access Token Manipulation Winlogon Duplicate Token Handle
id: dda126d7-1d99-4f0b-b72a-4c14031f9398
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -35,7 +35,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1134.001
- - T1134
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_access_token_winlogon_duplicate_handle_in_uncommon_path.yml b/detections/endpoint/windows_access_token_winlogon_duplicate_handle_in_uncommon_path.yml
index b3cc876fb9..662e51dcaf 100644
--- a/detections/endpoint/windows_access_token_winlogon_duplicate_handle_in_uncommon_path.yml
+++ b/detections/endpoint/windows_access_token_winlogon_duplicate_handle_in_uncommon_path.yml
@@ -1,7 +1,7 @@
name: Windows Access Token Winlogon Duplicate Handle In Uncommon Path
id: b8f7ed6b-0556-4c84-bffd-839c262b0278
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1134.001
- - T1134
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_account_access_removal_via_logoff_exec.yml b/detections/endpoint/windows_account_access_removal_via_logoff_exec.yml
index 709d34b600..efd6e3dd18 100644
--- a/detections/endpoint/windows_account_access_removal_via_logoff_exec.yml
+++ b/detections/endpoint/windows_account_access_removal_via_logoff_exec.yml
@@ -1,21 +1,27 @@
name: Windows Account Access Removal via Logoff Exec
id: 223572ab-8768-4e20-9b39-c38707af80dc
-version: 1
-date: '2024-12-17'
+version: 2
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
data_source:
- Sysmon EventID 1
type: Anomaly
status: production
-description: The following analytic detects the process of logging off a user through the use of the quser and logoff commands. By monitoring for these commands, the analytic identifies actions where a user session is forcibly terminated, which could be part of an administrative task or a potentially unauthorized access attempt. This detection helps identify potential misuse or malicious activity where a user’s access is revoked without proper authorization, providing insight into potential security incidents involving account management or session manipulation.
-search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
- where Processes.process_name = logoff.exe
- by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_guid Processes.dest Processes.user
- | `drop_dm_object_name(Processes)`
- | `security_content_ctime(firstTime)`
- | `security_content_ctime(lastTime)`
- | `windows_account_access_removal_via_logoff_exec_filter`'
-how_to_implement: The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging.
+description: The following analytic detects the process of logging off a user through
+ the use of the quser and logoff commands. By monitoring for these commands, the
+ analytic identifies actions where a user session is forcibly terminated, which could
+ be part of an administrative task or a potentially unauthorized access attempt.
+ This detection helps identify potential misuse or malicious activity where a user’s
+ access is revoked without proper authorization, providing insight into potential
+ security incidents involving account management or session manipulation.
+search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_time)
+ as lastTime from datamodel=Endpoint.Processes where Processes.process_name = logoff.exe
+ by Processes.parent_process_name Processes.parent_process Processes.process_name
+ Processes.process Processes.process_guid Processes.dest Processes.user | `drop_dm_object_name(Processes)`
+ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_account_access_removal_via_logoff_exec_filter`'
+how_to_implement: The following Hunting analytic requires PowerShell operational logs
+ to be imported. Modify the powershell macro as needed to match the sourcetype or
+ add index. This analytic is specific to 4104, or PowerShell Script Block Logging.
known_false_positives: Administrators or power users may use this command.
references:
- https://devblogs.microsoft.com/scripting/automating-quser-through-powershell/
@@ -25,7 +31,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -43,9 +54,8 @@ tags:
- Crypto Stealer
asset_type: Endpoint
mitre_attack_id:
- - T1531
- T1059.001
- - T1059
+ - T1531
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -54,6 +64,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/powershell_log_process_tree/powershell_logoff.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/powershell_log_process_tree/powershell_logoff.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_account_discovery_for_none_disable_user_account.yml b/detections/endpoint/windows_account_discovery_for_none_disable_user_account.yml
index 501c9abd55..7ddbfdb697 100644
--- a/detections/endpoint/windows_account_discovery_for_none_disable_user_account.yml
+++ b/detections/endpoint/windows_account_discovery_for_none_disable_user_account.yml
@@ -1,7 +1,7 @@
name: Windows Account Discovery for None Disable User Account
id: eddbf5ba-b89e-47ca-995e-2d259804e55e
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -35,7 +35,6 @@ tags:
- CISA AA23-347A
asset_type: Endpoint
mitre_attack_id:
- - T1087
- T1087.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_ad_abnormal_object_access_activity.yml b/detections/endpoint/windows_ad_abnormal_object_access_activity.yml
index d950358d37..30e8c78866 100644
--- a/detections/endpoint/windows_ad_abnormal_object_access_activity.yml
+++ b/detections/endpoint/windows_ad_abnormal_object_access_activity.yml
@@ -1,7 +1,7 @@
name: Windows AD Abnormal Object Access Activity
id: 71b289db-5f2c-4c43-8256-8bf26ae7324a
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Steven Dick
status: production
type: Anomaly
@@ -60,7 +60,6 @@ tags:
- BlackSuit Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1087
- T1087.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml b/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml
index 9b011c912c..87740e631d 100644
--- a/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml
+++ b/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml
@@ -1,6 +1,6 @@
name: Windows AD AdminSDHolder ACL Modified
id: 00d877c3-7b7b-443d-9562-6b231e2abab9
-version: 5
+version: 6
date: '2024-11-13'
author: Mauricio Velazco, Dean Luxton, Splunk
type: TTP
diff --git a/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml b/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml
index 1a951ffa45..79de518830 100644
--- a/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml
+++ b/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml
@@ -1,7 +1,7 @@
name: Windows AD Cross Domain SID History Addition
id: 41bbb371-28ba-439c-bb5c-d9930c28365d
-version: 5
-date: '2024-12-10'
+version: 7
+date: '2025-02-10'
author: Dean Luxton
type: TTP
status: production
@@ -62,7 +62,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1134.005
- - T1134
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_ad_domain_replication_acl_addition.yml b/detections/endpoint/windows_ad_domain_replication_acl_addition.yml
index 5afac44a1b..a303064df9 100644
--- a/detections/endpoint/windows_ad_domain_replication_acl_addition.yml
+++ b/detections/endpoint/windows_ad_domain_replication_acl_addition.yml
@@ -1,6 +1,6 @@
name: Windows AD Domain Replication ACL Addition
id: 8c372853-f459-4995-afdc-280c114d33ab
-version: 7
+version: 8
date: '2024-12-10'
author: Dean Luxton
type: TTP
diff --git a/detections/endpoint/windows_ad_privileged_account_sid_history_addition.yml b/detections/endpoint/windows_ad_privileged_account_sid_history_addition.yml
index b27e21cabe..c41aece18f 100644
--- a/detections/endpoint/windows_ad_privileged_account_sid_history_addition.yml
+++ b/detections/endpoint/windows_ad_privileged_account_sid_history_addition.yml
@@ -1,7 +1,7 @@
name: Windows AD Privileged Account SID History Addition
id: 6b521149-b91c-43aa-ba97-c2cac59ec830
-version: 6
-date: '2024-12-10'
+version: 7
+date: '2025-02-10'
author: Dean Luxton
type: TTP
status: production
@@ -58,7 +58,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1134.005
- - T1134
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_ad_privileged_object_access_activity.yml b/detections/endpoint/windows_ad_privileged_object_access_activity.yml
index 022e799c23..505c7fd59b 100644
--- a/detections/endpoint/windows_ad_privileged_object_access_activity.yml
+++ b/detections/endpoint/windows_ad_privileged_object_access_activity.yml
@@ -1,7 +1,7 @@
name: Windows AD Privileged Object Access Activity
id: dc2f58bc-8cd2-4e51-962a-694b963acde0
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
- BlackSuit Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1087
- T1087.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_ad_replication_request_initiated_by_user_account.yml b/detections/endpoint/windows_ad_replication_request_initiated_by_user_account.yml
index 559582d368..942a561d39 100644
--- a/detections/endpoint/windows_ad_replication_request_initiated_by_user_account.yml
+++ b/detections/endpoint/windows_ad_replication_request_initiated_by_user_account.yml
@@ -1,7 +1,7 @@
name: Windows AD Replication Request Initiated by User Account
id: 51307514-1236-49f6-8686-d46d93cc2821
-version: 6
-date: '2024-12-10'
+version: 7
+date: '2025-02-10'
author: Dean Luxton
type: TTP
status: production
@@ -73,7 +73,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.006
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml b/detections/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml
index 1d6a7be15c..7ec27540f3 100644
--- a/detections/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml
+++ b/detections/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml
@@ -1,7 +1,7 @@
name: Windows AD Replication Request Initiated from Unsanctioned Location
id: 50998483-bb15-457b-a870-965080d9e3d3
-version: 7
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Dean Luxton
type: TTP
status: production
@@ -77,7 +77,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.006
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml b/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml
index 00764a6d79..06ebf8cd4c 100644
--- a/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml
+++ b/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml
@@ -1,7 +1,7 @@
name: Windows AD Same Domain SID History Addition
id: 5fde0b7c-df7a-40b1-9b3a-294c00f0289d
-version: 6
-date: '2024-12-10'
+version: 7
+date: '2025-02-10'
author: Dean Luxton
type: TTP
status: production
@@ -63,7 +63,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1134.005
- - T1134
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_ad_sid_history_attribute_modified.yml b/detections/endpoint/windows_ad_sid_history_attribute_modified.yml
index 55ba1e1045..65a1e2eedf 100644
--- a/detections/endpoint/windows_ad_sid_history_attribute_modified.yml
+++ b/detections/endpoint/windows_ad_sid_history_attribute_modified.yml
@@ -1,7 +1,7 @@
name: Windows AD SID History Attribute Modified
id: 1155e47d-307f-4247-beab-71071e3a458c
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
type: TTP
status: production
@@ -56,7 +56,6 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- - T1134
- T1134.005
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_admon_default_group_policy_object_modified.yml b/detections/endpoint/windows_admon_default_group_policy_object_modified.yml
index dba80bbc1b..4194594106 100644
--- a/detections/endpoint/windows_admon_default_group_policy_object_modified.yml
+++ b/detections/endpoint/windows_admon_default_group_policy_object_modified.yml
@@ -1,7 +1,7 @@
name: Windows Admon Default Group Policy Object Modified
id: 83458004-db60-4170-857d-8572f16f070b
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- - T1484
- T1484.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_admon_group_policy_object_created.yml b/detections/endpoint/windows_admon_group_policy_object_created.yml
index 83a1435afa..88224156c8 100644
--- a/detections/endpoint/windows_admon_group_policy_object_created.yml
+++ b/detections/endpoint/windows_admon_group_policy_object_created.yml
@@ -1,7 +1,7 @@
name: Windows Admon Group Policy Object Created
id: 69201633-30d9-48ef-b1b6-e680805f0582
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -56,7 +56,6 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- - T1484
- T1484.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_alternate_datastream___base64_content.yml b/detections/endpoint/windows_alternate_datastream___base64_content.yml
index 7a95b21409..ecd4e049de 100644
--- a/detections/endpoint/windows_alternate_datastream___base64_content.yml
+++ b/detections/endpoint/windows_alternate_datastream___base64_content.yml
@@ -1,7 +1,7 @@
name: Windows Alternate DataStream - Base64 Content
id: 683f48de-982f-4a7e-9aac-9cec550da498
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Steven Dick, Teoderick Contreras, Michael Haag, Splunk
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
- Windows Defense Evasion Tactics
asset_type: Endpoint
mitre_attack_id:
- - T1564
- T1564.004
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_alternate_datastream___executable_content.yml b/detections/endpoint/windows_alternate_datastream___executable_content.yml
index 9ff5c8ee67..b60c3f31df 100644
--- a/detections/endpoint/windows_alternate_datastream___executable_content.yml
+++ b/detections/endpoint/windows_alternate_datastream___executable_content.yml
@@ -1,7 +1,7 @@
name: Windows Alternate DataStream - Executable Content
id: a258bf2a-34fd-4986-8086-78f506e00206
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Steven Dick, Teoderick Contreras, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
- Windows Defense Evasion Tactics
asset_type: Endpoint
mitre_attack_id:
- - T1564
- T1564.004
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_alternate_datastream___process_execution.yml b/detections/endpoint/windows_alternate_datastream___process_execution.yml
index 3e11a4fef5..8f69a19e36 100644
--- a/detections/endpoint/windows_alternate_datastream___process_execution.yml
+++ b/detections/endpoint/windows_alternate_datastream___process_execution.yml
@@ -1,7 +1,7 @@
name: Windows Alternate DataStream - Process Execution
id: 30c32c5c-41fe-45db-84fe-275e4320da3f
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -65,7 +65,6 @@ tags:
- Windows Defense Evasion Tactics
asset_type: Endpoint
mitre_attack_id:
- - T1564
- T1564.004
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_apache_benchmark_binary.yml b/detections/endpoint/windows_apache_benchmark_binary.yml
index 17a494d0c6..ecbb29f74e 100644
--- a/detections/endpoint/windows_apache_benchmark_binary.yml
+++ b/detections/endpoint/windows_apache_benchmark_binary.yml
@@ -1,6 +1,6 @@
name: Windows Apache Benchmark Binary
id: 894f48ea-8d85-4dcd-9132-c66cdb407c9b
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_archive_collected_data_via_rar.yml b/detections/endpoint/windows_archive_collected_data_via_rar.yml
index d3403433b5..7a1bc686a4 100644
--- a/detections/endpoint/windows_archive_collected_data_via_rar.yml
+++ b/detections/endpoint/windows_archive_collected_data_via_rar.yml
@@ -1,7 +1,7 @@
name: Windows Archive Collected Data via Rar
id: 2015de95-fe91-413d-9d62-2fe011b67e82
-version: 5
-date: '2025-01-27'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1560.001
- - T1560
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -76,6 +75,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility_darkgate/rar_sys.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility_darkgate/rar_sys.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_attempt_to_stop_security_service.yml b/detections/endpoint/windows_attempt_to_stop_security_service.yml
index 44e85bbc42..79ccda8ff8 100644
--- a/detections/endpoint/windows_attempt_to_stop_security_service.yml
+++ b/detections/endpoint/windows_attempt_to_stop_security_service.yml
@@ -1,18 +1,42 @@
name: Windows Attempt To Stop Security Service
id: 9ed27cea-4e27-4eff-b2c6-aac9e78a7517
-version: 1
-date: '2025-01-13'
+version: 3
+date: '2025-02-10'
author: Rico Valdez, Nasreddine Bencherchali, Splunk
status: production
type: TTP
-description: The following analytic detects attempts to stop security-related services on an endpoint, which may indicate malicious activity. It leverages data from Endpoint Detection and Response (EDR) agents, specifically searching for processes involving the "sc.exe" or "net.exe" command with the "stop" parameter or the PowerShell "Stop-Service" cmdlet. This activity is significant because disabling security services can undermine the organization's security posture, potentially leading to unauthorized access, data exfiltration, or further attacks like malware installation or privilege escalation. If confirmed malicious, this behavior could compromise the endpoint and the entire network, necessitating immediate investigation and response.
+description: The following analytic detects attempts to stop security-related services
+ on an endpoint, which may indicate malicious activity. It leverages data from Endpoint
+ Detection and Response (EDR) agents, specifically searching for processes involving
+ the "sc.exe" or "net.exe" command with the "stop" parameter or the PowerShell "Stop-Service"
+ cmdlet. This activity is significant because disabling security services can undermine
+ the organization's security posture, potentially leading to unauthorized access,
+ data exfiltration, or further attacks like malware installation or privilege escalation.
+ If confirmed malicious, this behavior could compromise the endpoint and the entire
+ network, necessitating immediate investigation and response.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
-search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where ((`process_net` OR `process_sc`) Processes.process="* stop *") OR Processes.process="*Stop-Service *" by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |lookup security_services_lookup service as process OUTPUTNEW category, description | search category=security | `windows_attempt_to_stop_security_service_filter`'
-how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
-known_false_positives: None identified. Attempts to disable security-related services should be identified and understood.
+search: '| tstats `security_content_summariesonly` values(Processes.process) as process
+ min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
+ where ((`process_net` OR `process_sc`) Processes.process="* stop *") OR Processes.process="*Stop-Service
+ *" by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name
+ Processes.process_name Processes.original_file_name Processes.process Processes.process_id
+ Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)` |lookup security_services_lookup service as
+ process OUTPUTNEW category, description | search category=security | `windows_attempt_to_stop_security_service_filter`'
+how_to_implement: The detection is based on data that originates from Endpoint Detection
+ and Response (EDR) agents. These agents are designed to provide security-related
+ telemetry from the endpoints where the agent is installed. To implement this search,
+ you must ingest logs that contain the process GUID, process name, and parent process.
+ Additionally, you must ingest complete command-line executions. These logs must
+ be processed using the appropriate Splunk Technology Add-ons that are specific to
+ the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
+ data model. Use the Splunk Common Information Model (CIM) to normalize the field
+ names and speed up the data modeling process.
+known_false_positives: None identified. Attempts to disable security-related services
+ should be identified and understood.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-14---disable-arbitrary-security-windows-service
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
@@ -22,7 +46,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
+ "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
+ as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
+ Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
+ as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
+ by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -51,7 +80,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -60,6 +88,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_defend_service_stop/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_defend_service_stop/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_autoit3_execution.yml b/detections/endpoint/windows_autoit3_execution.yml
index 27d70e95ba..e6ddf3ce77 100644
--- a/detections/endpoint/windows_autoit3_execution.yml
+++ b/detections/endpoint/windows_autoit3_execution.yml
@@ -1,6 +1,6 @@
name: Windows AutoIt3 Execution
id: 0ecb40d9-492b-4a57-9f87-515dd742794c
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml b/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml
index a14fab9b60..873c2df5da 100644
--- a/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml
+++ b/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml
@@ -1,7 +1,7 @@
name: Windows Binary Proxy Execution Mavinject DLL Injection
id: ccf4b61b-1b26-4f2e-a089-f2009c569c57
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -73,7 +73,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1218.013
- - T1218
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_bitlockertogo_process_execution.yml b/detections/endpoint/windows_bitlockertogo_process_execution.yml
index a6607a72a8..ac6f6b6ac4 100644
--- a/detections/endpoint/windows_bitlockertogo_process_execution.yml
+++ b/detections/endpoint/windows_bitlockertogo_process_execution.yml
@@ -1,10 +1,10 @@
name: Windows BitLockerToGo Process Execution
id: 68cbc9e9-2882-46f2-b636-3b5080589d58
-version: 2
+version: 3
date: '2025-01-21'
author: Michael Haag, Nasreddine Bencherchali, Splunk
data_source:
-- Sysmon Event ID 1
+- Sysmon EventID 1
- Windows Event Log Security 4688
type: Hunting
status: production
diff --git a/detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml b/detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml
index 974d986e9f..9a96351ff5 100644
--- a/detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml
+++ b/detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml
@@ -1,7 +1,7 @@
name: Windows Boot or Logon Autostart Execution In Startup Folder
id: 99d157cb-923f-4a00-aee9-1f385412146f
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -62,7 +62,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1547.001
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_bootloader_inventory.yml b/detections/endpoint/windows_bootloader_inventory.yml
index 375c844994..7346f0b9f4 100644
--- a/detections/endpoint/windows_bootloader_inventory.yml
+++ b/detections/endpoint/windows_bootloader_inventory.yml
@@ -1,7 +1,7 @@
name: Windows BootLoader Inventory
id: 4f7e3913-4db3-4ccd-afe4-31198982305d
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: experimental
type: Hunting
@@ -33,7 +33,6 @@ tags:
atomic_guid: []
mitre_attack_id:
- T1542.001
- - T1542
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_cached_domain_credentials_reg_query.yml b/detections/endpoint/windows_cached_domain_credentials_reg_query.yml
index b0cf4007cc..3b9b8d4394 100644
--- a/detections/endpoint/windows_cached_domain_credentials_reg_query.yml
+++ b/detections/endpoint/windows_cached_domain_credentials_reg_query.yml
@@ -1,7 +1,7 @@
name: Windows Cached Domain Credentials Reg Query
id: 40ccb8e0-1785-466e-901e-6a8b75c04ecd
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -68,7 +68,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.005
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_certutil_download_with_url_argument.yml b/detections/endpoint/windows_certutil_download_with_url_argument.yml
index e7ac8ebf6c..87ff45c03c 100644
--- a/detections/endpoint/windows_certutil_download_with_url_argument.yml
+++ b/detections/endpoint/windows_certutil_download_with_url_argument.yml
@@ -1,6 +1,6 @@
name: Windows CertUtil Download With URL Argument
id: 4fc5ca00-4c7c-46b3-8772-c98a4b8bd944
-version: 2
+version: 3
date: '2025-01-07'
author: Nasreddine Bencherchali, Splunk
status: production
diff --git a/detections/endpoint/windows_change_default_file_association_for_no_file_ext.yml b/detections/endpoint/windows_change_default_file_association_for_no_file_ext.yml
index 36f61bdd44..161c19a39e 100644
--- a/detections/endpoint/windows_change_default_file_association_for_no_file_ext.yml
+++ b/detections/endpoint/windows_change_default_file_association_for_no_file_ext.yml
@@ -1,7 +1,7 @@
name: Windows Change Default File Association For No File Ext
id: dbdf52ad-d6a1-4b68-975f-0a10939d8e38
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -68,7 +68,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1546.001
- - T1546
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_cmdline_tool_execution_from_non_shell_process.yml b/detections/endpoint/windows_cmdline_tool_execution_from_non_shell_process.yml
index 76789b01ac..ea35cf83bc 100644
--- a/detections/endpoint/windows_cmdline_tool_execution_from_non_shell_process.yml
+++ b/detections/endpoint/windows_cmdline_tool_execution_from_non_shell_process.yml
@@ -1,18 +1,42 @@
name: Windows Cmdline Tool Execution From Non-Shell Process
id: 2afa393f-b88d-41b7-9793-623c93a2dfde
-version: 1
-date: '2025-01-13'
+version: 3
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
-description: The following analytic identifies instances where `ipconfig.exe`, `systeminfo.exe`, or similar tools are executed by a non-standard shell parent process, excluding CMD, PowerShell, or Explorer. This detection leverages Endpoint Detection and Response (EDR) telemetry to monitor process creation events. Such behavior is significant as it may indicate adversaries using injected processes to perform system discovery, a tactic observed in FIN7's JSSLoader. If confirmed malicious, this activity could allow attackers to gather critical host information, aiding in further exploitation or lateral movement within the network.
+description: The following analytic identifies instances where `ipconfig.exe`, `systeminfo.exe`,
+ or similar tools are executed by a non-standard shell parent process, excluding
+ CMD, PowerShell, or Explorer. This detection leverages Endpoint Detection and Response
+ (EDR) telemetry to monitor process creation events. Such behavior is significant
+ as it may indicate adversaries using injected processes to perform system discovery,
+ a tactic observed in FIN7's JSSLoader. If confirmed malicious, this activity could
+ allow attackers to gather critical host information, aiding in further exploitation
+ or lateral movement within the network.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
-search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN ("ipconfig.exe", "systeminfo.exe", "net1.exe", "arp.exe", "nslookup.exe", "route.exe", "netstat.exe", "whoami.exe") AND NOT Processes.parent_process_name IN ("cmd.exe", "powershell.exe", "powershell_ise.exe", "pwsh.exe", "explorer.exe", "-", "unknown") by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.original_file_name Processes.process_id Processes.process Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_cmdline_tool_execution_from_non_shell_process_filter`'
-how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
-known_false_positives: A network operator or systems administrator may utilize an automated host discovery application that may generate false positives. Filter as needed.
+search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
+ as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN ("ipconfig.exe",
+ "systeminfo.exe", "net1.exe", "arp.exe", "nslookup.exe", "route.exe", "netstat.exe",
+ "whoami.exe") AND NOT Processes.parent_process_name IN ("cmd.exe", "powershell.exe",
+ "powershell_ise.exe", "pwsh.exe", "explorer.exe", "-", "unknown") by Processes.parent_process_name
+ Processes.parent_process Processes.process_name Processes.original_file_name Processes.process_id
+ Processes.process Processes.dest Processes.user | `drop_dm_object_name(Processes)`
+ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_cmdline_tool_execution_from_non_shell_process_filter`'
+how_to_implement: The detection is based on data that originates from Endpoint Detection
+ and Response (EDR) agents. These agents are designed to provide security-related
+ telemetry from the endpoints where the agent is installed. To implement this search,
+ you must ingest logs that contain the process GUID, process name, and parent process.
+ Additionally, you must ingest complete command-line executions. These logs must
+ be processed using the appropriate Splunk Technology Add-ons that are specific to
+ the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
+ data model. Use the Splunk Common Information Model (CIM) to normalize the field
+ names and speed up the data modeling process.
+known_false_positives: A network operator or systems administrator may utilize an
+ automated host discovery application that may generate false positives. Filter as
+ needed.
references:
- https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation
- https://attack.mitre.org/groups/G0046/
@@ -23,7 +47,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$" and "$user$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$",
+ "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
+ as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
+ Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
+ as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
+ by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -53,7 +82,6 @@ tags:
- Gozi Malware
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.007
product:
- Splunk Enterprise
@@ -63,6 +91,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/jssloader/sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/jssloader/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml b/detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml
index 80717d56c4..0e083199b3 100644
--- a/detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml
+++ b/detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml
@@ -1,7 +1,7 @@
name: Windows COM Hijacking InprocServer32 Modification
id: b7bd83c0-92b5-4fc7-b286-23eccfa2c561
-version: 6
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -73,7 +73,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1546.015
- - T1546
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml b/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml
index 68a89ff942..749ef2a798 100644
--- a/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml
+++ b/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml
@@ -1,7 +1,7 @@
name: Windows Command Shell DCRat ForkBomb Payload
id: 2bb1a362-7aa8-444a-92ed-1987e8da83e1
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -71,7 +71,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1059.003
- - T1059
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_create_local_account.yml b/detections/endpoint/windows_create_local_account.yml
index 91781c15e8..f6cc478ad7 100644
--- a/detections/endpoint/windows_create_local_account.yml
+++ b/detections/endpoint/windows_create_local_account.yml
@@ -1,7 +1,7 @@
name: Windows Create Local Account
id: 3fb2e8e3-7bc0-4567-9722-c5ab9f8595eb
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Anomaly
@@ -58,7 +58,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1136.001
- - T1136
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_create_local_administrator_account_via_net.yml b/detections/endpoint/windows_create_local_administrator_account_via_net.yml
index 518245a6d4..c555bb46ba 100644
--- a/detections/endpoint/windows_create_local_administrator_account_via_net.yml
+++ b/detections/endpoint/windows_create_local_administrator_account_via_net.yml
@@ -1,17 +1,40 @@
name: Windows Create Local Administrator Account Via Net
id: 2c568c34-bb57-4b43-9d75-19c605b98e70
-version: 1
-date: '2025-01-13'
+version: 3
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: Anomaly
-description: The following analytic detects the creation of a local administrator account using the "net.exe" command. It leverages Endpoint Detection and Response (EDR) data to identify processes named "net.exe" with the "/add" parameter and keywords related to administrator accounts. This activity is significant as it may indicate an attacker attempting to gain persistent access or escalate privileges. If confirmed malicious, this could lead to unauthorized access, data theft, or further system compromise. Review the process details, user context, and related artifacts to determine the legitimacy of the activity.
+description: The following analytic detects the creation of a local administrator
+ account using the "net.exe" command. It leverages Endpoint Detection and Response
+ (EDR) data to identify processes named "net.exe" with the "/add" parameter and keywords
+ related to administrator accounts. This activity is significant as it may indicate
+ an attacker attempting to gain persistent access or escalate privileges. If confirmed
+ malicious, this could lead to unauthorized access, data theft, or further system
+ compromise. Review the process details, user context, and related artifacts to determine
+ the legitimacy of the activity.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
-search: '| tstats `security_content_summariesonly` count values(Processes.user) as user values(Processes.parent_process) as parent_process values(parent_process_name) as parent_process_name min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` AND Processes.process=*/add* AND Processes.process IN ("*administrators*", "*administratoren*", "*administrateurs*", "*administrador*", "*amministratori*", "*administratorer*", "*Rendszergazda*", "*Администратор*", "*Administratör*") by Processes.process Processes.process_name Processes.parent_process_name Processes.dest Processes.user| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_create_local_administrator_account_via_net_filter`'
-how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
+search: '| tstats `security_content_summariesonly` count values(Processes.user) as
+ user values(Processes.parent_process) as parent_process values(parent_process_name)
+ as parent_process_name min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
+ where `process_net` AND Processes.process=*/add* AND Processes.process IN ("*administrators*",
+ "*administratoren*", "*administrateurs*", "*administrador*", "*amministratori*",
+ "*administratorer*", "*Rendszergazda*", "*Администратор*", "*Administratör*") by
+ Processes.process Processes.process_name Processes.parent_process_name Processes.dest
+ Processes.user| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)` | `windows_create_local_administrator_account_via_net_filter`'
+how_to_implement: The detection is based on data that originates from Endpoint Detection
+ and Response (EDR) agents. These agents are designed to provide security-related
+ telemetry from the endpoints where the agent is installed. To implement this search,
+ you must ingest logs that contain the process GUID, process name, and parent process.
+ Additionally, you must ingest complete command-line executions. These logs must
+ be processed using the appropriate Splunk Technology Add-ons that are specific to
+ the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
+ data model. Use the Splunk Common Information Model (CIM) to normalize the field
+ names and speed up the data modeling process.
known_false_positives: Administrators often leverage net.exe to create admin accounts.
references: []
drilldown_searches:
@@ -20,7 +43,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
+ "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
+ as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
+ Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
+ as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
+ by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -49,7 +77,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1136.001
- - T1136
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -58,6 +85,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_credential_dumping_lsass_memory_createdump.yml b/detections/endpoint/windows_credential_dumping_lsass_memory_createdump.yml
index 1308709d7f..b33e006ced 100644
--- a/detections/endpoint/windows_credential_dumping_lsass_memory_createdump.yml
+++ b/detections/endpoint/windows_credential_dumping_lsass_memory_createdump.yml
@@ -1,6 +1,6 @@
name: Windows Credential Dumping LSASS Memory Createdump
id: b3b7ce35-fce5-4c73-85f4-700aeada81a9
-version: 6
+version: 7
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_credentials_from_password_stores_chrome_copied_in_temp_dir.yml b/detections/endpoint/windows_credentials_from_password_stores_chrome_copied_in_temp_dir.yml
index 25c6142e2f..862f0b722b 100644
--- a/detections/endpoint/windows_credentials_from_password_stores_chrome_copied_in_temp_dir.yml
+++ b/detections/endpoint/windows_credentials_from_password_stores_chrome_copied_in_temp_dir.yml
@@ -1,7 +1,7 @@
name: Windows Credentials from Password Stores Chrome Copied in TEMP Dir
id: 4d14c86d-fdee-4393-94da-238d2706902f
-version: 2
-date: '2024-11-13'
+version: 3
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
data_source:
- Sysmon Event ID 11
@@ -58,7 +58,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1555.003
- - T1555
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_credentials_from_web_browsers_saved_in_temp_folder.yml b/detections/endpoint/windows_credentials_from_web_browsers_saved_in_temp_folder.yml
index f597206fbb..468917413d 100644
--- a/detections/endpoint/windows_credentials_from_web_browsers_saved_in_temp_folder.yml
+++ b/detections/endpoint/windows_credentials_from_web_browsers_saved_in_temp_folder.yml
@@ -1,7 +1,7 @@
name: Windows Credentials from Web Browsers Saved in TEMP Folder
id: b36b23ea-763c-417b-bd4a-6a378dabad1a
-version: 2
-date: '2024-11-13'
+version: 3
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
data_source:
- Sysmon Event ID 11
@@ -57,7 +57,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1555.003
- - T1555
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_credentials_in_registry_reg_query.yml b/detections/endpoint/windows_credentials_in_registry_reg_query.yml
index 5465160a3a..c0718bc539 100644
--- a/detections/endpoint/windows_credentials_in_registry_reg_query.yml
+++ b/detections/endpoint/windows_credentials_in_registry_reg_query.yml
@@ -1,7 +1,7 @@
name: Windows Credentials in Registry Reg Query
id: a8b3124e-2278-4b73-ae9c-585117079fb2
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -69,7 +69,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1552.002
- - T1552
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_curl_download_to_suspicious_path.yml b/detections/endpoint/windows_curl_download_to_suspicious_path.yml
index a267aa3e2f..fc5ad0009f 100644
--- a/detections/endpoint/windows_curl_download_to_suspicious_path.yml
+++ b/detections/endpoint/windows_curl_download_to_suspicious_path.yml
@@ -1,6 +1,6 @@
name: Windows Curl Download to Suspicious Path
id: c32f091e-30db-11ec-8738-acde48001122
-version: 7
+version: 8
date: '2025-01-27'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_curl_upload_to_remote_destination.yml b/detections/endpoint/windows_curl_upload_to_remote_destination.yml
index 0ebd3235eb..8b99b345c5 100644
--- a/detections/endpoint/windows_curl_upload_to_remote_destination.yml
+++ b/detections/endpoint/windows_curl_upload_to_remote_destination.yml
@@ -1,6 +1,6 @@
name: Windows Curl Upload to Remote Destination
id: 42f8f1a2-4228-11ec-aade-acde48001122
-version: 6
+version: 7
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_default_group_policy_object_modified.yml b/detections/endpoint/windows_default_group_policy_object_modified.yml
index 4955cf8b89..efebc1aedd 100644
--- a/detections/endpoint/windows_default_group_policy_object_modified.yml
+++ b/detections/endpoint/windows_default_group_policy_object_modified.yml
@@ -1,7 +1,7 @@
name: Windows Default Group Policy Object Modified
id: fe6a6cc4-9e0d-4d66-bcf4-2c7f44860876
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- - T1484
- T1484.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_default_group_policy_object_modified_with_gpme.yml b/detections/endpoint/windows_default_group_policy_object_modified_with_gpme.yml
index 6c21379d47..51664cc7ba 100644
--- a/detections/endpoint/windows_default_group_policy_object_modified_with_gpme.yml
+++ b/detections/endpoint/windows_default_group_policy_object_modified_with_gpme.yml
@@ -1,7 +1,7 @@
name: Windows Default Group Policy Object Modified with GPME
id: eaf688b3-bb8f-454d-b105-920a862cd8cb
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -73,7 +73,6 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- - T1484
- T1484.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_defender_exclusion_registry_entry.yml b/detections/endpoint/windows_defender_exclusion_registry_entry.yml
index f097a09992..185bb0b799 100644
--- a/detections/endpoint/windows_defender_exclusion_registry_entry.yml
+++ b/detections/endpoint/windows_defender_exclusion_registry_entry.yml
@@ -1,7 +1,7 @@
name: Windows Defender Exclusion Registry Entry
id: 13395a44-4dd9-11ec-9df7-acde48001122
-version: 8
-date: '2024-12-08'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -66,7 +66,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_delete_or_modify_system_firewall.yml b/detections/endpoint/windows_delete_or_modify_system_firewall.yml
index bcb293d9d4..db9789944c 100644
--- a/detections/endpoint/windows_delete_or_modify_system_firewall.yml
+++ b/detections/endpoint/windows_delete_or_modify_system_firewall.yml
@@ -1,7 +1,7 @@
name: Windows Delete or Modify System Firewall
id: b188d11a-eba7-419d-b8b6-cc265b4f2c4f
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -61,7 +61,6 @@ tags:
- ShrinkLocker
asset_type: Endpoint
mitre_attack_id:
- - T1562
- T1562.004
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_detect_network_scanner_behavior.yml b/detections/endpoint/windows_detect_network_scanner_behavior.yml
index 7a05993d0d..0f75aeb776 100644
--- a/detections/endpoint/windows_detect_network_scanner_behavior.yml
+++ b/detections/endpoint/windows_detect_network_scanner_behavior.yml
@@ -1,63 +1,80 @@
-name: Windows Detect Network Scanner Behavior
-id: 78e678d2-bf64-4fe6-aa52-2f7b11dddee7
-version: 2
-date: '2025-01-09'
-author: Steven Dick
-status: production
-type: Anomaly
-description: The following analytic detects when an application is used to connect a large number of unique ports/targets within a short time frame. Network enumeration may be used by adversaries as a method of discovery, lateral movement, or remote execution. This analytic may require significant tuning depending on the organization and applications being actively used, highly recommended to pre-populate the filter macro prior to activation.
-data_source:
-- Sysmon EventID 3
-search: '| tstats `security_content_summariesonly` count latest(All_Traffic.dest_port) as dest_port dc(All_Traffic.dest_port) as port_count dc(All_Traffic.dest) as dest_count min(_time) as firstTime max(_time) as lastTime values(All_Traffic.process_id) as process_id from datamodel=Network_Traffic.All_Traffic where sourcetype=XmlWinEventLog All_Traffic.app = "*\\*" All_Traffic.dest_port < 32000 NOT All_Traffic.dest_port IN (8443,8080,5353,3268,443,389,88,80,53,25) by host,All_Traffic.app,All_Traffic.src,All_Traffic.src_ip,All_Traffic.user _time span=5m
-| `drop_dm_object_name(All_Traffic)`
-| rex field=app ".*\\\(?.*)$"
-| where port_count > 10 OR dest_count > 10
-| stats latest(src) as src, latest(src_ip) as src_ip, max(dest_count) as dest_count, max(port_count) as port_count, latest(dest_port) as dest_port, min(firstTime) as firstTime, max(lastTime) as lastTime, max(count) as count by host,user,app,process_name
-| `security_content_ctime(firstTime)`
-| `security_content_ctime(lastTime)`
-| `windows_detect_network_scanner_behavior_filter`'
-how_to_implement: This detection relies on Sysmon EventID 3 events being ingested AND tagged into the Network_Traffic datamodel.
-known_false_positives: Various, could be noisy depending on processes in the organization and sysmon configuration used. Adjusted port/dest count thresholds as needed.
-references:
-- https://attack.mitre.org/techniques/T1595
-drilldown_searches:
-- name: View the detection results for - "$src$" and "$user$"
- search: '%original_detection_search% | search src = "$src$" user = "$user$"'
- earliest_offset: $info_min_time$
- latest_offset: $info_max_time$
-- name: View risk events for the last 7 days for - "$src$" and "$user$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
- earliest_offset: $info_min_time$
- latest_offset: $info_max_time$
-rba:
- message: A process exhibiting network scanning behavior [$process_name$] was detected on $src$
- risk_objects:
- - field: src
- type: system
- score: 25
- - field: user
- type: user
- score: 25
- threat_objects:
- - field: process_name
- type: process_name
-tags:
- analytic_story:
- - Network Discovery
- - Windows Discovery Techniques
- asset_type: Endpoint
- mitre_attack_id:
- - T1595
- - T1595.001
- - T1595.002
- product:
- - Splunk Enterprise
- - Splunk Enterprise Security
- - Splunk Cloud
- security_domain: network
-tests:
-- name: True Positive Test
- attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1595/sysmon_scanning_events/sysmon_scanning_events.log
- source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
- sourcetype: XmlWinEventLog
+name: Windows Detect Network Scanner Behavior
+id: 78e678d2-bf64-4fe6-aa52-2f7b11dddee7
+version: 4
+date: '2025-02-10'
+author: Steven Dick
+status: production
+type: Anomaly
+description: The following analytic detects when an application is used to connect
+ a large number of unique ports/targets within a short time frame. Network enumeration
+ may be used by adversaries as a method of discovery, lateral movement, or remote
+ execution. This analytic may require significant tuning depending on the organization
+ and applications being actively used, highly recommended to pre-populate the filter
+ macro prior to activation.
+data_source:
+- Sysmon EventID 3
+search: '| tstats `security_content_summariesonly` count latest(All_Traffic.dest_port)
+ as dest_port dc(All_Traffic.dest_port) as port_count dc(All_Traffic.dest) as dest_count
+ min(_time) as firstTime max(_time) as lastTime values(All_Traffic.process_id) as
+ process_id from datamodel=Network_Traffic.All_Traffic where sourcetype=XmlWinEventLog
+ All_Traffic.app = "*\\*" All_Traffic.dest_port < 32000 NOT All_Traffic.dest_port
+ IN (8443,8080,5353,3268,443,389,88,80,53,25) by host,All_Traffic.app,All_Traffic.src,All_Traffic.src_ip,All_Traffic.user
+ _time span=5m | `drop_dm_object_name(All_Traffic)` | rex field=app ".*\\\(?.*)$"
+ | where port_count > 10 OR dest_count > 10 | stats latest(src) as src, latest(src_ip)
+ as src_ip, max(dest_count) as dest_count, max(port_count) as port_count, latest(dest_port)
+ as dest_port, min(firstTime) as firstTime, max(lastTime) as lastTime, max(count)
+ as count by host,user,app,process_name | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
+ | `windows_detect_network_scanner_behavior_filter`'
+how_to_implement: This detection relies on Sysmon EventID 3 events being ingested
+ AND tagged into the Network_Traffic datamodel.
+known_false_positives: Various, could be noisy depending on processes in the organization
+ and sysmon configuration used. Adjusted port/dest count thresholds as needed.
+references:
+- https://attack.mitre.org/techniques/T1595
+drilldown_searches:
+- name: View the detection results for - "$src$" and "$user$"
+ search: '%original_detection_search% | search src = "$src$" user = "$user$"'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: View risk events for the last 7 days for - "$src$" and "$user$"
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+rba:
+ message: A process exhibiting network scanning behavior [$process_name$] was detected
+ on $src$
+ risk_objects:
+ - field: src
+ type: system
+ score: 25
+ - field: user
+ type: user
+ score: 25
+ threat_objects:
+ - field: process_name
+ type: process_name
+tags:
+ analytic_story:
+ - Network Discovery
+ - Windows Discovery Techniques
+ asset_type: Endpoint
+ mitre_attack_id:
+ - T1595.001
+ - T1595.002
+ product:
+ - Splunk Enterprise
+ - Splunk Enterprise Security
+ - Splunk Cloud
+ security_domain: network
+tests:
+- name: True Positive Test
+ attack_data:
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1595/sysmon_scanning_events/sysmon_scanning_events.log
+ source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
+ sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_disable_memory_crash_dump.yml b/detections/endpoint/windows_disable_memory_crash_dump.yml
index c8c1b362d2..c53c115e73 100644
--- a/detections/endpoint/windows_disable_memory_crash_dump.yml
+++ b/detections/endpoint/windows_disable_memory_crash_dump.yml
@@ -1,6 +1,6 @@
name: Windows Disable Memory Crash Dump
id: 59e54602-9680-11ec-a8a6-acde48001122
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml b/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml
index b21faffa59..89f5df049c 100644
--- a/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml
+++ b/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml
@@ -1,7 +1,7 @@
name: Windows Disable or Modify Tools Via Taskkill
id: a43ae66f-c410-4b3d-8741-9ce1ad17ddb0
-version: 6
-date: '2024-11-22'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -67,7 +67,6 @@ tags:
- Crypto Stealer
asset_type: Endpoint
mitre_attack_id:
- - T1562
- T1562.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_disable_or_stop_browser_process.yml b/detections/endpoint/windows_disable_or_stop_browser_process.yml
index 3c49e0a8d1..2447b0a67e 100644
--- a/detections/endpoint/windows_disable_or_stop_browser_process.yml
+++ b/detections/endpoint/windows_disable_or_stop_browser_process.yml
@@ -1,10 +1,10 @@
name: Windows Disable or Stop Browser Process
id: 220d34b7-b6c7-45fe-8dbb-c35cdd9fe6d5
-version: 2
-date: '2024-11-13'
+version: 3
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
data_source:
-- Sysmon Event ID 1
+- Sysmon EventID 1
type: TTP
status: production
description: The following analytic detects the use of the taskkill command in a process
@@ -66,7 +66,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_disable_windows_event_logging_disable_http_logging.yml b/detections/endpoint/windows_disable_windows_event_logging_disable_http_logging.yml
index 8419dcfa0e..05bec76722 100644
--- a/detections/endpoint/windows_disable_windows_event_logging_disable_http_logging.yml
+++ b/detections/endpoint/windows_disable_windows_event_logging_disable_http_logging.yml
@@ -1,7 +1,7 @@
name: Windows Disable Windows Event Logging Disable HTTP Logging
id: 23fb6787-255f-4d5b-9a66-9fd7504032b5
-version: 6
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -77,10 +77,8 @@ tags:
- Windows Defense Evasion Tactics
asset_type: Endpoint
mitre_attack_id:
- - T1562.002
- - T1562
- - T1505
- T1505.004
+ - T1562.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_disableantispyware_registry.yml b/detections/endpoint/windows_disableantispyware_registry.yml
index 4395bd7e96..0dda67a09d 100644
--- a/detections/endpoint/windows_disableantispyware_registry.yml
+++ b/detections/endpoint/windows_disableantispyware_registry.yml
@@ -1,7 +1,7 @@
name: Windows DisableAntiSpyware Registry
id: 23150a40-9301-4195-b802-5bb4f43067fb
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Rod Soto, Jose Hernandez, Michael Haag, Splunk
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_dism_remove_defender.yml b/detections/endpoint/windows_dism_remove_defender.yml
index 8a4786b5ea..8371b710fb 100644
--- a/detections/endpoint/windows_dism_remove_defender.yml
+++ b/detections/endpoint/windows_dism_remove_defender.yml
@@ -1,7 +1,7 @@
name: Windows DISM Remove Defender
id: 8567da9e-47f0-11ec-99a9-acde48001122
-version: 6
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -74,7 +74,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml b/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml
index 69a5506c40..709369aecf 100644
--- a/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml
+++ b/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml
@@ -1,7 +1,7 @@
name: Windows DLL Search Order Hijacking Hunt with Sysmon
id: 79c7d1fc-64c7-91be-a616-ccda752efe81
-version: 7
-date: '2024-11-13'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -35,7 +35,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1574.001
- - T1574
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_dll_search_order_hijacking_with_iscsicpl.yml b/detections/endpoint/windows_dll_search_order_hijacking_with_iscsicpl.yml
index 5ddb5d8355..d5d279ce64 100644
--- a/detections/endpoint/windows_dll_search_order_hijacking_with_iscsicpl.yml
+++ b/detections/endpoint/windows_dll_search_order_hijacking_with_iscsicpl.yml
@@ -1,6 +1,6 @@
name: Windows DLL Search Order Hijacking with iscsicpl
id: f39ee679-3b1e-4f47-841c-5c3c580acda2
-version: 6
+version: 7
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_dll_side_loading_in_calc.yml b/detections/endpoint/windows_dll_side_loading_in_calc.yml
index bbaa20e218..6e02110e63 100644
--- a/detections/endpoint/windows_dll_side_loading_in_calc.yml
+++ b/detections/endpoint/windows_dll_side_loading_in_calc.yml
@@ -1,7 +1,7 @@
name: Windows DLL Side-Loading In Calc
id: af01f6db-26ac-440e-8d89-2793e303f137
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1574.002
- - T1574
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml b/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml
index 1e661f00bf..3d856442b6 100644
--- a/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml
+++ b/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml
@@ -1,7 +1,7 @@
name: Windows DLL Side-Loading Process Child Of Calc
id: 295ca9ed-e97b-4520-90f7-dfb6469902e1
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -62,7 +62,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1574.002
- - T1574
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_dns_query_request_by_telegram_bot_api.yml b/detections/endpoint/windows_dns_query_request_by_telegram_bot_api.yml
index 39e7c9496e..94664fd032 100644
--- a/detections/endpoint/windows_dns_query_request_by_telegram_bot_api.yml
+++ b/detections/endpoint/windows_dns_query_request_by_telegram_bot_api.yml
@@ -1,20 +1,27 @@
name: Windows DNS Query Request by Telegram Bot API
id: 86f66f44-94d9-412d-a71d-5d8ed0fef72e
-version: 1
-date: '2024-12-12'
+version: 2
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
data_source:
- Sysmon EventID 22
type: Anomaly
status: production
-description: The following analytic detects the execution of a DNS query by a process to the associated Telegram API domain, which could indicate access via a Telegram bot commonly used by malware for command and control (C2) communications. By monitoring DNS queries related to Telegram's infrastructure, the detection identifies potential attempts to establish covert communication channels between a compromised system and external malicious actors. This behavior is often observed in cyberattacks where Telegram bots are used to receive commands or exfiltrate data, making it a key indicator of suspicious or malicious activity within a network.
+description: The following analytic detects the execution of a DNS query by a process
+ to the associated Telegram API domain, which could indicate access via a Telegram
+ bot commonly used by malware for command and control (C2) communications. By monitoring
+ DNS queries related to Telegram's infrastructure, the detection identifies potential
+ attempts to establish covert communication channels between a compromised system
+ and external malicious actors. This behavior is often observed in cyberattacks where
+ Telegram bots are used to receive commands or exfiltrate data, making it a key indicator
+ of suspicious or malicious activity within a network.
search: '`sysmon` EventCode=22 query = "api.telegram.org" process_name != "telegram.exe"
- | stats count min(_time) as firstTime max(_time) as lastTime by query answer QueryResults QueryStatus process_name process_guid Computer
- | rename Computer as dest
- | `security_content_ctime(firstTime)`
- | `security_content_ctime(lastTime)`
- | `windows_dns_query_request_by_telegram_bot_api_filter`'
-how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name and eventcode = 22 dnsquery executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
+ | stats count min(_time) as firstTime max(_time) as lastTime by query answer QueryResults
+ QueryStatus process_name process_guid Computer | rename Computer as dest | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)` | `windows_dns_query_request_by_telegram_bot_api_filter`'
+how_to_implement: To successfully implement this search, you need to be ingesting
+ logs with the process name and eventcode = 22 dnsquery executions from your endpoints.
+ If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
known_false_positives: a third part automation using telegram API.
references:
- https://www.splunk.com/en_us/blog/security/threat-advisory-telegram-crypto-botnet-strt-ta01.html
@@ -24,7 +31,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -39,10 +51,8 @@ tags:
- Crypto Stealer
asset_type: Endpoint
mitre_attack_id:
- - T1102.002
- T1071.004
- - T1071
- - T1102
+ - T1102.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -51,6 +61,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1102.002/telegram_api_dns/telegram_dns.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1102.002/telegram_api_dns/telegram_dns.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_domain_account_discovery_via_get_netcomputer.yml b/detections/endpoint/windows_domain_account_discovery_via_get_netcomputer.yml
index eb09f87426..ad894aeeb8 100644
--- a/detections/endpoint/windows_domain_account_discovery_via_get_netcomputer.yml
+++ b/detections/endpoint/windows_domain_account_discovery_via_get_netcomputer.yml
@@ -1,7 +1,7 @@
name: Windows Domain Account Discovery Via Get-NetComputer
id: a7fbbc4e-4571-424a-b627-6968e1c939e4
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -53,7 +53,6 @@ tags:
- CISA AA23-347A
asset_type: Endpoint
mitre_attack_id:
- - T1087
- T1087.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml b/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml
index a356cdce76..55465e1839 100644
--- a/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml
+++ b/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml
@@ -1,7 +1,7 @@
name: Windows DotNet Binary in Non Standard Path
id: fddf3b56-7933-11ec-98a6-acde48001122
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -82,9 +82,7 @@ tags:
- WhisperGate
asset_type: Endpoint
mitre_attack_id:
- - T1036
- T1036.003
- - T1218
- T1218.004
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_driver_load_non_standard_path.yml b/detections/endpoint/windows_driver_load_non_standard_path.yml
index bf5adb05b7..e36e98bcbd 100644
--- a/detections/endpoint/windows_driver_load_non_standard_path.yml
+++ b/detections/endpoint/windows_driver_load_non_standard_path.yml
@@ -1,7 +1,7 @@
name: Windows Driver Load Non-Standard Path
id: 9216ef3d-066a-4958-8f27-c84589465e62
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-01-27'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -17,7 +17,7 @@ data_source:
- Windows Event Log System 7045
search: >-
`wineventlog_system` EventCode=7045 ServiceType="kernel mode driver"
- | regex ImagePath!="(?i)^(\w:\\\\Windows\\\\|\w:\\\\Program\sFile|\\\\systemroot\\\\|%SystemRoot%|system32\\\\)"
+ | regex ImagePath!="(?i)^(\w:\\\\Windows\\\\|\w:\\\\Program\sFile|\\\\systemroot\\\\|%SystemRoot%|system32\\\\|\\\\ProgramData\\\\Microsoft\\\\Windows\sDefender\\\\Definition\sUpdates\\\\)"
| stats count min(_time) as firstTime max(_time) as lastTime by Computer EventCode
ImagePath ServiceName ServiceType | rename Computer as dest | `security_content_ctime(firstTime)` |
`security_content_ctime(lastTime)` | `windows_driver_load_non_standard_path_filter`
diff --git a/detections/endpoint/windows_esx_admins_group_creation_via_net.yml b/detections/endpoint/windows_esx_admins_group_creation_via_net.yml
index 0fecbadc81..373e172977 100644
--- a/detections/endpoint/windows_esx_admins_group_creation_via_net.yml
+++ b/detections/endpoint/windows_esx_admins_group_creation_via_net.yml
@@ -1,6 +1,6 @@
name: Windows ESX Admins Group Creation via Net
id: 3d7df60b-3332-4667-8090-afe03e08dce0
-version: 4
+version: 5
date: '2025-01-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_esx_admins_group_creation_via_powershell.yml b/detections/endpoint/windows_esx_admins_group_creation_via_powershell.yml
index 71b3808e94..fd301786bb 100644
--- a/detections/endpoint/windows_esx_admins_group_creation_via_powershell.yml
+++ b/detections/endpoint/windows_esx_admins_group_creation_via_powershell.yml
@@ -1,6 +1,6 @@
name: Windows ESX Admins Group Creation via PowerShell
id: f48a5557-be06-4b96-b8e8-be563e387620
-version: 3
+version: 4
date: '2024-11-13'
author: Michael Haag, Splunk
data_source:
diff --git a/detections/endpoint/windows_event_for_service_disabled.yml b/detections/endpoint/windows_event_for_service_disabled.yml
index 070028f5ee..aef5a45b51 100644
--- a/detections/endpoint/windows_event_for_service_disabled.yml
+++ b/detections/endpoint/windows_event_for_service_disabled.yml
@@ -1,7 +1,7 @@
name: Windows Event For Service Disabled
id: 9c2620a8-94a1-11ec-b40c-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -32,7 +32,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_event_log_cleared.yml b/detections/endpoint/windows_event_log_cleared.yml
index 2bfd8a88e7..cff4ffa150 100644
--- a/detections/endpoint/windows_event_log_cleared.yml
+++ b/detections/endpoint/windows_event_log_cleared.yml
@@ -1,7 +1,7 @@
name: Windows Event Log Cleared
id: ad517544-aff9-4c96-bd99-d6eb43bfbb6a
-version: 12
-date: '2024-12-10'
+version: 13
+date: '2025-02-10'
author: Rico Valdez, Michael Haag, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
- Clop Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1070
- T1070.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_excessive_disabled_services_event.yml b/detections/endpoint/windows_excessive_disabled_services_event.yml
index 9f17eac2d5..047bd056e9 100644
--- a/detections/endpoint/windows_excessive_disabled_services_event.yml
+++ b/detections/endpoint/windows_excessive_disabled_services_event.yml
@@ -1,7 +1,7 @@
name: Windows Excessive Disabled Services Event
id: c3f85976-94a5-11ec-9a58-acde48001122
-version: 7
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -56,7 +56,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_excessive_usage_of_net_app.yml b/detections/endpoint/windows_excessive_usage_of_net_app.yml
index 68d8e0a30f..10716cc575 100644
--- a/detections/endpoint/windows_excessive_usage_of_net_app.yml
+++ b/detections/endpoint/windows_excessive_usage_of_net_app.yml
@@ -1,6 +1,6 @@
name: Windows Excessive Usage Of Net App
id: 355ba810-0a20-4215-8485-9ce3f87f2e38
-version: 1
+version: 2
date: '2025-01-13'
author: Teoderick Contreras, Splunk
status: production
diff --git a/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml b/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml
index 576e79a52b..abbcec0359 100644
--- a/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml
+++ b/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml
@@ -1,6 +1,6 @@
name: Windows Execute Arbitrary Commands with MSDT
id: e1d5145f-38fe-42b9-a5d5-457796715f97
-version: 8
+version: 9
date: '2024-12-10'
author: Michael Haag, Teoderick Contreras, Splunk
status: production
diff --git a/detections/endpoint/windows_export_certificate.yml b/detections/endpoint/windows_export_certificate.yml
index bb27c581d8..745605dc64 100644
--- a/detections/endpoint/windows_export_certificate.yml
+++ b/detections/endpoint/windows_export_certificate.yml
@@ -1,7 +1,7 @@
name: Windows Export Certificate
id: d8ddfa9b-b724-4df9-9dbe-f34cc0936714
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Anomaly
@@ -51,7 +51,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1552.004
- - T1552
- T1649
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_file_transfer_protocol_in_non_common_process_path.yml b/detections/endpoint/windows_file_transfer_protocol_in_non_common_process_path.yml
index 314c2ed9fd..cbe465f6fb 100644
--- a/detections/endpoint/windows_file_transfer_protocol_in_non_common_process_path.yml
+++ b/detections/endpoint/windows_file_transfer_protocol_in_non_common_process_path.yml
@@ -1,7 +1,7 @@
name: Windows File Transfer Protocol In Non-Common Process Path
id: 0f43758f-1fe9-470a-a9e4-780acc4d5407
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -57,7 +57,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1071.003
- - T1071
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_files_and_dirs_access_rights_modification_via_icacls.yml b/detections/endpoint/windows_files_and_dirs_access_rights_modification_via_icacls.yml
index 6f4b92d1c5..356e3e7925 100644
--- a/detections/endpoint/windows_files_and_dirs_access_rights_modification_via_icacls.yml
+++ b/detections/endpoint/windows_files_and_dirs_access_rights_modification_via_icacls.yml
@@ -1,7 +1,7 @@
name: Windows Files and Dirs Access Rights Modification Via Icacls
id: c76b796c-27e1-4520-91c4-4a58695c749e
-version: 5
-date: '2024-12-16'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -72,7 +72,6 @@ tags:
- 3309f53e-b22b-4eb6-8fd2-a6cf58b355a9
mitre_attack_id:
- T1222.001
- - T1222
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml b/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml
index 936ae3761c..dd165dc33e 100644
--- a/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml
+++ b/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml
@@ -1,7 +1,7 @@
name: Windows Find Domain Organizational Units with GetDomainOU
id: 0ada2f82-b7af-40cc-b1d7-1e5985afcb4e
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1087
- T1087.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml b/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml
index e855820ea9..ffed352753 100644
--- a/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml
+++ b/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml
@@ -1,7 +1,7 @@
name: Windows Find Interesting ACL with FindInterestingDomainAcl
id: e4a96dfd-667a-4487-b942-ccef5a1e81e8
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1087
- T1087.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_findstr_gpp_discovery.yml b/detections/endpoint/windows_findstr_gpp_discovery.yml
index b141be9c81..2ce7f83865 100644
--- a/detections/endpoint/windows_findstr_gpp_discovery.yml
+++ b/detections/endpoint/windows_findstr_gpp_discovery.yml
@@ -1,7 +1,7 @@
name: Windows Findstr GPP Discovery
id: 1631ac2d-f2a9-42fa-8a59-d6e210d472f5
-version: 4
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
type: TTP
status: production
@@ -70,7 +70,6 @@ tags:
- Active Directory Privilege Escalation
asset_type: Endpoint
mitre_attack_id:
- - T1552
- T1552.006
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml b/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml
index aac21bf7bb..c8bcb30a51 100644
--- a/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml
+++ b/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml
@@ -1,7 +1,7 @@
name: Windows Forest Discovery with GetForestDomain
id: a14803b2-4bd9-4c08-8b57-c37980edebe8
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1087
- T1087.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_gather_victim_host_information_camera.yml b/detections/endpoint/windows_gather_victim_host_information_camera.yml
index 44ac29e470..9bf473e971 100644
--- a/detections/endpoint/windows_gather_victim_host_information_camera.yml
+++ b/detections/endpoint/windows_gather_victim_host_information_camera.yml
@@ -1,7 +1,7 @@
name: Windows Gather Victim Host Information Camera
id: e4df4676-ea41-4397-b160-3ee0140dc332
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -59,7 +59,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1592.001
- - T1592
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_gather_victim_identity_sam_info.yml b/detections/endpoint/windows_gather_victim_identity_sam_info.yml
index 58829b5f21..783965ba95 100644
--- a/detections/endpoint/windows_gather_victim_identity_sam_info.yml
+++ b/detections/endpoint/windows_gather_victim_identity_sam_info.yml
@@ -1,7 +1,7 @@
name: Windows Gather Victim Identity SAM Info
id: a18e85d7-8b98-4399-820c-d46a1ca3516f
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -34,7 +34,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1589.001
- - T1589
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_gather_victim_network_info_through_ip_check_web_services.yml b/detections/endpoint/windows_gather_victim_network_info_through_ip_check_web_services.yml
index 1f6f6dcc37..ddc18ae497 100644
--- a/detections/endpoint/windows_gather_victim_network_info_through_ip_check_web_services.yml
+++ b/detections/endpoint/windows_gather_victim_network_info_through_ip_check_web_services.yml
@@ -1,7 +1,7 @@
name: Windows Gather Victim Network Info Through Ip Check Web Services
id: 70f7c952-0758-46d6-9148-d8969c4481d1
-version: 8
-date: '2024-12-10'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -42,7 +42,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1590.005
- - T1590
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml b/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml
index 8d7779ac20..79e2ef2681 100644
--- a/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml
+++ b/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml
@@ -1,7 +1,7 @@
name: Windows Get Local Admin with FindLocalAdminAccess
id: d2988160-3ce9-4310-b59d-905334920cdd
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1087
- T1087.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_group_discovery_via_net.yml b/detections/endpoint/windows_group_discovery_via_net.yml
index b351dac9de..bd02d34030 100644
--- a/detections/endpoint/windows_group_discovery_via_net.yml
+++ b/detections/endpoint/windows_group_discovery_via_net.yml
@@ -1,17 +1,37 @@
name: Windows Group Discovery Via Net
id: c5c8e0f3-147a-43da-bf04-4cfaec27dc44
-version: 1
-date: '2025-01-13'
+version: 2
+date: '2025-02-10'
author: Michael Haag, Mauricio Velazco, Splunk
status: production
type: Hunting
-description: The following analytic identifies the execution of `net.exe` with command-line arguments used to query global, local and domain groups. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments. This activity is significant as it indicates potential reconnaissance efforts by adversaries to enumerate local or domain groups, which is a common step in Active Directory or privileged accounts discovery. If confirmed malicious, this behavior could allow attackers to gain insights into the domain structure, aiding in further attacks such as privilege escalation or lateral movement.
+description: The following analytic identifies the execution of `net.exe` with command-line
+ arguments used to query global, local and domain groups. It leverages data from
+ Endpoint Detection and Response (EDR) agents, focusing on process names and command-line
+ arguments. This activity is significant as it indicates potential reconnaissance
+ efforts by adversaries to enumerate local or domain groups, which is a common step
+ in Active Directory or privileged accounts discovery. If confirmed malicious, this
+ behavior could allow attackers to gain insights into the domain structure, aiding
+ in further attacks such as privilege escalation or lateral movement.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
-search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` Processes.process="*group*" AND NOT (Processes.process="*/add" OR Processes.process="*/delete") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_group_discovery_via_net_filter`'
-how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
+search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
+ as lastTime from datamodel=Endpoint.Processes where `process_net` Processes.process="*group*"
+ AND NOT (Processes.process="*/add" OR Processes.process="*/delete") by Processes.dest
+ Processes.user Processes.parent_process Processes.process_name Processes.process
+ Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
+ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_group_discovery_via_net_filter`'
+how_to_implement: The detection is based on data that originates from Endpoint Detection
+ and Response (EDR) agents. These agents are designed to provide security-related
+ telemetry from the endpoints where the agent is installed. To implement this search,
+ you must ingest logs that contain the process GUID, process name, and parent process.
+ Additionally, you must ingest complete command-line executions. These logs must
+ be processed using the appropriate Splunk Technology Add-ons that are specific to
+ the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
+ data model. Use the Splunk Common Information Model (CIM) to normalize the field
+ names and speed up the data modeling process.
known_false_positives: Administrators or power users may use this command for troubleshooting.
references:
- https://attack.mitre.org/techniques/T1069/002/
@@ -33,7 +53,6 @@ tags:
- Azorult
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.001
- T1069.002
product:
@@ -44,11 +63,13 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
- sourcetype: XmlWinEventLog
\ No newline at end of file
+ sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_group_policy_object_created.yml b/detections/endpoint/windows_group_policy_object_created.yml
index f3a08ffa82..bd4406e610 100644
--- a/detections/endpoint/windows_group_policy_object_created.yml
+++ b/detections/endpoint/windows_group_policy_object_created.yml
@@ -1,7 +1,7 @@
name: Windows Group Policy Object Created
id: 23add2a8-ea22-4fd4-8bc0-8c0b822373a1
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco
status: production
type: TTP
@@ -61,9 +61,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- - T1484
- - T1484.001
- T1078.002
+ - T1484.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_hijack_execution_flow_version_dll_side_load.yml b/detections/endpoint/windows_hijack_execution_flow_version_dll_side_load.yml
index 392783e8d3..20958cf465 100644
--- a/detections/endpoint/windows_hijack_execution_flow_version_dll_side_load.yml
+++ b/detections/endpoint/windows_hijack_execution_flow_version_dll_side_load.yml
@@ -1,7 +1,7 @@
name: Windows Hijack Execution Flow Version Dll Side Load
id: 8351340b-ac0e-41ec-8b07-dd01bf32d6ea
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -53,7 +53,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1574.001
- - T1574
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_http_network_communication_from_msiexec.yml b/detections/endpoint/windows_http_network_communication_from_msiexec.yml
index 46426413d7..d312721aa7 100644
--- a/detections/endpoint/windows_http_network_communication_from_msiexec.yml
+++ b/detections/endpoint/windows_http_network_communication_from_msiexec.yml
@@ -1,6 +1,6 @@
name: Windows HTTP Network Communication From MSIExec
id: b0fd38c7-f71a-43a2-870e-f3ca06bcdd99
-version: 1
+version: 2
date: '2025-01-17'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_hunting_system_account_targeting_lsass.yml b/detections/endpoint/windows_hunting_system_account_targeting_lsass.yml
index 8dd3e10940..f839a81cb1 100644
--- a/detections/endpoint/windows_hunting_system_account_targeting_lsass.yml
+++ b/detections/endpoint/windows_hunting_system_account_targeting_lsass.yml
@@ -1,7 +1,7 @@
name: Windows Hunting System Account Targeting Lsass
id: 1c6abb08-73d1-11ec-9ca0-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -38,7 +38,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.001
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_iis_components_add_new_module.yml b/detections/endpoint/windows_iis_components_add_new_module.yml
index bd66a0d8fb..b8e4617559 100644
--- a/detections/endpoint/windows_iis_components_add_new_module.yml
+++ b/detections/endpoint/windows_iis_components_add_new_module.yml
@@ -1,7 +1,7 @@
name: Windows IIS Components Add New Module
id: 38fe731c-1f13-43d4-b878-a5bbe44807e3
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Anomaly
@@ -76,7 +76,6 @@ tags:
- IIS Components
asset_type: Endpoint
mitre_attack_id:
- - T1505
- T1505.004
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_iis_components_get_webglobalmodule_module_query.yml b/detections/endpoint/windows_iis_components_get_webglobalmodule_module_query.yml
index 25f6016ba5..67cbd0e5c9 100644
--- a/detections/endpoint/windows_iis_components_get_webglobalmodule_module_query.yml
+++ b/detections/endpoint/windows_iis_components_get_webglobalmodule_module_query.yml
@@ -1,7 +1,7 @@
name: Windows IIS Components Get-WebGlobalModule Module Query
id: 20db5f70-34b4-4e83-8926-fa26119de173
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -33,7 +33,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1505.004
- - T1505
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_iis_components_module_failed_to_load.yml b/detections/endpoint/windows_iis_components_module_failed_to_load.yml
index cf09db6fe1..292c33dcc8 100644
--- a/detections/endpoint/windows_iis_components_module_failed_to_load.yml
+++ b/detections/endpoint/windows_iis_components_module_failed_to_load.yml
@@ -1,7 +1,7 @@
name: Windows IIS Components Module Failed to Load
id: 40c2ba5b-dd6a-496b-9e6e-c9524d0be167
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Anomaly
@@ -56,7 +56,6 @@ tags:
- IIS Components
asset_type: Endpoint
mitre_attack_id:
- - T1505
- T1505.004
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_iis_components_new_module_added.yml b/detections/endpoint/windows_iis_components_new_module_added.yml
index 6b24987b30..3042160dcc 100644
--- a/detections/endpoint/windows_iis_components_new_module_added.yml
+++ b/detections/endpoint/windows_iis_components_new_module_added.yml
@@ -1,7 +1,7 @@
name: Windows IIS Components New Module Added
id: 55f22929-cfd3-4388-ba5c-4d01fac7ee7e
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -56,7 +56,6 @@ tags:
- IIS Components
asset_type: Endpoint
mitre_attack_id:
- - T1505
- T1505.004
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml b/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml
index 2bc0b705bb..9b97d2d1cf 100644
--- a/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml
+++ b/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Add Xml Applocker Rules
id: 467ed9d9-8035-470e-ad5e-ae5189283033
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -43,7 +43,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_change_win_defender_health_check_intervals.yml b/detections/endpoint/windows_impair_defense_change_win_defender_health_check_intervals.yml
index 5ce4ca602b..01111a8dfa 100644
--- a/detections/endpoint/windows_impair_defense_change_win_defender_health_check_intervals.yml
+++ b/detections/endpoint/windows_impair_defense_change_win_defender_health_check_intervals.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Change Win Defender Health Check Intervals
id: 5211c260-820e-4366-b983-84bbfb5c263a
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_change_win_defender_quick_scan_interval.yml b/detections/endpoint/windows_impair_defense_change_win_defender_quick_scan_interval.yml
index a04ac54542..9bd8d4dcd9 100644
--- a/detections/endpoint/windows_impair_defense_change_win_defender_quick_scan_interval.yml
+++ b/detections/endpoint/windows_impair_defense_change_win_defender_quick_scan_interval.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Change Win Defender Quick Scan Interval
id: 783f0798-f679-4c17-b3b3-187febf0b9b8
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -59,7 +59,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_change_win_defender_throttle_rate.yml b/detections/endpoint/windows_impair_defense_change_win_defender_throttle_rate.yml
index 0be8d9fe47..56fe8964d2 100644
--- a/detections/endpoint/windows_impair_defense_change_win_defender_throttle_rate.yml
+++ b/detections/endpoint/windows_impair_defense_change_win_defender_throttle_rate.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Change Win Defender Throttle Rate
id: f7da5fca-9261-43de-a4d0-130dad1e4f4d
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_change_win_defender_tracing_level.yml b/detections/endpoint/windows_impair_defense_change_win_defender_tracing_level.yml
index a4a8c000b8..6f1170901c 100644
--- a/detections/endpoint/windows_impair_defense_change_win_defender_tracing_level.yml
+++ b/detections/endpoint/windows_impair_defense_change_win_defender_tracing_level.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Change Win Defender Tracing Level
id: fe9391cd-952a-4c64-8f56-727cb0d4f2d4
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_configure_app_install_control.yml b/detections/endpoint/windows_impair_defense_configure_app_install_control.yml
index 4e1f435595..c8924b0876 100644
--- a/detections/endpoint/windows_impair_defense_configure_app_install_control.yml
+++ b/detections/endpoint/windows_impair_defense_configure_app_install_control.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Configure App Install Control
id: c54b7439-cfb1-44c3-bb35-b0409553077c
-version: 5
-date: '2025-01-21'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_define_win_defender_threat_action.yml b/detections/endpoint/windows_impair_defense_define_win_defender_threat_action.yml
index 29afaf77bb..997dcd5e85 100644
--- a/detections/endpoint/windows_impair_defense_define_win_defender_threat_action.yml
+++ b/detections/endpoint/windows_impair_defense_define_win_defender_threat_action.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Define Win Defender Threat Action
id: 7215831c-8252-4ae3-8d43-db588e82f952
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml b/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml
index d8200b4cfd..a259c74bc3 100644
--- a/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml
+++ b/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Delete Win Defender Context Menu
id: 395ed5fe-ad13-4366-9405-a228427bdd91
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -39,7 +39,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml b/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml
index e431440431..c47f826bdd 100644
--- a/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml
+++ b/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Delete Win Defender Profile Registry
id: 65d4b105-ec52-48ec-ac46-289d0fbf7d96
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml b/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml
index 47a77e773c..a6c48f740b 100644
--- a/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml
+++ b/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Deny Security Software With Applocker
id: e0b6ca60-9e29-4450-b51a-bba0abae2313
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -65,7 +65,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_disable_controlled_folder_access.yml b/detections/endpoint/windows_impair_defense_disable_controlled_folder_access.yml
index d6b1155f4e..8f40b00e62 100644
--- a/detections/endpoint/windows_impair_defense_disable_controlled_folder_access.yml
+++ b/detections/endpoint/windows_impair_defense_disable_controlled_folder_access.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Disable Controlled Folder Access
id: 3032741c-d6fc-4c69-8988-be8043d6478c
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_disable_defender_firewall_and_network.yml b/detections/endpoint/windows_impair_defense_disable_defender_firewall_and_network.yml
index 17bd6686b7..9c02486387 100644
--- a/detections/endpoint/windows_impair_defense_disable_defender_firewall_and_network.yml
+++ b/detections/endpoint/windows_impair_defense_disable_defender_firewall_and_network.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Disable Defender Firewall And Network
id: 8467d8cd-b0f9-46fa-ac84-a30ad138983e
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_disable_defender_protocol_recognition.yml b/detections/endpoint/windows_impair_defense_disable_defender_protocol_recognition.yml
index c9c51d2ebb..ae01a2aeff 100644
--- a/detections/endpoint/windows_impair_defense_disable_defender_protocol_recognition.yml
+++ b/detections/endpoint/windows_impair_defense_disable_defender_protocol_recognition.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Disable Defender Protocol Recognition
id: b2215bfb-6171-4137-af17-1a02fdd8d043
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_disable_pua_protection.yml b/detections/endpoint/windows_impair_defense_disable_pua_protection.yml
index 0ec711df2b..9727759c6f 100644
--- a/detections/endpoint/windows_impair_defense_disable_pua_protection.yml
+++ b/detections/endpoint/windows_impair_defense_disable_pua_protection.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Disable PUA Protection
id: fbfef407-cfee-4866-88c1-f8de1c16147c
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_disable_realtime_signature_delivery.yml b/detections/endpoint/windows_impair_defense_disable_realtime_signature_delivery.yml
index 0516b79f28..a609983158 100644
--- a/detections/endpoint/windows_impair_defense_disable_realtime_signature_delivery.yml
+++ b/detections/endpoint/windows_impair_defense_disable_realtime_signature_delivery.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Disable Realtime Signature Delivery
id: ffd99aea-542f-448e-b737-091c1b417274
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_disable_web_evaluation.yml b/detections/endpoint/windows_impair_defense_disable_web_evaluation.yml
index 14fe3afff2..ca7527eacf 100644
--- a/detections/endpoint/windows_impair_defense_disable_web_evaluation.yml
+++ b/detections/endpoint/windows_impair_defense_disable_web_evaluation.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Disable Web Evaluation
id: e234970c-dcf5-4f80-b6a9-3a562544ca5b
-version: 5
-date: '2025-01-21'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_app_guard.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_app_guard.yml
index a9396eab83..4113418ced 100644
--- a/detections/endpoint/windows_impair_defense_disable_win_defender_app_guard.yml
+++ b/detections/endpoint/windows_impair_defense_disable_win_defender_app_guard.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Disable Win Defender App Guard
id: 8b700d7e-54ad-4d7d-81cc-1456c4703306
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_compute_file_hashes.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_compute_file_hashes.yml
index d8d1c3e1dd..0e827549ac 100644
--- a/detections/endpoint/windows_impair_defense_disable_win_defender_compute_file_hashes.yml
+++ b/detections/endpoint/windows_impair_defense_disable_win_defender_compute_file_hashes.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Disable Win Defender Compute File Hashes
id: fe52c280-98bd-4596-b6f6-a13bbf8ac7c6
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_gen_reports.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_gen_reports.yml
index 0b07829d29..508ebf0f28 100644
--- a/detections/endpoint/windows_impair_defense_disable_win_defender_gen_reports.yml
+++ b/detections/endpoint/windows_impair_defense_disable_win_defender_gen_reports.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Disable Win Defender Gen reports
id: 93f114f6-cb1e-419b-ac3f-9e11a3045e70
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_network_protection.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_network_protection.yml
index 2fd33fce86..f97411180b 100644
--- a/detections/endpoint/windows_impair_defense_disable_win_defender_network_protection.yml
+++ b/detections/endpoint/windows_impair_defense_disable_win_defender_network_protection.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Disable Win Defender Network Protection
id: 8b6c15c7-5556-463d-83c7-986326c21f12
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_report_infection.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_report_infection.yml
index 3311e301c4..118feb49cd 100644
--- a/detections/endpoint/windows_impair_defense_disable_win_defender_report_infection.yml
+++ b/detections/endpoint/windows_impair_defense_disable_win_defender_report_infection.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Disable Win Defender Report Infection
id: 201946c6-b1d5-42bb-a7e0-5f7123f47fc4
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_scan_on_update.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_scan_on_update.yml
index 9f723c9a7a..4d35f7fcf8 100644
--- a/detections/endpoint/windows_impair_defense_disable_win_defender_scan_on_update.yml
+++ b/detections/endpoint/windows_impair_defense_disable_win_defender_scan_on_update.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Disable Win Defender Scan On Update
id: 0418e72f-e710-4867-b656-0688e1523e09
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -59,7 +59,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_signature_retirement.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_signature_retirement.yml
index 1f812f4b95..828bc431c3 100644
--- a/detections/endpoint/windows_impair_defense_disable_win_defender_signature_retirement.yml
+++ b/detections/endpoint/windows_impair_defense_disable_win_defender_signature_retirement.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Disable Win Defender Signature Retirement
id: 7567a72f-bada-489d-aef1-59743fb64a66
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_overide_win_defender_phishing_filter.yml b/detections/endpoint/windows_impair_defense_overide_win_defender_phishing_filter.yml
index 89ec865e6b..fa8a6726f1 100644
--- a/detections/endpoint/windows_impair_defense_overide_win_defender_phishing_filter.yml
+++ b/detections/endpoint/windows_impair_defense_overide_win_defender_phishing_filter.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Overide Win Defender Phishing Filter
id: 10ca081c-57b1-4a78-ba56-14a40a7e116a
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_override_smartscreen_prompt.yml b/detections/endpoint/windows_impair_defense_override_smartscreen_prompt.yml
index 89c4b37a2d..25e00f2f42 100644
--- a/detections/endpoint/windows_impair_defense_override_smartscreen_prompt.yml
+++ b/detections/endpoint/windows_impair_defense_override_smartscreen_prompt.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Override SmartScreen Prompt
id: 08058866-7987-486f-b042-275715ef6e9d
-version: 5
-date: '2025-01-21'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defense_set_win_defender_smart_screen_level_to_warn.yml b/detections/endpoint/windows_impair_defense_set_win_defender_smart_screen_level_to_warn.yml
index 119a81d84b..c5e32b8b14 100644
--- a/detections/endpoint/windows_impair_defense_set_win_defender_smart_screen_level_to_warn.yml
+++ b/detections/endpoint/windows_impair_defense_set_win_defender_smart_screen_level_to_warn.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defense Set Win Defender Smart Screen Level To Warn
id: cc2a3425-2703-47e7-818f-3dca1b0bc56f
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defenses_disable_auto_logger_session.yml b/detections/endpoint/windows_impair_defenses_disable_auto_logger_session.yml
index 5a904d707d..1220aac4a3 100644
--- a/detections/endpoint/windows_impair_defenses_disable_auto_logger_session.yml
+++ b/detections/endpoint/windows_impair_defenses_disable_auto_logger_session.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defenses Disable Auto Logger Session
id: dc6a5613-d024-47e7-9997-ab6477a483d3
-version: 2
-date: '2025-01-07'
+version: 3
+date: '2025-02-10'
author: Nasreddine Bencherchali, Splunk
status: production
type: Anomaly
@@ -50,7 +50,8 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
- message: Windows Auto Logger Session or Provider registry value set to 'disabled' on $dest$
+ message: Windows Auto Logger Session or Provider registry value set to 'disabled'
+ on $dest$
risk_objects:
- field: dest
type: system
@@ -63,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defenses_disable_av_autostart_via_registry.yml b/detections/endpoint/windows_impair_defenses_disable_av_autostart_via_registry.yml
index 9d3ed5adac..0499d7e3de 100644
--- a/detections/endpoint/windows_impair_defenses_disable_av_autostart_via_registry.yml
+++ b/detections/endpoint/windows_impair_defenses_disable_av_autostart_via_registry.yml
@@ -1,6 +1,6 @@
name: Windows Impair Defenses Disable AV AutoStart via Registry
id: 31a13f43-812e-4752-a6ca-c6c87bf03e83
-version: 4
+version: 5
date: '2024-11-13'
author: Teoderick Contreras, Splunk
data_source:
diff --git a/detections/endpoint/windows_impair_defenses_disable_hvci.yml b/detections/endpoint/windows_impair_defenses_disable_hvci.yml
index 761a7e1811..cbcc2f8739 100644
--- a/detections/endpoint/windows_impair_defenses_disable_hvci.yml
+++ b/detections/endpoint/windows_impair_defenses_disable_hvci.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defenses Disable HVCI
id: b061dfcc-f0aa-42cc-a6d4-a87f172acb79
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
- 70bd71e6-eba4-4e00-92f7-617911dbe020
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml b/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml
index 26e0268183..4faf3a1895 100644
--- a/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml
+++ b/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml
@@ -1,7 +1,7 @@
name: Windows Impair Defenses Disable Win Defender Auto Logging
id: 76406a0f-f5e0-4167-8e1f-337fdc0f1b0c
-version: 5
-date: '2024-12-16'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -62,7 +62,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml b/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml
index 8bfb3df253..75fd3bf93a 100644
--- a/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml
+++ b/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml
@@ -1,6 +1,6 @@
name: Windows Ingress Tool Transfer Using Explorer
id: 76753bab-f116-4ea3-8fb9-89b638be58a9
-version: 6
+version: 7
date: '2024-11-13'
author: Teoderick Contreras, Splunk
status: production
diff --git a/detections/endpoint/windows_input_capture_using_credential_ui_dll.yml b/detections/endpoint/windows_input_capture_using_credential_ui_dll.yml
index 2f551ec808..6778cf87fd 100644
--- a/detections/endpoint/windows_input_capture_using_credential_ui_dll.yml
+++ b/detections/endpoint/windows_input_capture_using_credential_ui_dll.yml
@@ -1,7 +1,7 @@
name: Windows Input Capture Using Credential UI Dll
id: 406c21d6-6c75-4e9f-9ca9-48049a1dd90e
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -34,7 +34,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1056.002
- - T1056
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_installutil_credential_theft.yml b/detections/endpoint/windows_installutil_credential_theft.yml
index 715a74abb6..647e38256d 100644
--- a/detections/endpoint/windows_installutil_credential_theft.yml
+++ b/detections/endpoint/windows_installutil_credential_theft.yml
@@ -1,7 +1,7 @@
name: Windows InstallUtil Credential Theft
id: ccfeddec-43ec-11ec-b494-acde48001122
-version: 7
-date: '2024-11-13'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Mauricio Velazo, Splunk
status: production
type: TTP
@@ -56,7 +56,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1218.004
- - T1218
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_installutil_in_non_standard_path.yml b/detections/endpoint/windows_installutil_in_non_standard_path.yml
index 3f0452bd4f..139e8140d7 100644
--- a/detections/endpoint/windows_installutil_in_non_standard_path.yml
+++ b/detections/endpoint/windows_installutil_in_non_standard_path.yml
@@ -1,7 +1,7 @@
name: Windows InstallUtil in Non Standard Path
id: dcf74b22-7933-11ec-857c-acde48001122
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -81,9 +81,7 @@ tags:
- WhisperGate
asset_type: Endpoint
mitre_attack_id:
- - T1036
- T1036.003
- - T1218
- T1218.004
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_installutil_remote_network_connection.yml b/detections/endpoint/windows_installutil_remote_network_connection.yml
index 7058757a08..3c11ba94f9 100644
--- a/detections/endpoint/windows_installutil_remote_network_connection.yml
+++ b/detections/endpoint/windows_installutil_remote_network_connection.yml
@@ -1,7 +1,7 @@
name: Windows InstallUtil Remote Network Connection
id: 4fbf9270-43da-11ec-9486-acde48001122
-version: 8
-date: '2024-12-10'
+version: 10
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -76,7 +76,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1218.004
- - T1218
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_installutil_uninstall_option.yml b/detections/endpoint/windows_installutil_uninstall_option.yml
index 97ee5f6a58..014a79d1e8 100644
--- a/detections/endpoint/windows_installutil_uninstall_option.yml
+++ b/detections/endpoint/windows_installutil_uninstall_option.yml
@@ -1,7 +1,7 @@
name: Windows InstallUtil Uninstall Option
id: cfa7b9ac-43f0-11ec-9b48-acde48001122
-version: 7
-date: '2024-12-10'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -77,7 +77,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1218.004
- - T1218
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_installutil_uninstall_option_with_network.yml b/detections/endpoint/windows_installutil_uninstall_option_with_network.yml
index fb760e80bd..0b7b0f9896 100644
--- a/detections/endpoint/windows_installutil_uninstall_option_with_network.yml
+++ b/detections/endpoint/windows_installutil_uninstall_option_with_network.yml
@@ -1,7 +1,7 @@
name: Windows InstallUtil Uninstall Option with Network
id: 1a52c836-43ef-11ec-a36c-acde48001122
-version: 7
-date: '2024-12-10'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -78,7 +78,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1218.004
- - T1218
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_installutil_url_in_command_line.yml b/detections/endpoint/windows_installutil_url_in_command_line.yml
index bfae587299..3374400f25 100644
--- a/detections/endpoint/windows_installutil_url_in_command_line.yml
+++ b/detections/endpoint/windows_installutil_url_in_command_line.yml
@@ -1,7 +1,7 @@
name: Windows InstallUtil URL in Command Line
id: 28e06670-43df-11ec-a569-acde48001122
-version: 6
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -75,7 +75,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1218.004
- - T1218
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_iso_lnk_file_creation.yml b/detections/endpoint/windows_iso_lnk_file_creation.yml
index fcbbbebeea..06ff0f1426 100644
--- a/detections/endpoint/windows_iso_lnk_file_creation.yml
+++ b/detections/endpoint/windows_iso_lnk_file_creation.yml
@@ -1,7 +1,7 @@
name: Windows ISO LNK File Creation
id: d7c2c09b-9569-4a9e-a8b6-6a39a99c1d32
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -47,10 +47,8 @@ tags:
- Gozi Malware
asset_type: Endpoint
mitre_attack_id:
- - T1566.001
- - T1566
- T1204.001
- - T1204
+ - T1566.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_java_spawning_shells.yml b/detections/endpoint/windows_java_spawning_shells.yml
index 8ed67cb7ab..19a3260fbf 100644
--- a/detections/endpoint/windows_java_spawning_shells.yml
+++ b/detections/endpoint/windows_java_spawning_shells.yml
@@ -1,6 +1,6 @@
name: Windows Java Spawning Shells
id: 28c81306-5c47-11ec-bfea-acde48001122
-version: 7
+version: 8
date: '2024-12-16'
author: Michael Haag, Splunk
status: experimental
diff --git a/detections/endpoint/windows_known_abused_dll_created.yml b/detections/endpoint/windows_known_abused_dll_created.yml
index 8c1f4b886f..4ab43c381b 100644
--- a/detections/endpoint/windows_known_abused_dll_created.yml
+++ b/detections/endpoint/windows_known_abused_dll_created.yml
@@ -1,7 +1,7 @@
name: Windows Known Abused DLL Created
id: ea91651a-772a-4b02-ac3d-985b364a5f07
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Steven Dick
status: production
type: Anomaly
@@ -87,7 +87,6 @@ tags:
mitre_attack_id:
- T1574.001
- T1574.002
- - T1574
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml b/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml
index 1509baa004..fd906a1af0 100644
--- a/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml
+++ b/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml
@@ -1,7 +1,7 @@
name: Windows Known Abused DLL Loaded Suspiciously
id: dd6d1f16-adc0-4e87-9c34-06189516b803
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -68,7 +68,6 @@ tags:
mitre_attack_id:
- T1574.001
- T1574.002
- - T1574
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_known_graphicalproton_loaded_modules.yml b/detections/endpoint/windows_known_graphicalproton_loaded_modules.yml
index 0aca5b42c9..8d8b1036e8 100644
--- a/detections/endpoint/windows_known_graphicalproton_loaded_modules.yml
+++ b/detections/endpoint/windows_known_graphicalproton_loaded_modules.yml
@@ -1,7 +1,7 @@
name: Windows Known GraphicalProton Loaded Modules
id: bf471c94-0324-4b19-a113-d02749b969bc
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -56,7 +56,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1574.002
- - T1574
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_ldifde_directory_object_behavior.yml b/detections/endpoint/windows_ldifde_directory_object_behavior.yml
index f03a5ff5a1..30ab7ce4b3 100644
--- a/detections/endpoint/windows_ldifde_directory_object_behavior.yml
+++ b/detections/endpoint/windows_ldifde_directory_object_behavior.yml
@@ -1,6 +1,6 @@
name: Windows Ldifde Directory Object Behavior
id: 35cd29ca-f08c-4489-8815-f715c45460d3
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml b/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml
index f2b645134e..a18658909b 100644
--- a/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml
+++ b/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml
@@ -1,7 +1,7 @@
name: Windows Linked Policies In ADSI Discovery
id: 510ea428-4731-4d2f-8829-a28293e427aa
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -56,7 +56,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1087.002
- - T1087
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_local_administrator_credential_stuffing.yml b/detections/endpoint/windows_local_administrator_credential_stuffing.yml
index 4669dc1fbe..00ae64da90 100644
--- a/detections/endpoint/windows_local_administrator_credential_stuffing.yml
+++ b/detections/endpoint/windows_local_administrator_credential_stuffing.yml
@@ -1,7 +1,7 @@
name: Windows Local Administrator Credential Stuffing
id: 09555511-aca6-484a-b6ab-72cd03d73c34
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
type: TTP
status: production
@@ -62,7 +62,6 @@ tags:
- Active Directory Lateral Movement
asset_type: Endpoint
mitre_attack_id:
- - T1110
- T1110.004
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml b/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml
index 6a79741770..571055f6e9 100644
--- a/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml
+++ b/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml
@@ -1,7 +1,7 @@
name: Windows LOLBAS Executed As Renamed File
id: fd496996-7d9e-4894-8d40-bb85b6192dc6
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -74,7 +74,6 @@ tags:
- Windows Defense Evasion Tactics
asset_type: Endpoint
mitre_attack_id:
- - T1036
- T1036.003
- T1218.011
product:
diff --git a/detections/endpoint/windows_lolbas_executed_outside_expected_path.yml b/detections/endpoint/windows_lolbas_executed_outside_expected_path.yml
index a11c57c45e..3c51c0705d 100644
--- a/detections/endpoint/windows_lolbas_executed_outside_expected_path.yml
+++ b/detections/endpoint/windows_lolbas_executed_outside_expected_path.yml
@@ -1,7 +1,7 @@
name: Windows LOLBAS Executed Outside Expected Path
id: 326fdf44-b90c-4d2e-adca-1fd140b10536
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -65,7 +65,6 @@ tags:
- Windows Defense Evasion Tactics
asset_type: Endpoint
mitre_attack_id:
- - T1036
- T1036.005
- T1218.011
product:
diff --git a/detections/endpoint/windows_mail_protocol_in_non_common_process_path.yml b/detections/endpoint/windows_mail_protocol_in_non_common_process_path.yml
index f3b8b38435..6661897452 100644
--- a/detections/endpoint/windows_mail_protocol_in_non_common_process_path.yml
+++ b/detections/endpoint/windows_mail_protocol_in_non_common_process_path.yml
@@ -1,7 +1,7 @@
name: Windows Mail Protocol In Non-Common Process Path
id: ac3311f5-661d-4e99-bd1f-3ec665b05441
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -57,7 +57,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1071.003
- - T1071
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_masquerading_explorer_as_child_process.yml b/detections/endpoint/windows_masquerading_explorer_as_child_process.yml
index eba3eda086..ff9d52c49c 100644
--- a/detections/endpoint/windows_masquerading_explorer_as_child_process.yml
+++ b/detections/endpoint/windows_masquerading_explorer_as_child_process.yml
@@ -1,7 +1,7 @@
name: Windows Masquerading Explorer As Child Process
id: 61490da9-52a1-4855-a0c5-28233c88c481
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1574.002
- - T1574
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_mimikatz_binary_execution.yml b/detections/endpoint/windows_mimikatz_binary_execution.yml
index b33a7416d4..8578d406d4 100644
--- a/detections/endpoint/windows_mimikatz_binary_execution.yml
+++ b/detections/endpoint/windows_mimikatz_binary_execution.yml
@@ -1,6 +1,6 @@
name: Windows Mimikatz Binary Execution
id: a9e0d6d3-9676-4e26-994d-4e0406bb4467
-version: 6
+version: 7
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_modify_registry_valleyrat_c2_config.yml b/detections/endpoint/windows_modify_registry_valleyrat_c2_config.yml
index 6d180da12f..f83503b284 100644
--- a/detections/endpoint/windows_modify_registry_valleyrat_c2_config.yml
+++ b/detections/endpoint/windows_modify_registry_valleyrat_c2_config.yml
@@ -1,6 +1,6 @@
name: Windows Modify Registry ValleyRAT C2 Config
id: ac59298a-8d81-4c02-8c9b-ffdac993891f
-version: 4
+version: 5
date: '2024-11-13'
author: Teoderick Contreras, Splunk
data_source:
diff --git a/detections/endpoint/windows_modify_registry_valleyrat_pwn_reg_entry.yml b/detections/endpoint/windows_modify_registry_valleyrat_pwn_reg_entry.yml
index cc16e59756..1f0d757c88 100644
--- a/detections/endpoint/windows_modify_registry_valleyrat_pwn_reg_entry.yml
+++ b/detections/endpoint/windows_modify_registry_valleyrat_pwn_reg_entry.yml
@@ -1,6 +1,6 @@
name: Windows Modify Registry ValleyRat PWN Reg Entry
id: 6947c44e-be1f-4dd9-b198-bc42be5be196
-version: 5
+version: 6
date: '2024-12-16'
author: Teoderick Contreras, Splunk
data_source:
diff --git a/detections/endpoint/windows_modify_system_firewall_with_notable_process_path.yml b/detections/endpoint/windows_modify_system_firewall_with_notable_process_path.yml
index 3ace7c862d..97cd11c575 100644
--- a/detections/endpoint/windows_modify_system_firewall_with_notable_process_path.yml
+++ b/detections/endpoint/windows_modify_system_firewall_with_notable_process_path.yml
@@ -1,7 +1,7 @@
name: Windows Modify System Firewall with Notable Process Path
id: cd6d7410-9146-4471-a418-49edba6dadc4
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Will Metcalf, Splunk
status: production
type: TTP
@@ -69,7 +69,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.004
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_mof_event_triggered_execution_via_wmi.yml b/detections/endpoint/windows_mof_event_triggered_execution_via_wmi.yml
index 273ecf6bf3..5906eedfab 100644
--- a/detections/endpoint/windows_mof_event_triggered_execution_via_wmi.yml
+++ b/detections/endpoint/windows_mof_event_triggered_execution_via_wmi.yml
@@ -1,6 +1,6 @@
name: Windows MOF Event Triggered Execution via WMI
id: e59b5a73-32bf-4467-a585-452c36ae10c1
-version: 7
+version: 8
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_msexchange_management_mailbox_cmdlet_usage.yml b/detections/endpoint/windows_msexchange_management_mailbox_cmdlet_usage.yml
index 5e1bac285c..8cc18bc69f 100644
--- a/detections/endpoint/windows_msexchange_management_mailbox_cmdlet_usage.yml
+++ b/detections/endpoint/windows_msexchange_management_mailbox_cmdlet_usage.yml
@@ -1,7 +1,7 @@
name: Windows MSExchange Management Mailbox Cmdlet Usage
id: 396de86f-25e7-4b0e-be09-a330be35249d
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Anomaly
@@ -58,7 +58,6 @@ tags:
- ProxyNotShell
asset_type: Endpoint
mitre_attack_id:
- - T1059
- T1059.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_msiexec_dllregisterserver.yml b/detections/endpoint/windows_msiexec_dllregisterserver.yml
index fab94a6582..862e6c9f89 100644
--- a/detections/endpoint/windows_msiexec_dllregisterserver.yml
+++ b/detections/endpoint/windows_msiexec_dllregisterserver.yml
@@ -1,6 +1,6 @@
name: Windows MSIExec DLLRegisterServer
id: fdb59aef-d88f-4909-8369-ec2afbd2c398
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_msiexec_hidewindow_rundll32_execution.yml b/detections/endpoint/windows_msiexec_hidewindow_rundll32_execution.yml
index 92c0e1c8b6..c5d9918949 100644
--- a/detections/endpoint/windows_msiexec_hidewindow_rundll32_execution.yml
+++ b/detections/endpoint/windows_msiexec_hidewindow_rundll32_execution.yml
@@ -1,7 +1,7 @@
name: Windows MsiExec HideWindow Rundll32 Execution
id: 9683271d-92e4-43b5-a907-1983bfb9f7fd
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -66,7 +66,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1218.007
- - T1218
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_msiexec_remote_download.yml b/detections/endpoint/windows_msiexec_remote_download.yml
index 1d89715d94..ea822dfe4d 100644
--- a/detections/endpoint/windows_msiexec_remote_download.yml
+++ b/detections/endpoint/windows_msiexec_remote_download.yml
@@ -1,6 +1,6 @@
name: Windows MSIExec Remote Download
id: 6aa49ff2-3c92-4586-83e0-d83eb693dfda
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_msiexec_spawn_discovery_command.yml b/detections/endpoint/windows_msiexec_spawn_discovery_command.yml
index dde48d4cb7..a604c6a7d5 100644
--- a/detections/endpoint/windows_msiexec_spawn_discovery_command.yml
+++ b/detections/endpoint/windows_msiexec_spawn_discovery_command.yml
@@ -1,6 +1,6 @@
name: Windows MSIExec Spawn Discovery Command
id: e9d05aa2-32f0-411b-930c-5b8ca5c4fcee
-version: 6
+version: 7
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_msiexec_spawn_windbg.yml b/detections/endpoint/windows_msiexec_spawn_windbg.yml
index 4e4121a5d0..c80059d8d6 100644
--- a/detections/endpoint/windows_msiexec_spawn_windbg.yml
+++ b/detections/endpoint/windows_msiexec_spawn_windbg.yml
@@ -1,6 +1,6 @@
name: Windows MSIExec Spawn WinDBG
id: 9a18f7c2-1fe3-47b8-9467-8b3976770a30
-version: 6
+version: 7
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml b/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml
index b7255c3665..697c254586 100644
--- a/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml
+++ b/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml
@@ -1,6 +1,6 @@
name: Windows MSIExec Unregister DLLRegisterServer
id: a27db3c5-1a9a-46df-a577-765d3f1a3c24
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_multi_hop_proxy_tor_website_query.yml b/detections/endpoint/windows_multi_hop_proxy_tor_website_query.yml
index 382204bb18..f223d20020 100644
--- a/detections/endpoint/windows_multi_hop_proxy_tor_website_query.yml
+++ b/detections/endpoint/windows_multi_hop_proxy_tor_website_query.yml
@@ -1,7 +1,7 @@
name: Windows Multi hop Proxy TOR Website Query
id: 4c2d198b-da58-48d7-ba27-9368732d0054
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -55,7 +55,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1071.003
- - T1071
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml b/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml
index 730fe3867d..cc48eeadc3 100644
--- a/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml
+++ b/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml
@@ -1,7 +1,7 @@
name: Windows Multiple Disabled Users Failed To Authenticate Wth Kerberos
id: 98f22d82-9d62-11eb-9fcf-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
type: TTP
status: production
@@ -58,7 +58,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml b/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml
index 7696c03e9d..993132ddda 100644
--- a/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml
+++ b/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml
@@ -1,7 +1,7 @@
name: Windows Multiple Invalid Users Fail To Authenticate Using Kerberos
id: 001266a6-9d5b-11eb-829b-acde48001122
-date: '2024-11-13'
-version: 5
+date: '2025-02-10'
+version: 6
type: TTP
status: production
author: Mauricio Velazco, Splunk
@@ -58,7 +58,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml b/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml
index c8db8b309f..88dc4a2ca2 100644
--- a/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml
+++ b/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml
@@ -1,12 +1,12 @@
name: Windows Multiple Invalid Users Failed To Authenticate Using NTLM
id: 57ad5a64-9df7-11eb-a290-acde48001122
type: TTP
-version: 6
+version: 7
author: Mauricio Velazco, Splunk
status: production
data_source:
- Windows Event Log Security 4776
-date: '2024-11-13'
+date: '2025-02-10'
description: The following analytic detects a single source endpoint failing to authenticate
with 30 unique invalid users using the NTLM protocol. It leverages EventCode 4776
from Domain Controller logs, focusing on error code 0xC0000064, which indicates
@@ -58,7 +58,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_multiple_ntlm_null_domain_authentications.yml b/detections/endpoint/windows_multiple_ntlm_null_domain_authentications.yml
index cda160cc85..e9ffe53973 100644
--- a/detections/endpoint/windows_multiple_ntlm_null_domain_authentications.yml
+++ b/detections/endpoint/windows_multiple_ntlm_null_domain_authentications.yml
@@ -1,7 +1,7 @@
name: Windows Multiple NTLM Null Domain Authentications
id: c187ce2c-c88e-4cec-8a1c-607ca0dedd78
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
- Active Directory Password Spraying
asset_type: Endpoint
mitre_attack_id:
- - T1110
- T1110.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml b/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml
index c57c7baf7e..7d72b1462b 100644
--- a/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml
+++ b/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml
@@ -1,12 +1,12 @@
name: Windows Multiple Users Fail To Authenticate Wth ExplicitCredentials
id: e61918fa-9ca4-11eb-836c-acde48001122
type: TTP
-version: 6
+version: 7
status: production
author: Mauricio Velazco, Splunk
data_source:
- Windows Event Log Security 4648
-date: '2024-11-13'
+date: '2025-02-10'
description: The following analytic identifies a source user failing to authenticate
with 30 unique users using explicit credentials on a host. It leverages Windows
Event 4648, which is generated when a process attempts an account logon by explicitly
@@ -61,7 +61,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml
index 4791ed5824..d3c8a07eb4 100644
--- a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml
+++ b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml
@@ -3,10 +3,10 @@ id: 7ed272a4-9c77-11eb-af22-acde48001122
author: Mauricio Velazco, Splunk
type: TTP
status: production
-version: 6
+version: 7
data_source:
- Windows Event Log Security 4776
-date: '2024-11-13'
+date: '2025-02-10'
description: The following analytic identifies a single source endpoint failing to
authenticate with 30 unique valid users using the NTLM protocol. It leverages EventCode
4776 from Domain Controller logs, focusing on error code 0xC000006A, which indicates
@@ -57,7 +57,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml
index b4e4eb9ae2..8d8df90f05 100644
--- a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml
+++ b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml
@@ -1,12 +1,12 @@
name: Windows Multiple Users Failed To Authenticate From Process
id: 9015385a-9c84-11eb-bef2-acde48001122
type: TTP
-version: 6
+version: 7
status: production
author: Mauricio Velazco, Splunk
data_source:
- Windows Event Log Security 4625
-date: '2024-11-13'
+date: '2025-02-10'
description: The following analytic detects a source process failing to authenticate
with 30 unique users, indicating a potential Password Spraying attack. It leverages
Windows Event 4625 with Logon Type 2, collected from domain controllers, member
@@ -59,7 +59,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml b/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml
index 15df1ec8be..2a4325b756 100644
--- a/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml
+++ b/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml
@@ -1,8 +1,8 @@
name: Windows Multiple Users Failed To Authenticate Using Kerberos
id: 3a91a212-98a9-11eb-b86a-acde48001122
type: TTP
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
status: production
author: Mauricio Velazco, Splunk
data_source:
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml b/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml
index 3c72e172b9..8e5c99c808 100644
--- a/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml
+++ b/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml
@@ -3,8 +3,8 @@ id: 80f9d53e-9ca1-11eb-b0d6-acde48001122
author: Mauricio Velazco, Splunk
type: TTP
status: production
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
data_source:
- Windows Event Log Security 4625
description: The following analytic identifies a source host failing to authenticate
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_new_custom_security_descriptor_set_on_eventlog_channel.yml b/detections/endpoint/windows_new_custom_security_descriptor_set_on_eventlog_channel.yml
index bfeca92a28..4703844127 100644
--- a/detections/endpoint/windows_new_custom_security_descriptor_set_on_eventlog_channel.yml
+++ b/detections/endpoint/windows_new_custom_security_descriptor_set_on_eventlog_channel.yml
@@ -16,22 +16,9 @@ description: The following analytic detects suspicious modifications to the Even
viewing, ingesting and interacting event logs.
data_source:
- Sysmon EventID 13
-search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
- as lastTime FROM datamodel=Endpoint.Registry WHERE Registry.registry_path= "*\\Services\\Eventlog\\*"
- AND Registry.registry_value_name=CustomSD BY Registry.dest Registry.registry_value_data
- Registry.action Registry.process_guid Registry.process_id Registry.registry_key_name
- Registry.user Registry.registry_value_name Registry.registry_path | `drop_dm_object_name(Registry)` | where
- isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
- | `windows_new_custom_security_descriptor_set_on_eventlog_channel_filter`'
-how_to_implement: To successfully implement this search, you must be ingesting data
- that records registry activity from your hosts to populate the endpoint data model
- in the registry node. This is typically populated via endpoint detection-and-response
- product, such as Carbon Black or endpoint data sources, such as Sysmon. The data
- used for this search is typically generated via logs that report reads and writes
- to the registry. If you are using Sysmon, you must have at least version 2.0 of
- the official Sysmon TA. https://splunkbase.splunk.com/app/5709
-known_false_positives: None identified, setting up the "CustomSD" value is considered
- a legacy option and shouldn't be a common activity.
+search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry WHERE Registry.registry_path= "*\\Services\\Eventlog\\*" AND Registry.registry_value_name=CustomSD BY Registry.dest Registry.registry_value_data Registry.action Registry.process_guid Registry.process_id Registry.registry_key_name Registry.user Registry.registry_value_name Registry.registry_path | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_new_custom_security_descriptor_set_on_eventlog_channel_filter`'
+how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. If you are using Sysmon, you must have at least version 2.0 of the official Sysmon TA. https://splunkbase.splunk.com/app/5709
+known_false_positives: None identified, setting up the "CustomSD" value is considered a legacy option and shouldn't be a common activity.
references:
- https://learn.microsoft.com/en-us/troubleshoot/windows-server/group-policy/set-event-log-security-locally-or-via-group-policy
- https://attack.mitre.org/techniques/T1562/002/
diff --git a/detections/endpoint/windows_new_default_file_association_value_set.yml b/detections/endpoint/windows_new_default_file_association_value_set.yml
index ad44980ccf..74809b6e75 100644
--- a/detections/endpoint/windows_new_default_file_association_value_set.yml
+++ b/detections/endpoint/windows_new_default_file_association_value_set.yml
@@ -1,16 +1,35 @@
name: Windows New Default File Association Value Set
id: 7d1f031f-f1c9-43be-8b0b-c4e3e8a8928a
-version: 1
-date: '2025-01-15'
+version: 2
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
-description: The following analytic detects registry changes to the default file association value. It leverages data from the Endpoint data model, specifically monitoring registry paths under "HKCR\\*\\shell\\open\\command\\*". This activity can be significant because, attackers might alter the default file associations in order to execute arbitrary scripts or payloads when a user opens a file, leading to potential code execution. If confirmed malicious, this technique can enable attackers to persist on the compromised host and execute further malicious commands, posing a severe threat to the environment.
+description: The following analytic detects registry changes to the default file association
+ value. It leverages data from the Endpoint data model, specifically monitoring registry
+ paths under "HKCR\\*\\shell\\open\\command\\*". This activity can be significant
+ because, attackers might alter the default file associations in order to execute
+ arbitrary scripts or payloads when a user opens a file, leading to potential code
+ execution. If confirmed malicious, this technique can enable attackers to persist
+ on the compromised host and execute further malicious commands, posing a severe
+ threat to the environment.
data_source:
- Sysmon EventID 13
-search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\shell\\open\\command\\*" Registry.registry_path IN ("*HKCR\\*", "*HKEY_CLASSES_ROOT\\*") by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `windows_new_default_file_association_value_set_filter`'
-how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry.
-known_false_positives: Windows and third party software will create and modify these file associations during installation or upgrades. Additional filters needs to be applied to tune environment specific false positives.
+search: '| tstats `security_content_summariesonly` count min(_time) as firstTime
+ max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\shell\\open\\command\\*"
+ Registry.registry_path IN ("*HKCR\\*", "*HKEY_CLASSES_ROOT\\*") by Registry.dest Registry.user
+ Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
+ | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)`
+ | `windows_new_default_file_association_value_set_filter`'
+how_to_implement: To successfully implement this search, you must be ingesting data
+ that records registry activity from your hosts to populate the endpoint data model
+ in the registry node. This is typically populated via endpoint detection-and-response
+ product, such as Carbon Black or endpoint data sources, such as Sysmon. The data
+ used for this search is typically generated via logs that report reads and writes
+ to the registry.
+known_false_positives: Windows and third party software will create and modify these
+ file associations during installation or upgrades. Additional filters needs to be
+ applied to tune environment specific false positives.
references:
- https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/accessibility-features
drilldown_searches:
@@ -19,7 +38,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$" and "$user$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$",
+ "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
+ as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
+ Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
+ as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
+ by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
tags:
@@ -33,7 +57,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1546.001
- - T1546
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -42,6 +65,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.001/txtfile_reg/sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.001/txtfile_reg/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_ngrok_reverse_proxy_usage.yml b/detections/endpoint/windows_ngrok_reverse_proxy_usage.yml
index 9d6caf3abd..aae826157a 100644
--- a/detections/endpoint/windows_ngrok_reverse_proxy_usage.yml
+++ b/detections/endpoint/windows_ngrok_reverse_proxy_usage.yml
@@ -1,6 +1,6 @@
name: Windows Ngrok Reverse Proxy Usage
id: e2549f2c-0aef-408a-b0c1-e0f270623436
-version: 6
+version: 7
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_nirsoft_advancedrun.yml b/detections/endpoint/windows_nirsoft_advancedrun.yml
index 62b05e5300..4a5461615e 100644
--- a/detections/endpoint/windows_nirsoft_advancedrun.yml
+++ b/detections/endpoint/windows_nirsoft_advancedrun.yml
@@ -1,6 +1,6 @@
name: Windows NirSoft AdvancedRun
id: bb4f3090-7ae4-11ec-897f-acde48001122
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_njrat_fileless_storage_via_registry.yml b/detections/endpoint/windows_njrat_fileless_storage_via_registry.yml
index b152d8f05a..22f73f858f 100644
--- a/detections/endpoint/windows_njrat_fileless_storage_via_registry.yml
+++ b/detections/endpoint/windows_njrat_fileless_storage_via_registry.yml
@@ -1,7 +1,7 @@
name: Windows Njrat Fileless Storage via Registry
id: a5fffbbd-271f-4980-94ed-4fbf17f0af1c
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1027.011
- - T1027
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_non_system_account_targeting_lsass.yml b/detections/endpoint/windows_non_system_account_targeting_lsass.yml
index 0a6c933bc2..b6588d58e9 100644
--- a/detections/endpoint/windows_non_system_account_targeting_lsass.yml
+++ b/detections/endpoint/windows_non_system_account_targeting_lsass.yml
@@ -1,7 +1,7 @@
name: Windows Non-System Account Targeting Lsass
id: b1ce9a72-73cf-11ec-981b-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -66,7 +66,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.001
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_odbcconf_load_dll.yml b/detections/endpoint/windows_odbcconf_load_dll.yml
index 815aa3b02f..f7a52f0e6a 100644
--- a/detections/endpoint/windows_odbcconf_load_dll.yml
+++ b/detections/endpoint/windows_odbcconf_load_dll.yml
@@ -1,6 +1,6 @@
name: Windows Odbcconf Load DLL
id: 141e7fca-a9f0-40fd-a539-9aac8be41f1b
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_odbcconf_load_response_file.yml b/detections/endpoint/windows_odbcconf_load_response_file.yml
index 0fa23e5e03..7d234fd114 100644
--- a/detections/endpoint/windows_odbcconf_load_response_file.yml
+++ b/detections/endpoint/windows_odbcconf_load_response_file.yml
@@ -1,6 +1,6 @@
name: Windows Odbcconf Load Response File
id: 1acafff9-1347-4b40-abae-f35aa4ba85c1
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml b/detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml
index 52313880e5..f6134c4079 100644
--- a/detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml
+++ b/detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml
@@ -1,17 +1,36 @@
name: Windows Office Product Dropped Cab or Inf File
id: dbdd251e-dd45-4ec9-a555-f5e151391746
-version: 1
-date: '2025-01-20'
+version: 2
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
-description: The following analytic detects Office products writing .cab or .inf files, indicative of CVE-2021-40444 exploitation. It leverages the Endpoint.Processes and Endpoint.Filesystem data models to identify Office applications creating these file types. This activity is significant as it may signal an attempt to load malicious ActiveX controls and download remote payloads, a known attack vector. If confirmed malicious, this could lead to remote code execution, allowing attackers to gain control over the affected system and potentially compromise sensitive data.
+description: The following analytic detects Office products writing .cab or .inf files,
+ indicative of CVE-2021-40444 exploitation. It leverages the Endpoint.Processes and
+ Endpoint.Filesystem data models to identify Office applications creating these file
+ types. This activity is significant as it may signal an attempt to load malicious
+ ActiveX controls and download remote payloads, a known attack vector. If confirmed
+ malicious, this could lead to remote code execution, allowing attackers to gain
+ control over the affected system and potentially compromise sensitive data.
data_source:
- Sysmon EventID 1 AND Sysmon EventID 11
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
-search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_office_products` by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | join proc_guid, _time [ | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.cab", "*.inf") by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid | `drop_dm_object_name(Filesystem)` |rename process_guid as proc_guid | fields _time dest file_create_time file_name file_path process_name process_path process proc_guid] | dedup file_create_time | table dest, process_name, process, file_create_time, file_name, file_path, proc_guid | `windows_office_product_dropped_cab_or_inf_file_filter`'
-how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` node.
+search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
+ where `process_office_products` by _time span=1h Processes.process_id Processes.process_name
+ Processes.process Processes.dest Processes.process_guid | `drop_dm_object_name(Processes)`
+ |rename process_guid as proc_guid | join proc_guid, _time [ | tstats `security_content_summariesonly`
+ count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem
+ where Filesystem.file_name IN ("*.cab", "*.inf") by _time span=1h Filesystem.dest
+ Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid
+ | `drop_dm_object_name(Filesystem)` |rename process_guid as proc_guid | fields _time
+ dest file_create_time file_name file_path process_name process_path process proc_guid]
+ | dedup file_create_time | table dest, process_name, process, file_create_time,
+ file_name, file_path, proc_guid | `windows_office_product_dropped_cab_or_inf_file_filter`'
+how_to_implement: To successfully implement this search you need to be ingesting information
+ on process that include the name of the process responsible for the changes from
+ your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem`
+ node.
known_false_positives: The query is structured in a way that `action` (read, create)
is not defined. Review the results of this query, filter, and tune as necessary.
It may be necessary to generate this query specific to your endpoint product.
@@ -54,7 +73,6 @@ tags:
cve:
- CVE-2021-40444
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
@@ -64,6 +82,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_cabinf.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_cabinf.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_office_product_dropped_uncommon_file.yml b/detections/endpoint/windows_office_product_dropped_uncommon_file.yml
index bf3090d832..fad1a08049 100644
--- a/detections/endpoint/windows_office_product_dropped_uncommon_file.yml
+++ b/detections/endpoint/windows_office_product_dropped_uncommon_file.yml
@@ -1,15 +1,35 @@
name: Windows Office Product Dropped Uncommon File
id: 7ac0fced-9eae-4381-a748-90dcd1aa9393
-version: 1
-date: '2025-01-20'
+version: 2
+date: '2025-02-10'
author: Teoderick Contreras, Michael Haag, Splunk, TheLawsOfChaos, Github
status: production
type: Anomaly
-description: The following analytic detects Microsoft Office applications dropping or creating executables or scripts on a Windows OS. It leverages process creation and file system events from the Endpoint data model to identify Office applications like Word or Excel generating files with extensions such as ".exe", ".dll", or ".ps1". This behavior is significant as it is often associated with spear-phishing attacks where malicious files are dropped to compromise the host. If confirmed malicious, this activity could lead to code execution, privilege escalation, or persistent access, posing a severe threat to the environment.
+description: The following analytic detects Microsoft Office applications dropping
+ or creating executables or scripts on a Windows OS. It leverages process creation
+ and file system events from the Endpoint data model to identify Office applications
+ like Word or Excel generating files with extensions such as ".exe", ".dll", or ".ps1".
+ This behavior is significant as it is often associated with spear-phishing attacks
+ where malicious files are dropped to compromise the host. If confirmed malicious,
+ this activity could lead to code execution, privilege escalation, or persistent
+ access, posing a severe threat to the environment.
data_source:
- Sysmon EventID 1 AND Sysmon EventID 11
-search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_office_products` by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.process_guid | `drop_dm_object_name(Processes)` | join process_guid, _time [| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.dll", "*.exe", "*.js", "*.pif", "*.ps1", "*.scr", "*.vbe", "*.vbs") by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.process_guid Filesystem.file_path | `drop_dm_object_name(Filesystem)` | fields _time dest file_create_time file_name file_path process_name process_path process process_guid] | dedup file_create_time | table dest, process_name, process, file_create_time, file_name, file_path, process_guid | `windows_office_product_dropped_uncommon_file_filter`'
-how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used.
+search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
+ where `process_office_products` by _time span=1h Processes.process_id Processes.process_name
+ Processes.process Processes.dest Processes.process_guid | `drop_dm_object_name(Processes)`
+ | join process_guid, _time [| tstats `security_content_summariesonly` count min(_time)
+ as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name
+ IN ("*.dll", "*.exe", "*.js", "*.pif", "*.ps1", "*.scr", "*.vbe", "*.vbs") by _time
+ span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.process_guid
+ Filesystem.file_path | `drop_dm_object_name(Filesystem)` | fields _time dest file_create_time
+ file_name file_path process_name process_path process process_guid] | dedup file_create_time
+ | table dest, process_name, process, file_create_time, file_name, file_path, process_guid
+ | `windows_office_product_dropped_uncommon_file_filter`'
+how_to_implement: To successfully implement this search, you need to be ingesting
+ logs with the process name, parent process, and command-line executions from your
+ endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
+ Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used.
known_false_positives: office macro for automation may do this behavior
references:
- https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation
@@ -49,7 +69,6 @@ tags:
- PlugX
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
@@ -59,6 +78,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_macro_js_1/sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_macro_js_1/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_office_product_loaded_mshtml_module.yml b/detections/endpoint/windows_office_product_loaded_mshtml_module.yml
index 2d546a5b2b..cb6ba413cc 100644
--- a/detections/endpoint/windows_office_product_loaded_mshtml_module.yml
+++ b/detections/endpoint/windows_office_product_loaded_mshtml_module.yml
@@ -1,16 +1,31 @@
name: Windows Office Product Loaded MSHTML Module
id: 4cc015c9-687c-40d2-adcc-46350f66e10c
-version: 1
-date: '2025-01-20'
+version: 2
+date: '2025-02-10'
author: Michael Haag, Mauricio Velazco, Splunk
status: production
type: Anomaly
-description: The following analytic detects the loading of the mshtml.dll module into an Office product, which is indicative of CVE-2021-40444 exploitation. It leverages Sysmon EventID 7 to monitor image loads by specific Office processes. This activity is significant because it can indicate an attempt to exploit a vulnerability in the MSHTML component via a malicious document. If confirmed malicious, this could allow an attacker to execute arbitrary code, potentially leading to system compromise, data exfiltration, or further network penetration.
+description: The following analytic detects the loading of the mshtml.dll module into
+ an Office product, which is indicative of CVE-2021-40444 exploitation. It leverages
+ Sysmon EventID 7 to monitor image loads by specific Office processes. This activity
+ is significant because it can indicate an attempt to exploit a vulnerability in
+ the MSHTML component via a malicious document. If confirmed malicious, this could
+ allow an attacker to execute arbitrary code, potentially leading to system compromise,
+ data exfiltration, or further network penetration.
data_source:
- Sysmon EventID 7
-search: '`sysmon` EventID=7 process_name IN ("EQNEDT32.exe", "excel.exe", "Graph.exe", "msaccess.exe", "mspub.exe", "onenote.exe", "onenoteim.exe", "onenotem.exe", "outlook.exe", "powerpnt.exe", "visio.exe", "winproj.exe", "winword.exe", "wordpad.exe", "wordview.exe") loaded_file_path IN ("*\\mshtml.dll", "*\\Microsoft.mshtml.dll","*\\IE.Interop.MSHTML.dll","*\\MshtmlDac.dll","*\\MshtmlDed.dll","*\\MshtmlDer.dll") | stats count min(_time) as firstTime max(_time) as lastTime by user_id, dest, process_name, loaded_file, loaded_file_path, original_file_name, process_guid | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_office_product_loaded_mshtml_module_filter`'
-how_to_implement: To successfully implement this search, you need to be ingesting logs with the process names and image loads from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
-known_false_positives: Limited false positives will be present, however, tune as necessary. Some applications may legitimately load mshtml.dll.
+search: '`sysmon` EventID=7 process_name IN ("EQNEDT32.exe", "excel.exe", "Graph.exe",
+ "msaccess.exe", "mspub.exe", "onenote.exe", "onenoteim.exe", "onenotem.exe", "outlook.exe",
+ "powerpnt.exe", "visio.exe", "winproj.exe", "winword.exe", "wordpad.exe", "wordview.exe")
+ loaded_file_path IN ("*\\mshtml.dll", "*\\Microsoft.mshtml.dll","*\\IE.Interop.MSHTML.dll","*\\MshtmlDac.dll","*\\MshtmlDed.dll","*\\MshtmlDer.dll")
+ | stats count min(_time) as firstTime max(_time) as lastTime by user_id, dest, process_name,
+ loaded_file, loaded_file_path, original_file_name, process_guid | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)` | `windows_office_product_loaded_mshtml_module_filter`'
+how_to_implement: To successfully implement this search, you need to be ingesting
+ logs with the process names and image loads from your endpoints. If you are using
+ Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
+known_false_positives: Limited false positives will be present, however, tune as necessary.
+ Some applications may legitimately load mshtml.dll.
references:
- https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444
@@ -22,7 +37,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -44,7 +64,6 @@ tags:
cve:
- CVE-2021-40444
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
@@ -54,6 +73,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_mshtml.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_mshtml.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_office_product_loading_taskschd_dll.yml b/detections/endpoint/windows_office_product_loading_taskschd_dll.yml
index b16c25faa3..a7ba40103b 100644
--- a/detections/endpoint/windows_office_product_loading_taskschd_dll.yml
+++ b/detections/endpoint/windows_office_product_loading_taskschd_dll.yml
@@ -1,16 +1,33 @@
name: Windows Office Product Loading Taskschd DLL
id: d7297cfa-1f04-4714-bfbe-3679e0666959
-version: 1
-date: '2025-01-20'
+version: 2
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
-description: The following analytic detects an Office document creating a scheduled task, either through a macro VBA API or by loading `taskschd.dll`. This detection leverages Sysmon EventCode 7 to identify when Office applications load the `taskschd.dll` file. This activity is significant as it is a common technique used by malicious macro malware to establish persistence or initiate beaconing. If confirmed malicious, this could allow an attacker to maintain persistence, execute arbitrary commands, or schedule future malicious activities, posing a significant threat to the environment.
+description: The following analytic detects an Office document creating a scheduled
+ task, either through a macro VBA API or by loading `taskschd.dll`. This detection
+ leverages Sysmon EventCode 7 to identify when Office applications load the `taskschd.dll`
+ file. This activity is significant as it is a common technique used by malicious
+ macro malware to establish persistence or initiate beaconing. If confirmed malicious,
+ this could allow an attacker to maintain persistence, execute arbitrary commands,
+ or schedule future malicious activities, posing a significant threat to the environment.
data_source:
- Sysmon EventID 7
-search: '`sysmon` EventCode=7 process_name IN ("EQNEDT32.exe", "excel.exe", "Graph.exe", "msaccess.exe", "mspub.exe", "onenote.exe", "onenoteim.exe", "onenotem.exe", "outlook.exe", "powerpnt.exe", "visio.exe", "winproj.exe", "winword.exe") loaded_file_path = "*\\taskschd.dll" | stats min(_time) as firstTime max(_time) as lastTime count by user_id, dest, process_name,loaded_file, loaded_file_path, original_file_name, process_guid | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_office_product_loading_taskschd_dll_filter`'
-how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name and ImageLoaded (Like sysmon EventCode 7) from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Also be sure to include those monitored dll to your own sysmon config.
-known_false_positives: False positives may occur if legitimate office documents are creating scheduled tasks. Ensure to investigate the scheduled task and the command to be executed. If the task is benign, add the task name to the exclusion list. Some applications may legitimately load taskschd.dll.
+search: '`sysmon` EventCode=7 process_name IN ("EQNEDT32.exe", "excel.exe", "Graph.exe",
+ "msaccess.exe", "mspub.exe", "onenote.exe", "onenoteim.exe", "onenotem.exe", "outlook.exe",
+ "powerpnt.exe", "visio.exe", "winproj.exe", "winword.exe") loaded_file_path = "*\\taskschd.dll"
+ | stats min(_time) as firstTime max(_time) as lastTime count by user_id, dest, process_name,loaded_file,
+ loaded_file_path, original_file_name, process_guid | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)` | `windows_office_product_loading_taskschd_dll_filter`'
+how_to_implement: To successfully implement this search, you need to be ingesting
+ logs with the process name and ImageLoaded (Like sysmon EventCode 7) from your endpoints.
+ If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
+ Also be sure to include those monitored dll to your own sysmon config.
+known_false_positives: False positives may occur if legitimate office documents are
+ creating scheduled tasks. Ensure to investigate the scheduled task and the command
+ to be executed. If the task is benign, add the task name to the exclusion list.
+ Some applications may legitimately load taskschd.dll.
references:
- https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/
- https://redcanary.com/threat-detection-report/techniques/scheduled-task-job/
@@ -21,7 +38,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -37,7 +59,6 @@ tags:
- Spearphishing Attachments
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
@@ -47,6 +68,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_office_product_loading_vbe7_dll.yml b/detections/endpoint/windows_office_product_loading_vbe7_dll.yml
index d4aa93a79a..e68293a575 100644
--- a/detections/endpoint/windows_office_product_loading_vbe7_dll.yml
+++ b/detections/endpoint/windows_office_product_loading_vbe7_dll.yml
@@ -1,16 +1,33 @@
name: Windows Office Product Loading VBE7 DLL
id: 7cfec906-2697-43f7-898b-83634a051d9a
-version: 1
-date: '2025-01-20'
+version: 2
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
-description: The following analytic identifies office documents executing macro code. It leverages Sysmon EventCode 7 to detect when processes like WINWORD.EXE or EXCEL.EXE load specific DLLs associated with macros (e.g., VBE7.DLL). This activity is significant because macros are a common attack vector for delivering malicious payloads, such as malware. If confirmed malicious, this could lead to unauthorized code execution, data exfiltration, or further compromise of the system. Disabling macros by default is recommended to mitigate this risk.
+description: The following analytic identifies office documents executing macro code.
+ It leverages Sysmon EventCode 7 to detect when processes like WINWORD.EXE or EXCEL.EXE
+ load specific DLLs associated with macros (e.g., VBE7.DLL). This activity is significant
+ because macros are a common attack vector for delivering malicious payloads, such
+ as malware. If confirmed malicious, this could lead to unauthorized code execution,
+ data exfiltration, or further compromise of the system. Disabling macros by default
+ is recommended to mitigate this risk.
data_source:
- Sysmon EventID 7
-search: '`sysmon` EventCode=7 process_name IN ("EQNEDT32.exe", "excel.exe", "Graph.exe", "msaccess.exe", "mspub.exe", "onenote.exe", "onenoteim.exe", "onenotem.exe", "outlook.exe", "powerpnt.exe", "visio.exe", "winproj.exe", "winword.exe") loaded_file_path IN ("*\\VBE7INTL.DLL", "*\\VBE7.DLL", "*\\VBEUI.DLL") | stats min(_time) as firstTime max(_time) as lastTime values(loaded_file) as loaded_file count by dest EventCode process_name process_guid | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_office_product_loading_vbe7_dll_filter`'
-how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name and ImageLoaded (Like sysmon EventCode 7) from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Also be sure to include those monitored dll to your own sysmon config.
-known_false_positives: False positives may occur if legitimate office documents are executing macro code. Ensure to investigate the macro code and the command to be executed. If the macro code is benign, add the document name to the exclusion list. Some applications may legitimately load VBE7INTL.DLL, VBE7.DLL, or VBEUI.DLL.
+search: '`sysmon` EventCode=7 process_name IN ("EQNEDT32.exe", "excel.exe", "Graph.exe",
+ "msaccess.exe", "mspub.exe", "onenote.exe", "onenoteim.exe", "onenotem.exe", "outlook.exe",
+ "powerpnt.exe", "visio.exe", "winproj.exe", "winword.exe") loaded_file_path IN ("*\\VBE7INTL.DLL",
+ "*\\VBE7.DLL", "*\\VBEUI.DLL") | stats min(_time) as firstTime max(_time) as lastTime
+ values(loaded_file) as loaded_file count by dest EventCode process_name process_guid
+ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_office_product_loading_vbe7_dll_filter`'
+how_to_implement: To successfully implement this search, you need to be ingesting
+ logs with the process name and ImageLoaded (Like sysmon EventCode 7) from your endpoints.
+ If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
+ Also be sure to include those monitored dll to your own sysmon config.
+known_false_positives: False positives may occur if legitimate office documents are
+ executing macro code. Ensure to investigate the macro code and the command to be
+ executed. If the macro code is benign, add the document name to the exclusion list.
+ Some applications may legitimately load VBE7INTL.DLL, VBE7.DLL, or VBEUI.DLL.
references:
- https://www.joesandbox.com/analysis/386500/0/html
- https://www.joesandbox.com/analysis/702680/0/html
@@ -24,7 +41,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -48,7 +70,6 @@ tags:
- NjRAT
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
@@ -58,6 +79,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml b/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml
index 0b215898be..60bbc6b349 100644
--- a/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml
+++ b/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml
@@ -1,17 +1,38 @@
name: Windows Office Product Spawned Child Process For Download
id: f02b64b8-cbea-4f75-bf77-7a05111566b1
-version: 1
-date: '2025-01-14'
+version: 2
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
-description: The following analytic identifies Office applications spawning child processes to download content via HTTP/HTTPS. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process creation events where Office applications like Word or Excel initiate network connections, excluding common browsers. This activity is significant as it often indicates the use of malicious documents to execute living-off-the-land binaries (LOLBins) for payload delivery. If confirmed malicious, this behavior could lead to unauthorized code execution, data exfiltration, or further malware deployment, posing a severe threat to the organization's security.
+description: The following analytic identifies Office applications spawning child
+ processes to download content via HTTP/HTTPS. It leverages data from Endpoint Detection
+ and Response (EDR) agents, focusing on process creation events where Office applications
+ like Word or Excel initiate network connections, excluding common browsers. This
+ activity is significant as it often indicates the use of malicious documents to
+ execute living-off-the-land binaries (LOLBins) for payload delivery. If confirmed
+ malicious, this behavior could lead to unauthorized code execution, data exfiltration,
+ or further malware deployment, posing a severe threat to the organization's security.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
-search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` Processes.process IN ("*http:*","*https:*") NOT (Processes.original_file_name IN ("firefox.exe", "chrome.exe","iexplore.exe","msedge.exe")) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_office_product_spawned_child_process_for_download_filter`'
-how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
+search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
+ as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent`
+ Processes.process IN ("*http:*","*https:*") NOT (Processes.original_file_name IN
+ ("firefox.exe", "chrome.exe","iexplore.exe","msedge.exe")) by Processes.dest Processes.user
+ Processes.parent_process_name Processes.process_name Processes.process Processes.process_id
+ Processes.parent_process_id Processes.original_file_name | `drop_dm_object_name(Processes)`
+ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_office_product_spawned_child_process_for_download_filter`'
+how_to_implement: The detection is based on data that originates from Endpoint Detection
+ and Response (EDR) agents. These agents are designed to provide security-related
+ telemetry from the endpoints where the agent is installed. To implement this search,
+ you must ingest logs that contain the process GUID, process name, and parent process.
+ Additionally, you must ingest complete command-line executions. These logs must
+ be processed using the appropriate Splunk Technology Add-ons that are specific to
+ the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
+ data model. Use the Splunk Common Information Model (CIM) to normalize the field
+ names and speed up the data modeling process.
known_false_positives: Default browser not in the filter list.
references:
- https://app.any.run/tasks/92d7ef61-bfd7-4c92-bc15-322172b4ebec/
@@ -22,7 +43,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -40,7 +66,6 @@ tags:
- NjRAT
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
@@ -50,6 +75,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets2/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets2/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_office_product_spawned_control.yml b/detections/endpoint/windows_office_product_spawned_control.yml
index 5590c761b9..12ffb28a63 100644
--- a/detections/endpoint/windows_office_product_spawned_control.yml
+++ b/detections/endpoint/windows_office_product_spawned_control.yml
@@ -1,7 +1,7 @@
name: Windows Office Product Spawned Control
id: 081c485d-ac8d-4bee-ad4c-525772fead4d
-version: 1
-date: '2025-01-14'
+version: 3
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -17,7 +17,12 @@ data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
-search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` Processes.process_name=control.exe by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `windows_office_product_spawned_control_filter`'
+search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
+ as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent`
+ Processes.process_name=control.exe by Processes.dest Processes.user Processes.parent_process_name
+ Processes.parent_process Processes.process_name Processes.process Processes.process_id
+ Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`|
+ `security_content_ctime(lastTime)`| `windows_office_product_spawned_control_filter`'
how_to_implement: The detection is based on data that originates from Endpoint Detection
and Response (EDR) agents. These agents are designed to provide security-related
telemetry from the endpoints where the agent is installed. To implement this search,
@@ -71,7 +76,6 @@ tags:
cve:
- CVE-2021-40444
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
@@ -81,6 +85,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_control.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_control.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_office_product_spawned_msdt.yml b/detections/endpoint/windows_office_product_spawned_msdt.yml
index 3a79e47208..9f855ec660 100644
--- a/detections/endpoint/windows_office_product_spawned_msdt.yml
+++ b/detections/endpoint/windows_office_product_spawned_msdt.yml
@@ -1,7 +1,7 @@
name: Windows Office Product Spawned MSDT
id: a3148fad-3734-4b7f-9a71-62f08d39fab1
-version: 1
-date: '2025-01-14'
+version: 3
+date: '2025-02-10'
author: Michael Haag, Teoderick Contreras, Splunk
status: production
type: TTP
@@ -17,7 +17,12 @@ data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
-search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` Processes.process_name=msdt.exe by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_office_product_spawned_msdt_filter`'
+search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
+ as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent`
+ Processes.process_name=msdt.exe by Processes.dest Processes.user Processes.parent_process_name
+ Processes.parent_process Processes.process_name Processes.original_file_name Processes.process
+ Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
+ | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_office_product_spawned_msdt_filter`'
how_to_implement: The detection is based on data that originates from Endpoint Detection
and Response (EDR) agents. These agents are designed to provide security-related
telemetry from the endpoints where the agent is installed. To implement this search,
@@ -74,7 +79,6 @@ tags:
cve:
- CVE-2022-30190
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
@@ -84,6 +88,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/msdt.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/msdt.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_office_product_spawned_rundll32_with_no_dll.yml b/detections/endpoint/windows_office_product_spawned_rundll32_with_no_dll.yml
index 21813278bb..f44212470f 100644
--- a/detections/endpoint/windows_office_product_spawned_rundll32_with_no_dll.yml
+++ b/detections/endpoint/windows_office_product_spawned_rundll32_with_no_dll.yml
@@ -1,7 +1,7 @@
name: Windows Office Product Spawned Rundll32 With No DLL
id: f28e787e-69ca-480e-9f98-ab970e6d4bcc
-version: 1
-date: '2025-01-14'
+version: 2
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -17,7 +17,12 @@ data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
-search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` `process_rundll32` (Processes.process!=*.dll*) by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_office_product_spawned_rundll32_with_no_dll_filter`'
+search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
+ as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent`
+ `process_rundll32` (Processes.process!=*.dll*) by Processes.dest Processes.user
+ Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process
+ Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
+ | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_office_product_spawned_rundll32_with_no_dll_filter`'
how_to_implement: The detection is based on data that originates from Endpoint Detection
and Response (EDR) agents. These agents are designed to provide security-related
telemetry from the endpoints where the agent is installed. To implement this search,
@@ -68,7 +73,6 @@ tags:
- Crypto Stealer
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
@@ -78,6 +82,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_icedid.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_icedid.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_office_product_spawned_uncommon_process.yml b/detections/endpoint/windows_office_product_spawned_uncommon_process.yml
index 5dc516ea3d..be1ba871e9 100644
--- a/detections/endpoint/windows_office_product_spawned_uncommon_process.yml
+++ b/detections/endpoint/windows_office_product_spawned_uncommon_process.yml
@@ -1,17 +1,39 @@
name: Windows Office Product Spawned Uncommon Process
id: 55d8741c-fa32-4692-8109-410304961eb8
-version: 1
-date: '2025-01-13'
+version: 2
+date: '2025-02-10'
author: Michael Haag, Teoderick Contreras, Splunk
status: production
type: TTP
-description: The following analytic detects a Microsoft Office product spawning uncommon processes. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process creation events where Office applications are the parent process. This activity is significant as it may indicate an attempt of a malicious macro execution or exploitation of an unknown vulnerability in an office product, in order to bypass security controls. If confirmed malicious, this behavior could allow an attacker to execute arbitrary code, potentially leading to system compromise, data exfiltration, or further lateral movement within the network.
+description: The following analytic detects a Microsoft Office product spawning uncommon
+ processes. This detection leverages data from Endpoint Detection and Response (EDR)
+ agents, focusing on process creation events where Office applications are the parent
+ process. This activity is significant as it may indicate an attempt of a malicious
+ macro execution or exploitation of an unknown vulnerability in an office product,
+ in order to bypass security controls. If confirmed malicious, this behavior could
+ allow an attacker to execute arbitrary code, potentially leading to system compromise,
+ data exfiltration, or further lateral movement within the network.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
-search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` AND (`process_bitsadmin` OR `process_certutil` OR `process_cmd` OR `process_cscript` OR `process_mshta` OR `process_powershell` OR `process_regsvr32` OR `process_rundll32` OR `process_wmic` OR `process_wscript`) by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_office_product_spawned_uncommon_process_filter`'
-how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
+search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
+ as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent`
+ AND (`process_bitsadmin` OR `process_certutil` OR `process_cmd` OR `process_cscript`
+ OR `process_mshta` OR `process_powershell` OR `process_regsvr32` OR `process_rundll32`
+ OR `process_wmic` OR `process_wscript`) by Processes.dest Processes.user Processes.parent_process_name
+ Processes.parent_process Processes.process_name Processes.original_file_name Processes.process
+ Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
+ | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_office_product_spawned_uncommon_process_filter`'
+how_to_implement: The detection is based on data that originates from Endpoint Detection
+ and Response (EDR) agents. These agents are designed to provide security-related
+ telemetry from the endpoints where the agent is installed. To implement this search,
+ you must ingest logs that contain the process GUID, process name, and parent process.
+ Additionally, you must ingest complete command-line executions. These logs must
+ be processed using the appropriate Splunk Technology Add-ons that are specific to
+ the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
+ data model. Use the Splunk Common Information Model (CIM) to normalize the field
+ names and speed up the data modeling process.
known_false_positives: False positives should be limited, however filter as needed.
references:
- https://any.run/malware-trends/trickbot
@@ -74,7 +96,6 @@ tags:
- Warzone RAT
asset_type: Endpoint
mitre_attack_id:
- - T1566
- T1566.001
product:
- Splunk Enterprise
@@ -84,26 +105,31 @@ tags:
tests:
- name: True Positive Test - Macro
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
- name: True Positive Test - IcedId
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/phish_icedid/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/phish_icedid/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
-- name: True Positive Test
+- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.002/atomic_red_team/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.002/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
- name: True Positive Test - TrickBot
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/spear_phish/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/spear_phish/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_papercut_ng_spawn_shell.yml b/detections/endpoint/windows_papercut_ng_spawn_shell.yml
index 31198dc5a3..d647e50311 100644
--- a/detections/endpoint/windows_papercut_ng_spawn_shell.yml
+++ b/detections/endpoint/windows_papercut_ng_spawn_shell.yml
@@ -1,6 +1,6 @@
name: Windows PaperCut NG Spawn Shell
id: a602d9a2-aaea-45f8-bf0f-d851168d61ca
-version: 6
+version: 7
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_parent_pid_spoofing_with_explorer.yml b/detections/endpoint/windows_parent_pid_spoofing_with_explorer.yml
index 11cc9f084e..1fb1a5fb88 100644
--- a/detections/endpoint/windows_parent_pid_spoofing_with_explorer.yml
+++ b/detections/endpoint/windows_parent_pid_spoofing_with_explorer.yml
@@ -1,7 +1,7 @@
name: Windows Parent PID Spoofing with Explorer
id: 17f8f69c-5d00-4c88-9c6f-493bbdef20a1
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -62,7 +62,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1134.004
- - T1134
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_phishing_pdf_file_executes_url_link.yml b/detections/endpoint/windows_phishing_pdf_file_executes_url_link.yml
index 18c5531a67..13103b18d8 100644
--- a/detections/endpoint/windows_phishing_pdf_file_executes_url_link.yml
+++ b/detections/endpoint/windows_phishing_pdf_file_executes_url_link.yml
@@ -1,7 +1,7 @@
name: Windows Phishing PDF File Executes URL Link
id: 2fa9dec8-9d8e-46d3-96c1-202c06f0e6e1
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1566.001
- - T1566
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml b/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml
index 2b4bed4e9f..bc0b87b903 100644
--- a/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml
+++ b/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml
@@ -1,7 +1,7 @@
name: Windows Phishing Recent ISO Exec Registry
id: cb38ee66-8ae5-47de-bd66-231c7bbc0b2c
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -48,7 +48,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1566.001
- - T1566
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_possible_credential_dumping.yml b/detections/endpoint/windows_possible_credential_dumping.yml
index 470fcafb77..2d20510beb 100644
--- a/detections/endpoint/windows_possible_credential_dumping.yml
+++ b/detections/endpoint/windows_possible_credential_dumping.yml
@@ -1,7 +1,7 @@
name: Windows Possible Credential Dumping
id: e4723b92-7266-11ec-af45-acde48001122
-version: 7
-date: '2024-11-13'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -74,7 +74,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.001
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_powershell_add_module_to_global_assembly_cache.yml b/detections/endpoint/windows_powershell_add_module_to_global_assembly_cache.yml
index be0d947169..e74b775e06 100644
--- a/detections/endpoint/windows_powershell_add_module_to_global_assembly_cache.yml
+++ b/detections/endpoint/windows_powershell_add_module_to_global_assembly_cache.yml
@@ -1,7 +1,7 @@
name: Windows PowerShell Add Module to Global Assembly Cache
id: 3fc16961-97e5-4a5b-a079-e4ab0d9763eb
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -54,7 +54,6 @@ tags:
- IIS Components
asset_type: Endpoint
mitre_attack_id:
- - T1505
- T1505.004
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_powershell_cryptography_namespace.yml b/detections/endpoint/windows_powershell_cryptography_namespace.yml
index bf088f301f..cdcc825296 100644
--- a/detections/endpoint/windows_powershell_cryptography_namespace.yml
+++ b/detections/endpoint/windows_powershell_cryptography_namespace.yml
@@ -1,7 +1,7 @@
name: Windows Powershell Cryptography Namespace
id: f8b482f4-6d62-49fa-a905-dfa15698317b
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -58,7 +58,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1059.001
- - T1059
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_powershell_disable_http_logging.yml b/detections/endpoint/windows_powershell_disable_http_logging.yml
index 4c3060bb6a..b770a22794 100644
--- a/detections/endpoint/windows_powershell_disable_http_logging.yml
+++ b/detections/endpoint/windows_powershell_disable_http_logging.yml
@@ -1,7 +1,7 @@
name: Windows PowerShell Disable HTTP Logging
id: 27958de0-2857-43ca-9d4c-b255cf59dcab
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -58,10 +58,8 @@ tags:
- Windows Defense Evasion Tactics
asset_type: Endpoint
mitre_attack_id:
- - T1562
- - T1562.002
- - T1505
- T1505.004
+ - T1562.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_powershell_export_certificate.yml b/detections/endpoint/windows_powershell_export_certificate.yml
index bbe40a4adc..acbed42b34 100644
--- a/detections/endpoint/windows_powershell_export_certificate.yml
+++ b/detections/endpoint/windows_powershell_export_certificate.yml
@@ -1,7 +1,7 @@
name: Windows PowerShell Export Certificate
id: 5e38ded4-c964-41f4-8cb6-4a1a53c6929f
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Anomaly
@@ -55,7 +55,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1552.004
- - T1552
- T1649
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_powershell_export_pfxcertificate.yml b/detections/endpoint/windows_powershell_export_pfxcertificate.yml
index 7f493a22c9..8a44eca228 100644
--- a/detections/endpoint/windows_powershell_export_pfxcertificate.yml
+++ b/detections/endpoint/windows_powershell_export_pfxcertificate.yml
@@ -1,7 +1,7 @@
name: Windows PowerShell Export PfxCertificate
id: ed06725f-6da6-439f-9dcc-ab30e891297c
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Anomaly
@@ -54,7 +54,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1552.004
- - T1552
- T1649
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_powershell_iis_components_webglobalmodule_usage.yml b/detections/endpoint/windows_powershell_iis_components_webglobalmodule_usage.yml
index ae73b3a6e6..3a9bdc8cc3 100644
--- a/detections/endpoint/windows_powershell_iis_components_webglobalmodule_usage.yml
+++ b/detections/endpoint/windows_powershell_iis_components_webglobalmodule_usage.yml
@@ -1,7 +1,7 @@
name: Windows PowerShell IIS Components WebGlobalModule Usage
id: 33fc9f6f-0ce7-4696-924e-a69ec61a3d57
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Anomaly
@@ -58,7 +58,6 @@ tags:
- IIS Components
asset_type: Endpoint
mitre_attack_id:
- - T1505
- T1505.004
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_powershell_import_applocker_policy.yml b/detections/endpoint/windows_powershell_import_applocker_policy.yml
index a2cfb60449..b7e2a44f69 100644
--- a/detections/endpoint/windows_powershell_import_applocker_policy.yml
+++ b/detections/endpoint/windows_powershell_import_applocker_policy.yml
@@ -1,7 +1,7 @@
name: Windows Powershell Import Applocker Policy
id: 102af98d-0ca3-4aa4-98d6-7ab2b98b955a
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -58,9 +58,7 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1059.001
- - T1059
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_powershell_logoff_user_via_quser.yml b/detections/endpoint/windows_powershell_logoff_user_via_quser.yml
index c22dd241a4..1e2d7ad33b 100644
--- a/detections/endpoint/windows_powershell_logoff_user_via_quser.yml
+++ b/detections/endpoint/windows_powershell_logoff_user_via_quser.yml
@@ -1,20 +1,26 @@
name: Windows Powershell Logoff User via Quser
id: 6d70780d-4cfe-4820-bafd-1b43941986b5
-version: 1
-date: '2024-12-12'
+version: 2
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
data_source:
- Powershell Script Block Logging 4104
type: Anomaly
status: production
-description: The following analytic detects the process of logging off a user through the use of the quser and logoff commands. By monitoring for these commands, the analytic identifies actions where a user session is forcibly terminated, which could be part of an administrative task or a potentially unauthorized access attempt. This detection helps identify potential misuse or malicious activity where a user’s access is revoked without proper authorization, providing insight into potential security incidents involving account management or session manipulation.
-search: '`powershell` EventCode=4104 ScriptBlockText = "*quser*logoff*"
- | stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText UserID Computer
- | rename Computer as dest, UserID as user
- | `security_content_ctime(firstTime)`
- | `security_content_ctime(lastTime)`
- | `windows_powershell_logoff_user_via_quser_filter`'
-how_to_implement: The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging.
+description: The following analytic detects the process of logging off a user through
+ the use of the quser and logoff commands. By monitoring for these commands, the
+ analytic identifies actions where a user session is forcibly terminated, which could
+ be part of an administrative task or a potentially unauthorized access attempt.
+ This detection helps identify potential misuse or malicious activity where a user’s
+ access is revoked without proper authorization, providing insight into potential
+ security incidents involving account management or session manipulation.
+search: '`powershell` EventCode=4104 ScriptBlockText = "*quser*logoff*" | stats count
+ min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText UserID
+ Computer | rename Computer as dest, UserID as user | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)` | `windows_powershell_logoff_user_via_quser_filter`'
+how_to_implement: The following Hunting analytic requires PowerShell operational logs
+ to be imported. Modify the powershell macro as needed to match the sourcetype or
+ add index. This analytic is specific to 4104, or PowerShell Script Block Logging.
known_false_positives: Administrators or power users may use this command.
references:
- https://devblogs.microsoft.com/scripting/automating-quser-through-powershell/
@@ -24,11 +30,17 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
- message: Powershell process having commandline [$ScriptBlockText$] used to logoff user on [$dest$].
+ message: Powershell process having commandline [$ScriptBlockText$] used to logoff
+ user on [$dest$].
risk_objects:
- field: dest
type: system
@@ -39,9 +51,8 @@ tags:
- Crypto Stealer
asset_type: Endpoint
mitre_attack_id:
- - T1531
- T1059.001
- - T1059
+ - T1531
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -50,6 +61,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/log_off_user/pwh_quser_logoff.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/log_off_user/pwh_quser_logoff.log
source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_powershell_remotesigned_file.yml b/detections/endpoint/windows_powershell_remotesigned_file.yml
index 64bd011024..63df593e37 100644
--- a/detections/endpoint/windows_powershell_remotesigned_file.yml
+++ b/detections/endpoint/windows_powershell_remotesigned_file.yml
@@ -1,7 +1,7 @@
name: Windows Powershell RemoteSigned File
id: f7f7456b-470d-4a95-9703-698250645ff4
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -65,7 +65,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1059.001
- - T1059
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_powershell_scheduletask.yml b/detections/endpoint/windows_powershell_scheduletask.yml
index 2cb840930a..0aaa0d5614 100644
--- a/detections/endpoint/windows_powershell_scheduletask.yml
+++ b/detections/endpoint/windows_powershell_scheduletask.yml
@@ -1,7 +1,7 @@
name: Windows PowerShell ScheduleTask
id: ddf82fcb-e9ee-40e3-8712-a50b5bf323fc
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Anomaly
@@ -65,7 +65,6 @@ tags:
mitre_attack_id:
- T1053.005
- T1059.001
- - T1059
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_powershell_wmi_win32_scheduledjob.yml b/detections/endpoint/windows_powershell_wmi_win32_scheduledjob.yml
index 358d2f9f2c..4ec8982c98 100644
--- a/detections/endpoint/windows_powershell_wmi_win32_scheduledjob.yml
+++ b/detections/endpoint/windows_powershell_wmi_win32_scheduledjob.yml
@@ -1,7 +1,7 @@
name: Windows PowerShell WMI Win32 ScheduledJob
id: 47c69803-2c09-408b-b40a-063c064cbb16
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
type: TTP
status: production
@@ -58,7 +58,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1059.001
- - T1059
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_powersploit_gpp_discovery.yml b/detections/endpoint/windows_powersploit_gpp_discovery.yml
index c0bc3bffb3..cdd8803bc9 100644
--- a/detections/endpoint/windows_powersploit_gpp_discovery.yml
+++ b/detections/endpoint/windows_powersploit_gpp_discovery.yml
@@ -1,7 +1,7 @@
name: Windows PowerSploit GPP Discovery
id: 0130a0df-83a1-4647-9011-841e950ff302
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -59,7 +59,6 @@ tags:
- Active Directory Privilege Escalation
asset_type: Endpoint
mitre_attack_id:
- - T1552
- T1552.006
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_powerview_kerberos_service_ticket_request.yml b/detections/endpoint/windows_powerview_kerberos_service_ticket_request.yml
index 77bff74777..0fa3ee8fe5 100644
--- a/detections/endpoint/windows_powerview_kerberos_service_ticket_request.yml
+++ b/detections/endpoint/windows_powerview_kerberos_service_ticket_request.yml
@@ -1,7 +1,7 @@
name: Windows PowerView Kerberos Service Ticket Request
id: 970455a1-4ac2-47e1-a9a5-9e75443ddcb9
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
- Rhysida Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1558
- T1558.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_powerview_spn_discovery.yml b/detections/endpoint/windows_powerview_spn_discovery.yml
index a3184c2941..8abe7becab 100644
--- a/detections/endpoint/windows_powerview_spn_discovery.yml
+++ b/detections/endpoint/windows_powerview_spn_discovery.yml
@@ -1,7 +1,7 @@
name: Windows PowerView SPN Discovery
id: a7093c28-796c-4ebb-9997-e2c18b870837
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
- Active Directory Kerberos Attacks
asset_type: Endpoint
mitre_attack_id:
- - T1558
- T1558.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_private_keys_discovery.yml b/detections/endpoint/windows_private_keys_discovery.yml
index 27fffec337..74c47622aa 100644
--- a/detections/endpoint/windows_private_keys_discovery.yml
+++ b/detections/endpoint/windows_private_keys_discovery.yml
@@ -1,7 +1,7 @@
name: Windows Private Keys Discovery
id: 5c1c2877-06c0-40ee-a1a2-db71f1372b5b
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -70,7 +70,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1552.004
- - T1552
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_privilege_escalation_suspicious_process_elevation.yml b/detections/endpoint/windows_privilege_escalation_suspicious_process_elevation.yml
index 6b4490c90e..c94417e9e5 100644
--- a/detections/endpoint/windows_privilege_escalation_suspicious_process_elevation.yml
+++ b/detections/endpoint/windows_privilege_escalation_suspicious_process_elevation.yml
@@ -1,6 +1,6 @@
name: Windows Privilege Escalation Suspicious Process Elevation
id: 6a80300a-9f8a-4f22-bd3e-09ca577cfdfc
-version: 4
+version: 5
date: '2024-11-13'
author: Steven Dick
status: production
diff --git a/detections/endpoint/windows_process_executed_from_removable_media.yml b/detections/endpoint/windows_process_executed_from_removable_media.yml
new file mode 100644
index 0000000000..6e3b66300b
--- /dev/null
+++ b/detections/endpoint/windows_process_executed_from_removable_media.yml
@@ -0,0 +1,81 @@
+name: Windows Process Executed From Removable Media
+id: b483804a-4cc0-49a4-9f00-ac29ba844d08
+version: 1
+date: '2025-01-17'
+author: Steven Dick
+status: production
+type: Anomaly
+description: This analytic is used to identify when a removable media device is attached to a machine and then a process is executed from the same drive letter assigned to the removable media device. Adversaries and Insider Threats may use removable media devices for several malicious activities, including initial access, execution, and exfiltration.
+data_source:
+- Windows Security Event ID 4688
+- Sysmon Event ID 1
+- Sysmon Event ID 12
+- Sysmon Event ID 13
+- CrowdStrike ProcessRollup2
+search: |-
+ | tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_current_directory=* AND NOT Processes.process_current_directory IN ("C:\\*","*\\sysvol\\*") by Processes.dest Processes.user Processes.process_name Processes.parent_process_name Processes.process_current_directory
+ | `drop_dm_object_name(Processes)`
+ | rex field=process_current_directory "^(?[^\\\]+\\\)"
+ | where isnotnull(object_handle)
+ | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`
+ | join dest,object_handle
+ [| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_value_data="*:\\*" AND Registry.registry_path="*USBSTOR*" AND Registry.registry_path IN ("HKLM\\SOFTWARE\\Microsoft\\Windows Portable Devices\\Devices\\*","HKLM\\System\\CurrentControlSet\\Enum\\SWD\\WPDBUSENUM\\*") by Registry.dest,Registry.registry_value_data,Registry.registry_path
+ | `drop_dm_object_name(Registry)`
+ | eval object_handle = registry_value_data, object_name = replace(mvindex(split(mvindex(split(registry_path, "??"),1),"&"),2),"PROD_","")
+ ]
+ | `windows_process_executed_from_removable_media_filter`
+how_to_implement: To successfully implement this search, you must ingest endpoint logging that tracks changes to the HKLM\SOFTWARE\Microsoft\Windows Portable Devices\Devices\ or HKLM\System\CurrentControlSet\Enum\SWD\WPDBUSENUM\ registry keys as well as Process Execution commands. Ensure that the field from the event logs is being mapped to the proper fields in the Endpoint.Registry data model. This analytic joins the Process and Registry datamodels together based on the drive letter extract to the "object_handle" field from both datasets.
+known_false_positives: Legitimate USB activity will also be detected. Please verify and investigate as appropriate.
+references:
+- https://attack.mitre.org/techniques/T1200/
+- https://www.cisa.gov/news-events/news/using-caution-usb-drives
+- https://www.bleepingcomputer.com/news/security/fbi-hackers-use-badusb-to-target-defense-firms-with-ransomware/
+drilldown_searches:
+- name: View the detection results for - "$dest$" and "$user$"
+ search: '%original_detection_search% | search dest = "$dest$" and user= "$user$"'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: View risk events for the last 7 days for - "$dest$" and "$user$"
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$" , "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: Investigate USB events on $dest$
+ search: '| from datamodel:Endpoint.Processes | search dest=$dest$ process_current_directory=$object_handle$*'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+rba:
+ message: The process [$process_name$] was launched using files on a removable storage device named [$object_name$] by [$user$] on $dest$
+ risk_objects:
+ - field: user
+ type: user
+ score: 35
+ - field: dest
+ type: system
+ score: 35
+ threat_objects:
+ - field: process_name
+ type: process_name
+ - field: object_name
+ type: registry_value_name
+ - field: object_handle
+ type: registry_value_text
+tags:
+ analytic_story:
+ - Data Protection
+ asset_type: Endpoint
+ mitre_attack_id:
+ - T1200
+ - T1025
+ - T1091
+ product:
+ - Splunk Enterprise
+ - Splunk Enterprise Security
+ - Splunk Cloud
+ security_domain: endpoint
+tests:
+- name: True Positive Test
+ attack_data:
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1200/sysmon_usb_use_execution/sysmon_usb_use_execution.log
+ source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
+ sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_process_execution_in_temp_dir.yml b/detections/endpoint/windows_process_execution_in_temp_dir.yml
new file mode 100644
index 0000000000..c8909b0013
--- /dev/null
+++ b/detections/endpoint/windows_process_execution_in_temp_dir.yml
@@ -0,0 +1,87 @@
+name: Windows Process Execution in Temp Dir
+id: f6fbe929-4187-4ba4-901e-8a34be838443
+version: 1
+date: '2025-01-27'
+author: Teoderick Contreras, Splunk
+status: production
+type: Anomaly
+description: The following analytic identifies processes running from %temp% directory file paths.
+ It leverages data from Endpoint Detection and Response (EDR) agents, focusing on specific process paths within the Endpoint
+ data model. This activity is significant because adversaries often use unconventional file paths to execute malicious code without requiring administrative privileges. If confirmed malicious, this behavior could indicate an attempt to bypass security controls, leading to unauthorized software execution, potential system compromise, and further malicious activities within the environment.
+data_source:
+- Sysmon EventID 1
+- Windows Event Log Security 4688
+- CrowdStrike ProcessRollup2
+search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
+ where Processes.process_path IN("*\\temp\\*")
+ by Processes.parent_process_name Processes.parent_process Processes.process_path Processes.dest Processes.user
+ | `drop_dm_object_name(Processes)`
+ | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`
+ | `windows_process_execution_in_temp_dir_filter`'
+how_to_implement: The detection is based on data that originates from Endpoint Detection
+ and Response (EDR) agents. These agents are designed to provide security-related
+ telemetry from the endpoints where the agent is installed. To implement this search,
+ you must ingest logs that contain the process GUID, process name, and parent process.
+ Additionally, you must ingest complete command-line executions. These logs must
+ be processed using the appropriate Splunk Technology Add-ons that are specific to
+ the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
+ data model. Use the Splunk Common Information Model (CIM) to normalize the field
+ names and speed up the data modeling process.
+known_false_positives: Administrators may allow execution of specific binaries in
+ non-standard paths. Filter as needed.
+references:
+- https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/
+- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
+- https://twitter.com/pr0xylife/status/1590394227758104576
+- https://malpedia.caad.fkie.fraunhofer.de/details/win.asyncrat
+- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
+drilldown_searches:
+- name: View the detection results for - "$dest$"
+ search: '%original_detection_search% | search dest = "$dest$"'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: View risk events for the last 7 days for - "$dest$"
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+rba:
+ message: Suspicious process $process_name$ running from temp directory-
+ $process_path$ on host- $dest$
+ risk_objects:
+ - field: dest
+ type: system
+ score: 30
+ threat_objects:
+ - field: process_path
+ type: process_name
+tags:
+ analytic_story:
+ - Ryuk Ransomware
+ - Trickbot
+ - Qakbot
+ - AgentTesla
+ - Remcos
+ - NjRAT
+ - Ransomware
+ asset_type: Endpoint
+ mitre_attack_id:
+ - T1543
+ - T1036.005
+ product:
+ - Splunk Enterprise
+ - Splunk Enterprise Security
+ - Splunk Cloud
+ security_domain: endpoint
+tests:
+- name: True Positive Test
+ attack_data:
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/process_temp_path/process_temp_path.log
+ source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
+ sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_process_injection_into_notepad.yml b/detections/endpoint/windows_process_injection_into_notepad.yml
index 6e1e86e9f8..8a4a772575 100644
--- a/detections/endpoint/windows_process_injection_into_notepad.yml
+++ b/detections/endpoint/windows_process_injection_into_notepad.yml
@@ -1,7 +1,7 @@
name: Windows Process Injection into Notepad
id: b8340d0f-ba48-4391-bea7-9e793c5aae36
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
type: Anomaly
status: production
@@ -61,7 +61,6 @@ tags:
- BishopFox Sliver Adversary Emulation Framework
asset_type: Endpoint
mitre_attack_id:
- - T1055
- T1055.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml b/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml
index 7ca8139ceb..4c35239780 100644
--- a/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml
+++ b/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml
@@ -1,7 +1,7 @@
name: Windows Process Injection Of Wermgr to Known Browser
id: aec755a5-3a2c-4be0-ab34-6540e68644e9
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1055.001
- - T1055
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_process_injection_remote_thread.yml b/detections/endpoint/windows_process_injection_remote_thread.yml
index acb2c928e0..48d56aec9f 100644
--- a/detections/endpoint/windows_process_injection_remote_thread.yml
+++ b/detections/endpoint/windows_process_injection_remote_thread.yml
@@ -1,7 +1,7 @@
name: Windows Process Injection Remote Thread
id: 8a618ade-ca8f-4d04-b972-2d526ba59924
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
- Warzone RAT
asset_type: Endpoint
mitre_attack_id:
- - T1055
- T1055.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_process_injection_with_public_source_path.yml b/detections/endpoint/windows_process_injection_with_public_source_path.yml
index 6ff6638edb..3034d4db52 100644
--- a/detections/endpoint/windows_process_injection_with_public_source_path.yml
+++ b/detections/endpoint/windows_process_injection_with_public_source_path.yml
@@ -1,7 +1,7 @@
name: Windows Process Injection With Public Source Path
id: 492f09cf-5d60-4d87-99dd-0bc325532dda
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -33,7 +33,6 @@ tags:
- Brute Ratel C4
asset_type: Endpoint
mitre_attack_id:
- - T1055
- T1055.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_process_with_netexec_command_line_parameters.yml b/detections/endpoint/windows_process_with_netexec_command_line_parameters.yml
index 578832eea3..82eb5c76bd 100644
--- a/detections/endpoint/windows_process_with_netexec_command_line_parameters.yml
+++ b/detections/endpoint/windows_process_with_netexec_command_line_parameters.yml
@@ -1,70 +1,68 @@
-name: Windows Process With NetExec Command Line Parameters
-id: adbff89c-c1f2-4a2e-88a4-b5e645856510
-version: 2
-date: '2025-01-09'
-author: Steven Dick, Github Community
-status: production
-type: TTP
-description: The following analytic detects the use of NetExec (formally CrackmapExec) a toolset used for post-exploitation enumeration and attack within Active Directory environments through command line parameters. It leverages Endpoint Detection and Response (EDR) data to identify specific command-line arguments associated with actions like ticket manipulation, kerberoasting, and password spraying. This activity is significant as NetExec is used by adversaries to exploit Kerberos for privilege escalation and lateral movement. If confirmed malicious, this could lead to unauthorized access, persistence, and potential compromise of sensitive information within the network.
-data_source:
-- Windows Security Event ID 4688
-- Sysmon Event ID 1
-- CrowdStrike ProcessRollup2
-search: '| tstats `security_content_summariesonly` values(Processes.parent_process) as Processes.parent_process, values(Processes.process) as Processes.process values(Processes.process_current_directory) AS process_current_directory, values(Processes.process_id) as Processes.process_id, values(Processes.process_guid) as Processes.process_guid, count min(_time) AS firstTime, max(_time) AS lastTime FROM datamodel=Endpoint.Processes where Processes.process_name IN ("nxc.exe") OR Processes.original_file_name IN ("nxc.exe") OR (Processes.process IN ("* smb *","* ssh *","* ldap *","* ftp *","* wmi *","* winrm *","* rdp *","* vnc *","* mssql *","* nfs *") AND ((Processes.process = "* -p *" AND Processes.process = "* -u *") OR Processes.process IN ("* -x *","* -M *","* --*"))) BY _time span=1h Processes.user Processes.dest Processes.process_name Processes.parent_process_name
-|`drop_dm_object_name(Processes)`
-| `security_content_ctime(firstTime)`
-| `security_content_ctime(lastTime)`
-| `windows_process_with_netexec_command_line_parameters_filter`'
-how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
-known_false_positives: Although unlikely, legitimate applications may use the same command line parameters as NetExec. Filter as needed.
-references:
-- https://www.netexec.wiki/
-- https://www.johnvictorwolfe.com/2024/07/21/the-successor-to-crackmapexec/
-- https://attack.mitre.org/software/S0488/
-drilldown_searches:
-- name: View the detection results for - "$dest$" and "$user$"
- search: '%original_detection_search% | search dest = "$dest$" user = "$user$"'
- earliest_offset: $info_min_time$
- latest_offset: $info_max_time$
-- name: View risk events for the last 7 days for - "$dest$" and "$user$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$","$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
- earliest_offset: $info_min_time$
- latest_offset: $info_max_time$
-- name: Investigate processes on $dest$
- search: '| from datamodel:Endpoint.Processes | search dest=$dest$ process_name = $process_name$'
- earliest_offset: $info_min_time$
- latest_offset: $info_max_time$
-rba:
- message: NetExec command line parameters were used on $dest$ by $user$
- risk_objects:
- - field: user
- type: user
- score: 64
- - field: dest
- type: system
- score: 64
- threat_objects:
- - field: parent_process_name
- type: parent_process_name
-tags:
- analytic_story:
- - Active Directory Kerberos Attacks
- - Active Directory Privilege Escalation
- asset_type: Endpoint
- mitre_attack_id:
- - T1550
- - T1550.003
- - T1558
- - T1558.003
- - T1558.004
- product:
- - Splunk Enterprise
- - Splunk Enterprise Security
- - Splunk Cloud
- security_domain: endpoint
-tests:
-- name: True Positive Test
- attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550/netexec_toolkit_usage/netexec_toolkit_usage.log
- source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
- sourcetype: XmlWinEventLog
+name: Windows Process With NetExec Command Line Parameters
+id: adbff89c-c1f2-4a2e-88a4-b5e645856510
+version: 3
+date: '2025-02-11'
+author: Steven Dick, Github Community
+status: production
+type: TTP
+description: The following analytic detects the use of NetExec (formally CrackmapExec) a toolset used for post-exploitation enumeration and attack within Active Directory environments through command line parameters. It leverages Endpoint Detection and Response (EDR) data to identify specific command-line arguments associated with actions like ticket manipulation, kerberoasting, and password spraying. This activity is significant as NetExec is used by adversaries to exploit Kerberos for privilege escalation and lateral movement. If confirmed malicious, this could lead to unauthorized access, persistence, and potential compromise of sensitive information within the network.
+data_source:
+- Windows Security Event ID 4688
+- Sysmon EventID 1
+- CrowdStrike ProcessRollup2
+search: '| tstats `security_content_summariesonly` values(Processes.parent_process) as Processes.parent_process, values(Processes.process) as Processes.process values(Processes.process_current_directory) AS process_current_directory, values(Processes.process_id) as Processes.process_id, values(Processes.process_guid) as Processes.process_guid, count min(_time) AS firstTime, max(_time) AS lastTime FROM datamodel=Endpoint.Processes where Processes.process_name IN ("nxc.exe") OR Processes.original_file_name IN ("nxc.exe") OR (Processes.process IN ("* smb *","* ssh *","* ldap *","* ftp *","* wmi *","* winrm *","* rdp *","* vnc *","* mssql *","* nfs *") AND ((Processes.process = "* -p *" AND Processes.process = "* -u *") OR Processes.process IN ("* -x *","* -M *","* --*"))) BY _time span=1h Processes.user Processes.dest Processes.process_name Processes.parent_process_name
+|`drop_dm_object_name(Processes)`
+| `security_content_ctime(firstTime)`
+| `security_content_ctime(lastTime)`
+| `windows_process_with_netexec_command_line_parameters_filter`'
+how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
+known_false_positives: Although unlikely, legitimate applications may use the same command line parameters as NetExec. Filter as needed.
+references:
+- https://www.netexec.wiki/
+- https://www.johnvictorwolfe.com/2024/07/21/the-successor-to-crackmapexec/
+- https://attack.mitre.org/software/S0488/
+drilldown_searches:
+- name: View the detection results for - "$dest$" and "$user$"
+ search: '%original_detection_search% | search dest = "$dest$" user = "$user$"'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: View risk events for the last 7 days for - "$dest$" and "$user$"
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$","$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: Investigate processes on $dest$
+ search: '| from datamodel:Endpoint.Processes | search dest=$dest$ process_name = $process_name$'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+rba:
+ message: NetExec command line parameters were used on $dest$ by $user$
+ risk_objects:
+ - field: user
+ type: user
+ score: 64
+ - field: dest
+ type: system
+ score: 64
+ threat_objects:
+ - field: parent_process_name
+ type: parent_process_name
+tags:
+ analytic_story:
+ - Active Directory Kerberos Attacks
+ - Active Directory Privilege Escalation
+ asset_type: Endpoint
+ mitre_attack_id:
+ - T1550.003
+ - T1558.003
+ - T1558.004
+ product:
+ - Splunk Enterprise
+ - Splunk Enterprise Security
+ - Splunk Cloud
+ security_domain: endpoint
+tests:
+- name: True Positive Test
+ attack_data:
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550/netexec_toolkit_usage/netexec_toolkit_usage.log
+ source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
+ sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_protocol_tunneling_with_plink.yml b/detections/endpoint/windows_protocol_tunneling_with_plink.yml
index 3a6481da48..b55caf7791 100644
--- a/detections/endpoint/windows_protocol_tunneling_with_plink.yml
+++ b/detections/endpoint/windows_protocol_tunneling_with_plink.yml
@@ -1,6 +1,6 @@
name: Windows Protocol Tunneling with Plink
id: 8aac5e1e-0fab-4437-af0b-c6e60af23eed
-version: 6
+version: 7
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_proxy_via_netsh.yml b/detections/endpoint/windows_proxy_via_netsh.yml
index 66dcbfa6da..639a557efe 100644
--- a/detections/endpoint/windows_proxy_via_netsh.yml
+++ b/detections/endpoint/windows_proxy_via_netsh.yml
@@ -1,7 +1,7 @@
name: Windows Proxy Via Netsh
id: c137bfe8-6036-4cff-b77b-4e327dd0a1cf
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -71,7 +71,6 @@ tags:
- b8223ea9-4be2-44a6-b50a-9657a3d4e72a
mitre_attack_id:
- T1090.001
- - T1090
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_proxy_via_registry.yml b/detections/endpoint/windows_proxy_via_registry.yml
index df29fba982..ab99e0cb4e 100644
--- a/detections/endpoint/windows_proxy_via_registry.yml
+++ b/detections/endpoint/windows_proxy_via_registry.yml
@@ -1,7 +1,7 @@
name: Windows Proxy Via Registry
id: 0270455b-1385-4579-9ac5-e77046c508ae
-version: 5
-date: '2024-12-16'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -58,7 +58,6 @@ tags:
- b8223ea9-4be2-44a6-b50a-9657a3d4e72a
mitre_attack_id:
- T1090.001
- - T1090
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_raccine_scheduled_task_deletion.yml b/detections/endpoint/windows_raccine_scheduled_task_deletion.yml
index 4c61efa0c7..9e419ace18 100644
--- a/detections/endpoint/windows_raccine_scheduled_task_deletion.yml
+++ b/detections/endpoint/windows_raccine_scheduled_task_deletion.yml
@@ -1,6 +1,6 @@
name: Windows Raccine Scheduled Task Deletion
id: c9f010da-57ab-11ec-82bd-acde48001122
-version: 6
+version: 7
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_rasautou_dll_execution.yml b/detections/endpoint/windows_rasautou_dll_execution.yml
index f04f743ef0..8e15a67174 100644
--- a/detections/endpoint/windows_rasautou_dll_execution.yml
+++ b/detections/endpoint/windows_rasautou_dll_execution.yml
@@ -1,7 +1,7 @@
name: Windows Rasautou DLL Execution
id: 6f42b8be-8e96-11ec-ad5a-acde48001122
-version: 6
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -73,7 +73,6 @@ tags:
mitre_attack_id:
- T1055.001
- T1218
- - T1055
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml b/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml
index d6193ca528..b12079e3c2 100644
--- a/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml
+++ b/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml
@@ -1,7 +1,7 @@
name: Windows Raw Access To Disk Volume Partition
id: a85aa37e-9647-11ec-90c5-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -23,8 +23,9 @@ how_to_implement: To successfully implement this search, you need to be ingestin
logs with the raw access read event (like sysmon eventcode 9), process name and
process guid from your endpoints. If you are using Sysmon, you must have at least
version 6.0.4 of the Sysmon TA.
-known_false_positives: There are som minimal number of normal applications from system32 folder like svchost.exe accessing the MBR. In this
- case we used 'system32' and 'syswow64' path as a filter for this detection.
+known_false_positives: There are som minimal number of normal applications from system32
+ folder like svchost.exe accessing the MBR. In this case we used 'system32' and 'syswow64'
+ path as a filter for this detection.
references:
- https://blog.talosintelligence.com/2022/02/threat-advisory-hermeticwiper.html
drilldown_searches:
@@ -60,7 +61,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1561.002
- - T1561
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml b/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml
index 3692033d81..a689fa523f 100644
--- a/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml
+++ b/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml
@@ -1,7 +1,7 @@
name: Windows Raw Access To Master Boot Record Drive
id: 7b83f666-900c-11ec-a2d9-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -23,8 +23,9 @@ how_to_implement: To successfully implement this search, you need to be ingestin
logs with the raw access read event (like sysmon eventcode 9), process name and
process guid from your endpoints. If you are using Sysmon, you must have at least
version 6.0.4 of the Sysmon TA.
-known_false_positives: There are som minimal number of normal applications from system32 folder like svchost.exe accessing the MBR. In this
- case we used 'system32' and 'syswow64' path as a filter for this detection.
+known_false_positives: There are som minimal number of normal applications from system32
+ folder like svchost.exe accessing the MBR. In this case we used 'system32' and 'syswow64'
+ path as a filter for this detection.
references:
- https://www.splunk.com/en_us/blog/security/threat-advisory-strt-ta02-destructive-software.html
- https://www.crowdstrike.com/blog/technical-analysis-of-whispergate-malware/
@@ -63,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1561.002
- - T1561
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_registry_certificate_added.yml b/detections/endpoint/windows_registry_certificate_added.yml
index 2781d73827..f8c97ce6b7 100644
--- a/detections/endpoint/windows_registry_certificate_added.yml
+++ b/detections/endpoint/windows_registry_certificate_added.yml
@@ -1,7 +1,7 @@
name: Windows Registry Certificate Added
id: 5ee98b2f-8b9e-457a-8bdc-dd41aaba9e87
-version: 6
-date: '2025-01-21'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Teodeerick Contreras, Splunk
status: production
type: Anomaly
@@ -61,7 +61,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1553.004
- - T1553
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_registry_dotnet_etw_disabled_via_env_variable.yml b/detections/endpoint/windows_registry_dotnet_etw_disabled_via_env_variable.yml
index d938db4eac..5e2ddf9fce 100644
--- a/detections/endpoint/windows_registry_dotnet_etw_disabled_via_env_variable.yml
+++ b/detections/endpoint/windows_registry_dotnet_etw_disabled_via_env_variable.yml
@@ -1,7 +1,7 @@
name: Windows Registry Dotnet ETW Disabled Via ENV Variable
id: 55502381-5cce-491b-9277-7cb1d10bc0df
-version: 2
-date: '2025-01-07'
+version: 4
+date: '2025-02-10'
author: Nasreddine Bencherchali, Splunk
status: production
type: TTP
@@ -65,7 +65,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.006
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_registry_modification_for_safe_mode_persistence.yml b/detections/endpoint/windows_registry_modification_for_safe_mode_persistence.yml
index fbd1a12913..7a88c95d54 100644
--- a/detections/endpoint/windows_registry_modification_for_safe_mode_persistence.yml
+++ b/detections/endpoint/windows_registry_modification_for_safe_mode_persistence.yml
@@ -1,7 +1,7 @@
name: Windows Registry Modification for Safe Mode Persistence
id: c6149154-c9d8-11eb-9da7-acde48001122
-version: 8
-date: '2025-01-21'
+version: 9
+date: '2025-02-10'
author: Teoderick Contreras, Michael Haag, Splunk
status: production
type: TTP
@@ -65,7 +65,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1547.001
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_registry_payload_injection.yml b/detections/endpoint/windows_registry_payload_injection.yml
index 9a2dcd0047..e798fc114f 100644
--- a/detections/endpoint/windows_registry_payload_injection.yml
+++ b/detections/endpoint/windows_registry_payload_injection.yml
@@ -1,7 +1,7 @@
name: Windows Registry Payload Injection
id: c6b2d80f-179a-41a1-b95e-ce5601d7427a
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -77,7 +77,6 @@ tags:
- Unusual Processes
asset_type: Endpoint
mitre_attack_id:
- - T1027
- T1027.011
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_regsvr32_renamed_binary.yml b/detections/endpoint/windows_regsvr32_renamed_binary.yml
index 64e9e406e3..53b64d87dd 100644
--- a/detections/endpoint/windows_regsvr32_renamed_binary.yml
+++ b/detections/endpoint/windows_regsvr32_renamed_binary.yml
@@ -1,7 +1,7 @@
name: Windows Regsvr32 Renamed Binary
id: 7349a9e9-3cf6-4171-bb0c-75607a8dcd1a
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -62,7 +62,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1218.010
- - T1218
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_remote_assistance_spawning_process.yml b/detections/endpoint/windows_remote_assistance_spawning_process.yml
index 90cb689064..e6810e6c34 100644
--- a/detections/endpoint/windows_remote_assistance_spawning_process.yml
+++ b/detections/endpoint/windows_remote_assistance_spawning_process.yml
@@ -1,6 +1,6 @@
name: Windows Remote Assistance Spawning Process
id: ced50492-8849-11ec-9f68-acde48001122
-version: 6
+version: 7
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_remote_create_service.yml b/detections/endpoint/windows_remote_create_service.yml
index 93c28d5380..ffa6ead077 100644
--- a/detections/endpoint/windows_remote_create_service.yml
+++ b/detections/endpoint/windows_remote_create_service.yml
@@ -1,7 +1,7 @@
name: Windows Remote Create Service
id: 0dc44d03-8c00-482d-ba7c-796ba7ab18c9
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Anomaly
@@ -72,7 +72,6 @@ tags:
- BlackSuit Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1543
- T1543.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml b/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml
index 73d240c71e..780c0b7854 100644
--- a/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml
+++ b/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml
@@ -1,7 +1,7 @@
name: Windows Remote Service Rdpwinst Tool Execution
id: c8127f87-c7c9-4036-89ed-8fe4b30e678c
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -65,7 +65,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1021.001
- - T1021
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml b/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml
index 01e73f560f..52c5aed5a0 100644
--- a/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml
+++ b/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml
@@ -1,7 +1,7 @@
name: Windows Remote Services Allow Rdp In Firewall
id: 9170cb54-ea15-41e1-9dfc-9f3363ce9b02
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -66,7 +66,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1021.001
- - T1021
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_remote_services_allow_remote_assistance.yml b/detections/endpoint/windows_remote_services_allow_remote_assistance.yml
index 39dfcd8333..4f5028aa36 100644
--- a/detections/endpoint/windows_remote_services_allow_remote_assistance.yml
+++ b/detections/endpoint/windows_remote_services_allow_remote_assistance.yml
@@ -1,7 +1,7 @@
name: Windows Remote Services Allow Remote Assistance
id: 9bce3a97-bc97-4e89-a1aa-ead151c82fbb
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -58,7 +58,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1021.001
- - T1021
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_remote_services_rdp_enable.yml b/detections/endpoint/windows_remote_services_rdp_enable.yml
index db44d18d43..16dc4dcfb1 100644
--- a/detections/endpoint/windows_remote_services_rdp_enable.yml
+++ b/detections/endpoint/windows_remote_services_rdp_enable.yml
@@ -1,7 +1,7 @@
name: Windows Remote Services Rdp Enable
id: 8fbd2e88-4ea5-40b9-9217-fd0855e08cc0
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1021.001
- - T1021
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_root_domain_linked_policies_discovery.yml b/detections/endpoint/windows_root_domain_linked_policies_discovery.yml
index f006024e2d..b4b40d775a 100644
--- a/detections/endpoint/windows_root_domain_linked_policies_discovery.yml
+++ b/detections/endpoint/windows_root_domain_linked_policies_discovery.yml
@@ -1,7 +1,7 @@
name: Windows Root Domain linked policies Discovery
id: 80ffaede-1f12-49d5-a86e-b4b599b68b3c
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -56,7 +56,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1087.002
- - T1087
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_rundll32_apply_user_settings_changes.yml b/detections/endpoint/windows_rundll32_apply_user_settings_changes.yml
index 711d2c152e..f1c867ecd3 100644
--- a/detections/endpoint/windows_rundll32_apply_user_settings_changes.yml
+++ b/detections/endpoint/windows_rundll32_apply_user_settings_changes.yml
@@ -1,7 +1,7 @@
name: Windows Rundll32 Apply User Settings Changes
id: b9fb8d97-dbc9-4a09-804c-ff0e3862bb2d
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
- Rhysida Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1218
- T1218.011
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_rundll32_webdav_request.yml b/detections/endpoint/windows_rundll32_webdav_request.yml
index ce111cff26..68ccb04ab4 100644
--- a/detections/endpoint/windows_rundll32_webdav_request.yml
+++ b/detections/endpoint/windows_rundll32_webdav_request.yml
@@ -1,6 +1,6 @@
name: Windows Rundll32 WebDAV Request
id: 320099b7-7eb1-4153-a2b4-decb53267de2
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
type: TTP
diff --git a/detections/endpoint/windows_rundll32_webdav_with_network_connection.yml b/detections/endpoint/windows_rundll32_webdav_with_network_connection.yml
index de78c6f02b..8ef7992823 100644
--- a/detections/endpoint/windows_rundll32_webdav_with_network_connection.yml
+++ b/detections/endpoint/windows_rundll32_webdav_with_network_connection.yml
@@ -1,6 +1,6 @@
name: Windows Rundll32 WebDav With Network Connection
id: f03355e0-28b5-4e9b-815a-6adffc63b38c
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
type: TTP
diff --git a/detections/endpoint/windows_scheduled_task_created_via_xml.yml b/detections/endpoint/windows_scheduled_task_created_via_xml.yml
index b29963f952..0a239e80fc 100644
--- a/detections/endpoint/windows_scheduled_task_created_via_xml.yml
+++ b/detections/endpoint/windows_scheduled_task_created_via_xml.yml
@@ -1,7 +1,7 @@
name: Windows Scheduled Task Created Via XML
id: 7e03b682-3965-4598-8e91-a60a40a3f7e4
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -71,7 +71,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.005
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_scheduled_task_with_highest_privileges.yml b/detections/endpoint/windows_scheduled_task_with_highest_privileges.yml
index 2111e93ad4..0cb70faff7 100644
--- a/detections/endpoint/windows_scheduled_task_with_highest_privileges.yml
+++ b/detections/endpoint/windows_scheduled_task_with_highest_privileges.yml
@@ -1,7 +1,7 @@
name: Windows Scheduled Task with Highest Privileges
id: 2f15e1a4-0fc2-49dd-919e-cbbe60699218
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -68,7 +68,6 @@ tags:
- RedLine Stealer
asset_type: Endpoint
mitre_attack_id:
- - T1053
- T1053.005
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_schtasks_create_run_as_system.yml b/detections/endpoint/windows_schtasks_create_run_as_system.yml
index 0803309dab..bb349b102f 100644
--- a/detections/endpoint/windows_schtasks_create_run_as_system.yml
+++ b/detections/endpoint/windows_schtasks_create_run_as_system.yml
@@ -1,7 +1,7 @@
name: Windows Schtasks Create Run As System
id: 41a0e58e-884c-11ec-9976-acde48001122
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -71,7 +71,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.005
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_security_and_backup_services_stop.yml b/detections/endpoint/windows_security_and_backup_services_stop.yml
new file mode 100644
index 0000000000..47e8f2e8cf
--- /dev/null
+++ b/detections/endpoint/windows_security_and_backup_services_stop.yml
@@ -0,0 +1,78 @@
+name: Windows Security And Backup Services Stop
+id: 9c24aef6-cad9-4931-acce-74318aa5663b
+version: 1
+date: '2025-02-07'
+author: Teoderick Contreras, Splunk
+status: production
+type: TTP
+description: The following analytic detects the suspicious termination of known services
+ commonly targeted by ransomware before file encryption. It leverages Windows System
+ Event Logs (EventCode 7036) to identify when critical services such as Volume Shadow
+ Copy, backup, and antivirus services are stopped. This activity is significant because
+ ransomware often disables these services to avoid errors and ensure successful file
+ encryption. If confirmed malicious, this behavior could lead to widespread data
+ encryption, rendering files inaccessible and potentially causing significant operational
+ disruption and data loss.
+data_source:
+- Windows Event Log System 7036
+search: '`wineventlog_system` `normalized_service_binary_field`
+ | rename param1 as display_name
+ | where param2="stopped" AND (match(display_name, "(?i)(Volume Shadow Copy|VSS|backup|sophos|sql|memtas|mepocs|veeam|svc\$|DefWatch|ccEvtMgr|ccSetMgr|SavRoam|RTVscan|QBFCService|QBIDPService|Intuit\.QuickBooks\.FCS|QBCFMonitorService|YooBackup|YooIT|Veeam|PDVFSService|BackupExec|WdBoot|WdFilter|WdNisDrv|WdNisSvc|WinDefend|wscsvc|Sense|sppsvc|SecurityHealthService)")
+ OR match(normalized_service_name, "(?i)(Volume Shadow Copy|VSS|backup|sophos|sql|memtas|mepocs|veeam|svc\$|DefWatch|ccEvtMgr|ccSetMgr|SavRoam|RTVscan|QBFCService|QBIDPService|Intuit\.QuickBooks\.FCS|QBCFMonitorService|YooBackup|YooIT|Veeam|PDVFSService|BackupExec|WdBoot|WdFilter|WdNisDrv|WdNisSvc|WinDefend|wscsvc|Sense|sppsvc|SecurityHealthService)"))
+ | stats count min(_time) as firstTime max(_time) as lastTime by EventCode display_name dest normalized_service_name
+ | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`
+ | `windows_security_and_backup_services_stop_filter`'
+how_to_implement: To successfully implement this search, you need to be ingesting
+ logs with the 7036 EventCode ScManager in System audit Logs from your endpoints.
+known_false_positives: Admin activities or installing related updates may do a sudden
+ stop to list of services we monitor.
+references:
+- https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/
+- https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/
+- https://news.sophos.com/en-us/2020/04/24/lockbit-ransomware-borrows-tricks-to-keep-up-with-revil-and-maze/
+- https://blogs.vmware.com/security/2022/10/lockbit-3-0-also-known-as-lockbit-black.html
+drilldown_searches:
+- name: View the detection results for - "$dest$"
+ search: '%original_detection_search% | search dest = "$dest$"'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: View risk events for the last 7 days for - "$dest$"
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+rba:
+ message: Known services $param1$ terminated by a potential ransomware on $dest$
+ risk_objects:
+ - field: dest
+ type: system
+ score: 72
+ threat_objects:
+ - field: display_name
+ type: service
+tags:
+ analytic_story:
+ - LockBit Ransomware
+ - Ransomware
+ - Compromised Windows Host
+ - BlackMatter Ransomware
+ asset_type: Endpoint
+ mitre_attack_id:
+ - T1490
+ product:
+ - Splunk Enterprise
+ - Splunk Enterprise Security
+ - Splunk Cloud
+ security_domain: endpoint
+tests:
+- name: True Positive Test
+ attack_data:
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/known_services_killed_by_ransomware/windows-xml.log
+ source: XmlWinEventLog:System
+ sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_security_support_provider_reg_query.yml b/detections/endpoint/windows_security_support_provider_reg_query.yml
index 1ec47ad04d..78ab163dc2 100644
--- a/detections/endpoint/windows_security_support_provider_reg_query.yml
+++ b/detections/endpoint/windows_security_support_provider_reg_query.yml
@@ -1,7 +1,7 @@
name: Windows Security Support Provider Reg Query
id: 31302468-93c9-4eca-9ae3-2d41f53a4e2b
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -69,7 +69,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1547.005
- - T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_sensitive_group_discovery_with_net.yml b/detections/endpoint/windows_sensitive_group_discovery_with_net.yml
index 6a7c924fe9..57b7d6e524 100644
--- a/detections/endpoint/windows_sensitive_group_discovery_with_net.yml
+++ b/detections/endpoint/windows_sensitive_group_discovery_with_net.yml
@@ -1,17 +1,39 @@
name: Windows Sensitive Group Discovery With Net
id: d9eb7cda-5622-4722-bc88-7f2442f4b5af
-version: 1
-date: '2025-01-13'
+version: 2
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: Anomaly
-description: The following analytic detects the execution of `net.exe` with command-line arguments used to query elevated domain or sensitive groups. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions. This activity is significant as it indicates potential reconnaissance efforts by adversaries to identify high-privileged users within Active Directory. If confirmed malicious, this behavior could lead to further attacks aimed at compromising privileged accounts, escalating privileges, or gaining unauthorized access to sensitive systems and data.
+description: The following analytic detects the execution of `net.exe` with command-line
+ arguments used to query elevated domain or sensitive groups. It leverages data from
+ Endpoint Detection and Response (EDR) agents, focusing on process names and command-line
+ executions. This activity is significant as it indicates potential reconnaissance
+ efforts by adversaries to identify high-privileged users within Active Directory.
+ If confirmed malicious, this behavior could lead to further attacks aimed at compromising
+ privileged accounts, escalating privileges, or gaining unauthorized access to sensitive
+ systems and data.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
-search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` Processes.process="*group*" Processes.process IN ("*Domain Admins*", "*Enterprise Admins*", "*Schema Admins*", "*Account Operators*", "*Server Operators*", "*Protected Users*", "*Dns Admins*", "*Domain Computers*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_sensitive_group_discovery_with_net_filter`'
-how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
+search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
+ as lastTime from datamodel=Endpoint.Processes where `process_net` Processes.process="*group*"
+ Processes.process IN ("*Domain Admins*", "*Enterprise Admins*", "*Schema Admins*",
+ "*Account Operators*", "*Server Operators*", "*Protected Users*", "*Dns Admins*",
+ "*Domain Computers*") by Processes.dest Processes.user Processes.parent_process
+ Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
+ | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
+ | `windows_sensitive_group_discovery_with_net_filter`'
+how_to_implement: The detection is based on data that originates from Endpoint Detection
+ and Response (EDR) agents. These agents are designed to provide security-related
+ telemetry from the endpoints where the agent is installed. To implement this search,
+ you must ingest logs that contain the process GUID, process name, and parent process.
+ Additionally, you must ingest complete command-line executions. These logs must
+ be processed using the appropriate Splunk Technology Add-ons that are specific to
+ the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
+ data model. Use the Splunk Common Information Model (CIM) to normalize the field
+ names and speed up the data modeling process.
known_false_positives: Administrators or power users may use this command for troubleshooting.
references:
- https://attack.mitre.org/techniques/T1069/002/
@@ -25,7 +47,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -44,7 +71,6 @@ tags:
- IcedID
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.002
product:
- Splunk Enterprise
@@ -54,6 +80,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_sensitive_registry_hive_dump_via_commandline.yml b/detections/endpoint/windows_sensitive_registry_hive_dump_via_commandline.yml
index d8050741e3..fba9efd879 100644
--- a/detections/endpoint/windows_sensitive_registry_hive_dump_via_commandline.yml
+++ b/detections/endpoint/windows_sensitive_registry_hive_dump_via_commandline.yml
@@ -1,18 +1,41 @@
name: Windows Sensitive Registry Hive Dump Via CommandLine
id: 5aaff29d-0cce-405b-9ee8-5d06b49d045e
-version: 1
-date: '2025-01-15'
+version: 3
+date: '2025-02-10'
author: Michael Haag, Patrick Bareiss, Nasreddine Bencherchali, Splunk
status: production
type: TTP
-description: The following analytic detects the use of `reg.exe` to export Windows Registry hives, which may contain sensitive credentials. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions involving `save` or `export` actions targeting the `sam`, `system`, or `security` hives. This activity is significant as it indicates potential offline credential access attacks, often executed from untrusted processes or scripts. If confirmed malicious, attackers could gain access to credential data, enabling further compromise and lateral movement within the network.
+description: The following analytic detects the use of `reg.exe` to export Windows
+ Registry hives, which may contain sensitive credentials. This detection leverages
+ data from Endpoint Detection and Response (EDR) agents, focusing on command-line
+ executions involving `save` or `export` actions targeting the `sam`, `system`, or
+ `security` hives. This activity is significant as it indicates potential offline
+ credential access attacks, often executed from untrusted processes or scripts. If
+ confirmed malicious, attackers could gain access to credential data, enabling further
+ compromise and lateral movement within the network.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
-search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where ((`process_reg` Processes.process IN ("*save*", "*export*")) OR (`process_regedit` Processes.process IN ("*/E *", "*-E *"))) AND Processes.process IN ("*HKEY_LOCAL_MACHINE*", "*HKLM*") AND Processes.process IN ("*SAM*", "*System*", "*Security*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.parent_process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_sensitive_registry_hive_dump_via_commandline_filter`'
-how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
-known_false_positives: It is possible some agent based products will generate false positives. Filter as needed.
+search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
+ as lastTime from datamodel=Endpoint.Processes where ((`process_reg` Processes.process
+ IN ("*save*", "*export*")) OR (`process_regedit` Processes.process IN ("*/E *",
+ "*-E *"))) AND Processes.process IN ("*HKEY_LOCAL_MACHINE*", "*HKLM*") AND Processes.process
+ IN ("*SAM*", "*System*", "*Security*") by Processes.dest Processes.user Processes.parent_process
+ Processes.process_name Processes.parent_process_name Processes.process Processes.process_id
+ Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)` | `windows_sensitive_registry_hive_dump_via_commandline_filter`'
+how_to_implement: The detection is based on data that originates from Endpoint Detection
+ and Response (EDR) agents. These agents are designed to provide security-related
+ telemetry from the endpoints where the agent is installed. To implement this search,
+ you must ingest logs that contain the process GUID, process name, and parent process.
+ Additionally, you must ingest complete command-line executions. These logs must
+ be processed using the appropriate Splunk Technology Add-ons that are specific to
+ the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
+ data model. Use the Splunk Common Information Model (CIM) to normalize the field
+ names and speed up the data modeling process.
+known_false_positives: It is possible some agent based products will generate false
+ positives. Filter as needed.
references:
- https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md
@@ -23,7 +46,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
+ "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
+ as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
+ Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
+ as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
+ by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -53,7 +81,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1003.002
- - T1003
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -62,6 +89,7 @@ tags:
tests:
- name: True Positive Test - Sysmon
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_server_software_component_gacutil_install_to_gac.yml b/detections/endpoint/windows_server_software_component_gacutil_install_to_gac.yml
index 64c9bcdd4f..f0baa10770 100644
--- a/detections/endpoint/windows_server_software_component_gacutil_install_to_gac.yml
+++ b/detections/endpoint/windows_server_software_component_gacutil_install_to_gac.yml
@@ -1,7 +1,7 @@
name: Windows Server Software Component GACUtil Install to GAC
id: 7c025ef0-9e65-4c57-be39-1c13dbb1613e
-version: 5
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -73,7 +73,6 @@ tags:
- IIS Components
asset_type: Endpoint
mitre_attack_id:
- - T1505
- T1505.004
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_service_create_kernel_mode_driver.yml b/detections/endpoint/windows_service_create_kernel_mode_driver.yml
index a183f4a0d9..b9a59dae84 100644
--- a/detections/endpoint/windows_service_create_kernel_mode_driver.yml
+++ b/detections/endpoint/windows_service_create_kernel_mode_driver.yml
@@ -1,7 +1,7 @@
name: Windows Service Create Kernel Mode Driver
id: 0b4e3b06-1b2b-4885-b752-cf06d12a90cb
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -67,9 +67,8 @@ tags:
- CISA AA22-320A
asset_type: Endpoint
mitre_attack_id:
- - T1543.003
- - T1543
- T1068
+ - T1543.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_service_create_remcomsvc.yml b/detections/endpoint/windows_service_create_remcomsvc.yml
index 23e3442fbb..642022aaff 100644
--- a/detections/endpoint/windows_service_create_remcomsvc.yml
+++ b/detections/endpoint/windows_service_create_remcomsvc.yml
@@ -1,7 +1,7 @@
name: Windows Service Create RemComSvc
id: 0be4b5d6-c449-4084-b945-2392b519c33b
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
type: Anomaly
status: production
@@ -53,7 +53,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1543.003
- - T1543
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_service_create_sliverc2.yml b/detections/endpoint/windows_service_create_sliverc2.yml
index 43a0ccd75b..d9279cedf9 100644
--- a/detections/endpoint/windows_service_create_sliverc2.yml
+++ b/detections/endpoint/windows_service_create_sliverc2.yml
@@ -1,7 +1,7 @@
name: Windows Service Create SliverC2
id: 89dad3ee-57ec-43dc-9044-131c4edd663f
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
type: TTP
status: production
@@ -53,7 +53,6 @@ tags:
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- - T1569
- T1569.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_service_create_with_tscon.yml b/detections/endpoint/windows_service_create_with_tscon.yml
index 150f198cc2..747300e74b 100644
--- a/detections/endpoint/windows_service_create_with_tscon.yml
+++ b/detections/endpoint/windows_service_create_with_tscon.yml
@@ -1,7 +1,7 @@
name: Windows Service Create with Tscon
id: c13b3d74-6b63-4db5-a841-4206f0370077
-version: 6
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
type: TTP
status: production
@@ -81,9 +81,8 @@ tags:
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- - T1563.002
- - T1563
- T1543.003
+ - T1563.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_service_created_with_suspicious_service_path.yml b/detections/endpoint/windows_service_created_with_suspicious_service_path.yml
index 9dfedd34e8..d87ac0bdb8 100644
--- a/detections/endpoint/windows_service_created_with_suspicious_service_path.yml
+++ b/detections/endpoint/windows_service_created_with_suspicious_service_path.yml
@@ -1,7 +1,7 @@
name: Windows Service Created with Suspicious Service Path
id: 429141be-8311-11eb-adb6-acde48001122
-version: 11
-date: '2025-01-27'
+version: 12
+date: '2025-02-10'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -68,7 +68,6 @@ tags:
- Earth Estries
asset_type: Endpoint
mitre_attack_id:
- - T1569
- T1569.002
product:
- Splunk Enterprise
@@ -78,6 +77,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/windows_service_created_with_suspicious_service_path/windows-xml.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/windows_service_created_with_suspicious_service_path/windows-xml.log
source: XmlWinEventLog:System
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_service_created_within_public_path.yml b/detections/endpoint/windows_service_created_within_public_path.yml
index 6ff175c139..393b3eb567 100644
--- a/detections/endpoint/windows_service_created_within_public_path.yml
+++ b/detections/endpoint/windows_service_created_within_public_path.yml
@@ -1,7 +1,7 @@
name: Windows Service Created Within Public Path
id: 3abb2eda-4bb8-11ec-9ae4-3e22fbd008af
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
- Snake Malware
asset_type: Endpoint
mitre_attack_id:
- - T1543
- T1543.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_service_creation_on_remote_endpoint.yml b/detections/endpoint/windows_service_creation_on_remote_endpoint.yml
index 19ea16bb63..ec3397951e 100644
--- a/detections/endpoint/windows_service_creation_on_remote_endpoint.yml
+++ b/detections/endpoint/windows_service_creation_on_remote_endpoint.yml
@@ -1,7 +1,7 @@
name: Windows Service Creation on Remote Endpoint
id: e0eea4fa-4274-11ec-882b-3e22fbd008af
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -66,7 +66,6 @@ tags:
- CISA AA23-347A
asset_type: Endpoint
mitre_attack_id:
- - T1543
- T1543.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_service_execution_remcom.yml b/detections/endpoint/windows_service_execution_remcom.yml
index 01840501c6..43198428c0 100644
--- a/detections/endpoint/windows_service_execution_remcom.yml
+++ b/detections/endpoint/windows_service_execution_remcom.yml
@@ -1,6 +1,6 @@
name: Windows Service Execution RemCom
id: 7e3d68db-ea4d-419b-adbd-e14a525ecf09
-version: 2
+version: 3
date: '2025-01-07'
author: Michael Haag, Splunk
type: TTP
diff --git a/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml b/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml
index 2a3c2b3981..0c2963cf1d 100644
--- a/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml
+++ b/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml
@@ -1,7 +1,7 @@
name: Windows Service Initiation on Remote Endpoint
id: 3f519894-4276-11ec-ab02-3e22fbd008af
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
- CISA AA23-347A
asset_type: Endpoint
mitre_attack_id:
- - T1543
- T1543.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_soaphound_binary_execution.yml b/detections/endpoint/windows_soaphound_binary_execution.yml
index cfe3f8ce09..0629cd8492 100644
--- a/detections/endpoint/windows_soaphound_binary_execution.yml
+++ b/detections/endpoint/windows_soaphound_binary_execution.yml
@@ -1,7 +1,7 @@
name: Windows SOAPHound Binary Execution
id: 8e53f839-e127-4d6d-a54d-a2f67044a57f
-version: 6
-date: '2024-12-10'
+version: 7
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -70,13 +70,11 @@ tags:
asset_type: Endpoint
atomic_guid: []
mitre_attack_id:
- - T1087.002
- T1069.001
- - T1482
- - T1087.001
- - T1087
- T1069.002
- - T1069
+ - T1087.001
+ - T1087.002
+ - T1482
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_spearphishing_attachment_connect_to_none_ms_office_domain.yml b/detections/endpoint/windows_spearphishing_attachment_connect_to_none_ms_office_domain.yml
index 9da99670ce..b59cd135c2 100644
--- a/detections/endpoint/windows_spearphishing_attachment_connect_to_none_ms_office_domain.yml
+++ b/detections/endpoint/windows_spearphishing_attachment_connect_to_none_ms_office_domain.yml
@@ -1,7 +1,7 @@
name: Windows Spearphishing Attachment Connect To None MS Office Domain
id: 1cb40e15-cffa-45cc-abbd-e35884a49766
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -36,7 +36,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1566.001
- - T1566
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml b/detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml
index c11e520d5a..52b946ec39 100644
--- a/detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml
+++ b/detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml
@@ -1,7 +1,7 @@
name: Windows Spearphishing Attachment Onenote Spawn Mshta
id: 35aeb0e7-7de5-444a-ac45-24d6788796ec
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -68,7 +68,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1566.001
- - T1566
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_sql_spawning_certutil.yml b/detections/endpoint/windows_sql_spawning_certutil.yml
index f2e58cc866..d612a17e7e 100644
--- a/detections/endpoint/windows_sql_spawning_certutil.yml
+++ b/detections/endpoint/windows_sql_spawning_certutil.yml
@@ -1,6 +1,6 @@
name: Windows SQL Spawning CertUtil
id: dfc18a5a-946e-44ee-a373-c0f60d06e676
-version: 6
+version: 7
date: '2024-12-16'
author: Michael Haag, Splunk
status: experimental
diff --git a/detections/endpoint/windows_steal_authentication_certificates___esc1_abuse.yml b/detections/endpoint/windows_steal_authentication_certificates___esc1_abuse.yml
index f62cbf81c9..10ca564046 100644
--- a/detections/endpoint/windows_steal_authentication_certificates___esc1_abuse.yml
+++ b/detections/endpoint/windows_steal_authentication_certificates___esc1_abuse.yml
@@ -1,6 +1,6 @@
name: Windows Steal Authentication Certificates - ESC1 Abuse
id: cbe761fc-d945-4c8c-a71d-e26d12255d32
-version: 5
+version: 6
date: '2024-11-13'
author: Steven Dick
status: production
diff --git a/detections/endpoint/windows_steal_authentication_certificates___esc1_authentication.yml b/detections/endpoint/windows_steal_authentication_certificates___esc1_authentication.yml
index 725f04e04e..5fcaaba267 100644
--- a/detections/endpoint/windows_steal_authentication_certificates___esc1_authentication.yml
+++ b/detections/endpoint/windows_steal_authentication_certificates___esc1_authentication.yml
@@ -1,6 +1,6 @@
name: Windows Steal Authentication Certificates - ESC1 Authentication
id: f0306acf-a6ab-437a-bbc6-8628f8d5c97e
-version: 5
+version: 6
date: '2024-12-10'
author: Steven Dick
status: production
diff --git a/detections/endpoint/windows_steal_authentication_certificates_certutil_backup.yml b/detections/endpoint/windows_steal_authentication_certificates_certutil_backup.yml
index bf954e1d52..9e7ceb2759 100644
--- a/detections/endpoint/windows_steal_authentication_certificates_certutil_backup.yml
+++ b/detections/endpoint/windows_steal_authentication_certificates_certutil_backup.yml
@@ -1,6 +1,6 @@
name: Windows Steal Authentication Certificates CertUtil Backup
id: bac85b56-0b65-4ce5-aad5-d94880df0967
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_steal_authentication_certificates_export_certificate.yml b/detections/endpoint/windows_steal_authentication_certificates_export_certificate.yml
index d1a5eb3d7b..af44db774c 100644
--- a/detections/endpoint/windows_steal_authentication_certificates_export_certificate.yml
+++ b/detections/endpoint/windows_steal_authentication_certificates_export_certificate.yml
@@ -1,6 +1,6 @@
name: Windows Steal Authentication Certificates Export Certificate
id: e39dc429-c2a5-4f1f-9c3c-6b211af6b332
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_steal_authentication_certificates_export_pfxcertificate.yml b/detections/endpoint/windows_steal_authentication_certificates_export_pfxcertificate.yml
index 459417802e..2e01886698 100644
--- a/detections/endpoint/windows_steal_authentication_certificates_export_pfxcertificate.yml
+++ b/detections/endpoint/windows_steal_authentication_certificates_export_pfxcertificate.yml
@@ -1,6 +1,6 @@
name: Windows Steal Authentication Certificates Export PfxCertificate
id: 391329f3-c14b-4b8d-8b37-ac5012637360
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml b/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml
index 3b28765cce..b418e2f4d2 100644
--- a/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml
+++ b/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml
@@ -1,7 +1,7 @@
name: Windows Suspect Process With Authentication Traffic
id: 953322db-128a-4ce9-8e89-56e039e33d98
-version: 4
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Steven Dick
status: production
type: Anomaly
@@ -66,9 +66,7 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1087
- T1087.002
- - T1204
- T1204.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_suspicious_child_process_spawned_from_webserver.yml b/detections/endpoint/windows_suspicious_child_process_spawned_from_webserver.yml
index 57257bec13..00bfe7a17b 100644
--- a/detections/endpoint/windows_suspicious_child_process_spawned_from_webserver.yml
+++ b/detections/endpoint/windows_suspicious_child_process_spawned_from_webserver.yml
@@ -1,7 +1,7 @@
name: Windows Suspicious Child Process Spawned From WebServer
id: 2d4470ef-7158-4b47-b68b-1f7f16382156
-version: 1
-date: '2025-01-13'
+version: 2
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -87,7 +87,6 @@ tags:
- BlackByte Ransomware
asset_type: Endpoint
mitre_attack_id:
- - T1505
- T1505.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_suspicious_driver_loaded_path.yml b/detections/endpoint/windows_suspicious_driver_loaded_path.yml
new file mode 100644
index 0000000000..60383739c7
--- /dev/null
+++ b/detections/endpoint/windows_suspicious_driver_loaded_path.yml
@@ -0,0 +1,75 @@
+name: Windows Suspicious Driver Loaded Path
+id: 2ca1c4a1-8342-4750-9363-905650e0c933
+version: 1
+date: '2025-02-03'
+author: Teoderick Contreras, Splunk
+status: production
+type: TTP
+description: The following analytic detects the loading of drivers from suspicious
+ paths, which is a technique often used by malicious software such as coin miners
+ (e.g., xmrig). It leverages Sysmon EventCode 6 to identify drivers loaded from non-standard
+ directories. This activity is significant because legitimate drivers typically reside
+ in specific system directories, and deviations may indicate malicious activity.
+ If confirmed malicious, this could allow an attacker to execute code at the kernel
+ level, potentially leading to privilege escalation, persistence, or further system
+ compromise.
+data_source:
+- Sysmon EventID 6
+search: '`sysmon` EventCode=6 ImageLoaded = "*.sys" NOT (ImageLoaded IN("*\\WINDOWS\\inf","*\\WINDOWS\\System32\\drivers\\*",
+ "*\\WINDOWS\\System32\\DriverStore\\FileRepository\\*","*:\Windows\\WinSxS\\*","*\\ProgramData\\Microsoft\\Windows Defender\\Definition Updates\\*")) | stats min(_time) as
+ firstTime max(_time) as lastTime count by dest ImageLoaded Hashes IMPHASH Signature
+ Signed| rename ImageLoaded as file_name | `security_content_ctime(firstTime)` |
+ `security_content_ctime(lastTime)` | `windows_suspicious_driver_loaded_path_filter`'
+how_to_implement: To successfully implement this search, you need to be ingesting
+ logs with the driver loaded and Signature from your endpoints. If you are using
+ Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
+known_false_positives: Limited false positives will be present. Some applications
+ do load drivers
+references:
+- https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/
+- https://redcanary.com/blog/tracking-driver-inventory-to-expose-rootkits/
+drilldown_searches:
+- name: View the detection results for - "$dest$"
+ search: '%original_detection_search% | search dest = "$dest$"'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: View risk events for the last 7 days for - "$dest$"
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+rba:
+ message: Suspicious driver $file_name$ on $dest$
+ risk_objects:
+ - field: dest
+ type: system
+ score: 60
+ threat_objects:
+ - field: file_name
+ type: file_name
+tags:
+ analytic_story:
+ - XMRig
+ - CISA AA22-320A
+ - AgentTesla
+ - BlackByte Ransomware
+ - Snake Keylogger
+ asset_type: Endpoint
+ mitre_attack_id:
+ - T1543.003
+ product:
+ - Splunk Enterprise
+ - Splunk Enterprise Security
+ - Splunk Cloud
+ security_domain: endpoint
+tests:
+- name: True Positive Test
+ attack_data:
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
+ source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
+ sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_suspicious_process_file_path.yml b/detections/endpoint/windows_suspicious_process_file_path.yml
new file mode 100644
index 0000000000..0675251a94
--- /dev/null
+++ b/detections/endpoint/windows_suspicious_process_file_path.yml
@@ -0,0 +1,121 @@
+name: Windows Suspicious Process File Path
+id: ecddae4e-3d4b-41e2-b3df-e46a88b38521
+version: 7
+date: '2025-02-10'
+author: Teoderick Contreras, Splunk
+status: production
+type: TTP
+description: The following analytic identifies processes running from file paths not
+ typically associated with legitimate software. It leverages data from Endpoint Detection
+ and Response (EDR) agents, focusing on specific process paths within the Endpoint
+ data model. This activity is significant because adversaries often use unconventional
+ file paths to execute malicious code without requiring administrative privileges.
+ If confirmed malicious, this behavior could indicate an attempt to bypass security
+ controls, leading to unauthorized software execution, potential system compromise,
+ and further malicious activities within the environment.
+data_source:
+- Sysmon EventID 1
+- Windows Event Log Security 4688
+- CrowdStrike ProcessRollup2
+search: '| tstats `security_content_summariesonly` count values(Processes.process_name)
+ as process_name values(Processes.process) as process min(_time) as firstTime max(_time)
+ as lastTime from datamodel=Endpoint.Processes
+ where Processes.process_path IN("*\\windows\\fonts\\*", "*\\users\\public\\*", "*\\windows\\debug\\*", "*\\Users\\Administrator\\Music\\*", "*Recycle.bin*", "*\\Windows\\Media\\*","\\Windows\\repair\\*", "*\\PerfLogs\\*", "*:\\Windows\\Prefetch\\*", "*:\\Windows\\Cursors\\*", "*:\\Windows\\INF\\*") AND NOT(Processes.process_path IN ("*\\temp\\*"))
+ by Processes.parent_process_name Processes.parent_process Processes.process_path Processes.dest Processes.user
+ | `drop_dm_object_name(Processes)`
+ | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`
+ | `windows_suspicious_process_file_path_filter`'
+how_to_implement: The detection is based on data that originates from Endpoint Detection
+ and Response (EDR) agents. These agents are designed to provide security-related
+ telemetry from the endpoints where the agent is installed. To implement this search,
+ you must ingest logs that contain the process GUID, process name, and parent process.
+ Additionally, you must ingest complete command-line executions. These logs must
+ be processed using the appropriate Splunk Technology Add-ons that are specific to
+ the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
+ data model. Use the Splunk Common Information Model (CIM) to normalize the field
+ names and speed up the data modeling process.
+known_false_positives: Administrators may allow execution of specific binaries in
+ non-standard paths. Filter as needed.
+references:
+- https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/
+- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
+- https://twitter.com/pr0xylife/status/1590394227758104576
+- https://malpedia.caad.fkie.fraunhofer.de/details/win.asyncrat
+- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
+drilldown_searches:
+- name: View the detection results for - "$dest$"
+ search: '%original_detection_search% | search dest = "$dest$"'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: View risk events for the last 7 days for - "$dest$"
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
+ starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
+ values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
+ as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
+ as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+rba:
+ message: Suspicious process $process_name$ running from a suspicious process path-
+ $process_path$ on host- $dest$
+ risk_objects:
+ - field: dest
+ type: system
+ score: 60
+ threat_objects:
+ - field: process_path
+ type: process_name
+tags:
+ analytic_story:
+ - Double Zero Destructor
+ - Graceful Wipe Out Attack
+ - AsyncRAT
+ - WhisperGate
+ - Prestige Ransomware
+ - DarkGate Malware
+ - AgentTesla
+ - Brute Ratel C4
+ - RedLine Stealer
+ - Rhysida Ransomware
+ - Swift Slicer
+ - IcedID
+ - DarkCrystal RAT
+ - Chaos Ransomware
+ - PlugX
+ - Industroyer2
+ - Azorult
+ - Remcos
+ - XMRig
+ - Qakbot
+ - Volt Typhoon
+ - Hermetic Wiper
+ - Warzone RAT
+ - Trickbot
+ - Amadey
+ - BlackByte Ransomware
+ - LockBit Ransomware
+ - CISA AA23-347A
+ - Data Destruction
+ - Phemedrone Stealer
+ - Handala Wiper
+ - MoonPeak
+ - ValleyRAT
+ - Meduza Stealer
+ asset_type: Endpoint
+ mitre_attack_id:
+ - T1543
+ - T1036.005
+ product:
+ - Splunk Enterprise
+ - Splunk Enterprise Security
+ - Splunk Cloud
+ security_domain: endpoint
+tests:
+- name: True Positive Test
+ attack_data:
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/suspicious_process_path/susp_path_sysmon1.log
+ source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
+ sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml b/detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml
index 115d30093e..54ade9f424 100644
--- a/detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml
+++ b/detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml
@@ -1,7 +1,7 @@
name: Windows System Binary Proxy Execution Compiled HTML File Decompile
id: 2acf0e19-4149-451c-a3f3-39cd3c77e37d
-version: 6
-date: '2024-12-10'
+version: 8
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -72,7 +72,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1218.001
- - T1218
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_system_remote_discovery_with_query.yml b/detections/endpoint/windows_system_remote_discovery_with_query.yml
new file mode 100644
index 0000000000..58b97c3df7
--- /dev/null
+++ b/detections/endpoint/windows_system_remote_discovery_with_query.yml
@@ -0,0 +1,64 @@
+name: Windows System Remote Discovery With Query
+id: 94859172-a521-474f-97ac-4cf4b09634a3
+version: 1
+date: '2025-02-05'
+author: Steven Dick
+status: production
+type: Anomaly
+description: The following analytic detects the execution of `query.exe` with command-line arguments aimed at discovering data on remote devices. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions. This activity is significant as adversaries may use `query.exe` to gain situational awareness and perform Active Directory discovery on compromised endpoints. If confirmed malicious, this behavior could allow attackers to identify various details about a system, aiding in further lateral movement and privilege escalation within the network.
+data_source:
+- Sysmon Event ID 1
+- Windows Security Event ID 4688
+- CrowdStrike ProcessRollup2
+search: |-
+ | tstats `security_content_summariesonly` values(Processes.process_current_directory) as Processes.process_current_directory values(Processes.process_id) as Processes.process_id values(Processes.process) as Processes.process values(Processes.parent_process_id) as Processes.parent_process_id values(Processes.parent_process) as Processes.parent_process count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="query.exe" OR Processes.original_file_name="query.exe") AND (Processes.process="*/server*") AND NOT Processes.process IN ("*/server:localhost*", "*/server:127.0.0.1*") by Processes.dest Processes.user Processes.process_name Processes.parent_process_name
+ | `drop_dm_object_name(Processes)`
+ | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`
+ | `windows_system_remote_discovery_with_query_filter`
+how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
+known_false_positives: Administrators or power users may use this command for troubleshooting.
+references:
+- https://attack.mitre.org/techniques/T1033/
+drilldown_searches:
+- name: View the detection results for - "$dest$" and "$user$"
+ search: '%original_detection_search% | search dest = "$dest$" user = "$user$"'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: View risk events for the last 7 days for - "$dest$" and "$user$"
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$","$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: Investigate processes on $dest$
+ search: '| from datamodel:Endpoint.Processes | search dest=$dest$ process_name = $process_name|s$'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+rba:
+ message: The user $user$ ran the Query command to enumerate the remote system $dest$
+ risk_objects:
+ - field: user
+ type: user
+ score: 25
+ - field: dest
+ type: system
+ score: 25
+ threat_objects:
+ - field: process_name
+ type: process_name
+tags:
+ analytic_story:
+ - Active Directory Discovery
+ asset_type: Endpoint
+ mitre_attack_id:
+ - T1033
+ product:
+ - Splunk Enterprise
+ - Splunk Enterprise Security
+ - Splunk Cloud
+ security_domain: endpoint
+tests:
+- name: True Positive Test
+ attack_data:
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/query_remote_usage/query_remote_usage.log
+ source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
+ sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml b/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml
index 40f299551f..151b86c366 100644
--- a/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml
+++ b/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml
@@ -1,6 +1,6 @@
name: Windows System Script Proxy Execution Syncappvpublishingserver
id: 8dd73f89-682d-444c-8b41-8e679966ad3c
-version: 5
+version: 6
date: '2024-11-13'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_terminating_lsass_process.yml b/detections/endpoint/windows_terminating_lsass_process.yml
index 1010e55878..4ac22b6fea 100644
--- a/detections/endpoint/windows_terminating_lsass_process.yml
+++ b/detections/endpoint/windows_terminating_lsass_process.yml
@@ -1,7 +1,7 @@
name: Windows Terminating Lsass Process
id: 7ab3c319-a4e7-4211-9e8c-40a049d0dba6
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -59,7 +59,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_time_based_evasion.yml b/detections/endpoint/windows_time_based_evasion.yml
index a6e2eda7af..a7a30342b6 100644
--- a/detections/endpoint/windows_time_based_evasion.yml
+++ b/detections/endpoint/windows_time_based_evasion.yml
@@ -1,7 +1,7 @@
name: Windows Time Based Evasion
id: 34502357-deb1-499a-8261-ffe144abf561
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
- NjRAT
asset_type: Endpoint
mitre_attack_id:
- - T1497
- T1497.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_time_based_evasion_via_choice_exec.yml b/detections/endpoint/windows_time_based_evasion_via_choice_exec.yml
index 69fcad7d31..5453cc7fef 100644
--- a/detections/endpoint/windows_time_based_evasion_via_choice_exec.yml
+++ b/detections/endpoint/windows_time_based_evasion_via_choice_exec.yml
@@ -1,7 +1,7 @@
name: Windows Time Based Evasion via Choice Exec
id: d5f54b38-10bf-4b3a-b6fc-85949862ed50
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1497.003
- - T1497
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_uac_bypass_suspicious_child_process.yml b/detections/endpoint/windows_uac_bypass_suspicious_child_process.yml
index ffd2829b98..ced7799775 100644
--- a/detections/endpoint/windows_uac_bypass_suspicious_child_process.yml
+++ b/detections/endpoint/windows_uac_bypass_suspicious_child_process.yml
@@ -1,7 +1,7 @@
name: Windows UAC Bypass Suspicious Child Process
id: 453a6b0f-b0ea-48fa-9cf4-20537ffdd22c
-version: 4
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -69,7 +69,6 @@ tags:
- Living Off The Land
asset_type: Endpoint
mitre_attack_id:
- - T1548
- T1548.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_uac_bypass_suspicious_escalation_behavior.yml b/detections/endpoint/windows_uac_bypass_suspicious_escalation_behavior.yml
index 29e8eca705..e6c5b3452a 100644
--- a/detections/endpoint/windows_uac_bypass_suspicious_escalation_behavior.yml
+++ b/detections/endpoint/windows_uac_bypass_suspicious_escalation_behavior.yml
@@ -1,7 +1,7 @@
name: Windows UAC Bypass Suspicious Escalation Behavior
id: 00d050d3-a5b4-4565-a6a5-a31f69681dc3
-version: 5
-date: '2024-12-10'
+version: 7
+date: '2025-02-10'
author: Steven Dick
status: production
type: TTP
@@ -86,7 +86,6 @@ tags:
- Windows Defense Evasion Tactics
asset_type: Endpoint
mitre_attack_id:
- - T1548
- T1548.002
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_unsigned_dll_side_loading_in_same_process_path.yml b/detections/endpoint/windows_unsigned_dll_side_loading_in_same_process_path.yml
index 08803a7cd9..b064f55c1f 100644
--- a/detections/endpoint/windows_unsigned_dll_side_loading_in_same_process_path.yml
+++ b/detections/endpoint/windows_unsigned_dll_side_loading_in_same_process_path.yml
@@ -1,7 +1,7 @@
name: Windows Unsigned DLL Side-Loading In Same Process Path
id: 3cf85c02-f9d6-4186-bf3c-e70ee99fbc7f
-version: 6
-date: '2025-01-27'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
data_source:
- Sysmon EventID 7
@@ -62,7 +62,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1574.002
- - T1574
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -71,6 +70,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.002/unsigned_dll_loaded_same_process_path/unsigned_dll_process_path.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.002/unsigned_dll_loaded_same_process_path/unsigned_dll_process_path.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml b/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml
index c2fca2d205..63b6bc6fe8 100644
--- a/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml
+++ b/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml
@@ -1,8 +1,8 @@
name: Windows Unusual Count Of Disabled Users Failed Auth Using Kerberos
id: f65aa026-b811-42ab-b4b9-d9088137648f
-date: '2024-11-13'
+date: '2025-02-10'
type: Anomaly
-version: 4
+version: 5
status: production
author: Mauricio Velazco, Splunk
data_source:
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml b/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml
index 99987eef1c..3526b02f99 100644
--- a/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml
+++ b/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml
@@ -1,8 +1,8 @@
name: Windows Unusual Count Of Invalid Users Fail To Auth Using Kerberos
id: f122cb2e-d773-4f11-8399-62a3572d8dd7
type: Anomaly
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
status: production
author: Mauricio Velazco, Splunk
data_source:
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml b/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml
index 423d4f8f23..5dbcdccc4e 100644
--- a/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml
+++ b/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml
@@ -1,9 +1,9 @@
name: Windows Unusual Count Of Invalid Users Failed To Auth Using NTLM
id: 15603165-147d-4a6e-9778-bd0ff39e668f
type: Anomaly
-version: 5
+version: 6
status: production
-date: '2024-11-13'
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source:
- Windows Event Log Security 4776
@@ -64,7 +64,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml b/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml
index 44f94c13c8..8d72b7869c 100644
--- a/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml
+++ b/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml
@@ -1,9 +1,9 @@
name: Windows Unusual Count Of Users Fail To Auth Wth ExplicitCredentials
id: 14f414cf-3080-4b9b-aaf6-55a4ce947b93
type: Anomaly
-version: 5
+version: 6
status: production
-date: '2024-11-13'
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source:
- Windows Event Log Security 4648
@@ -65,7 +65,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml b/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml
index 437f332a2f..8d4f21783d 100644
--- a/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml
+++ b/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml
@@ -1,8 +1,8 @@
name: Windows Unusual Count Of Users Failed To Auth Using Kerberos
id: bc9cb715-08ba-40c3-9758-6e2b26e455cb
-date: '2024-11-13'
+date: '2025-02-10'
type: Anomaly
-version: 4
+version: 5
status: production
author: Mauricio Velazco, Splunk
data_source:
@@ -62,7 +62,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml
index e7fa32d047..4390ea59a9 100644
--- a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml
+++ b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml
@@ -1,9 +1,9 @@
name: Windows Unusual Count Of Users Failed To Authenticate From Process
id: 25bdb6cb-2e49-4d34-a93c-d6c567c122fe
type: Anomaly
-version: 5
+version: 6
status: production
-date: '2024-11-13'
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source:
- Windows Event Log Security 4625
@@ -65,7 +65,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml
index 51d1787dea..851a0ac391 100644
--- a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml
+++ b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml
@@ -1,9 +1,9 @@
name: Windows Unusual Count Of Users Failed To Authenticate Using NTLM
id: 6f6c8fd7-6a6b-4af9-a0e9-57cfc47a58b4
type: Anomaly
-version: 5
+version: 6
status: production
-date: '2024-11-13'
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source:
- Windows Event Log Security 4776
@@ -61,7 +61,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml b/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml
index f3cb730dff..602d834ebc 100644
--- a/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml
+++ b/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml
@@ -1,9 +1,9 @@
name: Windows Unusual Count Of Users Remotely Failed To Auth From Host
id: cf06a0ee-ffa9-4ed3-be77-0670ed9bab52
type: Anomaly
-version: 5
+version: 6
status: production
-date: '2024-11-13'
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source:
- Windows Event Log Security 4625
@@ -61,7 +61,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1110.003
- - T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_source.yml b/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_source.yml
index 8a5066b1b8..dfe94f5f83 100644
--- a/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_source.yml
+++ b/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_source.yml
@@ -1,7 +1,7 @@
name: Windows Unusual NTLM Authentication Destinations By Source
id: ae9b0df5-5fb0-477f-abc9-47faf42aa91d
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Steven Dick
status: production
type: Anomaly
@@ -63,7 +63,6 @@ tags:
- Active Directory Password Spraying
asset_type: Endpoint
mitre_attack_id:
- - T1110
- T1110.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_user.yml b/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_user.yml
index f9d5c01f64..d58eb04003 100644
--- a/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_user.yml
+++ b/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_user.yml
@@ -1,7 +1,7 @@
name: Windows Unusual NTLM Authentication Destinations By User
id: a4d86702-402b-4a4f-8d06-9d61e6c39cad
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Steven Dick
status: production
type: Anomaly
@@ -63,7 +63,6 @@ tags:
- Active Directory Password Spraying
asset_type: Endpoint
mitre_attack_id:
- - T1110
- T1110.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_unusual_ntlm_authentication_users_by_destination.yml b/detections/endpoint/windows_unusual_ntlm_authentication_users_by_destination.yml
index 7474361923..48f11d9078 100644
--- a/detections/endpoint/windows_unusual_ntlm_authentication_users_by_destination.yml
+++ b/detections/endpoint/windows_unusual_ntlm_authentication_users_by_destination.yml
@@ -1,7 +1,7 @@
name: Windows Unusual NTLM Authentication Users By Destination
id: 1120a204-8444-428b-8657-6ea4e1f3e840
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Steven Dick
status: production
type: Anomaly
@@ -65,7 +65,6 @@ tags:
- Active Directory Password Spraying
asset_type: Endpoint
mitre_attack_id:
- - T1110
- T1110.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_unusual_ntlm_authentication_users_by_source.yml b/detections/endpoint/windows_unusual_ntlm_authentication_users_by_source.yml
index d6a3b2c0de..e55d1b5084 100644
--- a/detections/endpoint/windows_unusual_ntlm_authentication_users_by_source.yml
+++ b/detections/endpoint/windows_unusual_ntlm_authentication_users_by_source.yml
@@ -1,7 +1,7 @@
name: Windows Unusual NTLM Authentication Users By Source
id: 80fcc4d4-fd90-488e-b55a-4e7190ae6ce2
-version: 3
-date: '2024-11-13'
+version: 4
+date: '2025-02-10'
author: Steven Dick
status: production
type: Anomaly
@@ -63,7 +63,6 @@ tags:
- Active Directory Password Spraying
asset_type: Endpoint
mitre_attack_id:
- - T1110
- T1110.003
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_usbstor_registry_key_modification.yml b/detections/endpoint/windows_usbstor_registry_key_modification.yml
new file mode 100644
index 0000000000..4ae1abf576
--- /dev/null
+++ b/detections/endpoint/windows_usbstor_registry_key_modification.yml
@@ -0,0 +1,67 @@
+name: Windows USBSTOR Registry Key Modification
+id: a345980a-417d-4ed3-9fb4-cac30c9405a0
+version: 1
+date: '2025-01-17'
+author: Steven Dick
+status: production
+type: Anomaly
+description: This analytic is used to identify when a USB removable media device is attached to a Windows host. In this scenario we are querying the Endpoint Registry data model to look for modifications to the HKLM\System\CurrentControlSet\Enum\USBSTOR\ key. Adversaries and Insider Threats may use removable media devices for several malicious activities, including initial access, execution, and exfiltration.
+data_source:
+- Sysmon Event ID 12
+- Sysmon Event ID 13
+search: |-
+ | tstats `security_content_summariesonly` values(Registry.registry_value_data) as registry_value_data, values(Registry.registry_value_name) as registry_value_name, min(_time) as firstTime, max(_time) as lastTime, count from datamodel=Endpoint.Registry where Registry.registry_path IN ("HKLM\\System\\CurrentControlSet\\Enum\\USBSTOR\\*") AND Registry.registry_value_name ="FriendlyName" by Registry.dest,Registry.registry_value_data,Registry.registry_path
+ | `drop_dm_object_name(Registry)`
+ | eval object_name = registry_value_data, object_handle = split(mvindex(split(registry_path, "\\"),6),"&"), object_handle = mvindex(mvfilter(NOT len(object_handle)=1),0)
+ | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`
+ | `windows_usbstor_registry_key_modification_filter`
+how_to_implement: To successfully implement this search, you must ingest endpoint logging that tracks changes to the HKLM\System\CurrentControlSet\Enum\USBSTOR\ registry keys. Ensure that the field from the event logs is being mapped to the proper fields in the Endpoint.Registry data model.
+known_false_positives: Legitimate USB activity will also be detected. Please verify and investigate as appropriate.
+references:
+- https://attack.mitre.org/techniques/T1200/
+- https://www.cisa.gov/news-events/news/using-caution-usb-drives
+- https://www.bleepingcomputer.com/news/security/fbi-hackers-use-badusb-to-target-defense-firms-with-ransomware/
+drilldown_searches:
+- name: View the detection results for - "$dest$"
+ search: '%original_detection_search% | search dest = "$dest$"'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: View risk events for the last 7 days for - "$dest$"
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: Investigate USB events on $dest$
+ search: '| from datamodel:Endpoint.Registry | search dest=$dest$ registry_path IN ("HKLM\\System\\CurrentControlSet\\Enum\\USBSTOR\\*")'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+rba:
+ message: A removable storage device named [$object_name$] with drive letter [$object_handle$] was attached to $dest$
+ risk_objects:
+ - field: dest
+ type: system
+ score: 10
+ threat_objects:
+ - field: object_name
+ type: registry_value_name
+ - field: object_handle
+ type: registry_value_text
+tags:
+ analytic_story:
+ - Data Protection
+ asset_type: Endpoint
+ mitre_attack_id:
+ - T1200
+ - T1025
+ - T1091
+ product:
+ - Splunk Enterprise
+ - Splunk Enterprise Security
+ - Splunk Cloud
+ security_domain: endpoint
+tests:
+- name: True Positive Test
+ attack_data:
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1200/sysmon_usb_use_execution/sysmon_usb_use_execution.log
+ source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
+ sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_user_deletion_via_net.yml b/detections/endpoint/windows_user_deletion_via_net.yml
index 33ae19c5ea..32bb43dd91 100644
--- a/detections/endpoint/windows_user_deletion_via_net.yml
+++ b/detections/endpoint/windows_user_deletion_via_net.yml
@@ -1,6 +1,6 @@
name: Windows User Deletion Via Net
id: b0b6fd2c-8953-4d1b-8f7b-56075ea6ab3e
-version: 1
+version: 2
date: '2025-01-13'
author: Teoderick Contreras, Splunk
status: production
diff --git a/detections/endpoint/windows_user_disabled_via_net.yml b/detections/endpoint/windows_user_disabled_via_net.yml
index dd390a4128..547248419e 100644
--- a/detections/endpoint/windows_user_disabled_via_net.yml
+++ b/detections/endpoint/windows_user_disabled_via_net.yml
@@ -1,6 +1,6 @@
name: Windows User Disabled Via Net
id: b0359e05-c87b-4354-83d8-aee0d890243f
-version: 1
+version: 2
date: '2025-01-13'
author: Teoderick Contreras, Splunk
status: production
diff --git a/detections/endpoint/windows_user_discovery_via_net.yml b/detections/endpoint/windows_user_discovery_via_net.yml
index 9f736b6b2d..670b59cbaa 100644
--- a/detections/endpoint/windows_user_discovery_via_net.yml
+++ b/detections/endpoint/windows_user_discovery_via_net.yml
@@ -1,7 +1,7 @@
name: Windows User Discovery Via Net
id: 7742987e-88c1-476b-a626-a869e088ab72
-version: 1
-date: '2025-01-13'
+version: 2
+date: '2025-02-10'
author: Mauricio Velazco, Teoderick Contreras, Nasreddine Bencherchali, Splunk
status: production
type: Hunting
@@ -17,8 +17,22 @@ data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
-search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` (Processes.process="*user" OR Processes.process="*users" OR Processes.process="*users *" OR Processes.process="*user *") AND NOT (Processes.process="*/add" OR Processes.process="*/delete") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_user_discovery_via_net_filter`'
-how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
+search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
+ as lastTime from datamodel=Endpoint.Processes where `process_net` (Processes.process="*user"
+ OR Processes.process="*users" OR Processes.process="*users *" OR Processes.process="*user
+ *") AND NOT (Processes.process="*/add" OR Processes.process="*/delete") by Processes.dest
+ Processes.user Processes.parent_process Processes.process_name Processes.process
+ Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
+ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_user_discovery_via_net_filter`'
+how_to_implement: The detection is based on data that originates from Endpoint Detection
+ and Response (EDR) agents. These agents are designed to provide security-related
+ telemetry from the endpoints where the agent is installed. To implement this search,
+ you must ingest logs that contain the process GUID, process name, and parent process.
+ Additionally, you must ingest complete command-line executions. These logs must
+ be processed using the appropriate Splunk Technology Add-ons that are specific to
+ the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
+ data model. Use the Splunk Common Information Model (CIM) to normalize the field
+ names and speed up the data modeling process.
known_false_positives: Administrators or power users may use this command for troubleshooting.
references:
- https://attack.mitre.org/techniques/T1087/001/
@@ -28,7 +42,6 @@ tags:
- Sandworm Tools
asset_type: Endpoint
mitre_attack_id:
- - T1087
- T1087.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml b/detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml
index 0ee3bb1eaa..a9521c99f0 100644
--- a/detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml
+++ b/detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml
@@ -1,7 +1,7 @@
name: Windows User Execution Malicious URL Shortcut File
id: 5c7ee6ad-baf4-44fb-b2f0-0cfeddf82dbc
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1204.002
- - T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/windows_windbg_spawning_autoit3.yml b/detections/endpoint/windows_windbg_spawning_autoit3.yml
index ddf09e5373..323c29de1d 100644
--- a/detections/endpoint/windows_windbg_spawning_autoit3.yml
+++ b/detections/endpoint/windows_windbg_spawning_autoit3.yml
@@ -1,6 +1,6 @@
name: Windows WinDBG Spawning AutoIt3
id: 7aec015b-cd69-46c3-85ed-dac152056aa4
-version: 6
+version: 7
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_wpdbusenum_registry_key_modification.yml b/detections/endpoint/windows_wpdbusenum_registry_key_modification.yml
new file mode 100644
index 0000000000..d87be77ae0
--- /dev/null
+++ b/detections/endpoint/windows_wpdbusenum_registry_key_modification.yml
@@ -0,0 +1,67 @@
+name: Windows WPDBusEnum Registry Key Modification
+id: 52b48e8b-eb6e-48b0-b8f1-73273f6b134e
+version: 1
+date: '2025-01-17'
+author: Steven Dick
+status: production
+type: Anomaly
+description: This analytic is used to identify when a USB removable media device is attached to a Windows host. In this scenario we are querying the Endpoint Registry data model to look for modifications to the Windows Portable Device keys HKLM\SOFTWARE\Microsoft\Windows Portable Devices\Devices\ or HKLM\System\CurrentControlSet\Enum\SWD\WPDBUSENUM\ . Adversaries and Insider Threats may use removable media devices for several malicious activities, including initial access, execution, and exfiltration.
+data_source:
+- Sysmon Event ID 12
+- Sysmon Event ID 13
+search: |-
+ | tstats `security_content_summariesonly` latest(Registry.registry_path) as registry_path, values(Registry.registry_value_name) as registry_value_name, min(_time) as firstTime, max(_time) as lastTime, count from datamodel=Endpoint.Registry where Registry.registry_path IN ("HKLM\\SOFTWARE\\Microsoft\\Windows Portable Devices\\Devices\\*","HKLM\\System\\CurrentControlSet\\Enum\\SWD\\WPDBUSENUM\\*") AND Registry.registry_value_name ="FriendlyName" AND Registry.registry_path="*USBSTOR*" by Registry.dest,Registry.registry_value_data
+ | `drop_dm_object_name(Registry)`
+ | eval object_handle = registry_value_data, object_name = replace(mvindex(split(mvindex(split(registry_path, "??"),1),"&"),2),"PROD_","")
+ | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`
+ | `windows_wpdbusenum_registry_key_modification_filter`
+how_to_implement: To successfully implement this search, you must ingest endpoint logging that tracks changes to the HKLM\SOFTWARE\Microsoft\Windows Portable Devices\Devices\ or HKLM\System\CurrentControlSet\Enum\SWD\WPDBUSENUM\ registry keys. Ensure that the field from the event logs is being mapped to the proper fields in the Endpoint.Registry data model.
+known_false_positives: Legitimate USB activity will also be detected. Please verify and investigate as appropriate.
+references:
+- https://attack.mitre.org/techniques/T1200/
+- https://www.cisa.gov/news-events/news/using-caution-usb-drives
+- https://www.bleepingcomputer.com/news/security/fbi-hackers-use-badusb-to-target-defense-firms-with-ransomware/
+drilldown_searches:
+- name: View the detection results for - "$dest$"
+ search: '%original_detection_search% | search dest = "$dest$"'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: View risk events for the last 7 days for - "$dest$"
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: Investigate USB events on $dest$
+ search: '| from datamodel:Endpoint.Registry | search dest=$dest$ registry_path IN ("HKLM\\SOFTWARE\\Microsoft\\Windows Portable Devices\\Devices\\*","HKLM\\System\\CurrentControlSet\\Enum\\SWD\\WPDBUSENUM\\*")'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+rba:
+ message: A removable storage device named [$object_name$] with drive letter [$object_handle$] was attached to $dest$
+ risk_objects:
+ - field: dest
+ type: system
+ score: 10
+ threat_objects:
+ - field: object_name
+ type: registry_value_name
+ - field: object_handle
+ type: registry_value_text
+tags:
+ analytic_story:
+ - Data Protection
+ asset_type: Endpoint
+ mitre_attack_id:
+ - T1200
+ - T1025
+ - T1091
+ product:
+ - Splunk Enterprise
+ - Splunk Enterprise Security
+ - Splunk Cloud
+ security_domain: endpoint
+tests:
+- name: True Positive Test
+ attack_data:
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1200/sysmon_usb_use_execution/sysmon_usb_use_execution.log
+ source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
+ sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml b/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml
index 690c5bffb5..36d6515acc 100644
--- a/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml
+++ b/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml
@@ -1,7 +1,7 @@
name: WinEvent Scheduled Task Created to Spawn Shell
id: 203ef0ea-9bd8-11eb-8201-acde48001122
-version: 8
-date: '2025-01-27'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -67,7 +67,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.005
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -76,6 +75,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/winevent_scheduled_task_created_to_spawn_shell/windows-xml.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/winevent_scheduled_task_created_to_spawn_shell/windows-xml.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml b/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml
index 7c383641be..b7a530c00d 100644
--- a/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml
+++ b/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml
@@ -1,7 +1,7 @@
name: WinEvent Scheduled Task Created Within Public Path
id: 5d9c6eee-988c-11eb-8253-acde48001122
-version: 8
-date: '2025-01-27'
+version: 9
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -73,7 +73,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1053.005
- - T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -82,6 +81,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/winevent_scheduled_task_created_to_spawn_shell/windows-xml.log
+ - data:
+ https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/winevent_scheduled_task_created_to_spawn_shell/windows-xml.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/winhlp32_spawning_a_process.yml b/detections/endpoint/winhlp32_spawning_a_process.yml
index 97671e24f0..71018871f9 100644
--- a/detections/endpoint/winhlp32_spawning_a_process.yml
+++ b/detections/endpoint/winhlp32_spawning_a_process.yml
@@ -1,6 +1,6 @@
name: Winhlp32 Spawning a Process
id: d17dae9e-2618-11ec-b9f5-acde48001122
-version: 6
+version: 7
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/winrar_spawning_shell_application.yml b/detections/endpoint/winrar_spawning_shell_application.yml
index 9ef1be04ff..104bc4f1d3 100644
--- a/detections/endpoint/winrar_spawning_shell_application.yml
+++ b/detections/endpoint/winrar_spawning_shell_application.yml
@@ -1,6 +1,6 @@
name: WinRAR Spawning Shell Application
id: d2f36034-37fa-4bd4-8801-26807c15540f
-version: 6
+version: 7
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml b/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml
index e544a4480e..c21bc05de0 100644
--- a/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml
+++ b/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml
@@ -1,7 +1,7 @@
name: WMI Permanent Event Subscription - Sysmon
id: ad05aae6-3b2a-4f73-af97-57bd26cee3b9
-version: 5
-date: '2024-11-13'
+version: 6
+date: '2025-02-10'
author: Rico Valdez, Michael Haag, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1546.003
- - T1546
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/wmic_group_discovery.yml b/detections/endpoint/wmic_group_discovery.yml
index 1387e90ee7..3d38511475 100644
--- a/detections/endpoint/wmic_group_discovery.yml
+++ b/detections/endpoint/wmic_group_discovery.yml
@@ -1,7 +1,7 @@
name: Wmic Group Discovery
id: 83317b08-155b-11ec-8e00-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -41,7 +41,6 @@ tags:
- Active Directory Discovery
asset_type: Endpoint
mitre_attack_id:
- - T1069
- T1069.001
product:
- Splunk Enterprise
diff --git a/detections/endpoint/wmic_noninteractive_app_uninstallation.yml b/detections/endpoint/wmic_noninteractive_app_uninstallation.yml
index a45718c22e..cb48b0dacc 100644
--- a/detections/endpoint/wmic_noninteractive_app_uninstallation.yml
+++ b/detections/endpoint/wmic_noninteractive_app_uninstallation.yml
@@ -1,7 +1,7 @@
name: Wmic NonInteractive App Uninstallation
id: bff0e7a0-317f-11ec-ab4e-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -44,7 +44,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- - T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/wmic_xsl_execution_via_url.yml b/detections/endpoint/wmic_xsl_execution_via_url.yml
index b8efe7f1fc..a9fa113597 100644
--- a/detections/endpoint/wmic_xsl_execution_via_url.yml
+++ b/detections/endpoint/wmic_xsl_execution_via_url.yml
@@ -1,6 +1,6 @@
name: WMIC XSL Execution via URL
id: 787e9dd0-4328-11ec-a029-acde48001122
-version: 6
+version: 7
date: '2024-12-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml b/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml
index bdff837caf..931de61b80 100644
--- a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml
+++ b/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml
@@ -1,7 +1,7 @@
name: Wscript Or Cscript Suspicious Child Process
id: 1f35e1da-267b-11ec-90a9-acde48001122
-version: 5
-date: '2024-12-10'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -72,9 +72,8 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1055
- - T1543
- T1134.004
- - T1134
+ - T1543
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/wsmprovhost_lolbas_execution_process_spawn.yml b/detections/endpoint/wsmprovhost_lolbas_execution_process_spawn.yml
index 702bb0a66e..9ae72bafa1 100644
--- a/detections/endpoint/wsmprovhost_lolbas_execution_process_spawn.yml
+++ b/detections/endpoint/wsmprovhost_lolbas_execution_process_spawn.yml
@@ -1,7 +1,7 @@
name: Wsmprovhost LOLBAS Execution Process Spawn
id: 2eed004c-4c0d-11ec-93e8-3e22fbd008af
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -75,7 +75,6 @@ tags:
- CISA AA24-241A
asset_type: Endpoint
mitre_attack_id:
- - T1021
- T1021.006
product:
- Splunk Enterprise
diff --git a/detections/endpoint/wsreset_uac_bypass.yml b/detections/endpoint/wsreset_uac_bypass.yml
index 14b7aa39d9..1879fa36d4 100644
--- a/detections/endpoint/wsreset_uac_bypass.yml
+++ b/detections/endpoint/wsreset_uac_bypass.yml
@@ -1,7 +1,7 @@
name: WSReset UAC Bypass
id: 8b5901bc-da63-11eb-be43-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-10'
author: Steven Dick, Teoderick Contreras, Splunk
status: production
type: TTP
@@ -73,7 +73,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1548.002
- - T1548
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/xmrig_driver_loaded.yml b/detections/endpoint/xmrig_driver_loaded.yml
index 475bc420de..2c08457e9e 100644
--- a/detections/endpoint/xmrig_driver_loaded.yml
+++ b/detections/endpoint/xmrig_driver_loaded.yml
@@ -1,7 +1,7 @@
name: XMRIG Driver Loaded
id: 90080fa6-a8df-11eb-91e4-acde48001122
-version: 4
-date: '2024-11-13'
+version: 5
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -54,7 +54,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1543.003
- - T1543
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/endpoint/xsl_script_execution_with_wmic.yml b/detections/endpoint/xsl_script_execution_with_wmic.yml
index 02f24699a2..28584c4d66 100644
--- a/detections/endpoint/xsl_script_execution_with_wmic.yml
+++ b/detections/endpoint/xsl_script_execution_with_wmic.yml
@@ -1,6 +1,6 @@
name: XSL Script Execution With WMIC
id: 004e32e2-146d-11ec-a83f-acde48001122
-version: 5
+version: 6
date: '2024-11-13'
author: Teoderick Contreras, Splunk
status: production
diff --git a/detections/network/detect_arp_poisoning.yml b/detections/network/detect_arp_poisoning.yml
index 108276a3d7..1e3b9d8998 100644
--- a/detections/network/detect_arp_poisoning.yml
+++ b/detections/network/detect_arp_poisoning.yml
@@ -1,7 +1,7 @@
name: Detect ARP Poisoning
id: b44bebd6-bd39-467b-9321-73971bcd1aac
-version: 5
-date: '2024-11-15'
+version: 6
+date: '2025-02-10'
author: Mikael Bjerkeland, Splunk
status: experimental
type: TTP
@@ -44,7 +44,6 @@ tags:
mitre_attack_id:
- T1200
- T1498
- - T1557
- T1557.002
product:
- Splunk Enterprise
diff --git a/detections/network/detect_ipv6_network_infrastructure_threats.yml b/detections/network/detect_ipv6_network_infrastructure_threats.yml
index a45007b944..5be89b972e 100644
--- a/detections/network/detect_ipv6_network_infrastructure_threats.yml
+++ b/detections/network/detect_ipv6_network_infrastructure_threats.yml
@@ -1,7 +1,7 @@
name: Detect IPv6 Network Infrastructure Threats
id: c3be767e-7959-44c5-8976-0e9c12a91ad2
-version: 4
-date: '2024-11-15'
+version: 5
+date: '2025-02-10'
author: Mikael Bjerkeland, Splunk
status: experimental
type: TTP
@@ -52,7 +52,6 @@ tags:
mitre_attack_id:
- T1200
- T1498
- - T1557
- T1557.002
product:
- Splunk Enterprise
diff --git a/detections/network/detect_large_outbound_icmp_packets.yml b/detections/network/detect_large_outbound_icmp_packets.yml
index e4bdf54ffc..9fa1a7f4b5 100644
--- a/detections/network/detect_large_outbound_icmp_packets.yml
+++ b/detections/network/detect_large_outbound_icmp_packets.yml
@@ -1,6 +1,6 @@
name: Detect Large Outbound ICMP Packets
id: e9c102de-4d43-42a7-b1c8-8062ea297419
-version: 8
+version: 9
date: '2025-01-27'
author: Rico Valdez, Dean Luxton, Splunk
status: production
diff --git a/detections/network/detect_outbound_smb_traffic.yml b/detections/network/detect_outbound_smb_traffic.yml
index 3a2cbf6989..0e0acc3144 100644
--- a/detections/network/detect_outbound_smb_traffic.yml
+++ b/detections/network/detect_outbound_smb_traffic.yml
@@ -1,7 +1,7 @@
name: Detect Outbound SMB Traffic
id: 1bed7774-304a-4e8f-9d72-d80e45ff492b
-version: 7
-date: '2024-11-15'
+version: 8
+date: '2025-02-10'
author: Bhavin Patel, Stuart Hopkins, Patrick Bareiss
status: experimental
type: TTP
@@ -30,10 +30,10 @@ how_to_implement: This search also requires you to be ingesting your network tra
known_false_positives: It is likely that the outbound Server Message Block (SMB) traffic
is legitimate, if the company's internal networks are not well-defined in the Assets
and Identity Framework. Categorize the internal CIDR blocks as `internal` in the
- lookup file to avoid creating findings for traffic destined to those CIDR
- blocks. Any other network connection that is going out to the Internet should be
- investigated and blocked. Best practices suggest preventing external communications
- of all SMB versions and related protocols at the network boundary.
+ lookup file to avoid creating findings for traffic destined to those CIDR blocks.
+ Any other network connection that is going out to the Internet should be investigated
+ and blocked. Best practices suggest preventing external communications of all SMB
+ versions and related protocols at the network boundary.
references: []
rba:
message: An outbound SMB connection from $src_ip$ in your infrastructure connecting
@@ -53,7 +53,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1071.002
- - T1071
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/network/detect_port_security_violation.yml b/detections/network/detect_port_security_violation.yml
index 66a16461fd..0126710dbb 100644
--- a/detections/network/detect_port_security_violation.yml
+++ b/detections/network/detect_port_security_violation.yml
@@ -1,7 +1,7 @@
name: Detect Port Security Violation
id: 2de3d5b8-a4fa-45c5-8540-6d071c194d24
-version: 5
-date: '2024-11-15'
+version: 6
+date: '2025-02-10'
author: Mikael Bjerkeland, Splunk
status: experimental
type: TTP
@@ -44,7 +44,6 @@ tags:
mitre_attack_id:
- T1200
- T1498
- - T1557
- T1557.002
product:
- Splunk Enterprise
diff --git a/detections/network/detect_remote_access_software_usage_dns.yml b/detections/network/detect_remote_access_software_usage_dns.yml
index e01bd31544..f7744a4f63 100644
--- a/detections/network/detect_remote_access_software_usage_dns.yml
+++ b/detections/network/detect_remote_access_software_usage_dns.yml
@@ -1,6 +1,6 @@
name: Detect Remote Access Software Usage DNS
id: a16b797d-e309-41bd-8ba0-5067dae2e4be
-version: 5
+version: 6
date: '2024-11-15'
author: Steven Dick
status: production
@@ -52,21 +52,28 @@ drilldown_searches:
| `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
+- name: Investigate traffic to $query$
+ search: '| from datamodel:Network_Resolution.DNS | search src=$src$ query=$query$'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
rba:
message: A domain for a known remote access software $query$ was contacted by $src$.
risk_objects:
- field: src
type: system
- score: 4
+ score: 25
threat_objects:
- field: query
type: domain
+ - field: signature
+ type: signature
tags:
analytic_story:
- Insider Threat
- Command And Control
- Ransomware
- CISA AA24-241A
+ - Remote Monitoring and Management Software
asset_type: Endpoint
mitre_attack_id:
- T1219
diff --git a/detections/network/detect_remote_access_software_usage_traffic.yml b/detections/network/detect_remote_access_software_usage_traffic.yml
index aeb0b45f21..526fe6f906 100644
--- a/detections/network/detect_remote_access_software_usage_traffic.yml
+++ b/detections/network/detect_remote_access_software_usage_traffic.yml
@@ -1,6 +1,6 @@
name: Detect Remote Access Software Usage Traffic
id: 885ea672-07ee-475a-879e-60d28aa5dd42
-version: 5
+version: 6
date: '2024-11-15'
author: Steven Dick
status: production
@@ -52,6 +52,10 @@ drilldown_searches:
| `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
+- name: Investigate application traffic for $app$
+ search: '| from datamodel:Network_Traffic.All_Traffic | search src=$src$ app=$app$'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
rba:
message: Application traffic for a known remote access software [$signature$] was
detected from $src$.
@@ -59,12 +63,18 @@ rba:
- field: src
type: system
score: 25
- threat_objects: []
+ - field: user
+ type: user
+ score: 25
+ threat_objects:
+ - field: signature
+ type: signature
tags:
analytic_story:
- Insider Threat
- Command And Control
- Ransomware
+ - Remote Monitoring and Management Software
asset_type: Network
mitre_attack_id:
- T1219
diff --git a/detections/network/detect_software_download_to_network_device.yml b/detections/network/detect_software_download_to_network_device.yml
index d11e5395c6..5f16395c2c 100644
--- a/detections/network/detect_software_download_to_network_device.yml
+++ b/detections/network/detect_software_download_to_network_device.yml
@@ -1,7 +1,7 @@
name: Detect Software Download To Network Device
id: cc590c66-f65f-48f2-986a-4797244762f8
-version: 4
-date: '2024-11-15'
+version: 5
+date: '2025-02-10'
author: Mikael Bjerkeland, Splunk
status: experimental
type: TTP
@@ -44,7 +44,6 @@ tags:
asset_type: Infrastructure
mitre_attack_id:
- T1542.005
- - T1542
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/network/detect_traffic_mirroring.yml b/detections/network/detect_traffic_mirroring.yml
index a8121dd68b..b9982c9d34 100644
--- a/detections/network/detect_traffic_mirroring.yml
+++ b/detections/network/detect_traffic_mirroring.yml
@@ -1,7 +1,7 @@
name: Detect Traffic Mirroring
id: 42b3b753-5925-49c5-9742-36fa40a73990
-version: 5
-date: '2024-11-15'
+version: 6
+date: '2025-02-10'
author: Mikael Bjerkeland, Splunk
status: experimental
type: TTP
@@ -41,10 +41,9 @@ tags:
- Router and Infrastructure Security
asset_type: Infrastructure
mitre_attack_id:
- - T1200
- - T1020
- - T1498
- T1020.001
+ - T1200
+ - T1498
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/network/dns_query_length_outliers___mltk.yml b/detections/network/dns_query_length_outliers___mltk.yml
index 629215e272..2c4743e19d 100644
--- a/detections/network/dns_query_length_outliers___mltk.yml
+++ b/detections/network/dns_query_length_outliers___mltk.yml
@@ -1,7 +1,7 @@
name: DNS Query Length Outliers - MLTK
id: 85fbcfe8-9718-4911-adf6-7000d077a3a9
-version: 5
-date: '2024-11-15'
+version: 6
+date: '2025-02-10'
author: Rico Valdez, Splunk
status: experimental
type: Anomaly
@@ -56,7 +56,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1071.004
- - T1071
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/network/dns_query_length_with_high_standard_deviation.yml b/detections/network/dns_query_length_with_high_standard_deviation.yml
index 744203b569..686ce2e6d7 100644
--- a/detections/network/dns_query_length_with_high_standard_deviation.yml
+++ b/detections/network/dns_query_length_with_high_standard_deviation.yml
@@ -1,7 +1,7 @@
name: DNS Query Length With High Standard Deviation
id: 1a67f15a-f4ff-4170-84e9-08cf6f75d6f5
-version: 8
-date: '2024-11-15'
+version: 9
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: Anomaly
@@ -56,7 +56,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1048.003
- - T1048
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/network/excessive_dns_failures.yml b/detections/network/excessive_dns_failures.yml
index 96cd124e74..b809df4dbf 100644
--- a/detections/network/excessive_dns_failures.yml
+++ b/detections/network/excessive_dns_failures.yml
@@ -1,7 +1,7 @@
name: Excessive DNS Failures
id: 104658f4-afdc-499e-9719-17243f9826f1
-version: 6
-date: '2024-11-15'
+version: 7
+date: '2025-02-10'
author: bowesmana, Bhavin Patel, Splunk
status: experimental
type: Anomaly
@@ -43,7 +43,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1071.004
- - T1071
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml b/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml
index 16c268125d..86532055ed 100644
--- a/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml
+++ b/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml
@@ -1,7 +1,7 @@
name: Hosts receiving high volume of network traffic from email server
id: 7f5fb3e1-4209-4914-90db-0ec21b556368
-version: 5
-date: '2024-11-15'
+version: 6
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: experimental
type: Anomaly
@@ -51,7 +51,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1114.002
- - T1114
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/network/large_volume_of_dns_any_queries.yml b/detections/network/large_volume_of_dns_any_queries.yml
index b73ca41645..1be208ea08 100644
--- a/detections/network/large_volume_of_dns_any_queries.yml
+++ b/detections/network/large_volume_of_dns_any_queries.yml
@@ -1,7 +1,7 @@
name: Large Volume of DNS ANY Queries
id: 8fa891f7-a533-4b3c-af85-5aa2e7c1f1eb
-version: 4
-date: '2024-11-15'
+version: 5
+date: '2025-02-10'
author: Bhavin Patel, Splunk
status: experimental
type: Anomaly
@@ -35,7 +35,6 @@ tags:
- DNS Amplification Attacks
asset_type: DNS Servers
mitre_attack_id:
- - T1498
- T1498.002
product:
- Splunk Enterprise
diff --git a/detections/network/protocol_or_port_mismatch.yml b/detections/network/protocol_or_port_mismatch.yml
index d935eff540..727748a951 100644
--- a/detections/network/protocol_or_port_mismatch.yml
+++ b/detections/network/protocol_or_port_mismatch.yml
@@ -1,7 +1,7 @@
name: Protocol or Port Mismatch
id: 54dc1265-2f74-4b6d-b30d-49eb506a31b3
-version: 5
-date: '2024-11-15'
+version: 6
+date: '2025-02-10'
author: Rico Valdez, Splunk
status: experimental
type: Anomaly
@@ -42,7 +42,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1048.003
- - T1048
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/network/remote_desktop_network_bruteforce.yml b/detections/network/remote_desktop_network_bruteforce.yml
deleted file mode 100644
index 35dcd16a5c..0000000000
--- a/detections/network/remote_desktop_network_bruteforce.yml
+++ /dev/null
@@ -1,51 +0,0 @@
-name: Remote Desktop Network Bruteforce
-id: a98727cc-286b-4ff2-b898-41df64695923
-version: 6
-date: '2024-11-15'
-author: Jose Hernandez, Splunk
-status: experimental
-type: TTP
-description: The following analytic identifies potential Remote Desktop Protocol (RDP)
- brute force attacks by monitoring network traffic for RDP application activity.
- It detects anomalies by filtering source and destination pairs that generate traffic
- exceeding twice the standard deviation of the average traffic. This method leverages
- the Network_Traffic data model to identify unusual patterns indicative of brute
- force attempts. This activity is significant as it may indicate an attacker attempting
- to gain unauthorized access to systems via RDP. If confirmed malicious, this could
- lead to unauthorized access, data exfiltration, or further network compromise.
-data_source: []
-search: >-
- | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
- as lastTime from datamodel=Network_Traffic where (All_Traffic.app=rdp OR All_Traffic.dest_port=3389)
- AND All_Traffic.action=allowed by All_Traffic.src All_Traffic.dest All_Traffic.dest_port |
- eventstats stdev(count) AS stdev avg(count) AS avg p50(count) AS p50 | where count>(avg
- + stdev*2) | rename All_Traffic.src AS src All_Traffic.dest AS dest | table firstTime
- lastTime src dest count avg p50 stdev | `remote_desktop_network_bruteforce_filter`
-how_to_implement: You must ensure that your network traffic data is populating the
- Network_Traffic data model.
-known_false_positives: RDP gateways may have unusually high amounts of traffic from
- all other hosts' RDP applications in the network.
-references: []
-rba:
- message: $dest$ may be the target of an RDP Bruteforce
- risk_objects:
- - field: dest
- type: system
- score: 25
- - field: src
- type: system
- score: 25
- threat_objects: []
-tags:
- analytic_story:
- - SamSam Ransomware
- - Ryuk Ransomware
- asset_type: Endpoint
- mitre_attack_id:
- - T1021.001
- - T1021
- product:
- - Splunk Enterprise
- - Splunk Enterprise Security
- - Splunk Cloud
- security_domain: network
diff --git a/detections/network/remote_desktop_network_traffic.yml b/detections/network/remote_desktop_network_traffic.yml
index dea3884a91..866c4cc5e4 100644
--- a/detections/network/remote_desktop_network_traffic.yml
+++ b/detections/network/remote_desktop_network_traffic.yml
@@ -1,7 +1,7 @@
name: Remote Desktop Network Traffic
id: 272b8407-842d-4b3d-bead-a704584003d3
-version: 8
-date: '2024-11-15'
+version: 9
+date: '2025-02-10'
author: David Dorsey, Splunk
status: production
type: Anomaly
@@ -63,7 +63,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1021.001
- - T1021
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/network/smb_traffic_spike.yml b/detections/network/smb_traffic_spike.yml
index 7154a35162..122c6cb228 100644
--- a/detections/network/smb_traffic_spike.yml
+++ b/detections/network/smb_traffic_spike.yml
@@ -1,7 +1,7 @@
name: SMB Traffic Spike
id: 7f5fb3e1-4209-4914-90db-0ec21b936378
-version: 6
-date: '2024-11-15'
+version: 7
+date: '2025-02-10'
author: David Dorsey, Splunk
status: experimental
type: Anomaly
@@ -43,7 +43,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1021.002
- - T1021
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/network/smb_traffic_spike___mltk.yml b/detections/network/smb_traffic_spike___mltk.yml
index 0ec7d9fe16..38c6b024a6 100644
--- a/detections/network/smb_traffic_spike___mltk.yml
+++ b/detections/network/smb_traffic_spike___mltk.yml
@@ -1,7 +1,7 @@
name: SMB Traffic Spike - MLTK
id: d25773ba-9ad8-48d1-858e-07ad0bbeb828
-version: 6
-date: '2024-11-15'
+version: 7
+date: '2025-02-10'
author: Rico Valdez, Splunk
status: experimental
type: Anomaly
@@ -31,11 +31,10 @@ how_to_implement: "To successfully implement this search, you will need to ensur
should periodically re-run the support search to rebuild the model with the latest
data available in your environment.\nThis search produces a field (Number of events,count)
that are not yet supported by ES Incident Review and therefore cannot be viewed
- when a finding is raised. This field contributes additional context to the
- finding. To see the additional metadata, add the following field, if not already
- present, to Incident Review - Event Attributes (Configure > Incident Management
- > Incident Review Settings > Add New Entry):\n* **Label:** Number of events, **Field:**
- count"
+ when a finding is raised. This field contributes additional context to the finding.
+ To see the additional metadata, add the following field, if not already present,
+ to Incident Review - Event Attributes (Configure > Incident Management > Incident
+ Review Settings > Add New Entry):\n* **Label:** Number of events, **Field:** count"
known_false_positives: If you are seeing more results than desired, you may consider
reducing the value of the threshold in the search. You should also periodically
re-run the support search to re-build the ML model on the latest data. Please update
@@ -57,7 +56,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1021.002
- - T1021
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/network/tor_traffic.yml b/detections/network/tor_traffic.yml
index 07c2e15ab9..4b1d821c41 100644
--- a/detections/network/tor_traffic.yml
+++ b/detections/network/tor_traffic.yml
@@ -1,7 +1,7 @@
name: TOR Traffic
id: ea688274-9c06-4473-b951-e4cb7a5d7a45
-version: 6
-date: '2024-11-15'
+version: 7
+date: '2025-02-10'
author: David Dorsey, Bhavin Patel, Splunk
status: production
type: TTP
@@ -59,7 +59,6 @@ tags:
- Command And Control
asset_type: Endpoint
mitre_attack_id:
- - T1090
- T1090.003
product:
- Splunk Enterprise
diff --git a/detections/network/windows_ad_replication_service_traffic.yml b/detections/network/windows_ad_replication_service_traffic.yml
index 17845e1f82..59036dc908 100644
--- a/detections/network/windows_ad_replication_service_traffic.yml
+++ b/detections/network/windows_ad_replication_service_traffic.yml
@@ -1,7 +1,7 @@
name: Windows AD Replication Service Traffic
id: c6e24183-a5f4-4b2a-ad01-2eb456d09b67
-version: 4
-date: '2024-11-15'
+version: 5
+date: '2025-02-10'
author: Steven Dick
type: TTP
status: experimental
@@ -42,7 +42,6 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- - T1003
- T1003.006
- T1207
product:
diff --git a/detections/network/windows_remote_desktop_network_bruteforce_attempt.yml b/detections/network/windows_remote_desktop_network_bruteforce_attempt.yml
new file mode 100644
index 0000000000..38f166c9d9
--- /dev/null
+++ b/detections/network/windows_remote_desktop_network_bruteforce_attempt.yml
@@ -0,0 +1,60 @@
+name: Windows Remote Desktop Network Bruteforce Attempt
+id: 908bf0d5-0983-4afd-b6a4-e9eb5d361a7d
+version: 2
+date: '2025-02-11'
+author: Jose Hernandez, Bhavin Patel, Splunk
+status: production
+type: Anomaly
+description: The following analytic identifies potential Remote Desktop Protocol (RDP) brute force attacks by monitoring network traffic for RDP application activity. This query detects potential RDP brute force attacks by identifying source IPs that have made more than 10 connection attempts to the same RDP port on a host within a one-hour window. The results are presented in a table that includes the source and destination IPs, destination port, number of attempts, and the times of the first and last connection attempts, helping to prioritize IPs based on the intensity of activity.
+data_source:
+- Sysmon EventID 3
+search: >-
+ | tstats `security_content_summariesonly` count, min(_time) as firstTime, max(_time) as lastTime values(Al_Traffic.action) as action from datamodel=Network_Traffic where (All_Traffic.app=rdp OR All_Traffic.dest_port=3389) by All_Traffic.src, All_Traffic.dest, All_Traffic.dest_port All_Traffic.user All_Traffic.vendor_product
+ | `drop_dm_object_name("All_Traffic")`
+ | eval duration=lastTime-firstTime
+ | where count > 10 AND duration < 3600
+ | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`
+ | `windows_remote_desktop_network_bruteforce_attempt_filter`
+how_to_implement: You must ensure that your network traffic data is populating the Network_Traffic data model. Adjust the count and duration thresholds as necessary to tune the sensitivity of your detection.
+known_false_positives: RDP gateways may have unusually high amounts of traffic from all other hosts' RDP applications in the network.Any legitimate RDP traffic using wrong/expired credentials will be also detected as a false positive.
+references:
+- https://www.zscaler.com/blogs/security-research/ransomware-delivered-using-rdp-brute-force-attack
+- https://www.reliaquest.com/blog/rdp-brute-force-attacks/
+drilldown_searches:
+- name: View the detection results for - "$dest$"
+ search: '%original_detection_search% | search dest = "$dest$"'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: View risk events for the last 7 days for - "$dest$"
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+rba:
+ message: $dest$ may be the target of an RDP Bruteforce from $src$
+ risk_objects:
+ - field: dest
+ type: system
+ score: 25
+ threat_objects:
+ - field: src
+ type: ip_address
+tags:
+ analytic_story:
+ - SamSam Ransomware
+ - Ryuk Ransomware
+ - Compromised User Account
+ asset_type: Endpoint
+ mitre_attack_id:
+ - T1110.001
+ product:
+ - Splunk Enterprise
+ - Splunk Enterprise Security
+ - Splunk Cloud
+ security_domain: network
+tests:
+- name: True Positive Test
+ attack_data:
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.001/rdp_brute_sysmon/sysmon.log
+ source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
+ sourcetype: XmlWinEventLog
diff --git a/detections/web/detect_remote_access_software_usage_url.yml b/detections/web/detect_remote_access_software_usage_url.yml
index d60f2af086..6f186e9379 100644
--- a/detections/web/detect_remote_access_software_usage_url.yml
+++ b/detections/web/detect_remote_access_software_usage_url.yml
@@ -1,6 +1,6 @@
name: Detect Remote Access Software Usage URL
id: 9296f515-073c-43a5-88ec-eda5a4626654
-version: 5
+version: 7
date: '2024-11-15'
author: Steven Dick
status: production
@@ -52,6 +52,10 @@ drilldown_searches:
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
+- name: Investigate traffic to $url_domain$
+ search: '| from datamodel:Web | search src=$src$ url_domain=$url_domain$'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
rba:
message: A domain for a known remote access software $url_domain$ was contacted
by $src$.
@@ -65,12 +69,15 @@ rba:
threat_objects:
- field: url_domain
type: domain
+ - field: signature
+ type: signature
tags:
analytic_story:
- Insider Threat
- Command And Control
- Ransomware
- CISA AA24-241A
+ - Remote Monitoring and Management Software
asset_type: Network
mitre_attack_id:
- T1219
diff --git a/detections/web/exploit_public_facing_application_via_apache_commons_text.yml b/detections/web/exploit_public_facing_application_via_apache_commons_text.yml
index d9b87dfcf0..162db64b40 100644
--- a/detections/web/exploit_public_facing_application_via_apache_commons_text.yml
+++ b/detections/web/exploit_public_facing_application_via_apache_commons_text.yml
@@ -1,7 +1,7 @@
name: Exploit Public Facing Application via Apache Commons Text
id: 19a481e0-c97c-4d14-b1db-75a708eb592e
-version: 5
-date: '2024-11-15'
+version: 6
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Anomaly
@@ -72,10 +72,9 @@ tags:
cve:
- CVE-2022-42889
mitre_attack_id:
- - T1505.003
- - T1505
- - T1190
- T1133
+ - T1190
+ - T1505.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/web/multiple_archive_files_http_post_traffic.yml b/detections/web/multiple_archive_files_http_post_traffic.yml
index 725f31561f..7e4978a2c5 100644
--- a/detections/web/multiple_archive_files_http_post_traffic.yml
+++ b/detections/web/multiple_archive_files_http_post_traffic.yml
@@ -1,7 +1,7 @@
name: Multiple Archive Files Http Post Traffic
id: 4477f3ea-a28f-11eb-b762-acde48001122
-version: 5
-date: '2024-11-15'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1048.003
- - T1048
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/web/plain_http_post_exfiltrated_data.yml b/detections/web/plain_http_post_exfiltrated_data.yml
index f94dbe9139..1272c755a0 100644
--- a/detections/web/plain_http_post_exfiltrated_data.yml
+++ b/detections/web/plain_http_post_exfiltrated_data.yml
@@ -1,7 +1,7 @@
name: Plain HTTP POST Exfiltrated Data
id: e2b36208-a364-11eb-8909-acde48001122
-version: 5
-date: '2024-11-15'
+version: 6
+date: '2025-02-10'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -55,7 +55,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1048.003
- - T1048
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/web/spring4shell_payload_url_request.yml b/detections/web/spring4shell_payload_url_request.yml
index 1ba92e50e9..adec62590e 100644
--- a/detections/web/spring4shell_payload_url_request.yml
+++ b/detections/web/spring4shell_payload_url_request.yml
@@ -1,7 +1,7 @@
name: Spring4Shell Payload URL Request
id: 9d44d649-7d67-4559-95c1-8022ff49420b
-version: 4
-date: '2024-11-15'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -57,10 +57,9 @@ tags:
cve:
- CVE-2022-22965
mitre_attack_id:
- - T1505.003
- - T1505
- - T1190
- T1133
+ - T1190
+ - T1505.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/web/web_jsp_request_via_url.yml b/detections/web/web_jsp_request_via_url.yml
index 3aea7b2a94..fbf4f4991c 100644
--- a/detections/web/web_jsp_request_via_url.yml
+++ b/detections/web/web_jsp_request_via_url.yml
@@ -1,7 +1,7 @@
name: Web JSP Request via URL
id: 2850c734-2d44-4431-8139-1a56f6f54c01
-version: 4
-date: '2024-11-15'
+version: 5
+date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -58,10 +58,9 @@ tags:
cve:
- CVE-2022-22965
mitre_attack_id:
- - T1505.003
- - T1505
- - T1190
- T1133
+ - T1190
+ - T1505.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
diff --git a/detections/web/zscaler_adware_activities_threat_blocked.yml b/detections/web/zscaler_adware_activities_threat_blocked.yml
index f662cc0a16..c47abd8740 100644
--- a/detections/web/zscaler_adware_activities_threat_blocked.yml
+++ b/detections/web/zscaler_adware_activities_threat_blocked.yml
@@ -1,6 +1,6 @@
name: Zscaler Adware Activities Threat Blocked
id: 3407b250-345a-4d71-80db-c91e555a3ece
-version: 4
+version: 5
date: '2024-11-15'
author: Gowthamaraj Rajendran, Splunk
status: production
diff --git a/detections/web/zscaler_behavior_analysis_threat_blocked.yml b/detections/web/zscaler_behavior_analysis_threat_blocked.yml
index 8875d8762b..8a55d3f407 100644
--- a/detections/web/zscaler_behavior_analysis_threat_blocked.yml
+++ b/detections/web/zscaler_behavior_analysis_threat_blocked.yml
@@ -1,6 +1,6 @@
name: Zscaler Behavior Analysis Threat Blocked
id: 289ad59f-8939-4331-b805-f2bd51d36fb8
-version: 4
+version: 5
date: '2024-11-15'
author: Rod Soto, Gowthamaraj Rajendran, Splunk
status: production
diff --git a/detections/web/zscaler_exploit_threat_blocked.yml b/detections/web/zscaler_exploit_threat_blocked.yml
index 0da0906592..e88d087743 100644
--- a/detections/web/zscaler_exploit_threat_blocked.yml
+++ b/detections/web/zscaler_exploit_threat_blocked.yml
@@ -1,6 +1,6 @@
name: Zscaler Exploit Threat Blocked
id: 94665d8c-b841-4ff4-acb4-34d613e2cbfe
-version: 4
+version: 5
date: '2024-11-15'
author: Rod Soto, Gowthamaraj Rajendran, Splunk
status: production
diff --git a/detections/web/zscaler_malware_activity_threat_blocked.yml b/detections/web/zscaler_malware_activity_threat_blocked.yml
index 3494bd9e23..34061dc5be 100644
--- a/detections/web/zscaler_malware_activity_threat_blocked.yml
+++ b/detections/web/zscaler_malware_activity_threat_blocked.yml
@@ -1,6 +1,6 @@
name: Zscaler Malware Activity Threat Blocked
id: ae874ad8-e353-40a7-87d4-420cdfb27d1a
-version: 4
+version: 5
date: '2024-11-15'
author: Rod Soto, Gowthamaraj Rajendran, Splunk
status: production
diff --git a/detections/web/zscaler_potentially_abused_file_download.yml b/detections/web/zscaler_potentially_abused_file_download.yml
index 040b02ae71..f18bdfe4f0 100644
--- a/detections/web/zscaler_potentially_abused_file_download.yml
+++ b/detections/web/zscaler_potentially_abused_file_download.yml
@@ -1,6 +1,6 @@
name: Zscaler Potentially Abused File Download
id: b0c21379-f4ba-4bac-a958-897e260f964a
-version: 4
+version: 5
date: '2024-11-15'
author: Gowthamaraj Rajendran, Rod Soto, Splunk
status: production
diff --git a/detections/web/zscaler_privacy_risk_destinations_threat_blocked.yml b/detections/web/zscaler_privacy_risk_destinations_threat_blocked.yml
index cad5f20065..abf94751e3 100644
--- a/detections/web/zscaler_privacy_risk_destinations_threat_blocked.yml
+++ b/detections/web/zscaler_privacy_risk_destinations_threat_blocked.yml
@@ -1,6 +1,6 @@
name: Zscaler Privacy Risk Destinations Threat Blocked
id: 5456bdef-d765-4565-8e1f-61ca027bc50d
-version: 4
+version: 5
date: '2024-11-15'
author: Gowthamaraj Rajendran, Rod Soto, Splunk
status: production
diff --git a/detections/web/zscaler_scam_destinations_threat_blocked.yml b/detections/web/zscaler_scam_destinations_threat_blocked.yml
index d91cf5e7e9..5c7281924b 100644
--- a/detections/web/zscaler_scam_destinations_threat_blocked.yml
+++ b/detections/web/zscaler_scam_destinations_threat_blocked.yml
@@ -1,6 +1,6 @@
name: Zscaler Scam Destinations Threat Blocked
id: a0c21379-f4ba-4bac-a958-897e260f964a
-version: 4
+version: 5
date: '2024-11-15'
author: Gowthamaraj Rajendran, Rod Soto, Splunk
status: production
diff --git a/detections/web/zscaler_virus_download_threat_blocked.yml b/detections/web/zscaler_virus_download_threat_blocked.yml
index 656efd2fac..f0c094a07c 100644
--- a/detections/web/zscaler_virus_download_threat_blocked.yml
+++ b/detections/web/zscaler_virus_download_threat_blocked.yml
@@ -1,6 +1,6 @@
name: Zscaler Virus Download threat blocked
id: aa19e627-d448-4a31-85cd-82068dec5691
-version: 4
+version: 5
date: '2024-11-15'
author: Gowthamaraj Rajendran, Rod Soto, Splunk
status: production
From 590baee7429830dc91d15e8341a9ac4386a162c9 Mon Sep 17 00:00:00 2001
From: pyth0n1c
Date: Tue, 25 Feb 2025 14:57:46 -0800
Subject: [PATCH 09/67] create new deprecation file
---
.../deprecated_detection_mapping_updated.yml | 902 ++++++++++++++++++
1 file changed, 902 insertions(+)
create mode 100644 deprecated/deprecated_detection_mapping_updated.yml
diff --git a/deprecated/deprecated_detection_mapping_updated.yml b/deprecated/deprecated_detection_mapping_updated.yml
new file mode 100644
index 0000000000..db32b776a2
--- /dev/null
+++ b/deprecated/deprecated_detection_mapping_updated.yml
@@ -0,0 +1,902 @@
+detections:
+ - deprecated_content: ASL AWS Excessive Security Scanning
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: AWS Cloud Provisioning From Previously Unseen Region
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Provisioning Activity From Previously Unseen Region
+ - deprecated_content: First time seen command line argument
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Windows connhost exe started forcefully
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Detect Mimikatz Using Loaded Images
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Kubernetes Azure detect sensitive role access
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Web Fraud - Anomalous User Clickspeed
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: EC2 Instance Started With Previously Unseen Instance Type
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Compute Instance Created With Previously Unseen Instance Type
+ - deprecated_content: EC2 Instance Started With Previously Unseen AMI
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Compute Instance Created With Previously Unseen Image
+ - deprecated_content: Domain Group Discovery With Net
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - Windows Group Discovery Via Net
+ - deprecated_content: Kubernetes AWS detect sensitive role access
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Winword Spawning Windows Script Host
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: "The following analytics was deprecated in favour of a more generic approach.
+ Where instead of creating specific analytic for every potentially suspicious child
+ of an office product. We group them by threat level.\nThis would ease management
+ and false positives tuning."
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Winword Spawning PowerShell
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Attempted Credential Dump From Registry via Reg exe
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: This analytic had some overlap with another one, hence the deprecation.
+ It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry
+ Hive Dump Via CommandLine
+ replacement_content:
+ - Windows Sensitive Registry Hive Dump Via CommandLine
+ - deprecated_content: Detect processes used for System Network Configuration Discovery
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Potential System Network Configuration Discovery Activity
+ - deprecated_content: Execution of File With Spaces Before Extension
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Updated to a new detection name
+ replacement_content:
+ - Execution of File with Multiple Extensions
+ - deprecated_content: EC2 Instance Started In Previously Unseen Region
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Compute Instance Created In Previously Unused Region
+ - deprecated_content: Office Document Spawned Child Process To Download
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Spawned Child Process For Download
+ - deprecated_content: Detect new API calls from user roles
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud API Calls From Previously Unseen User Roles
+ - deprecated_content: Cmdline Tool Not Executed In CMD Shell
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Cmdline Tool Execution From Non-Shell Process
+ - deprecated_content: Linux Auditd Find Private Keys
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Linux Auditd Private Keys and Certificate Enumeration
+ - deprecated_content: Detect AWS API Activities From Unapproved Accounts
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Monitor DNS For Brand Abuse
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Kubernetes GCP detect sensitive object access
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Kubernetes Azure scan fingerprint
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: ASL AWS Password Policy Changes
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: O365 Suspicious Admin Email Forwarding
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - O365 Mailbox Email Forwarding Enabled
+ - deprecated_content: AWS Cloud Provisioning From Previously Unseen City
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Provisioning Activity From Previously Unseen City
+ - deprecated_content: Kubernetes AWS detect service accounts forbidden failure access
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Osquery pack - ColdRoot detection
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Windows Modify Registry Reg Restore
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Registry Entries Restored Via Reg
+ - deprecated_content: Kubernetes GCP detect most active service accounts by pod
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Scheduled tasks used in BadRabbit ransomware
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Updated to a new detection name
+ replacement_content:
+ - Scheduled Task Deleted Or Created via CMD
+ - deprecated_content: Suspicious Rundll32 Rename
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Remote System Discovery with Net
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: "This analytic was focusing on 2 separate and unrelated type of threats
+ or actions. It was split into other analytics, namely:\r\n\r\nWindows Network
+ Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277\r\nWindows Sensitive
+ Group Discovery With Net / a23a0e20-0b1b-4a07-82e5-ec5f70811e7a"
+ replacement_content:
+ - Windows Network Share Interaction With Net
+ - deprecated_content: Remote System Discovery with Net
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - Windows Sensitive Group Discovery With Net
+ - deprecated_content: DNS Query Requests Resolved by Unauthorized DNS Servers
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Suspicious Changes to File Associations
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: GCP Detect high risk permissions by resource and account
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Office Product Writing cab or inf
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Dropped Cab or Inf File
+ - deprecated_content: Identify New User Accounts
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Office Product Spawn CMD Process
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Windows DLL Search Order Hijacking Hunt
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Windows DLL Search Order Hijacking Hunt with Sysmon
+ - deprecated_content: ASL AWS CreateAccessKey
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - ASL AWS Create Access Key
+ - deprecated_content: Okta ThreatInsight Login Failure with High Unknown users
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Detect Spike in Security Group Activity
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Abnormally High Number Of Cloud Security Group API Calls
+ - deprecated_content: Office Product Spawning BITSAdmin
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Create local admin accounts using net exe
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Create Local Administrator Account Via Net
+ - deprecated_content: Abnormally High AWS Instances Terminated by User - MLTK
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Windows Office Product Spawning MSDT
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Spawned MSDT
+ - deprecated_content: Detect Spike in AWS API Activity
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - ''
+ - deprecated_content: Office Product Spawning Windows Script Host
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Prohibited Software On Endpoint
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - Attacker Tools On Endpoint
+ - deprecated_content: AWS Cloud Provisioning From Previously Unseen Country
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Provisioning Activity From Previously Unseen Country
+ - deprecated_content: Detect Critical Alerts from Security Tools
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: As discussed internally, this analytic was too generic for an analyst to
+ do anything with it. It was deprecated in favor of the more specific approach
+ provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender
+ Incident Alerts. Going forward analytics from leveraging alerts from vendors will
+ have their specific analytics.
+ replacement_content:
+ - Microsoft Defender ATP Alerts
+ - deprecated_content: Detect Critical Alerts from Security Tools
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - Microsoft Defender Incident Alerts
+ - deprecated_content: Excel Spawning PowerShell
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Office Application Spawn rundll32 process
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Excessive Usage Of Net App
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Excessive Usage Of Net App
+ - deprecated_content: Elevated Group Discovery With Net
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Sensitive Group Discovery With Net
+ - deprecated_content: Local Account Discovery with Net
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows User Discovery Via Net
+ - deprecated_content: Windows Command Shell Fetch Env Variables
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows List ENV Variables Via SET Command From Uncommon Parent
+ - deprecated_content: Suspicious Email - UBA Anomaly
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Detect web traffic to dynamic domain providers
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Updated to use a different log source
+ replacement_content:
+ - Detect hosts connecting to dynamic domain providers
+ - deprecated_content: Okta Failed SSO Attempts
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Okta Unauthorized Access to Application
+ - deprecated_content: Kubernetes AWS detect RBAC authorization by account
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Kubernetes Azure detect service accounts forbidden failure access
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Remote Registry Key modifications
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: O365 Suspicious User Email Forwarding
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - O365 Mailbox Email Forwarding Enabled
+ - deprecated_content: Office Product Spawning MSHTA
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Kubernetes AWS detect most active service accounts by pod
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Correlation by Repository and Risk
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the datamodel
+ replacement_content:
+ - Risk Rule for Dev Sec Ops by Repository
+ - deprecated_content: Kubernetes Azure detect RBAC authorization by account
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Clients Connecting to Multiple DNS Servers
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Excessive Service Stop Attempt
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Excessive Service Stop Attempt
+ - deprecated_content: Multiple Okta Users With Invalid Credentials From The Same IP
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Okta Multiple Users Failing To Authenticate From Ip
+ - deprecated_content: Suspicious writes to System Volume Information
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Detect new user AWS Console Login
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Detect AWS Console Login by New User
+ - deprecated_content: Domain Account Discovery With Net App
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: "This analytic was a TTP that looked only for commands that tries to query
+ info about the users via net user /do. This had a couple of issues, such as triggering
+ on creation of users via the /add flag etc..\nIt was deprecated in favor of a
+ more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122"
+ replacement_content:
+ - Windows User Discovery Via Net
+ - deprecated_content: Detection of DNS Tunnels
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Detect DNS requests to Phishing Sites leveraging EvilGinx2
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Office Document Creating Schedule Task
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Loading Taskschd DLL
+ - deprecated_content: Okta Account Locked Out
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Okta Multiple Accounts Locked Out
+ - deprecated_content: Unsuccessful Netbackup backups
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Detect Mimikatz Via PowerShell And EventCode 4703
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Updated to a new detection name
+ replacement_content:
+ - Detect Mimikatz With PowerShell Script Block Logging
+ - deprecated_content: Winword Spawning Cmd
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: GCP Kubernetes cluster scan detection
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Kubernetes Scanning by Unauthenticated IP Address
+ - deprecated_content: Kubernetes GCP detect suspicious kubectl calls
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: gcp detect oauth token abuse
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Correlation by User and Risk
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the datamodel
+ replacement_content:
+ - Risk Rule for Dev Sec Ops by Repository
+ - deprecated_content: Processes created by netsh
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Updated to a new detection name
+ replacement_content:
+ - Processes launching netsh
+ - deprecated_content: Office Product Spawning Wmic
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Extraction of Registry Hives
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Sensitive Registry Hive Dump Via CommandLine
+ - deprecated_content: Attempt To Stop Security Service
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Attempt To Stop Security Service
+ - deprecated_content: Windows MSIExec With Network Connections
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows HTTP Network Communication From MSIExec
+ - deprecated_content: Windows Query Registry Reg Save
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Registry Entries Exported Via Reg
+ - deprecated_content: Cloud Network Access Control List Deleted
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - AWS Network Access Control List Deleted
+ - deprecated_content: O365 Suspicious Rights Delegation
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - O365 Elevated Mailbox Permission Assigned
+ - deprecated_content: Abnormally High AWS Instances Launched by User - MLTK
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Reg exe used to hide files directories via registry keys
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Detect Long DNS TXT Record Response
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Password Policy Discovery with Net
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Password Policy Discovery with Net
+ - deprecated_content: AWS Cloud Provisioning From Previously Unseen IP Address
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Provisioning Activity From Previously Unseen IP Address
+ - deprecated_content: Network Connection Discovery With Net
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Network Connection Discovery Via Net
+ - deprecated_content: Kubernetes Azure detect suspicious kubectl calls
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Kubernetes GCP detect sensitive role access
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Detect Webshell Exploit Behavior
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Suspicious Child Process Spawned From WebServer
+ - deprecated_content: DNS record changed
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Unsigned Image Loaded by LSASS
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - ''
+ - deprecated_content: Detect USB device insertion
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Windows Network Share Interaction With Net
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Network Share Interaction Via Net
+ - deprecated_content: Account Discovery With Net App
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: This analytic was a TTP that focused on unrelated things and called account
+ discovery. Since there were other detection that overlapped with it. I choose
+ to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122
+ / Windows Excessive Usage Of Net App.
+ replacement_content:
+ - Windows Excessive Usage Of Net App
+ - deprecated_content: Change Default File Association
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows New Default File Association Value Set
+ - deprecated_content: Windows Lateral Tool Transfer RemCom
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Updated to a new detection name
+ replacement_content:
+ - Windows Service Execution RemCom
+ - deprecated_content: Office Document Executing Macro Code
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Loading VBE7 DLL
+ - deprecated_content: Okta Account Lockout Events
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Okta Multiple Accounts Locked Out
+ - deprecated_content: Abnormally High AWS Instances Launched by User
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Abnormally High Number Of Cloud Instances Launched
+ - deprecated_content: EC2 Instance Modified With Previously Unseen User
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud API Calls From Previously Unseen User Roles
+ - deprecated_content: Windows Valid Account With Never Expires Password
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Set Account Password Policy To Unlimited Via Net
+ - deprecated_content: Windows hosts file modification
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: MSHTML Module Load in Office Product
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Loaded MSHTML Module
+ - deprecated_content: Abnormally High AWS Instances Terminated by User
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Abnormally High Number Of Cloud Instances Destroyed
+ - deprecated_content: Web Fraud - Account Harvesting
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Office Spawning Control
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Spawned Control
+ - deprecated_content: Detect Activity Related to Pass the Hash Attacks
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Deleting Of Net Users
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows User Deletion Via Net
+ - deprecated_content: Suspicious File Write
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - ''
+ - deprecated_content: AWS EKS Kubernetes cluster sensitive object access
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Kubernetes Abuse of Secret by Unusual Location
+ - deprecated_content: Spectre and Meltdown Vulnerable Systems
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: EC2 Instance Started With Previously Unseen User
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Compute Instance Created By Previously Unseen User
+ - deprecated_content: Office Product Spawning CertUtil
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Kubernetes GCP detect RBAC authorizations by account
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Office Application Drop Executable
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Dropped Uncommon File
+ - deprecated_content: Kubernetes Azure active service accounts by pod namespace
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Kubernetes Azure pod scan fingerprint
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Detect Spike in Network ACL Activity
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Abnormally High Number Of Cloud Infrastructure API Calls
+ - deprecated_content: Suspicious Powershell Command-Line Arguments
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - Malicious PowerShell Process - Encoded Command
+ - deprecated_content: Office Application Spawn Regsvr32 process
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Detect API activity from users without MFA
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - AWS Successful Single-Factor Authentication
+ - deprecated_content: Kubernetes Azure detect sensitive object access
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Web Fraud - Password Sharing Across Accounts
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Disabling Net User Account
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows User Disabled Via Net
+ - deprecated_content: GCP Detect accounts with high risk roles by project
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Kubernetes GCP detect service accounts forbidden failure access
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Extended Period Without Successful Netbackup Backups
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Office Product Spawning Rundll32 with no DLL
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Spawned Rundll32 With No DLL
+ - deprecated_content: Okta ThreatInsight Suspected PasswordSpray Attack
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Okta ThreatInsight Threat Detected
+ - deprecated_content: Net Localgroup Discovery
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44
+ / Windows Group Discovery Via Net
+ replacement_content:
+ - Windows Group Discovery Via Net
+ - deprecated_content: Uncommon Processes On Endpoint
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: ''
+ replacement_content:
+ - Attacker Tools On Endpoint
+ - deprecated_content: Dump LSASS via procdump Rename
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Updated to a new detection name
+ replacement_content:
+ - Dump LSASS via procdump
+ - deprecated_content: Okta Two or More Rejected Okta Pushes
+ deprecated_in_version: 5.0.2
+ deprecated_date: '2025-03-07'
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Okta Multiple Failed MFA Requests For User
From 1bda87e60c635147b048d255c66743395d97f6c7 Mon Sep 17 00:00:00 2001
From: pyth0n1c
Date: Tue, 25 Feb 2025 16:46:41 -0800
Subject: [PATCH 10/67] fix format of deprecated file again
---
.../deprecated_detection_mapping_updated.yml | 616 +++++++++---------
1 file changed, 308 insertions(+), 308 deletions(-)
diff --git a/deprecated/deprecated_detection_mapping_updated.yml b/deprecated/deprecated_detection_mapping_updated.yml
index db32b776a2..322dea112d 100644
--- a/deprecated/deprecated_detection_mapping_updated.yml
+++ b/deprecated/deprecated_detection_mapping_updated.yml
@@ -1,69 +1,69 @@
detections:
- deprecated_content: ASL AWS Excessive Security Scanning
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: AWS Cloud Provisioning From Previously Unseen Region
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Provisioning Activity From Previously Unseen Region
- deprecated_content: First time seen command line argument
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Windows connhost exe started forcefully
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Detect Mimikatz Using Loaded Images
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Kubernetes Azure detect sensitive role access
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Web Fraud - Anomalous User Clickspeed
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: EC2 Instance Started With Previously Unseen Instance Type
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Compute Instance Created With Previously Unseen Instance Type
- deprecated_content: EC2 Instance Started With Previously Unseen AMI
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Compute Instance Created With Previously Unseen Image
- deprecated_content: Domain Group Discovery With Net
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content:
- Windows Group Discovery Via Net
- deprecated_content: Kubernetes AWS detect sensitive role access
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Winword Spawning Windows Script Host
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: "The following analytics was deprecated in favour of a more generic approach.
Where instead of creating specific analytic for every potentially suspicious child
of an office product. We group them by threat level.\nThis would ease management
@@ -71,137 +71,137 @@ detections:
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Winword Spawning PowerShell
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Attempted Credential Dump From Registry via Reg exe
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: This analytic had some overlap with another one, hence the deprecation.
It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry
Hive Dump Via CommandLine
replacement_content:
- Windows Sensitive Registry Hive Dump Via CommandLine
- deprecated_content: Detect processes used for System Network Configuration Discovery
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Potential System Network Configuration Discovery Activity
- deprecated_content: Execution of File With Spaces Before Extension
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Updated to a new detection name
replacement_content:
- Execution of File with Multiple Extensions
- deprecated_content: EC2 Instance Started In Previously Unseen Region
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Compute Instance Created In Previously Unused Region
- deprecated_content: Office Document Spawned Child Process To Download
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Spawned Child Process For Download
- deprecated_content: Detect new API calls from user roles
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud API Calls From Previously Unseen User Roles
- deprecated_content: Cmdline Tool Not Executed In CMD Shell
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Cmdline Tool Execution From Non-Shell Process
- deprecated_content: Linux Auditd Find Private Keys
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Linux Auditd Private Keys and Certificate Enumeration
- deprecated_content: Detect AWS API Activities From Unapproved Accounts
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Monitor DNS For Brand Abuse
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Kubernetes GCP detect sensitive object access
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Kubernetes Azure scan fingerprint
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: ASL AWS Password Policy Changes
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: O365 Suspicious Admin Email Forwarding
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- O365 Mailbox Email Forwarding Enabled
- deprecated_content: AWS Cloud Provisioning From Previously Unseen City
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Provisioning Activity From Previously Unseen City
- deprecated_content: Kubernetes AWS detect service accounts forbidden failure access
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Osquery pack - ColdRoot detection
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Windows Modify Registry Reg Restore
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Registry Entries Restored Via Reg
- deprecated_content: Kubernetes GCP detect most active service accounts by pod
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Scheduled tasks used in BadRabbit ransomware
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Updated to a new detection name
replacement_content:
- Scheduled Task Deleted Or Created via CMD
- deprecated_content: Suspicious Rundll32 Rename
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Remote System Discovery with Net
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: "This analytic was focusing on 2 separate and unrelated type of threats
or actions. It was split into other analytics, namely:\r\n\r\nWindows Network
Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277\r\nWindows Sensitive
@@ -209,120 +209,119 @@ detections:
replacement_content:
- Windows Network Share Interaction With Net
- deprecated_content: Remote System Discovery with Net
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content:
- Windows Sensitive Group Discovery With Net
- deprecated_content: DNS Query Requests Resolved by Unauthorized DNS Servers
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Suspicious Changes to File Associations
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: GCP Detect high risk permissions by resource and account
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Office Product Writing cab or inf
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Dropped Cab or Inf File
- deprecated_content: Identify New User Accounts
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Office Product Spawn CMD Process
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Windows DLL Search Order Hijacking Hunt
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Windows DLL Search Order Hijacking Hunt with Sysmon
- deprecated_content: ASL AWS CreateAccessKey
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- ASL AWS Create Access Key
- deprecated_content: Okta ThreatInsight Login Failure with High Unknown users
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Detect Spike in Security Group Activity
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Abnormally High Number Of Cloud Security Group API Calls
- deprecated_content: Office Product Spawning BITSAdmin
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Create local admin accounts using net exe
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Create Local Administrator Account Via Net
- deprecated_content: Abnormally High AWS Instances Terminated by User - MLTK
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Windows Office Product Spawning MSDT
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Spawned MSDT
- deprecated_content: Detect Spike in AWS API Activity
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
- replacement_content:
- - ''
+ replacement_content: []
- deprecated_content: Office Product Spawning Windows Script Host
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Prohibited Software On Endpoint
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content:
- Attacker Tools On Endpoint
- deprecated_content: AWS Cloud Provisioning From Previously Unseen Country
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Provisioning Activity From Previously Unseen Country
- deprecated_content: Detect Critical Alerts from Security Tools
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: As discussed internally, this analytic was too generic for an analyst to
do anything with it. It was deprecated in favor of the more specific approach
provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender
@@ -331,142 +330,142 @@ detections:
replacement_content:
- Microsoft Defender ATP Alerts
- deprecated_content: Detect Critical Alerts from Security Tools
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content:
- Microsoft Defender Incident Alerts
- deprecated_content: Excel Spawning PowerShell
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Office Application Spawn rundll32 process
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Excessive Usage Of Net App
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Excessive Usage Of Net App
- deprecated_content: Elevated Group Discovery With Net
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Sensitive Group Discovery With Net
- deprecated_content: Local Account Discovery with Net
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows User Discovery Via Net
- deprecated_content: Windows Command Shell Fetch Env Variables
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows List ENV Variables Via SET Command From Uncommon Parent
- deprecated_content: Suspicious Email - UBA Anomaly
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Detect web traffic to dynamic domain providers
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Updated to use a different log source
replacement_content:
- Detect hosts connecting to dynamic domain providers
- deprecated_content: Okta Failed SSO Attempts
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Unauthorized Access to Application
- deprecated_content: Kubernetes AWS detect RBAC authorization by account
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Kubernetes Azure detect service accounts forbidden failure access
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Remote Registry Key modifications
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: O365 Suspicious User Email Forwarding
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- O365 Mailbox Email Forwarding Enabled
- deprecated_content: Office Product Spawning MSHTA
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Kubernetes AWS detect most active service accounts by pod
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Correlation by Repository and Risk
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the datamodel
replacement_content:
- Risk Rule for Dev Sec Ops by Repository
- deprecated_content: Kubernetes Azure detect RBAC authorization by account
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Clients Connecting to Multiple DNS Servers
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Excessive Service Stop Attempt
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Excessive Service Stop Attempt
- deprecated_content: Multiple Okta Users With Invalid Credentials From The Same IP
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Multiple Users Failing To Authenticate From Ip
- deprecated_content: Suspicious writes to System Volume Information
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Detect new user AWS Console Login
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Detect AWS Console Login by New User
- deprecated_content: Domain Account Discovery With Net App
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: "This analytic was a TTP that looked only for commands that tries to query
info about the users via net user /do. This had a couple of issues, such as triggering
on creation of users via the /add flag etc..\nIt was deprecated in favor of a
@@ -474,193 +473,192 @@ detections:
replacement_content:
- Windows User Discovery Via Net
- deprecated_content: Detection of DNS Tunnels
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Detect DNS requests to Phishing Sites leveraging EvilGinx2
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Office Document Creating Schedule Task
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Loading Taskschd DLL
- deprecated_content: Okta Account Locked Out
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Multiple Accounts Locked Out
- deprecated_content: Unsuccessful Netbackup backups
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Detect Mimikatz Via PowerShell And EventCode 4703
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Updated to a new detection name
replacement_content:
- Detect Mimikatz With PowerShell Script Block Logging
- deprecated_content: Winword Spawning Cmd
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: GCP Kubernetes cluster scan detection
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Kubernetes Scanning by Unauthenticated IP Address
- deprecated_content: Kubernetes GCP detect suspicious kubectl calls
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: gcp detect oauth token abuse
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Correlation by User and Risk
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the datamodel
replacement_content:
- Risk Rule for Dev Sec Ops by Repository
- deprecated_content: Processes created by netsh
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Updated to a new detection name
replacement_content:
- Processes launching netsh
- deprecated_content: Office Product Spawning Wmic
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Extraction of Registry Hives
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Sensitive Registry Hive Dump Via CommandLine
- deprecated_content: Attempt To Stop Security Service
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Attempt To Stop Security Service
- deprecated_content: Windows MSIExec With Network Connections
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows HTTP Network Communication From MSIExec
- deprecated_content: Windows Query Registry Reg Save
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Registry Entries Exported Via Reg
- deprecated_content: Cloud Network Access Control List Deleted
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- AWS Network Access Control List Deleted
- deprecated_content: O365 Suspicious Rights Delegation
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- O365 Elevated Mailbox Permission Assigned
- deprecated_content: Abnormally High AWS Instances Launched by User - MLTK
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Reg exe used to hide files directories via registry keys
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Detect Long DNS TXT Record Response
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Password Policy Discovery with Net
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Password Policy Discovery with Net
- deprecated_content: AWS Cloud Provisioning From Previously Unseen IP Address
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Provisioning Activity From Previously Unseen IP Address
- deprecated_content: Network Connection Discovery With Net
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Network Connection Discovery Via Net
- deprecated_content: Kubernetes Azure detect suspicious kubectl calls
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Kubernetes GCP detect sensitive role access
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Detect Webshell Exploit Behavior
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Suspicious Child Process Spawned From WebServer
- deprecated_content: DNS record changed
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Unsigned Image Loaded by LSASS
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
- replacement_content:
- - ''
+ replacement_content: []
- deprecated_content: Detect USB device insertion
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Windows Network Share Interaction With Net
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Network Share Interaction Via Net
- deprecated_content: Account Discovery With Net App
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: This analytic was a TTP that focused on unrelated things and called account
discovery. Since there were other detection that overlapped with it. I choose
to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122
@@ -668,235 +666,237 @@ detections:
replacement_content:
- Windows Excessive Usage Of Net App
- deprecated_content: Change Default File Association
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows New Default File Association Value Set
- deprecated_content: Windows Lateral Tool Transfer RemCom
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Updated to a new detection name
replacement_content:
- Windows Service Execution RemCom
- deprecated_content: Office Document Executing Macro Code
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Loading VBE7 DLL
- deprecated_content: Okta Account Lockout Events
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Multiple Accounts Locked Out
- deprecated_content: Abnormally High AWS Instances Launched by User
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Abnormally High Number Of Cloud Instances Launched
- deprecated_content: EC2 Instance Modified With Previously Unseen User
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud API Calls From Previously Unseen User Roles
- deprecated_content: Windows Valid Account With Never Expires Password
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Set Account Password Policy To Unlimited Via Net
- deprecated_content: Windows hosts file modification
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: MSHTML Module Load in Office Product
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Loaded MSHTML Module
- deprecated_content: Abnormally High AWS Instances Terminated by User
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Abnormally High Number Of Cloud Instances Destroyed
- deprecated_content: Web Fraud - Account Harvesting
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Office Spawning Control
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Spawned Control
- deprecated_content: Detect Activity Related to Pass the Hash Attacks
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Deleting Of Net Users
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows User Deletion Via Net
- deprecated_content: Suspicious File Write
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
- replacement_content:
- - ''
+ replacement_content: []
- deprecated_content: AWS EKS Kubernetes cluster sensitive object access
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Kubernetes Abuse of Secret by Unusual Location
- deprecated_content: Spectre and Meltdown Vulnerable Systems
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: EC2 Instance Started With Previously Unseen User
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Compute Instance Created By Previously Unseen User
- deprecated_content: Office Product Spawning CertUtil
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Kubernetes GCP detect RBAC authorizations by account
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Office Application Drop Executable
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Dropped Uncommon File
- deprecated_content: Kubernetes Azure active service accounts by pod namespace
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Kubernetes Azure pod scan fingerprint
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Detect Spike in Network ACL Activity
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Abnormally High Number Of Cloud Infrastructure API Calls
- deprecated_content: Suspicious Powershell Command-Line Arguments
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content:
- Malicious PowerShell Process - Encoded Command
- deprecated_content: Office Application Spawn Regsvr32 process
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Detect API activity from users without MFA
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- AWS Successful Single-Factor Authentication
- deprecated_content: Kubernetes Azure detect sensitive object access
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Web Fraud - Password Sharing Across Accounts
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Disabling Net User Account
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows User Disabled Via Net
- deprecated_content: GCP Detect accounts with high risk roles by project
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Kubernetes GCP detect service accounts forbidden failure access
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Extended Period Without Successful Netbackup Backups
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content: []
- deprecated_content: Office Product Spawning Rundll32 with no DLL
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Spawned Rundll32 With No DLL
- deprecated_content: Okta ThreatInsight Suspected PasswordSpray Attack
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta ThreatInsight Threat Detected
- deprecated_content: Net Localgroup Discovery
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44
/ Windows Group Discovery Via Net
replacement_content:
- Windows Group Discovery Via Net
- deprecated_content: Uncommon Processes On Endpoint
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: ''
replacement_content:
- Attacker Tools On Endpoint
- deprecated_content: Dump LSASS via procdump Rename
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Updated to a new detection name
replacement_content:
- Dump LSASS via procdump
- deprecated_content: Okta Two or More Rejected Okta Pushes
- deprecated_in_version: 5.0.2
- deprecated_date: '2025-03-07'
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Multiple Failed MFA Requests For User
+baselines: []
+investigations: []
+stories: []
\ No newline at end of file
From 60b9b728c57cdd2f5ad3a14cca9e9d7e62de5e2e Mon Sep 17 00:00:00 2001
From: pyth0n1c
Date: Tue, 25 Feb 2025 16:54:49 -0800
Subject: [PATCH 11/67] fix file names
---
deprecated/deprecated_detection_mapping.yml | 2162 +++++++----------
.../deprecated_detection_mapping_updated.yml | 902 -------
2 files changed, 902 insertions(+), 2162 deletions(-)
delete mode 100644 deprecated/deprecated_detection_mapping_updated.yml
diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml
index ca0e64dcb3..322dea112d 100644
--- a/deprecated/deprecated_detection_mapping.yml
+++ b/deprecated/deprecated_detection_mapping.yml
@@ -1,1260 +1,902 @@
-- deprecated_name: ASL AWS Excessive Security Scanning
- deprecated_id: ff2bfdbc-65b7-4434-8f08-d55761d1d446
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: AWS Cloud Provisioning From Previously Unseen Region
- deprecated_id: 7971d3df-da82-4648-a6e5-b5637bea5253
- replacement_name: Cloud Provisioning Activity From Previously Unseen Region
- replacement_id: 5aba1860-9617-4af9-b19d-aecac16fe4f2
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: First time seen command line argument
- deprecated_id: a1b6e73f-98d5-470f-99ac-77aacd578473
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Windows connhost exe started forcefully
- deprecated_id: c114aaca-68ee-41c2-ad8c-32bf21db8769
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Detect Mimikatz Using Loaded Images
- deprecated_id: 29e307ba-40af-4ab2-91b2-3c6b392bbba0
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Kubernetes Azure detect sensitive role access
- deprecated_id: f27349e5-1641-4f6a-9e68-30402be0ad4c
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Web Fraud - Anomalous User Clickspeed
- deprecated_id: 31337bbb-bc22-4752-b599-ef192df2dc7a
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: EC2 Instance Started With Previously Unseen Instance Type
- deprecated_id: 65541c80-03c7-4e05-83c8-1dcd57a2e1ad
- replacement_name: Cloud Compute Instance Created With Previously Unseen Instance
- Type
- replacement_id: c6ddbf53-9715-49f3-bb4c-fb2e8a309cda
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: EC2 Instance Started With Previously Unseen AMI
- deprecated_id: 347ec301-601b-48b9-81aa-9ddf9c829dd3
- replacement_name: Cloud Compute Instance Created With Previously Unseen Image
- replacement_id: bc24922d-987c-4645-b288-f8c73ec194c4
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Domain Group Discovery With Net
- deprecated_id: f2f14ac7-fa81-471a-80d5-7eb65c3c7349
- replacement_name: Windows Group Discovery Via Net
- replacement_id: c5c8e0f3-147a-43da-bf04-4cfaec27dc44
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Kubernetes AWS detect sensitive role access
- deprecated_id: b6013a7b-85e0-4a45-b051-10b252d69569
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Winword Spawning Windows Script Host
- deprecated_id: 637e1b5c-9be1-11eb-9c32-acde48001122
- replacement_name: Windows Office Product Spawned Uncommon Process
- replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: 'The following analytics was deprecated in favour of a more generic approach.
- Where instead of creating specific analytic for every potentially suspicious child
- of an office product. We group them by threat level.
-
- This would ease management and false positives tuning.'
-- deprecated_name: Winword Spawning PowerShell
- deprecated_id: b2c950b8-9be2-11eb-8658-acde48001122
- replacement_name: Windows Office Product Spawned Uncommon Process
- replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Attempted Credential Dump From Registry via Reg exe
- deprecated_id: e9fb4a59-c5fb-440a-9f24-191fbc6b2911
- replacement_name: Windows Sensitive Registry Hive Dump Via CommandLine
- replacement_id: 8bbb7d58-b360-11eb-ba21-acde48001122
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: This analytic had some overlap with another one, hence the deprecation.
- It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry
- Hive Dump Via CommandLine
-- deprecated_name: Detect processes used for System Network Configuration Discovery
- deprecated_id: a51bfe1a-94f0-48cc-b1e4-16ae10145893
- replacement_name: Potential System Network Configuration Discovery Activity
- replacement_id: 3f0b95e3-3195-46ac-bea3-84fb59e7fac5
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Execution of File With Spaces Before Extension
- deprecated_id: ab0353e6-a956-420b-b724-a8b4846d5d5a
- replacement_name: Execution of File with Multiple Extensions
- replacement_id: b06a555e-dce0-417d-a2eb-28a5d8d66ef7
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Updated to a new detection name
-- deprecated_name: EC2 Instance Started In Previously Unseen Region
- deprecated_id: ada0f478-84a8-4641-a3f3-d82362d6fd75
- replacement_name: Cloud Compute Instance Created In Previously Unused Region
- replacement_id: fa4089e2-50e3-40f7-8469-d2cc1564ca59
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Office Document Spawned Child Process To Download
- deprecated_id: 6fed27d2-9ec7-11eb-8fe4-aa665a019aa3
- replacement_name: Windows Office Product Spawned Child Process For Download
- replacement_id: f02b64b8-cbea-4f75-bf77-7a05111566b1
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Detect new API calls from user roles
- deprecated_id: 22773e84-bac0-4595-b086-20d3f335b4f1
- replacement_name: Cloud API Calls From Previously Unseen User Roles
- replacement_id: 2181ad1f-1e73-4d0c-9780-e8880482a08f
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Cmdline Tool Not Executed In CMD Shell
- deprecated_id: 6c3f7dd8-153c-11ec-ac2d-acde48001122
- replacement_name: Windows Cmdline Tool Execution From Non-Shell Process
- replacement_id: 2afa393f-b88d-41b7-9793-623c93a2dfde
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Linux Auditd Find Private Keys
- deprecated_id: 80bb9988-190b-4ee0-a3c3-509545a8f678
- replacement_name: Linux Auditd Private Keys and Certificate Enumeration
- replacement_id: 892eb674-3344-4143-8e52-4775b1daf3f1
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Detect AWS API Activities From Unapproved Accounts
- deprecated_id: ada0f478-84a8-4641-a3f1-d82362d4bd55
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Monitor DNS For Brand Abuse
- deprecated_id: 24dd17b1-e2fb-4c31-878c-d4f746595bfa
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Kubernetes GCP detect sensitive object access
- deprecated_id: bdb6d596-86a0-4aba-8369-418ae8b9963a
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Kubernetes Azure scan fingerprint
- deprecated_id: c5e5bd5c-1013-4841-8b23-e7b3253c840a
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: ASL AWS Password Policy Changes
- deprecated_id: 5ade5937-11a2-4363-ba6b-39a3ee8d5b1a
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: O365 Suspicious Admin Email Forwarding
- deprecated_id: 7f398cfb-918d-41f4-8db8-2e2474e02c28
- replacement_name: O365 Mailbox Email Forwarding Enabled
- replacement_id: 0b6bc75c-05d1-4101-9fc3-97e706168f24
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: AWS Cloud Provisioning From Previously Unseen City
- deprecated_id: 344a1778-0b25-490c-adb1-de8beddf59cd
- replacement_name: Cloud Provisioning Activity From Previously Unseen City
- replacement_id: e7ecc5e0-88df-48b9-91af-51104c68f02f
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Kubernetes AWS detect service accounts forbidden failure access
- deprecated_id: a6959c57-fa8f-4277-bb86-7c32fba579d5
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Osquery pack - ColdRoot detection
- deprecated_id: a6fffe5e-05c3-4c04-badc-887607fbb8dc
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Windows Modify Registry Reg Restore
- deprecated_id: d0072bd2-6d73-4c1b-bc77-ded6d2da3a4e
- replacement_name: Windows Registry Entries Restored Via Reg
- replacement_id: a17af481-e2ad-494c-9da6-afb4d243a019
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Kubernetes GCP detect most active service accounts by pod
- deprecated_id: 7f5c2779-88a0-4824-9caa-0f606c8f260f
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Scheduled tasks used in BadRabbit ransomware
- deprecated_id: 1297fb80-f42a-4b4a-9c8b-78c066437cf6
- replacement_name: Scheduled Task Deleted Or Created via CMD
- replacement_id: d5af132c-7c17-439c-9d31-13d55340f36c
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Updated to a new detection name
-- deprecated_name: Suspicious Rundll32 Rename
- deprecated_id: 7360137f-abad-473e-8189-acbdaa34d114
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Remote System Discovery with Net
- deprecated_id: 9df16706-04a2-41e2-bbfe-9b38b34409d3
- replacement_name: Windows Network Share Interaction With Net
- replacement_id: 4dc3951f-b3f8-4f46-b412-76a483f72277
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: "This analytic was focusing on 2 separate and unrelated type of threats\
- \ or actions. It was split into other analytics, namely:\r\n\r\nWindows Network\
- \ Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277\r\nWindows\
- \ Sensitive Group Discovery With Net / a23a0e20-0b1b-4a07-82e5-ec5f70811e7a"
-- deprecated_name: Remote System Discovery with Net
- deprecated_id: 9df16706-04a2-41e2-bbfe-9b38b34409d3
- replacement_name: Windows Sensitive Group Discovery With Net
- replacement_id: a23a0e20-0b1b-4a07-82e5-ec5f70811e7a
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: DNS Query Requests Resolved by Unauthorized DNS Servers
- deprecated_id: 1a67f15a-f4ff-4170-84e9-08cf6f75d6f6
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Suspicious Changes to File Associations
- deprecated_id: 1b989a0e-0129-4446-a695-f193a5b746fc
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: GCP Detect high risk permissions by resource and account
- deprecated_id: 2e70ef35-2187-431f-aedc-4503dc9b06ba
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Office Product Writing cab or inf
- deprecated_id: f48cd1d4-125a-11ec-a447-acde48001122
- replacement_name: Windows Office Product Dropped Cab or Inf File
- replacement_id: dbdd251e-dd45-4ec9-a555-f5e151391746
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Identify New User Accounts
- deprecated_id: 475b9e27-17e4-46e2-b7e2-648221be3b89
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Office Product Spawn CMD Process
- deprecated_id: b8b19420-e892-11eb-9244-acde48001122
- replacement_name: Windows Office Product Spawned Uncommon Process
- replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Windows DLL Search Order Hijacking Hunt
- deprecated_id: 79c7d0fc-60c7-41be-a616-ccda752efe89
- replacement_name: Windows DLL Search Order Hijacking Hunt with Sysmon
- replacement_id: 79c7d1fc-64c7-91be-a616-ccda752efe81
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: ASL AWS CreateAccessKey
- deprecated_id: ccb3e4af-23d6-407f-9842-a26212816c9e
- replacement_name: ASL AWS Create Access Key
- replacement_id: 81a9f2fe-1697-473c-af1d-086b0d8b63c8
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Okta ThreatInsight Login Failure with High Unknown users
- deprecated_id: 632663b0-4562-4aad-abe9-9f621a049738
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Detect Spike in Security Group Activity
- deprecated_id: ada0f478-84a8-4641-a3f1-e32372d4bd53
- replacement_name: Abnormally High Number Of Cloud Security Group API Calls
- replacement_id: d4dfb7f3-7a37-498a-b5df-f19334e871af
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Office Product Spawning BITSAdmin
- deprecated_id: e8c591f4-a6d7-11eb-8cf7-acde48001122
- replacement_name: Windows Office Product Spawned Uncommon Process
- replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Create local admin accounts using net exe
- deprecated_id: b89919ed-fe5f-492c-b139-151bb162040e
- replacement_name: Windows Create Local Administrator Account Via Net
- replacement_id: 2c568c34-bb57-4b43-9d75-19c605b98e70
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Abnormally High AWS Instances Terminated by User - MLTK
- deprecated_id: 1c02b86a-cd85-473e-a50b-014a9ac8fe3e
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Windows Office Product Spawning MSDT
- deprecated_id: 127eba64-c981-40bf-8589-1830638864a7
- replacement_name: Windows Office Product Spawned MSDT
- replacement_id: a3148fad-3734-4b7f-9a71-62f08d39fab1
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Detect Spike in AWS API Activity
- deprecated_id: ada0f478-84a8-4641-a3f1-d32362d4bd55
- replacement_name: ''
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Office Product Spawning Windows Script Host
- deprecated_id: b3628a5b-8d02-42fa-a891-eebf2351cbe1
- replacement_name: Windows Office Product Spawned Uncommon Process
- replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Prohibited Software On Endpoint
- deprecated_id: a51bfe1a-94f0-48cc-b4e4-b6ae50145893
- replacement_name: Attacker Tools On Endpoint
- replacement_id: a51bfe1a-94f0-48cc-b4e4-16a110145893
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: AWS Cloud Provisioning From Previously Unseen Country
- deprecated_id: ceb8d3d8-06cb-49eb-beaf-829526e33ff0
- replacement_name: Cloud Provisioning Activity From Previously Unseen Country
- replacement_id: 94994255-3acf-4213-9b3f-0494df03bb31
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Detect Critical Alerts from Security Tools
- deprecated_id: 483e8a68-f2f7-45be-8fc9-bf725f0e22fd
- replacement_name: Microsoft Defender ATP Alerts
- replacement_id: 38f034ed-1598-46c8-95e8-14edf05fdf5d
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: As discussed internally, this analytic was too generic for an analyst to
- do anything with it. It was deprecated in favor of the more specific approach
- provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender
- Incident Alerts. Going forward analytics from leveraging alerts from vendors will
- have their specific analytics.
-- deprecated_name: Detect Critical Alerts from Security Tools
- deprecated_id: 483e8a68-f2f7-45be-8fc9-bf725f0e22fd
- replacement_name: Microsoft Defender Incident Alerts
- replacement_id: 13435b55-afd8-46d4-9045-7d5457f430a5
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Excel Spawning PowerShell
- deprecated_id: 42d40a22-9be3-11eb-8f08-acde48001122
- replacement_name: Windows Office Product Spawned Uncommon Process
- replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Office Application Spawn rundll32 process
- deprecated_id: 958751e4-9c5f-11eb-b103-acde48001122
- replacement_name: Windows Office Product Spawned Uncommon Process
- replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Excessive Usage Of Net App
- deprecated_id: 45e52536-ae42-11eb-b5c6-acde48001122
- replacement_name: Windows Excessive Usage Of Net App
- replacement_id: 355ba810-0a20-4215-8485-9ce3f87f2e38
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Elevated Group Discovery With Net
- deprecated_id: a23a0e20-0b1b-4a07-82e5-ec5f70811e7a
- replacement_name: Windows Sensitive Group Discovery With Net
- replacement_id: d9eb7cda-5622-4722-bc88-7f2442f4b5af
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Local Account Discovery with Net
- deprecated_id: 5d0d4830-0133-11ec-bae3-acde48001122
- replacement_name: Windows User Discovery Via Net
- replacement_id: 7742987e-88c1-476b-a626-a869e088ab72
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Windows Command Shell Fetch Env Variables
- deprecated_id: 048839e4-1eaa-43ff-8a22-86d17f6fcc13
- replacement_name: Windows List ENV Variables Via SET Command From Uncommon Parent
- replacement_id: aec157f4-8783-4584-aca6-754c4dc7fba9
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Suspicious Email - UBA Anomaly
- deprecated_id: 56e877a6-1455-4479-ad16-0550dc1e33f8
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Detect web traffic to dynamic domain providers
- deprecated_id: 134da869-e264-4a8f-8d7e-fcd01c18f301
- replacement_name: Detect hosts connecting to dynamic domain providers
- replacement_id: a1e761ac-1344-4dbd-88b2-3f34c912d359
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Updated to use a different log source
-- deprecated_name: Okta Failed SSO Attempts
- deprecated_id: 371a6545-2618-4032-ad84-93386b8698c5
- replacement_name: Okta Unauthorized Access to Application
- replacement_id: 5f661629-9750-4cb9-897c-1f05d6db8727
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Kubernetes AWS detect RBAC authorization by account
- deprecated_id: de7264ed-3ed9-4fef-bb01-6eefc87cefe8
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Kubernetes Azure detect service accounts forbidden failure access
- deprecated_id: 019690d7-420f-4da0-b320-f27b09961514
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Remote Registry Key modifications
- deprecated_id: c9f4b923-f8af-4155-b697-1354f5dcbc5e
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: O365 Suspicious User Email Forwarding
- deprecated_id: f8dfe015-dbb3-4569-ba75-b13787e06aa4
- replacement_name: O365 Mailbox Email Forwarding Enabled
- replacement_id: 0b6bc75c-05d1-4101-9fc3-97e706168f24
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Office Product Spawning MSHTA
- deprecated_id: 6078fa20-a6d2-11eb-b662-acde48001122
- replacement_name: Windows Office Product Spawned Uncommon Process
- replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Kubernetes AWS detect most active service accounts by pod
- deprecated_id: 5b30b25d-7d32-42d8-95ca-64dfcd9076e6
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Correlation by Repository and Risk
- deprecated_id: 8da9fdd9-6a1b-4ae0-8a34-8c25e6be9687
- replacement_name: Risk Rule for Dev Sec Ops by Repository
- replacement_id: 161bc0ca-4651-4c13-9c27-27770660cf67
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the datamodel
-- deprecated_name: Kubernetes Azure detect RBAC authorization by account
- deprecated_id: 47af7d20-0607-4079-97d7-7a29af58b54e
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Clients Connecting to Multiple DNS Servers
- deprecated_id: 74ec6f18-604b-4202-a567-86b2066be3ce
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Excessive Service Stop Attempt
- deprecated_id: ae8d3f4a-acd7-11eb-8846-acde48001122
- replacement_name: Windows Excessive Service Stop Attempt
- replacement_id: 8f3a614f-6b98-4f7d-82dd-d0df38452a8b
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Multiple Okta Users With Invalid Credentials From The Same IP
- deprecated_id: 19cba45f-cad3-4032-8911-0c09e0444552
- replacement_name: Okta Multiple Users Failing To Authenticate From Ip
- replacement_id: de365ffa-42f5-46b5-b43f-fa72290b8218
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Suspicious writes to System Volume Information
- deprecated_id: cd6297cd-2bdd-4aa1-84aa-5d2f84228fac
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Detect new user AWS Console Login
- deprecated_id: ada0f478-84a8-4641-a3f3-d82362dffd75
- replacement_name: Detect AWS Console Login by New User
- replacement_id: bc91a8cd-35e7-4bb2-6140-e756cc46fd71
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Domain Account Discovery With Net App
- deprecated_id: 98f6a534-04c2-11ec-96b2-acde48001122
- replacement_name: Windows User Discovery Via Net
- replacement_id: 5d0d4830-0133-11ec-bae3-acde48001122
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: 'This analytic was a TTP that looked only for commands that tries to query
- info about the users via net user /do. This had a couple of issues, such as triggering
- on creation of users via the /add flag etc..
-
- It was deprecated in favor of a more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122'
-- deprecated_name: Detection of DNS Tunnels
- deprecated_id: 104658f4-afdc-499f-9719-17a43f9826f4
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Detect DNS requests to Phishing Sites leveraging EvilGinx2
- deprecated_id: 24dd17b1-e2fb-4c31-878c-d4f226595bfa
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Office Document Creating Schedule Task
- deprecated_id: cc8b7b74-9d0f-11eb-8342-acde48001122
- replacement_name: Windows Office Product Loading Taskschd DLL
- replacement_id: d7297cfa-1f04-4714-bfbe-3679e0666959
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Okta Account Locked Out
- deprecated_id: d650c0ae-bdc5-400e-9f0f-f7aa0a010ef1
- replacement_name: Okta Multiple Accounts Locked Out
- replacement_id: a511426e-184f-4de6-8711-cfd2af29d1e1
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Unsuccessful Netbackup backups
- deprecated_id: a34aae96-ccf8-4aaa-952c-3ea21444444f
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Detect Mimikatz Via PowerShell And EventCode 4703
- deprecated_id: 98917be2-bfc8-475a-8618-a9bb06575188
- replacement_name: Detect Mimikatz With PowerShell Script Block Logging
- replacement_id: 8148c29c-c952-11eb-9255-acde48001122
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Updated to a new detection name
-- deprecated_name: Winword Spawning Cmd
- deprecated_id: 6fcbaedc-a37b-11eb-956b-acde48001122
- replacement_name: Windows Office Product Spawned Uncommon Process
- replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: GCP Kubernetes cluster scan detection
- deprecated_id: db5957ec-0144-4c56-b512-9dccbe7a2d26
- replacement_name: Kubernetes Scanning by Unauthenticated IP Address
- replacement_id: f9cadf4e-df22-4f4e-a08f-9d3344c2165d
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Kubernetes GCP detect suspicious kubectl calls
- deprecated_id: a5bed417-070a-41f2-a1e4-82b6aa281557
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: gcp detect oauth token abuse
- deprecated_id: a7e9f7bb-8901-4ad0-8d88-0a4ab07b1972
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Correlation by User and Risk
- deprecated_id: 610e12dc-b6fa-4541-825e-4a0b3b6f6773
- replacement_name: Risk Rule for Dev Sec Ops by Repository
- replacement_id: 161bc0ca-4651-4c13-9c27-27770660cf67
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the datamodel
-- deprecated_name: Processes created by netsh
- deprecated_id: b89919ed-fe5f-492c-b139-95dbb162041e
- replacement_name: Processes launching netsh
- replacement_id: b89919ed-fe5f-492c-b139-95dbb162040e
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Updated to a new detection name
-- deprecated_name: Office Product Spawning Wmic
- deprecated_id: ffc236d6-a6c9-11eb-95f1-acde48001122
- replacement_name: Windows Office Product Spawned Uncommon Process
- replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Extraction of Registry Hives
- deprecated_id: 8bbb7d58-b360-11eb-ba21-acde48001122
- replacement_name: Windows Sensitive Registry Hive Dump Via CommandLine
- replacement_id: 5aaff29d-0cce-405b-9ee8-5d06b49d045e
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Attempt To Stop Security Service
- deprecated_id: c8e349c6-b97c-486e-8949-bd7bcd1f3910
- replacement_name: Windows Attempt To Stop Security Service
- replacement_id: 9ed27cea-4e27-4eff-b2c6-aac9e78a7517
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Windows MSIExec With Network Connections
- deprecated_id: 827409a1-5393-4d8d-8da4-bbb297c262a7
- replacement_name: Windows HTTP Network Communication From MSIExec
- replacement_id: b0fd38c7-f71a-43a2-870e-f3ca06bcdd99
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Windows Query Registry Reg Save
- deprecated_id: cbee60c1-b776-456f-83c2-faa56bdbe6c6
- replacement_name: Windows Registry Entries Exported Via Reg
- replacement_id: 466379bc-0f47-476c-8202-16ef38112e0d
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Cloud Network Access Control List Deleted
- deprecated_id: 021abc51-1862-41dd-ad43-43c739c0a983
- replacement_name: AWS Network Access Control List Deleted
- replacement_id: ada0f478-84a8-4641-a3f1-d82362d6fd75
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: O365 Suspicious Rights Delegation
- deprecated_id: b25d2973-303e-47c8-bacd-52b61604c6a7
- replacement_name: O365 Elevated Mailbox Permission Assigned
- replacement_id: 2246c142-a678-45f8-8546-aaed7e0efd30
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Abnormally High AWS Instances Launched by User - MLTK
- deprecated_id: dec41ad5-d579-42cb-b4c6-f5dbb778bbe5
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Reg exe used to hide files directories via registry keys
- deprecated_id: 61a7d1e6-f5d4-41d9-a9be-39a1ffe69459
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Detect Long DNS TXT Record Response
- deprecated_id: 05437c07-62f5-452e-afdc-04dd44815bb9
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Password Policy Discovery with Net
- deprecated_id: 09336538-065a-11ec-8665-acde48001122
- replacement_name: Windows Password Policy Discovery with Net
- replacement_id: e52f7865-be78-46bf-b7ed-150fbe447613
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: AWS Cloud Provisioning From Previously Unseen IP Address
- deprecated_id: 42e15012-ac14-4801-94f4-f1acbe64880b
- replacement_name: Cloud Provisioning Activity From Previously Unseen IP Address
- replacement_id: f86a8ec9-b042-45eb-92f4-e9ed1d781078
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Network Connection Discovery With Net
- deprecated_id: 640337e5-6e41-4b7f-af06-9d9eab5e1e2d
- replacement_name: Windows Network Connection Discovery Via Net
- replacement_id: 86a5b949-679b-4197-8d4c-9c180a818c45
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Kubernetes Azure detect suspicious kubectl calls
- deprecated_id: 4b6d1ba8-0000-4cec-87e6-6cbbd71651b5
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Kubernetes GCP detect sensitive role access
- deprecated_id: a46923f6-36b9-4806-a681-31f314907c30
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Detect Webshell Exploit Behavior
- deprecated_id: 22597426-6dbd-49bd-bcdc-4ec19857192f
- replacement_name: Windows Suspicious Child Process Spawned From WebServer
- replacement_id: 2d4470ef-7158-4b47-b68b-1f7f16382156
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: DNS record changed
- deprecated_id: 44d3a43e-dcd5-49f7-8356-5209bb369065
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Unsigned Image Loaded by LSASS
- deprecated_id: 56ef054c-76ef-45f9-af4a-a634695dcd65
- replacement_name: ''
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Detect USB device insertion
- deprecated_id: 104658f4-afdc-499f-9719-17a43f9826f5
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Windows Network Share Interaction With Net
- deprecated_id: 4dc3951f-b3f8-4f46-b412-76a483f72277
- replacement_name: Windows Network Share Interaction Via Net
- replacement_id: e51fbdb0-0be0-474f-92ea-d289f71a695e
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Account Discovery With Net App
- deprecated_id: 339805ce-ac30-11eb-b87d-acde48001122
- replacement_name: Windows Excessive Usage Of Net App
- replacement_id: 45e52536-ae42-11eb-b5c6-acde48001122
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: This analytic was a TTP that focused on unrelated things and called account
- discovery. Since there were other detection that overlapped with it. I choose
- to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122
- / Windows Excessive Usage Of Net App.
-- deprecated_name: Change Default File Association
- deprecated_id: 462d17d8-1f71-11ec-ad07-acde48001122
- replacement_name: Windows New Default File Association Value Set
- replacement_id: 7d1f031f-f1c9-43be-8b0b-c4e3e8a8928a
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Windows Lateral Tool Transfer RemCom
- deprecated_id: e373a840-5bdc-47ef-b2fd-9cc7aaf387f0
- replacement_name: Windows Service Execution RemCom
- replacement_id: 7e3d68db-ea4d-419b-adbd-e14a525ecf09
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Updated to a new detection name
-- deprecated_name: Office Document Executing Macro Code
- deprecated_id: b12c89bc-9d06-11eb-a592-acde48001122
- replacement_name: Windows Office Product Loading VBE7 DLL
- replacement_id: 7cfec906-2697-43f7-898b-83634a051d9a
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Okta Account Lockout Events
- deprecated_id: 62b70968-a0a5-4724-8ac4-67871e6f544d
- replacement_name: Okta Multiple Accounts Locked Out
- replacement_id: a511426e-184f-4de6-8711-cfd2af29d1e1
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Abnormally High AWS Instances Launched by User
- deprecated_id: 2a9b80d3-6340-4345-b5ad-290bf5d0dac4
- replacement_name: Abnormally High Number Of Cloud Instances Launched
- replacement_id: f2361e9f-3928-496c-a556-120cd4223a65
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: EC2 Instance Modified With Previously Unseen User
- deprecated_id: 56f91724-cf3f-4666-84e1-e3712fb41e76
- replacement_name: Cloud API Calls From Previously Unseen User Roles
- replacement_id: 2181ad1f-1e73-4d0c-9780-e8880482a08f
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Windows Valid Account With Never Expires Password
- deprecated_id: 73a931db-1830-48b3-8296-cd9cfa09c3c8
- replacement_name: Windows Set Account Password Policy To Unlimited Via Net
- replacement_id: 11f93009-8083-43fd-82a7-821fcbdc8342
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Windows hosts file modification
- deprecated_id: 06a6fc63-a72d-41dc-8736-7e3dd9612116
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: MSHTML Module Load in Office Product
- deprecated_id: 5f1c168e-118b-11ec-84ff-acde48001122
- replacement_name: Windows Office Product Loaded MSHTML Module
- replacement_id: 4cc015c9-687c-40d2-adcc-46350f66e10c
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Abnormally High AWS Instances Terminated by User
- deprecated_id: 8d301246-fccf-45e2-a8e7-3655fd14379c
- replacement_name: Abnormally High Number Of Cloud Instances Destroyed
- replacement_id: ef629fc9-1583-4590-b62a-f2247fbf7bbf
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Web Fraud - Account Harvesting
- deprecated_id: bf1d7b5c-df2f-4249-a401-c09fdc221ddf
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Office Spawning Control
- deprecated_id: 053e027c-10c7-11ec-8437-acde48001122
- replacement_name: Windows Office Product Spawned Control
- replacement_id: 081c485d-ac8d-4bee-ad4c-525772fead4d
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Detect Activity Related to Pass the Hash Attacks
- deprecated_id: f5939373-8054-40ad-8c64-cec478a22a4b
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Deleting Of Net Users
- deprecated_id: 1c8c6f66-acce-11eb-aafb-acde48001122
- replacement_name: Windows User Deletion Via Net
- replacement_id: b0b6fd2c-8953-4d1b-8f7b-56075ea6ab3e
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Suspicious File Write
- deprecated_id: 57f76b8a-32f0-42ed-b358-d9fa3ca7bac8
- replacement_name: ''
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: AWS EKS Kubernetes cluster sensitive object access
- deprecated_id: 7f227943-2196-4d4d-8d6a-ac8cb308e61c
- replacement_name: Kubernetes Abuse of Secret by Unusual Location
- replacement_id: 40a064c1-4ec1-4381-9e35-61192ba8ef82
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Spectre and Meltdown Vulnerable Systems
- deprecated_id: 354be8e0-32cd-4da0-8c47-796de13b60ea
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: EC2 Instance Started With Previously Unseen User
- deprecated_id: 22773e84-bac0-4595-b086-20d3f735b4f1
- replacement_name: Cloud Compute Instance Created By Previously Unseen User
- replacement_id: 37a0ec8d-827e-4d6d-8025-cedf31f3a149
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Office Product Spawning CertUtil
- deprecated_id: 6925fe72-a6d5-11eb-9e17-acde48001122
- replacement_name: Windows Office Product Spawned Uncommon Process
- replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Kubernetes GCP detect RBAC authorizations by account
- deprecated_id: 99487de3-7192-4b41-939d-fbe9acfb1340
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Office Application Drop Executable
- deprecated_id: 73ce70c4-146d-11ec-9184-acde48001122
- replacement_name: Windows Office Product Dropped Uncommon File
- replacement_id: 7ac0fced-9eae-4381-a748-90dcd1aa9393
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Kubernetes Azure active service accounts by pod namespace
- deprecated_id: 55a2264a-b7f0-45e5-addd-1e5ab3415c72
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Kubernetes Azure pod scan fingerprint
- deprecated_id: 86aad3e0-732f-4f66-bbbc-70df448e461d
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Detect Spike in Network ACL Activity
- deprecated_id: ada0f478-84a8-4641-a1f1-e32372d4bd53
- replacement_name: Abnormally High Number Of Cloud Infrastructure API Calls
- replacement_id: 0840ddf1-8c89-46ff-b730-c8d6722478c0
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Suspicious Powershell Command-Line Arguments
- deprecated_id: 2cdb91d2-542c-497f-b252-be495e71f38c
- replacement_name: Malicious PowerShell Process - Encoded Command
- replacement_id: c4db14d9-7909-48b4-a054-aa14d89dbb19
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Office Application Spawn Regsvr32 process
- deprecated_id: 2d9fc90c-f11f-11eb-9300-acde48001122
- replacement_name: Windows Office Product Spawned Uncommon Process
- replacement_id: 55d8741c-fa32-4692-8109-410304961eb8
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Detect API activity from users without MFA
- deprecated_id: 4d46e8bd-4072-48e4-92db-0325889ef894
- replacement_name: AWS Successful Single-Factor Authentication
- replacement_id: a520b1fe-cc9e-4f56-b762-18354594c52f
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Kubernetes Azure detect sensitive object access
- deprecated_id: 1bba382b-07fd-4ffa-b390-8002739b76e8
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Web Fraud - Password Sharing Across Accounts
- deprecated_id: 31337a1a-53b9-4e05-96e9-55c934cb71d3
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Disabling Net User Account
- deprecated_id: c0325326-acd6-11eb-98c2-acde48001122
- replacement_name: Windows User Disabled Via Net
- replacement_id: b0359e05-c87b-4354-83d8-aee0d890243f
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: GCP Detect accounts with high risk roles by project
- deprecated_id: 27af8c15-38b0-4408-b339-920170724adb
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Kubernetes GCP detect service accounts forbidden failure access
- deprecated_id: 7094808d-432a-48e7-bb3c-77e96c894f3b
- replacement_name: '- '
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Extended Period Without Successful Netbackup Backups
- deprecated_id: a34aae96-ccf8-4aef-952c-3ea214444440
- replacement_name: '-'
- replacement_id: ''
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Office Product Spawning Rundll32 with no DLL
- deprecated_id: c661f6be-a38c-11eb-be57-acde48001122
- replacement_name: Windows Office Product Spawned Rundll32 With No DLL
- replacement_id: f28e787e-69ca-480e-9f98-ab970e6d4bcc
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Renamed and updated logic
-- deprecated_name: Okta ThreatInsight Suspected PasswordSpray Attack
- deprecated_id: 25dbad05-6682-4dd5-9ce9-8adecf0d9ae2
- replacement_name: Okta ThreatInsight Threat Detected
- replacement_id: 140504ae-5fe2-4d65-b2bc-a211813fbca6
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
-- deprecated_name: Net Localgroup Discovery
- deprecated_id: 54f5201e-155b-11ec-a6e2-acde48001122
- replacement_name: Windows Group Discovery Via Net
- replacement_id: c5c8e0f3-147a-43da-bf04-4cfaec27dc44
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44
- / Windows Group Discovery Via Net
-- deprecated_name: Uncommon Processes On Endpoint
- deprecated_id: 29ccce64-a10c-4389-a45f-337cb29ba1f7
- replacement_name: Attacker Tools On Endpoint
- replacement_id: a51bfe1a-94f0-48cc-b4e4-16a110145893
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: ''
-- deprecated_name: Dump LSASS via procdump Rename
- deprecated_id: 21276daa-663d-11eb-ae93-0242ac130002
- replacement_name: Dump LSASS via procdump
- replacement_id: 3742ebfe-64c2-11eb-ae93-0242ac130002
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Updated to a new detection name
-- deprecated_name: Okta Two or More Rejected Okta Pushes
- deprecated_id: d93f785e-4c2c-4262-b8c7-12b77a13fd39
- replacement_name: Okta Multiple Failed MFA Requests For User
- replacement_id: 826dbaae-a1e6-4c8c-b384-d16898956e73
- date: '2025-01-28'
- escu_version: 5.0.0
- migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
- reason: Detections updated to use the new search logic and field names due to the
- TA update
+detections:
+ - deprecated_content: ASL AWS Excessive Security Scanning
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: AWS Cloud Provisioning From Previously Unseen Region
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Provisioning Activity From Previously Unseen Region
+ - deprecated_content: First time seen command line argument
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Windows connhost exe started forcefully
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Detect Mimikatz Using Loaded Images
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Kubernetes Azure detect sensitive role access
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Web Fraud - Anomalous User Clickspeed
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: EC2 Instance Started With Previously Unseen Instance Type
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Compute Instance Created With Previously Unseen Instance Type
+ - deprecated_content: EC2 Instance Started With Previously Unseen AMI
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Compute Instance Created With Previously Unseen Image
+ - deprecated_content: Domain Group Discovery With Net
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content:
+ - Windows Group Discovery Via Net
+ - deprecated_content: Kubernetes AWS detect sensitive role access
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Winword Spawning Windows Script Host
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: "The following analytics was deprecated in favour of a more generic approach.
+ Where instead of creating specific analytic for every potentially suspicious child
+ of an office product. We group them by threat level.\nThis would ease management
+ and false positives tuning."
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Winword Spawning PowerShell
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Attempted Credential Dump From Registry via Reg exe
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: This analytic had some overlap with another one, hence the deprecation.
+ It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry
+ Hive Dump Via CommandLine
+ replacement_content:
+ - Windows Sensitive Registry Hive Dump Via CommandLine
+ - deprecated_content: Detect processes used for System Network Configuration Discovery
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Potential System Network Configuration Discovery Activity
+ - deprecated_content: Execution of File With Spaces Before Extension
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Updated to a new detection name
+ replacement_content:
+ - Execution of File with Multiple Extensions
+ - deprecated_content: EC2 Instance Started In Previously Unseen Region
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Compute Instance Created In Previously Unused Region
+ - deprecated_content: Office Document Spawned Child Process To Download
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Spawned Child Process For Download
+ - deprecated_content: Detect new API calls from user roles
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud API Calls From Previously Unseen User Roles
+ - deprecated_content: Cmdline Tool Not Executed In CMD Shell
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Cmdline Tool Execution From Non-Shell Process
+ - deprecated_content: Linux Auditd Find Private Keys
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Linux Auditd Private Keys and Certificate Enumeration
+ - deprecated_content: Detect AWS API Activities From Unapproved Accounts
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Monitor DNS For Brand Abuse
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Kubernetes GCP detect sensitive object access
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Kubernetes Azure scan fingerprint
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: ASL AWS Password Policy Changes
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: O365 Suspicious Admin Email Forwarding
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - O365 Mailbox Email Forwarding Enabled
+ - deprecated_content: AWS Cloud Provisioning From Previously Unseen City
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Provisioning Activity From Previously Unseen City
+ - deprecated_content: Kubernetes AWS detect service accounts forbidden failure access
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Osquery pack - ColdRoot detection
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Windows Modify Registry Reg Restore
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Registry Entries Restored Via Reg
+ - deprecated_content: Kubernetes GCP detect most active service accounts by pod
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Scheduled tasks used in BadRabbit ransomware
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Updated to a new detection name
+ replacement_content:
+ - Scheduled Task Deleted Or Created via CMD
+ - deprecated_content: Suspicious Rundll32 Rename
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Remote System Discovery with Net
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: "This analytic was focusing on 2 separate and unrelated type of threats
+ or actions. It was split into other analytics, namely:\r\n\r\nWindows Network
+ Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277\r\nWindows Sensitive
+ Group Discovery With Net / a23a0e20-0b1b-4a07-82e5-ec5f70811e7a"
+ replacement_content:
+ - Windows Network Share Interaction With Net
+ - deprecated_content: Remote System Discovery with Net
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content:
+ - Windows Sensitive Group Discovery With Net
+ - deprecated_content: DNS Query Requests Resolved by Unauthorized DNS Servers
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Suspicious Changes to File Associations
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: GCP Detect high risk permissions by resource and account
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Office Product Writing cab or inf
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Dropped Cab or Inf File
+ - deprecated_content: Identify New User Accounts
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Office Product Spawn CMD Process
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Windows DLL Search Order Hijacking Hunt
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Windows DLL Search Order Hijacking Hunt with Sysmon
+ - deprecated_content: ASL AWS CreateAccessKey
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - ASL AWS Create Access Key
+ - deprecated_content: Okta ThreatInsight Login Failure with High Unknown users
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Detect Spike in Security Group Activity
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Abnormally High Number Of Cloud Security Group API Calls
+ - deprecated_content: Office Product Spawning BITSAdmin
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Create local admin accounts using net exe
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Create Local Administrator Account Via Net
+ - deprecated_content: Abnormally High AWS Instances Terminated by User - MLTK
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Windows Office Product Spawning MSDT
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Spawned MSDT
+ - deprecated_content: Detect Spike in AWS API Activity
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Office Product Spawning Windows Script Host
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Prohibited Software On Endpoint
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content:
+ - Attacker Tools On Endpoint
+ - deprecated_content: AWS Cloud Provisioning From Previously Unseen Country
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Provisioning Activity From Previously Unseen Country
+ - deprecated_content: Detect Critical Alerts from Security Tools
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: As discussed internally, this analytic was too generic for an analyst to
+ do anything with it. It was deprecated in favor of the more specific approach
+ provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender
+ Incident Alerts. Going forward analytics from leveraging alerts from vendors will
+ have their specific analytics.
+ replacement_content:
+ - Microsoft Defender ATP Alerts
+ - deprecated_content: Detect Critical Alerts from Security Tools
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content:
+ - Microsoft Defender Incident Alerts
+ - deprecated_content: Excel Spawning PowerShell
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Office Application Spawn rundll32 process
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Excessive Usage Of Net App
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Excessive Usage Of Net App
+ - deprecated_content: Elevated Group Discovery With Net
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Sensitive Group Discovery With Net
+ - deprecated_content: Local Account Discovery with Net
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows User Discovery Via Net
+ - deprecated_content: Windows Command Shell Fetch Env Variables
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows List ENV Variables Via SET Command From Uncommon Parent
+ - deprecated_content: Suspicious Email - UBA Anomaly
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Detect web traffic to dynamic domain providers
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Updated to use a different log source
+ replacement_content:
+ - Detect hosts connecting to dynamic domain providers
+ - deprecated_content: Okta Failed SSO Attempts
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Okta Unauthorized Access to Application
+ - deprecated_content: Kubernetes AWS detect RBAC authorization by account
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Kubernetes Azure detect service accounts forbidden failure access
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Remote Registry Key modifications
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: O365 Suspicious User Email Forwarding
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - O365 Mailbox Email Forwarding Enabled
+ - deprecated_content: Office Product Spawning MSHTA
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Kubernetes AWS detect most active service accounts by pod
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Correlation by Repository and Risk
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the datamodel
+ replacement_content:
+ - Risk Rule for Dev Sec Ops by Repository
+ - deprecated_content: Kubernetes Azure detect RBAC authorization by account
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Clients Connecting to Multiple DNS Servers
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Excessive Service Stop Attempt
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Excessive Service Stop Attempt
+ - deprecated_content: Multiple Okta Users With Invalid Credentials From The Same IP
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Okta Multiple Users Failing To Authenticate From Ip
+ - deprecated_content: Suspicious writes to System Volume Information
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Detect new user AWS Console Login
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Detect AWS Console Login by New User
+ - deprecated_content: Domain Account Discovery With Net App
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: "This analytic was a TTP that looked only for commands that tries to query
+ info about the users via net user /do. This had a couple of issues, such as triggering
+ on creation of users via the /add flag etc..\nIt was deprecated in favor of a
+ more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122"
+ replacement_content:
+ - Windows User Discovery Via Net
+ - deprecated_content: Detection of DNS Tunnels
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Detect DNS requests to Phishing Sites leveraging EvilGinx2
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Office Document Creating Schedule Task
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Loading Taskschd DLL
+ - deprecated_content: Okta Account Locked Out
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Okta Multiple Accounts Locked Out
+ - deprecated_content: Unsuccessful Netbackup backups
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Detect Mimikatz Via PowerShell And EventCode 4703
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Updated to a new detection name
+ replacement_content:
+ - Detect Mimikatz With PowerShell Script Block Logging
+ - deprecated_content: Winword Spawning Cmd
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: GCP Kubernetes cluster scan detection
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Kubernetes Scanning by Unauthenticated IP Address
+ - deprecated_content: Kubernetes GCP detect suspicious kubectl calls
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: gcp detect oauth token abuse
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Correlation by User and Risk
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the datamodel
+ replacement_content:
+ - Risk Rule for Dev Sec Ops by Repository
+ - deprecated_content: Processes created by netsh
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Updated to a new detection name
+ replacement_content:
+ - Processes launching netsh
+ - deprecated_content: Office Product Spawning Wmic
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Extraction of Registry Hives
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Sensitive Registry Hive Dump Via CommandLine
+ - deprecated_content: Attempt To Stop Security Service
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Attempt To Stop Security Service
+ - deprecated_content: Windows MSIExec With Network Connections
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows HTTP Network Communication From MSIExec
+ - deprecated_content: Windows Query Registry Reg Save
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Registry Entries Exported Via Reg
+ - deprecated_content: Cloud Network Access Control List Deleted
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - AWS Network Access Control List Deleted
+ - deprecated_content: O365 Suspicious Rights Delegation
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - O365 Elevated Mailbox Permission Assigned
+ - deprecated_content: Abnormally High AWS Instances Launched by User - MLTK
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Reg exe used to hide files directories via registry keys
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Detect Long DNS TXT Record Response
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Password Policy Discovery with Net
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Password Policy Discovery with Net
+ - deprecated_content: AWS Cloud Provisioning From Previously Unseen IP Address
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Provisioning Activity From Previously Unseen IP Address
+ - deprecated_content: Network Connection Discovery With Net
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Network Connection Discovery Via Net
+ - deprecated_content: Kubernetes Azure detect suspicious kubectl calls
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Kubernetes GCP detect sensitive role access
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Detect Webshell Exploit Behavior
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Suspicious Child Process Spawned From WebServer
+ - deprecated_content: DNS record changed
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Unsigned Image Loaded by LSASS
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Detect USB device insertion
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Windows Network Share Interaction With Net
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Network Share Interaction Via Net
+ - deprecated_content: Account Discovery With Net App
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: This analytic was a TTP that focused on unrelated things and called account
+ discovery. Since there were other detection that overlapped with it. I choose
+ to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122
+ / Windows Excessive Usage Of Net App.
+ replacement_content:
+ - Windows Excessive Usage Of Net App
+ - deprecated_content: Change Default File Association
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows New Default File Association Value Set
+ - deprecated_content: Windows Lateral Tool Transfer RemCom
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Updated to a new detection name
+ replacement_content:
+ - Windows Service Execution RemCom
+ - deprecated_content: Office Document Executing Macro Code
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Loading VBE7 DLL
+ - deprecated_content: Okta Account Lockout Events
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Okta Multiple Accounts Locked Out
+ - deprecated_content: Abnormally High AWS Instances Launched by User
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Abnormally High Number Of Cloud Instances Launched
+ - deprecated_content: EC2 Instance Modified With Previously Unseen User
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud API Calls From Previously Unseen User Roles
+ - deprecated_content: Windows Valid Account With Never Expires Password
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Set Account Password Policy To Unlimited Via Net
+ - deprecated_content: Windows hosts file modification
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: MSHTML Module Load in Office Product
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Loaded MSHTML Module
+ - deprecated_content: Abnormally High AWS Instances Terminated by User
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Abnormally High Number Of Cloud Instances Destroyed
+ - deprecated_content: Web Fraud - Account Harvesting
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Office Spawning Control
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Spawned Control
+ - deprecated_content: Detect Activity Related to Pass the Hash Attacks
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Deleting Of Net Users
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows User Deletion Via Net
+ - deprecated_content: Suspicious File Write
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: AWS EKS Kubernetes cluster sensitive object access
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Kubernetes Abuse of Secret by Unusual Location
+ - deprecated_content: Spectre and Meltdown Vulnerable Systems
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: EC2 Instance Started With Previously Unseen User
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Cloud Compute Instance Created By Previously Unseen User
+ - deprecated_content: Office Product Spawning CertUtil
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Kubernetes GCP detect RBAC authorizations by account
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Office Application Drop Executable
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Dropped Uncommon File
+ - deprecated_content: Kubernetes Azure active service accounts by pod namespace
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Kubernetes Azure pod scan fingerprint
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Detect Spike in Network ACL Activity
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Abnormally High Number Of Cloud Infrastructure API Calls
+ - deprecated_content: Suspicious Powershell Command-Line Arguments
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content:
+ - Malicious PowerShell Process - Encoded Command
+ - deprecated_content: Office Application Spawn Regsvr32 process
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content:
+ - Windows Office Product Spawned Uncommon Process
+ - deprecated_content: Detect API activity from users without MFA
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - AWS Successful Single-Factor Authentication
+ - deprecated_content: Kubernetes Azure detect sensitive object access
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Web Fraud - Password Sharing Across Accounts
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Disabling Net User Account
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows User Disabled Via Net
+ - deprecated_content: GCP Detect accounts with high risk roles by project
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Kubernetes GCP detect service accounts forbidden failure access
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Extended Period Without Successful Netbackup Backups
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Office Product Spawning Rundll32 with no DLL
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Renamed and updated logic
+ replacement_content:
+ - Windows Office Product Spawned Rundll32 With No DLL
+ - deprecated_content: Okta ThreatInsight Suspected PasswordSpray Attack
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Okta ThreatInsight Threat Detected
+ - deprecated_content: Net Localgroup Discovery
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44
+ / Windows Group Discovery Via Net
+ replacement_content:
+ - Windows Group Discovery Via Net
+ - deprecated_content: Uncommon Processes On Endpoint
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content:
+ - Attacker Tools On Endpoint
+ - deprecated_content: Dump LSASS via procdump Rename
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Updated to a new detection name
+ replacement_content:
+ - Dump LSASS via procdump
+ - deprecated_content: Okta Two or More Rejected Okta Pushes
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Detections updated to use the new search logic and field names due to the
+ TA update
+ replacement_content:
+ - Okta Multiple Failed MFA Requests For User
+baselines: []
+investigations: []
+stories: []
\ No newline at end of file
diff --git a/deprecated/deprecated_detection_mapping_updated.yml b/deprecated/deprecated_detection_mapping_updated.yml
deleted file mode 100644
index 322dea112d..0000000000
--- a/deprecated/deprecated_detection_mapping_updated.yml
+++ /dev/null
@@ -1,902 +0,0 @@
-detections:
- - deprecated_content: ASL AWS Excessive Security Scanning
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: AWS Cloud Provisioning From Previously Unseen Region
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud Provisioning Activity From Previously Unseen Region
- - deprecated_content: First time seen command line argument
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Windows connhost exe started forcefully
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Detect Mimikatz Using Loaded Images
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Kubernetes Azure detect sensitive role access
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Web Fraud - Anomalous User Clickspeed
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: EC2 Instance Started With Previously Unseen Instance Type
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud Compute Instance Created With Previously Unseen Instance Type
- - deprecated_content: EC2 Instance Started With Previously Unseen AMI
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud Compute Instance Created With Previously Unseen Image
- - deprecated_content: Domain Group Discovery With Net
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content:
- - Windows Group Discovery Via Net
- - deprecated_content: Kubernetes AWS detect sensitive role access
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Winword Spawning Windows Script Host
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: "The following analytics was deprecated in favour of a more generic approach.
- Where instead of creating specific analytic for every potentially suspicious child
- of an office product. We group them by threat level.\nThis would ease management
- and false positives tuning."
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
- - deprecated_content: Winword Spawning PowerShell
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
- - deprecated_content: Attempted Credential Dump From Registry via Reg exe
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: This analytic had some overlap with another one, hence the deprecation.
- It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry
- Hive Dump Via CommandLine
- replacement_content:
- - Windows Sensitive Registry Hive Dump Via CommandLine
- - deprecated_content: Detect processes used for System Network Configuration Discovery
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Potential System Network Configuration Discovery Activity
- - deprecated_content: Execution of File With Spaces Before Extension
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Updated to a new detection name
- replacement_content:
- - Execution of File with Multiple Extensions
- - deprecated_content: EC2 Instance Started In Previously Unseen Region
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud Compute Instance Created In Previously Unused Region
- - deprecated_content: Office Document Spawned Child Process To Download
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Office Product Spawned Child Process For Download
- - deprecated_content: Detect new API calls from user roles
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud API Calls From Previously Unseen User Roles
- - deprecated_content: Cmdline Tool Not Executed In CMD Shell
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Cmdline Tool Execution From Non-Shell Process
- - deprecated_content: Linux Auditd Find Private Keys
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Linux Auditd Private Keys and Certificate Enumeration
- - deprecated_content: Detect AWS API Activities From Unapproved Accounts
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Monitor DNS For Brand Abuse
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Kubernetes GCP detect sensitive object access
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Kubernetes Azure scan fingerprint
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: ASL AWS Password Policy Changes
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: O365 Suspicious Admin Email Forwarding
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - O365 Mailbox Email Forwarding Enabled
- - deprecated_content: AWS Cloud Provisioning From Previously Unseen City
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud Provisioning Activity From Previously Unseen City
- - deprecated_content: Kubernetes AWS detect service accounts forbidden failure access
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Osquery pack - ColdRoot detection
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Windows Modify Registry Reg Restore
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Registry Entries Restored Via Reg
- - deprecated_content: Kubernetes GCP detect most active service accounts by pod
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Scheduled tasks used in BadRabbit ransomware
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Updated to a new detection name
- replacement_content:
- - Scheduled Task Deleted Or Created via CMD
- - deprecated_content: Suspicious Rundll32 Rename
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Remote System Discovery with Net
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: "This analytic was focusing on 2 separate and unrelated type of threats
- or actions. It was split into other analytics, namely:\r\n\r\nWindows Network
- Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277\r\nWindows Sensitive
- Group Discovery With Net / a23a0e20-0b1b-4a07-82e5-ec5f70811e7a"
- replacement_content:
- - Windows Network Share Interaction With Net
- - deprecated_content: Remote System Discovery with Net
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content:
- - Windows Sensitive Group Discovery With Net
- - deprecated_content: DNS Query Requests Resolved by Unauthorized DNS Servers
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Suspicious Changes to File Associations
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: GCP Detect high risk permissions by resource and account
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Office Product Writing cab or inf
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Office Product Dropped Cab or Inf File
- - deprecated_content: Identify New User Accounts
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Office Product Spawn CMD Process
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
- - deprecated_content: Windows DLL Search Order Hijacking Hunt
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Windows DLL Search Order Hijacking Hunt with Sysmon
- - deprecated_content: ASL AWS CreateAccessKey
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - ASL AWS Create Access Key
- - deprecated_content: Okta ThreatInsight Login Failure with High Unknown users
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Detect Spike in Security Group Activity
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Abnormally High Number Of Cloud Security Group API Calls
- - deprecated_content: Office Product Spawning BITSAdmin
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
- - deprecated_content: Create local admin accounts using net exe
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Create Local Administrator Account Via Net
- - deprecated_content: Abnormally High AWS Instances Terminated by User - MLTK
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Windows Office Product Spawning MSDT
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Office Product Spawned MSDT
- - deprecated_content: Detect Spike in AWS API Activity
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Office Product Spawning Windows Script Host
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
- - deprecated_content: Prohibited Software On Endpoint
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content:
- - Attacker Tools On Endpoint
- - deprecated_content: AWS Cloud Provisioning From Previously Unseen Country
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud Provisioning Activity From Previously Unseen Country
- - deprecated_content: Detect Critical Alerts from Security Tools
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: As discussed internally, this analytic was too generic for an analyst to
- do anything with it. It was deprecated in favor of the more specific approach
- provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender
- Incident Alerts. Going forward analytics from leveraging alerts from vendors will
- have their specific analytics.
- replacement_content:
- - Microsoft Defender ATP Alerts
- - deprecated_content: Detect Critical Alerts from Security Tools
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content:
- - Microsoft Defender Incident Alerts
- - deprecated_content: Excel Spawning PowerShell
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
- - deprecated_content: Office Application Spawn rundll32 process
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
- - deprecated_content: Excessive Usage Of Net App
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Excessive Usage Of Net App
- - deprecated_content: Elevated Group Discovery With Net
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Sensitive Group Discovery With Net
- - deprecated_content: Local Account Discovery with Net
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows User Discovery Via Net
- - deprecated_content: Windows Command Shell Fetch Env Variables
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows List ENV Variables Via SET Command From Uncommon Parent
- - deprecated_content: Suspicious Email - UBA Anomaly
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Detect web traffic to dynamic domain providers
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Updated to use a different log source
- replacement_content:
- - Detect hosts connecting to dynamic domain providers
- - deprecated_content: Okta Failed SSO Attempts
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Okta Unauthorized Access to Application
- - deprecated_content: Kubernetes AWS detect RBAC authorization by account
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Kubernetes Azure detect service accounts forbidden failure access
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Remote Registry Key modifications
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: O365 Suspicious User Email Forwarding
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - O365 Mailbox Email Forwarding Enabled
- - deprecated_content: Office Product Spawning MSHTA
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
- - deprecated_content: Kubernetes AWS detect most active service accounts by pod
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Correlation by Repository and Risk
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the datamodel
- replacement_content:
- - Risk Rule for Dev Sec Ops by Repository
- - deprecated_content: Kubernetes Azure detect RBAC authorization by account
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Clients Connecting to Multiple DNS Servers
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Excessive Service Stop Attempt
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Excessive Service Stop Attempt
- - deprecated_content: Multiple Okta Users With Invalid Credentials From The Same IP
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Okta Multiple Users Failing To Authenticate From Ip
- - deprecated_content: Suspicious writes to System Volume Information
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Detect new user AWS Console Login
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Detect AWS Console Login by New User
- - deprecated_content: Domain Account Discovery With Net App
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: "This analytic was a TTP that looked only for commands that tries to query
- info about the users via net user /do. This had a couple of issues, such as triggering
- on creation of users via the /add flag etc..\nIt was deprecated in favor of a
- more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122"
- replacement_content:
- - Windows User Discovery Via Net
- - deprecated_content: Detection of DNS Tunnels
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Detect DNS requests to Phishing Sites leveraging EvilGinx2
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Office Document Creating Schedule Task
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Office Product Loading Taskschd DLL
- - deprecated_content: Okta Account Locked Out
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Okta Multiple Accounts Locked Out
- - deprecated_content: Unsuccessful Netbackup backups
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Detect Mimikatz Via PowerShell And EventCode 4703
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Updated to a new detection name
- replacement_content:
- - Detect Mimikatz With PowerShell Script Block Logging
- - deprecated_content: Winword Spawning Cmd
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
- - deprecated_content: GCP Kubernetes cluster scan detection
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Kubernetes Scanning by Unauthenticated IP Address
- - deprecated_content: Kubernetes GCP detect suspicious kubectl calls
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: gcp detect oauth token abuse
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Correlation by User and Risk
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the datamodel
- replacement_content:
- - Risk Rule for Dev Sec Ops by Repository
- - deprecated_content: Processes created by netsh
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Updated to a new detection name
- replacement_content:
- - Processes launching netsh
- - deprecated_content: Office Product Spawning Wmic
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
- - deprecated_content: Extraction of Registry Hives
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Sensitive Registry Hive Dump Via CommandLine
- - deprecated_content: Attempt To Stop Security Service
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Attempt To Stop Security Service
- - deprecated_content: Windows MSIExec With Network Connections
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows HTTP Network Communication From MSIExec
- - deprecated_content: Windows Query Registry Reg Save
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Registry Entries Exported Via Reg
- - deprecated_content: Cloud Network Access Control List Deleted
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - AWS Network Access Control List Deleted
- - deprecated_content: O365 Suspicious Rights Delegation
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - O365 Elevated Mailbox Permission Assigned
- - deprecated_content: Abnormally High AWS Instances Launched by User - MLTK
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Reg exe used to hide files directories via registry keys
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Detect Long DNS TXT Record Response
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Password Policy Discovery with Net
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Password Policy Discovery with Net
- - deprecated_content: AWS Cloud Provisioning From Previously Unseen IP Address
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud Provisioning Activity From Previously Unseen IP Address
- - deprecated_content: Network Connection Discovery With Net
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Network Connection Discovery Via Net
- - deprecated_content: Kubernetes Azure detect suspicious kubectl calls
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Kubernetes GCP detect sensitive role access
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Detect Webshell Exploit Behavior
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Suspicious Child Process Spawned From WebServer
- - deprecated_content: DNS record changed
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Unsigned Image Loaded by LSASS
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Detect USB device insertion
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Windows Network Share Interaction With Net
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Network Share Interaction Via Net
- - deprecated_content: Account Discovery With Net App
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: This analytic was a TTP that focused on unrelated things and called account
- discovery. Since there were other detection that overlapped with it. I choose
- to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122
- / Windows Excessive Usage Of Net App.
- replacement_content:
- - Windows Excessive Usage Of Net App
- - deprecated_content: Change Default File Association
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows New Default File Association Value Set
- - deprecated_content: Windows Lateral Tool Transfer RemCom
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Updated to a new detection name
- replacement_content:
- - Windows Service Execution RemCom
- - deprecated_content: Office Document Executing Macro Code
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Office Product Loading VBE7 DLL
- - deprecated_content: Okta Account Lockout Events
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Okta Multiple Accounts Locked Out
- - deprecated_content: Abnormally High AWS Instances Launched by User
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Abnormally High Number Of Cloud Instances Launched
- - deprecated_content: EC2 Instance Modified With Previously Unseen User
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud API Calls From Previously Unseen User Roles
- - deprecated_content: Windows Valid Account With Never Expires Password
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Set Account Password Policy To Unlimited Via Net
- - deprecated_content: Windows hosts file modification
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: MSHTML Module Load in Office Product
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Office Product Loaded MSHTML Module
- - deprecated_content: Abnormally High AWS Instances Terminated by User
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Abnormally High Number Of Cloud Instances Destroyed
- - deprecated_content: Web Fraud - Account Harvesting
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Office Spawning Control
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Office Product Spawned Control
- - deprecated_content: Detect Activity Related to Pass the Hash Attacks
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Deleting Of Net Users
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows User Deletion Via Net
- - deprecated_content: Suspicious File Write
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: AWS EKS Kubernetes cluster sensitive object access
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Kubernetes Abuse of Secret by Unusual Location
- - deprecated_content: Spectre and Meltdown Vulnerable Systems
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: EC2 Instance Started With Previously Unseen User
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Cloud Compute Instance Created By Previously Unseen User
- - deprecated_content: Office Product Spawning CertUtil
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
- - deprecated_content: Kubernetes GCP detect RBAC authorizations by account
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Office Application Drop Executable
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Office Product Dropped Uncommon File
- - deprecated_content: Kubernetes Azure active service accounts by pod namespace
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Kubernetes Azure pod scan fingerprint
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Detect Spike in Network ACL Activity
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Abnormally High Number Of Cloud Infrastructure API Calls
- - deprecated_content: Suspicious Powershell Command-Line Arguments
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content:
- - Malicious PowerShell Process - Encoded Command
- - deprecated_content: Office Application Spawn Regsvr32 process
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content:
- - Windows Office Product Spawned Uncommon Process
- - deprecated_content: Detect API activity from users without MFA
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - AWS Successful Single-Factor Authentication
- - deprecated_content: Kubernetes Azure detect sensitive object access
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Web Fraud - Password Sharing Across Accounts
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Disabling Net User Account
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows User Disabled Via Net
- - deprecated_content: GCP Detect accounts with high risk roles by project
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Kubernetes GCP detect service accounts forbidden failure access
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Extended Period Without Successful Netbackup Backups
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Office Product Spawning Rundll32 with no DLL
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Renamed and updated logic
- replacement_content:
- - Windows Office Product Spawned Rundll32 With No DLL
- - deprecated_content: Okta ThreatInsight Suspected PasswordSpray Attack
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Okta ThreatInsight Threat Detected
- - deprecated_content: Net Localgroup Discovery
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44
- / Windows Group Discovery Via Net
- replacement_content:
- - Windows Group Discovery Via Net
- - deprecated_content: Uncommon Processes On Endpoint
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content:
- - Attacker Tools On Endpoint
- - deprecated_content: Dump LSASS via procdump Rename
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Updated to a new detection name
- replacement_content:
- - Dump LSASS via procdump
- - deprecated_content: Okta Two or More Rejected Okta Pushes
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Detections updated to use the new search logic and field names due to the
- TA update
- replacement_content:
- - Okta Multiple Failed MFA Requests For User
-baselines: []
-investigations: []
-stories: []
\ No newline at end of file
From 2fe8bc5638a8078fce5a9b1a08bbfad99148b9a5 Mon Sep 17 00:00:00 2001
From: research-bot
Date: Wed, 26 Feb 2025 10:39:51 -0800
Subject: [PATCH 12/67] remove 152 public detections
---
.../abnormally_high_aws_instances_launched_by_user.yml | 0
.../abnormally_high_aws_instances_launched_by_user___mltk.yml | 0
.../abnormally_high_aws_instances_terminated_by_user.yml | 0
.../abnormally_high_aws_instances_terminated_by_user___mltk.yml | 0
.../detections}/account_discovery_with_net_app.yml | 0
.../detections}/asl_aws_createaccesskey.yml | 0
.../detections}/asl_aws_excessive_security_scanning.yml | 0
.../detections}/asl_aws_password_policy_changes.yml | 0
.../detections}/attempt_to_stop_security_service.yml | 0
.../attempted_credential_dump_from_registry_via_reg_exe.yml | 0
.../aws_cloud_provisioning_from_previously_unseen_city.yml | 0
.../aws_cloud_provisioning_from_previously_unseen_country.yml | 0
.../aws_cloud_provisioning_from_previously_unseen_ip_address.yml | 0
.../aws_cloud_provisioning_from_previously_unseen_region.yml | 0
.../aws_eks_kubernetes_cluster_sensitive_object_access.yml | 0
.../detections}/change_default_file_association.yml | 0
.../detections}/clients_connecting_to_multiple_dns_servers.yml | 0
.../detections}/cloud_network_access_control_list_deleted.yml | 0
.../detections}/cmdline_tool_not_executed_in_cmd_shell.yml | 0
.../detections}/correlation_by_repository_and_risk.yml | 0
.../detections}/correlation_by_user_and_risk.yml | 0
.../detections}/create_local_admin_accounts_using_net_exe.yml | 0
.../detections}/deleting_of_net_users.yml | 0
.../detect_activity_related_to_pass_the_hash_attacks.yml | 0
.../detections}/detect_api_activity_from_users_without_mfa.yml | 0
.../detect_aws_api_activities_from_unapproved_accounts.yml | 0
.../detections}/detect_critical_alerts_from_security_tools.yml | 0
...detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml | 0
.../detections}/detect_long_dns_txt_record_response.yml | 0
.../detections}/detect_mimikatz_using_loaded_images.yml | 0
.../detect_mimikatz_via_powershell_and_eventcode_4703.yml | 0
.../detections}/detect_new_api_calls_from_user_roles.yml | 0
.../detections}/detect_new_user_aws_console_login.yml | 0
..._processes_used_for_system_network_configuration_discovery.yml | 0
.../detections}/detect_spike_in_aws_api_activity.yml | 0
.../detections}/detect_spike_in_network_acl_activity.yml | 0
.../detections}/detect_spike_in_security_group_activity.yml | 0
.../detections}/detect_usb_device_insertion.yml | 0
.../detect_web_traffic_to_dynamic_domain_providers.yml | 0
.../detections}/detect_webshell_exploit_behavior.yml | 0
.../detections}/detection_of_dns_tunnels.yml | 0
.../detections}/disabling_net_user_account.yml | 0
.../dns_query_requests_resolved_by_unauthorized_dns_servers.yml | 0
.../deprecated => deprecated/detections}/dns_record_changed.yml | 0
.../detections}/domain_account_discovery_with_net_app.yml | 0
.../detections}/domain_group_discovery_with_net.yml | 0
.../detections}/dump_lsass_via_procdump_rename.yml | 0
.../ec2_instance_modified_with_previously_unseen_user.yml | 0
.../ec2_instance_started_in_previously_unseen_region.yml | 0
.../ec2_instance_started_with_previously_unseen_ami.yml | 0
.../ec2_instance_started_with_previously_unseen_instance_type.yml | 0
.../ec2_instance_started_with_previously_unseen_user.yml | 0
.../detections}/elevated_group_discovery_with_net.yml | 0
.../detections}/excel_spawning_powershell.yml | 0
.../detections}/excel_spawning_windows_script_host.yml | 0
.../detections}/excessive_service_stop_attempt.yml | 0
.../detections}/excessive_usage_of_net_app.yml | 0
.../execution_of_file_with_spaces_before_extension.yml | 0
.../extended_period_without_successful_netbackup_backups.yml | 0
.../detections}/extraction_of_registry_hives.yml | 0
.../detections}/first_time_seen_command_line_argument.yml | 0
.../gcp_detect_accounts_with_high_risk_roles_by_project.yml | 0
.../gcp_detect_high_risk_permissions_by_resource_and_account.yml | 0
.../detections}/gcp_detect_oauth_token_abuse.yml | 0
.../detections}/gcp_kubernetes_cluster_scan_detection.yml | 0
.../detections}/identify_new_user_accounts.yml | 0
.../kubernetes_aws_detect_most_active_service_accounts_by_pod.yml | 0
.../kubernetes_aws_detect_rbac_authorization_by_account.yml | 0
.../detections}/kubernetes_aws_detect_sensitive_role_access.yml | 0
...netes_aws_detect_service_accounts_forbidden_failure_access.yml | 0
.../kubernetes_azure_active_service_accounts_by_pod_namespace.yml | 0
.../kubernetes_azure_detect_rbac_authorization_by_account.yml | 0
.../kubernetes_azure_detect_sensitive_object_access.yml | 0
.../detections}/kubernetes_azure_detect_sensitive_role_access.yml | 0
...tes_azure_detect_service_accounts_forbidden_failure_access.yml | 0
.../kubernetes_azure_detect_suspicious_kubectl_calls.yml | 0
.../detections}/kubernetes_azure_pod_scan_fingerprint.yml | 0
.../detections}/kubernetes_azure_scan_fingerprint.yml | 0
.../kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml | 0
.../kubernetes_gcp_detect_rbac_authorizations_by_account.yml | 0
.../detections}/kubernetes_gcp_detect_sensitive_object_access.yml | 0
.../detections}/kubernetes_gcp_detect_sensitive_role_access.yml | 0
...netes_gcp_detect_service_accounts_forbidden_failure_access.yml | 0
.../kubernetes_gcp_detect_suspicious_kubectl_calls.yml | 0
.../detections}/linux_auditd_find_private_keys.yml | 0
.../detections}/local_account_discovery_with_net.yml | 0
.../detections}/monitor_dns_for_brand_abuse.yml | 0
.../detections}/mshtml_module_load_in_office_product.yml | 0
...tiple_okta_users_with_invalid_credentials_from_the_same_ip.yml | 0
.../detections}/net_localgroup_discovery.yml | 0
.../detections}/network_connection_discovery_with_net.yml | 0
.../detections}/o365_suspicious_admin_email_forwarding.yml | 0
.../detections}/o365_suspicious_rights_delegation.yml | 0
.../detections}/o365_suspicious_user_email_forwarding.yml | 0
.../detections}/office_application_drop_executable.yml | 0
.../detections}/office_application_spawn_regsvr32_process.yml | 0
.../detections}/office_application_spawn_rundll32_process.yml | 0
.../detections}/office_document_creating_schedule_task.yml | 0
.../detections}/office_document_executing_macro_code.yml | 0
.../office_document_spawned_child_process_to_download.yml | 0
.../detections}/office_product_spawn_cmd_process.yml | 0
.../detections}/office_product_spawning_bitsadmin.yml | 0
.../detections}/office_product_spawning_certutil.yml | 0
.../detections}/office_product_spawning_mshta.yml | 0
.../detections}/office_product_spawning_rundll32_with_no_dll.yml | 0
.../detections}/office_product_spawning_windows_script_host.yml | 0
.../detections}/office_product_spawning_wmic.yml | 0
.../detections}/office_product_writing_cab_or_inf.yml | 0
.../detections}/office_spawning_control.yml | 0
.../detections}/okta_account_locked_out.yml | 0
.../detections}/okta_account_lockout_events.yml | 0
.../detections}/okta_failed_sso_attempts.yml | 0
.../okta_threatinsight_login_failure_with_high_unknown_users.yml | 0
.../okta_threatinsight_suspected_passwordspray_attack.yml | 0
.../detections}/okta_two_or_more_rejected_okta_pushes.yml | 0
.../detections}/osquery_pack___coldroot_detection.yml | 0
.../detections}/password_policy_discovery_with_net.yml | 0
.../detections}/processes_created_by_netsh.yml | 0
.../detections}/prohibited_software_on_endpoint.yml | 0
.../reg_exe_used_to_hide_files_directories_via_registry_keys.yml | 0
.../detections}/remote_registry_key_modifications.yml | 0
.../detections}/remote_system_discovery_with_net.yml | 0
.../detections}/scheduled_tasks_used_in_badrabbit_ransomware.yml | 0
.../detections}/spectre_and_meltdown_vulnerable_systems.yml | 0
.../detections}/suspicious_changes_to_file_associations.yml | 0
.../detections}/suspicious_email___uba_anomaly.yml | 0
.../detections}/suspicious_file_write.yml | 0
.../detections}/suspicious_powershell_command_line_arguments.yml | 0
.../detections}/suspicious_rundll32_rename.yml | 0
.../suspicious_writes_to_system_volume_information.yml | 0
.../detections}/uncommon_processes_on_endpoint.yml | 0
.../detections}/unsigned_image_loaded_by_lsass.yml | 0
.../detections}/unsuccessful_netbackup_backups.yml | 0
.../detections}/web_fraud___account_harvesting.yml | 0
.../detections}/web_fraud___anomalous_user_clickspeed.yml | 0
.../detections}/web_fraud___password_sharing_across_accounts.yml | 0
.../detections}/windows_command_shell_fetch_env_variables.yml | 0
.../detections}/windows_connhost_exe_started_forcefully.yml | 0
.../detections}/windows_dll_search_order_hijacking_hunt.yml | 0
.../detections}/windows_hosts_file_modification.yml | 0
.../detections}/windows_lateral_tool_transfer_remcom.yml | 0
.../detections}/windows_modify_registry_reg_restore.yml | 0
.../detections}/windows_msiexec_with_network_connections.yml | 0
.../detections}/windows_network_share_interaction_with_net.yml | 0
.../detections}/windows_office_product_spawning_msdt.yml | 0
.../detections}/windows_query_registry_reg_save.yml | 0
.../windows_service_stop_via_net__and_sc_application.yml | 0
.../windows_valid_account_with_never_expires_password.yml | 0
.../deprecated => deprecated/detections}/winword_spawning_cmd.yml | 0
.../detections}/winword_spawning_powershell.yml | 0
.../detections}/winword_spawning_windows_script_host.yml | 0
151 files changed, 0 insertions(+), 0 deletions(-)
rename {detections/deprecated => deprecated/detections}/abnormally_high_aws_instances_launched_by_user.yml (100%)
rename {detections/deprecated => deprecated/detections}/abnormally_high_aws_instances_launched_by_user___mltk.yml (100%)
rename {detections/deprecated => deprecated/detections}/abnormally_high_aws_instances_terminated_by_user.yml (100%)
rename {detections/deprecated => deprecated/detections}/abnormally_high_aws_instances_terminated_by_user___mltk.yml (100%)
rename {detections/deprecated => deprecated/detections}/account_discovery_with_net_app.yml (100%)
rename {detections/deprecated => deprecated/detections}/asl_aws_createaccesskey.yml (100%)
rename {detections/deprecated => deprecated/detections}/asl_aws_excessive_security_scanning.yml (100%)
rename {detections/deprecated => deprecated/detections}/asl_aws_password_policy_changes.yml (100%)
rename {detections/deprecated => deprecated/detections}/attempt_to_stop_security_service.yml (100%)
rename {detections/deprecated => deprecated/detections}/attempted_credential_dump_from_registry_via_reg_exe.yml (100%)
rename {detections/deprecated => deprecated/detections}/aws_cloud_provisioning_from_previously_unseen_city.yml (100%)
rename {detections/deprecated => deprecated/detections}/aws_cloud_provisioning_from_previously_unseen_country.yml (100%)
rename {detections/deprecated => deprecated/detections}/aws_cloud_provisioning_from_previously_unseen_ip_address.yml (100%)
rename {detections/deprecated => deprecated/detections}/aws_cloud_provisioning_from_previously_unseen_region.yml (100%)
rename {detections/deprecated => deprecated/detections}/aws_eks_kubernetes_cluster_sensitive_object_access.yml (100%)
rename {detections/deprecated => deprecated/detections}/change_default_file_association.yml (100%)
rename {detections/deprecated => deprecated/detections}/clients_connecting_to_multiple_dns_servers.yml (100%)
rename {detections/deprecated => deprecated/detections}/cloud_network_access_control_list_deleted.yml (100%)
rename {detections/deprecated => deprecated/detections}/cmdline_tool_not_executed_in_cmd_shell.yml (100%)
rename {detections/deprecated => deprecated/detections}/correlation_by_repository_and_risk.yml (100%)
rename {detections/deprecated => deprecated/detections}/correlation_by_user_and_risk.yml (100%)
rename {detections/deprecated => deprecated/detections}/create_local_admin_accounts_using_net_exe.yml (100%)
rename {detections/deprecated => deprecated/detections}/deleting_of_net_users.yml (100%)
rename {detections/deprecated => deprecated/detections}/detect_activity_related_to_pass_the_hash_attacks.yml (100%)
rename {detections/deprecated => deprecated/detections}/detect_api_activity_from_users_without_mfa.yml (100%)
rename {detections/deprecated => deprecated/detections}/detect_aws_api_activities_from_unapproved_accounts.yml (100%)
rename {detections/deprecated => deprecated/detections}/detect_critical_alerts_from_security_tools.yml (100%)
rename {detections/deprecated => deprecated/detections}/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml (100%)
rename {detections/deprecated => deprecated/detections}/detect_long_dns_txt_record_response.yml (100%)
rename {detections/deprecated => deprecated/detections}/detect_mimikatz_using_loaded_images.yml (100%)
rename {detections/deprecated => deprecated/detections}/detect_mimikatz_via_powershell_and_eventcode_4703.yml (100%)
rename {detections/deprecated => deprecated/detections}/detect_new_api_calls_from_user_roles.yml (100%)
rename {detections/deprecated => deprecated/detections}/detect_new_user_aws_console_login.yml (100%)
rename {detections/deprecated => deprecated/detections}/detect_processes_used_for_system_network_configuration_discovery.yml (100%)
rename {detections/deprecated => deprecated/detections}/detect_spike_in_aws_api_activity.yml (100%)
rename {detections/deprecated => deprecated/detections}/detect_spike_in_network_acl_activity.yml (100%)
rename {detections/deprecated => deprecated/detections}/detect_spike_in_security_group_activity.yml (100%)
rename {detections/deprecated => deprecated/detections}/detect_usb_device_insertion.yml (100%)
rename {detections/deprecated => deprecated/detections}/detect_web_traffic_to_dynamic_domain_providers.yml (100%)
rename {detections/deprecated => deprecated/detections}/detect_webshell_exploit_behavior.yml (100%)
rename {detections/deprecated => deprecated/detections}/detection_of_dns_tunnels.yml (100%)
rename {detections/deprecated => deprecated/detections}/disabling_net_user_account.yml (100%)
rename {detections/deprecated => deprecated/detections}/dns_query_requests_resolved_by_unauthorized_dns_servers.yml (100%)
rename {detections/deprecated => deprecated/detections}/dns_record_changed.yml (100%)
rename {detections/deprecated => deprecated/detections}/domain_account_discovery_with_net_app.yml (100%)
rename {detections/deprecated => deprecated/detections}/domain_group_discovery_with_net.yml (100%)
rename {detections/deprecated => deprecated/detections}/dump_lsass_via_procdump_rename.yml (100%)
rename {detections/deprecated => deprecated/detections}/ec2_instance_modified_with_previously_unseen_user.yml (100%)
rename {detections/deprecated => deprecated/detections}/ec2_instance_started_in_previously_unseen_region.yml (100%)
rename {detections/deprecated => deprecated/detections}/ec2_instance_started_with_previously_unseen_ami.yml (100%)
rename {detections/deprecated => deprecated/detections}/ec2_instance_started_with_previously_unseen_instance_type.yml (100%)
rename {detections/deprecated => deprecated/detections}/ec2_instance_started_with_previously_unseen_user.yml (100%)
rename {detections/deprecated => deprecated/detections}/elevated_group_discovery_with_net.yml (100%)
rename {detections/deprecated => deprecated/detections}/excel_spawning_powershell.yml (100%)
rename {detections/deprecated => deprecated/detections}/excel_spawning_windows_script_host.yml (100%)
rename {detections/deprecated => deprecated/detections}/excessive_service_stop_attempt.yml (100%)
rename {detections/deprecated => deprecated/detections}/excessive_usage_of_net_app.yml (100%)
rename {detections/deprecated => deprecated/detections}/execution_of_file_with_spaces_before_extension.yml (100%)
rename {detections/deprecated => deprecated/detections}/extended_period_without_successful_netbackup_backups.yml (100%)
rename {detections/deprecated => deprecated/detections}/extraction_of_registry_hives.yml (100%)
rename {detections/deprecated => deprecated/detections}/first_time_seen_command_line_argument.yml (100%)
rename {detections/deprecated => deprecated/detections}/gcp_detect_accounts_with_high_risk_roles_by_project.yml (100%)
rename {detections/deprecated => deprecated/detections}/gcp_detect_high_risk_permissions_by_resource_and_account.yml (100%)
rename {detections/deprecated => deprecated/detections}/gcp_detect_oauth_token_abuse.yml (100%)
rename {detections/deprecated => deprecated/detections}/gcp_kubernetes_cluster_scan_detection.yml (100%)
rename {detections/deprecated => deprecated/detections}/identify_new_user_accounts.yml (100%)
rename {detections/deprecated => deprecated/detections}/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml (100%)
rename {detections/deprecated => deprecated/detections}/kubernetes_aws_detect_rbac_authorization_by_account.yml (100%)
rename {detections/deprecated => deprecated/detections}/kubernetes_aws_detect_sensitive_role_access.yml (100%)
rename {detections/deprecated => deprecated/detections}/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml (100%)
rename {detections/deprecated => deprecated/detections}/kubernetes_azure_active_service_accounts_by_pod_namespace.yml (100%)
rename {detections/deprecated => deprecated/detections}/kubernetes_azure_detect_rbac_authorization_by_account.yml (100%)
rename {detections/deprecated => deprecated/detections}/kubernetes_azure_detect_sensitive_object_access.yml (100%)
rename {detections/deprecated => deprecated/detections}/kubernetes_azure_detect_sensitive_role_access.yml (100%)
rename {detections/deprecated => deprecated/detections}/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml (100%)
rename {detections/deprecated => deprecated/detections}/kubernetes_azure_detect_suspicious_kubectl_calls.yml (100%)
rename {detections/deprecated => deprecated/detections}/kubernetes_azure_pod_scan_fingerprint.yml (100%)
rename {detections/deprecated => deprecated/detections}/kubernetes_azure_scan_fingerprint.yml (100%)
rename {detections/deprecated => deprecated/detections}/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml (100%)
rename {detections/deprecated => deprecated/detections}/kubernetes_gcp_detect_rbac_authorizations_by_account.yml (100%)
rename {detections/deprecated => deprecated/detections}/kubernetes_gcp_detect_sensitive_object_access.yml (100%)
rename {detections/deprecated => deprecated/detections}/kubernetes_gcp_detect_sensitive_role_access.yml (100%)
rename {detections/deprecated => deprecated/detections}/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml (100%)
rename {detections/deprecated => deprecated/detections}/kubernetes_gcp_detect_suspicious_kubectl_calls.yml (100%)
rename {detections/deprecated => deprecated/detections}/linux_auditd_find_private_keys.yml (100%)
rename {detections/deprecated => deprecated/detections}/local_account_discovery_with_net.yml (100%)
rename {detections/deprecated => deprecated/detections}/monitor_dns_for_brand_abuse.yml (100%)
rename {detections/deprecated => deprecated/detections}/mshtml_module_load_in_office_product.yml (100%)
rename {detections/deprecated => deprecated/detections}/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml (100%)
rename {detections/deprecated => deprecated/detections}/net_localgroup_discovery.yml (100%)
rename {detections/deprecated => deprecated/detections}/network_connection_discovery_with_net.yml (100%)
rename {detections/deprecated => deprecated/detections}/o365_suspicious_admin_email_forwarding.yml (100%)
rename {detections/deprecated => deprecated/detections}/o365_suspicious_rights_delegation.yml (100%)
rename {detections/deprecated => deprecated/detections}/o365_suspicious_user_email_forwarding.yml (100%)
rename {detections/deprecated => deprecated/detections}/office_application_drop_executable.yml (100%)
rename {detections/deprecated => deprecated/detections}/office_application_spawn_regsvr32_process.yml (100%)
rename {detections/deprecated => deprecated/detections}/office_application_spawn_rundll32_process.yml (100%)
rename {detections/deprecated => deprecated/detections}/office_document_creating_schedule_task.yml (100%)
rename {detections/deprecated => deprecated/detections}/office_document_executing_macro_code.yml (100%)
rename {detections/deprecated => deprecated/detections}/office_document_spawned_child_process_to_download.yml (100%)
rename {detections/deprecated => deprecated/detections}/office_product_spawn_cmd_process.yml (100%)
rename {detections/deprecated => deprecated/detections}/office_product_spawning_bitsadmin.yml (100%)
rename {detections/deprecated => deprecated/detections}/office_product_spawning_certutil.yml (100%)
rename {detections/deprecated => deprecated/detections}/office_product_spawning_mshta.yml (100%)
rename {detections/deprecated => deprecated/detections}/office_product_spawning_rundll32_with_no_dll.yml (100%)
rename {detections/deprecated => deprecated/detections}/office_product_spawning_windows_script_host.yml (100%)
rename {detections/deprecated => deprecated/detections}/office_product_spawning_wmic.yml (100%)
rename {detections/deprecated => deprecated/detections}/office_product_writing_cab_or_inf.yml (100%)
rename {detections/deprecated => deprecated/detections}/office_spawning_control.yml (100%)
rename {detections/deprecated => deprecated/detections}/okta_account_locked_out.yml (100%)
rename {detections/deprecated => deprecated/detections}/okta_account_lockout_events.yml (100%)
rename {detections/deprecated => deprecated/detections}/okta_failed_sso_attempts.yml (100%)
rename {detections/deprecated => deprecated/detections}/okta_threatinsight_login_failure_with_high_unknown_users.yml (100%)
rename {detections/deprecated => deprecated/detections}/okta_threatinsight_suspected_passwordspray_attack.yml (100%)
rename {detections/deprecated => deprecated/detections}/okta_two_or_more_rejected_okta_pushes.yml (100%)
rename {detections/deprecated => deprecated/detections}/osquery_pack___coldroot_detection.yml (100%)
rename {detections/deprecated => deprecated/detections}/password_policy_discovery_with_net.yml (100%)
rename {detections/deprecated => deprecated/detections}/processes_created_by_netsh.yml (100%)
rename {detections/deprecated => deprecated/detections}/prohibited_software_on_endpoint.yml (100%)
rename {detections/deprecated => deprecated/detections}/reg_exe_used_to_hide_files_directories_via_registry_keys.yml (100%)
rename {detections/deprecated => deprecated/detections}/remote_registry_key_modifications.yml (100%)
rename {detections/deprecated => deprecated/detections}/remote_system_discovery_with_net.yml (100%)
rename {detections/deprecated => deprecated/detections}/scheduled_tasks_used_in_badrabbit_ransomware.yml (100%)
rename {detections/deprecated => deprecated/detections}/spectre_and_meltdown_vulnerable_systems.yml (100%)
rename {detections/deprecated => deprecated/detections}/suspicious_changes_to_file_associations.yml (100%)
rename {detections/deprecated => deprecated/detections}/suspicious_email___uba_anomaly.yml (100%)
rename {detections/deprecated => deprecated/detections}/suspicious_file_write.yml (100%)
rename {detections/deprecated => deprecated/detections}/suspicious_powershell_command_line_arguments.yml (100%)
rename {detections/deprecated => deprecated/detections}/suspicious_rundll32_rename.yml (100%)
rename {detections/deprecated => deprecated/detections}/suspicious_writes_to_system_volume_information.yml (100%)
rename {detections/deprecated => deprecated/detections}/uncommon_processes_on_endpoint.yml (100%)
rename {detections/deprecated => deprecated/detections}/unsigned_image_loaded_by_lsass.yml (100%)
rename {detections/deprecated => deprecated/detections}/unsuccessful_netbackup_backups.yml (100%)
rename {detections/deprecated => deprecated/detections}/web_fraud___account_harvesting.yml (100%)
rename {detections/deprecated => deprecated/detections}/web_fraud___anomalous_user_clickspeed.yml (100%)
rename {detections/deprecated => deprecated/detections}/web_fraud___password_sharing_across_accounts.yml (100%)
rename {detections/deprecated => deprecated/detections}/windows_command_shell_fetch_env_variables.yml (100%)
rename {detections/deprecated => deprecated/detections}/windows_connhost_exe_started_forcefully.yml (100%)
rename {detections/deprecated => deprecated/detections}/windows_dll_search_order_hijacking_hunt.yml (100%)
rename {detections/deprecated => deprecated/detections}/windows_hosts_file_modification.yml (100%)
rename {detections/deprecated => deprecated/detections}/windows_lateral_tool_transfer_remcom.yml (100%)
rename {detections/deprecated => deprecated/detections}/windows_modify_registry_reg_restore.yml (100%)
rename {detections/deprecated => deprecated/detections}/windows_msiexec_with_network_connections.yml (100%)
rename {detections/deprecated => deprecated/detections}/windows_network_share_interaction_with_net.yml (100%)
rename {detections/deprecated => deprecated/detections}/windows_office_product_spawning_msdt.yml (100%)
rename {detections/deprecated => deprecated/detections}/windows_query_registry_reg_save.yml (100%)
rename {detections/deprecated => deprecated/detections}/windows_service_stop_via_net__and_sc_application.yml (100%)
rename {detections/deprecated => deprecated/detections}/windows_valid_account_with_never_expires_password.yml (100%)
rename {detections/deprecated => deprecated/detections}/winword_spawning_cmd.yml (100%)
rename {detections/deprecated => deprecated/detections}/winword_spawning_powershell.yml (100%)
rename {detections/deprecated => deprecated/detections}/winword_spawning_windows_script_host.yml (100%)
diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml b/deprecated/detections/abnormally_high_aws_instances_launched_by_user.yml
similarity index 100%
rename from detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml
rename to deprecated/detections/abnormally_high_aws_instances_launched_by_user.yml
diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml b/deprecated/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml
similarity index 100%
rename from detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml
rename to deprecated/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml
diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml b/deprecated/detections/abnormally_high_aws_instances_terminated_by_user.yml
similarity index 100%
rename from detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml
rename to deprecated/detections/abnormally_high_aws_instances_terminated_by_user.yml
diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml b/deprecated/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml
similarity index 100%
rename from detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml
rename to deprecated/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml
diff --git a/detections/deprecated/account_discovery_with_net_app.yml b/deprecated/detections/account_discovery_with_net_app.yml
similarity index 100%
rename from detections/deprecated/account_discovery_with_net_app.yml
rename to deprecated/detections/account_discovery_with_net_app.yml
diff --git a/detections/deprecated/asl_aws_createaccesskey.yml b/deprecated/detections/asl_aws_createaccesskey.yml
similarity index 100%
rename from detections/deprecated/asl_aws_createaccesskey.yml
rename to deprecated/detections/asl_aws_createaccesskey.yml
diff --git a/detections/deprecated/asl_aws_excessive_security_scanning.yml b/deprecated/detections/asl_aws_excessive_security_scanning.yml
similarity index 100%
rename from detections/deprecated/asl_aws_excessive_security_scanning.yml
rename to deprecated/detections/asl_aws_excessive_security_scanning.yml
diff --git a/detections/deprecated/asl_aws_password_policy_changes.yml b/deprecated/detections/asl_aws_password_policy_changes.yml
similarity index 100%
rename from detections/deprecated/asl_aws_password_policy_changes.yml
rename to deprecated/detections/asl_aws_password_policy_changes.yml
diff --git a/detections/deprecated/attempt_to_stop_security_service.yml b/deprecated/detections/attempt_to_stop_security_service.yml
similarity index 100%
rename from detections/deprecated/attempt_to_stop_security_service.yml
rename to deprecated/detections/attempt_to_stop_security_service.yml
diff --git a/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml b/deprecated/detections/attempted_credential_dump_from_registry_via_reg_exe.yml
similarity index 100%
rename from detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml
rename to deprecated/detections/attempted_credential_dump_from_registry_via_reg_exe.yml
diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_city.yml
similarity index 100%
rename from detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml
rename to deprecated/detections/aws_cloud_provisioning_from_previously_unseen_city.yml
diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_country.yml
similarity index 100%
rename from detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml
rename to deprecated/detections/aws_cloud_provisioning_from_previously_unseen_country.yml
diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml
similarity index 100%
rename from detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml
rename to deprecated/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml
diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_region.yml
similarity index 100%
rename from detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml
rename to deprecated/detections/aws_cloud_provisioning_from_previously_unseen_region.yml
diff --git a/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml b/deprecated/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml
similarity index 100%
rename from detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml
rename to deprecated/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml
diff --git a/detections/deprecated/change_default_file_association.yml b/deprecated/detections/change_default_file_association.yml
similarity index 100%
rename from detections/deprecated/change_default_file_association.yml
rename to deprecated/detections/change_default_file_association.yml
diff --git a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml b/deprecated/detections/clients_connecting_to_multiple_dns_servers.yml
similarity index 100%
rename from detections/deprecated/clients_connecting_to_multiple_dns_servers.yml
rename to deprecated/detections/clients_connecting_to_multiple_dns_servers.yml
diff --git a/detections/deprecated/cloud_network_access_control_list_deleted.yml b/deprecated/detections/cloud_network_access_control_list_deleted.yml
similarity index 100%
rename from detections/deprecated/cloud_network_access_control_list_deleted.yml
rename to deprecated/detections/cloud_network_access_control_list_deleted.yml
diff --git a/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml b/deprecated/detections/cmdline_tool_not_executed_in_cmd_shell.yml
similarity index 100%
rename from detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml
rename to deprecated/detections/cmdline_tool_not_executed_in_cmd_shell.yml
diff --git a/detections/deprecated/correlation_by_repository_and_risk.yml b/deprecated/detections/correlation_by_repository_and_risk.yml
similarity index 100%
rename from detections/deprecated/correlation_by_repository_and_risk.yml
rename to deprecated/detections/correlation_by_repository_and_risk.yml
diff --git a/detections/deprecated/correlation_by_user_and_risk.yml b/deprecated/detections/correlation_by_user_and_risk.yml
similarity index 100%
rename from detections/deprecated/correlation_by_user_and_risk.yml
rename to deprecated/detections/correlation_by_user_and_risk.yml
diff --git a/detections/deprecated/create_local_admin_accounts_using_net_exe.yml b/deprecated/detections/create_local_admin_accounts_using_net_exe.yml
similarity index 100%
rename from detections/deprecated/create_local_admin_accounts_using_net_exe.yml
rename to deprecated/detections/create_local_admin_accounts_using_net_exe.yml
diff --git a/detections/deprecated/deleting_of_net_users.yml b/deprecated/detections/deleting_of_net_users.yml
similarity index 100%
rename from detections/deprecated/deleting_of_net_users.yml
rename to deprecated/detections/deleting_of_net_users.yml
diff --git a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml b/deprecated/detections/detect_activity_related_to_pass_the_hash_attacks.yml
similarity index 100%
rename from detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml
rename to deprecated/detections/detect_activity_related_to_pass_the_hash_attacks.yml
diff --git a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml b/deprecated/detections/detect_api_activity_from_users_without_mfa.yml
similarity index 100%
rename from detections/deprecated/detect_api_activity_from_users_without_mfa.yml
rename to deprecated/detections/detect_api_activity_from_users_without_mfa.yml
diff --git a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml b/deprecated/detections/detect_aws_api_activities_from_unapproved_accounts.yml
similarity index 100%
rename from detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml
rename to deprecated/detections/detect_aws_api_activities_from_unapproved_accounts.yml
diff --git a/detections/deprecated/detect_critical_alerts_from_security_tools.yml b/deprecated/detections/detect_critical_alerts_from_security_tools.yml
similarity index 100%
rename from detections/deprecated/detect_critical_alerts_from_security_tools.yml
rename to deprecated/detections/detect_critical_alerts_from_security_tools.yml
diff --git a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml b/deprecated/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml
similarity index 100%
rename from detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml
rename to deprecated/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml
diff --git a/detections/deprecated/detect_long_dns_txt_record_response.yml b/deprecated/detections/detect_long_dns_txt_record_response.yml
similarity index 100%
rename from detections/deprecated/detect_long_dns_txt_record_response.yml
rename to deprecated/detections/detect_long_dns_txt_record_response.yml
diff --git a/detections/deprecated/detect_mimikatz_using_loaded_images.yml b/deprecated/detections/detect_mimikatz_using_loaded_images.yml
similarity index 100%
rename from detections/deprecated/detect_mimikatz_using_loaded_images.yml
rename to deprecated/detections/detect_mimikatz_using_loaded_images.yml
diff --git a/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml b/deprecated/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml
similarity index 100%
rename from detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml
rename to deprecated/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml
diff --git a/detections/deprecated/detect_new_api_calls_from_user_roles.yml b/deprecated/detections/detect_new_api_calls_from_user_roles.yml
similarity index 100%
rename from detections/deprecated/detect_new_api_calls_from_user_roles.yml
rename to deprecated/detections/detect_new_api_calls_from_user_roles.yml
diff --git a/detections/deprecated/detect_new_user_aws_console_login.yml b/deprecated/detections/detect_new_user_aws_console_login.yml
similarity index 100%
rename from detections/deprecated/detect_new_user_aws_console_login.yml
rename to deprecated/detections/detect_new_user_aws_console_login.yml
diff --git a/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml b/deprecated/detections/detect_processes_used_for_system_network_configuration_discovery.yml
similarity index 100%
rename from detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml
rename to deprecated/detections/detect_processes_used_for_system_network_configuration_discovery.yml
diff --git a/detections/deprecated/detect_spike_in_aws_api_activity.yml b/deprecated/detections/detect_spike_in_aws_api_activity.yml
similarity index 100%
rename from detections/deprecated/detect_spike_in_aws_api_activity.yml
rename to deprecated/detections/detect_spike_in_aws_api_activity.yml
diff --git a/detections/deprecated/detect_spike_in_network_acl_activity.yml b/deprecated/detections/detect_spike_in_network_acl_activity.yml
similarity index 100%
rename from detections/deprecated/detect_spike_in_network_acl_activity.yml
rename to deprecated/detections/detect_spike_in_network_acl_activity.yml
diff --git a/detections/deprecated/detect_spike_in_security_group_activity.yml b/deprecated/detections/detect_spike_in_security_group_activity.yml
similarity index 100%
rename from detections/deprecated/detect_spike_in_security_group_activity.yml
rename to deprecated/detections/detect_spike_in_security_group_activity.yml
diff --git a/detections/deprecated/detect_usb_device_insertion.yml b/deprecated/detections/detect_usb_device_insertion.yml
similarity index 100%
rename from detections/deprecated/detect_usb_device_insertion.yml
rename to deprecated/detections/detect_usb_device_insertion.yml
diff --git a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml b/deprecated/detections/detect_web_traffic_to_dynamic_domain_providers.yml
similarity index 100%
rename from detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml
rename to deprecated/detections/detect_web_traffic_to_dynamic_domain_providers.yml
diff --git a/detections/deprecated/detect_webshell_exploit_behavior.yml b/deprecated/detections/detect_webshell_exploit_behavior.yml
similarity index 100%
rename from detections/deprecated/detect_webshell_exploit_behavior.yml
rename to deprecated/detections/detect_webshell_exploit_behavior.yml
diff --git a/detections/deprecated/detection_of_dns_tunnels.yml b/deprecated/detections/detection_of_dns_tunnels.yml
similarity index 100%
rename from detections/deprecated/detection_of_dns_tunnels.yml
rename to deprecated/detections/detection_of_dns_tunnels.yml
diff --git a/detections/deprecated/disabling_net_user_account.yml b/deprecated/detections/disabling_net_user_account.yml
similarity index 100%
rename from detections/deprecated/disabling_net_user_account.yml
rename to deprecated/detections/disabling_net_user_account.yml
diff --git a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml b/deprecated/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml
similarity index 100%
rename from detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml
rename to deprecated/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml
diff --git a/detections/deprecated/dns_record_changed.yml b/deprecated/detections/dns_record_changed.yml
similarity index 100%
rename from detections/deprecated/dns_record_changed.yml
rename to deprecated/detections/dns_record_changed.yml
diff --git a/detections/deprecated/domain_account_discovery_with_net_app.yml b/deprecated/detections/domain_account_discovery_with_net_app.yml
similarity index 100%
rename from detections/deprecated/domain_account_discovery_with_net_app.yml
rename to deprecated/detections/domain_account_discovery_with_net_app.yml
diff --git a/detections/deprecated/domain_group_discovery_with_net.yml b/deprecated/detections/domain_group_discovery_with_net.yml
similarity index 100%
rename from detections/deprecated/domain_group_discovery_with_net.yml
rename to deprecated/detections/domain_group_discovery_with_net.yml
diff --git a/detections/deprecated/dump_lsass_via_procdump_rename.yml b/deprecated/detections/dump_lsass_via_procdump_rename.yml
similarity index 100%
rename from detections/deprecated/dump_lsass_via_procdump_rename.yml
rename to deprecated/detections/dump_lsass_via_procdump_rename.yml
diff --git a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml b/deprecated/detections/ec2_instance_modified_with_previously_unseen_user.yml
similarity index 100%
rename from detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml
rename to deprecated/detections/ec2_instance_modified_with_previously_unseen_user.yml
diff --git a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml b/deprecated/detections/ec2_instance_started_in_previously_unseen_region.yml
similarity index 100%
rename from detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml
rename to deprecated/detections/ec2_instance_started_in_previously_unseen_region.yml
diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml b/deprecated/detections/ec2_instance_started_with_previously_unseen_ami.yml
similarity index 100%
rename from detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml
rename to deprecated/detections/ec2_instance_started_with_previously_unseen_ami.yml
diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml b/deprecated/detections/ec2_instance_started_with_previously_unseen_instance_type.yml
similarity index 100%
rename from detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml
rename to deprecated/detections/ec2_instance_started_with_previously_unseen_instance_type.yml
diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml b/deprecated/detections/ec2_instance_started_with_previously_unseen_user.yml
similarity index 100%
rename from detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml
rename to deprecated/detections/ec2_instance_started_with_previously_unseen_user.yml
diff --git a/detections/deprecated/elevated_group_discovery_with_net.yml b/deprecated/detections/elevated_group_discovery_with_net.yml
similarity index 100%
rename from detections/deprecated/elevated_group_discovery_with_net.yml
rename to deprecated/detections/elevated_group_discovery_with_net.yml
diff --git a/detections/deprecated/excel_spawning_powershell.yml b/deprecated/detections/excel_spawning_powershell.yml
similarity index 100%
rename from detections/deprecated/excel_spawning_powershell.yml
rename to deprecated/detections/excel_spawning_powershell.yml
diff --git a/detections/deprecated/excel_spawning_windows_script_host.yml b/deprecated/detections/excel_spawning_windows_script_host.yml
similarity index 100%
rename from detections/deprecated/excel_spawning_windows_script_host.yml
rename to deprecated/detections/excel_spawning_windows_script_host.yml
diff --git a/detections/deprecated/excessive_service_stop_attempt.yml b/deprecated/detections/excessive_service_stop_attempt.yml
similarity index 100%
rename from detections/deprecated/excessive_service_stop_attempt.yml
rename to deprecated/detections/excessive_service_stop_attempt.yml
diff --git a/detections/deprecated/excessive_usage_of_net_app.yml b/deprecated/detections/excessive_usage_of_net_app.yml
similarity index 100%
rename from detections/deprecated/excessive_usage_of_net_app.yml
rename to deprecated/detections/excessive_usage_of_net_app.yml
diff --git a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml b/deprecated/detections/execution_of_file_with_spaces_before_extension.yml
similarity index 100%
rename from detections/deprecated/execution_of_file_with_spaces_before_extension.yml
rename to deprecated/detections/execution_of_file_with_spaces_before_extension.yml
diff --git a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml b/deprecated/detections/extended_period_without_successful_netbackup_backups.yml
similarity index 100%
rename from detections/deprecated/extended_period_without_successful_netbackup_backups.yml
rename to deprecated/detections/extended_period_without_successful_netbackup_backups.yml
diff --git a/detections/deprecated/extraction_of_registry_hives.yml b/deprecated/detections/extraction_of_registry_hives.yml
similarity index 100%
rename from detections/deprecated/extraction_of_registry_hives.yml
rename to deprecated/detections/extraction_of_registry_hives.yml
diff --git a/detections/deprecated/first_time_seen_command_line_argument.yml b/deprecated/detections/first_time_seen_command_line_argument.yml
similarity index 100%
rename from detections/deprecated/first_time_seen_command_line_argument.yml
rename to deprecated/detections/first_time_seen_command_line_argument.yml
diff --git a/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml b/deprecated/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml
similarity index 100%
rename from detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml
rename to deprecated/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml
diff --git a/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml b/deprecated/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml
similarity index 100%
rename from detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml
rename to deprecated/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml
diff --git a/detections/deprecated/gcp_detect_oauth_token_abuse.yml b/deprecated/detections/gcp_detect_oauth_token_abuse.yml
similarity index 100%
rename from detections/deprecated/gcp_detect_oauth_token_abuse.yml
rename to deprecated/detections/gcp_detect_oauth_token_abuse.yml
diff --git a/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml b/deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml
similarity index 100%
rename from detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml
rename to deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml
diff --git a/detections/deprecated/identify_new_user_accounts.yml b/deprecated/detections/identify_new_user_accounts.yml
similarity index 100%
rename from detections/deprecated/identify_new_user_accounts.yml
rename to deprecated/detections/identify_new_user_accounts.yml
diff --git a/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml b/deprecated/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml
similarity index 100%
rename from detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml
rename to deprecated/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml
diff --git a/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml b/deprecated/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml
similarity index 100%
rename from detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml
rename to deprecated/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml
diff --git a/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml b/deprecated/detections/kubernetes_aws_detect_sensitive_role_access.yml
similarity index 100%
rename from detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml
rename to deprecated/detections/kubernetes_aws_detect_sensitive_role_access.yml
diff --git a/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml b/deprecated/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml
similarity index 100%
rename from detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml
rename to deprecated/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml
diff --git a/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml b/deprecated/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml
similarity index 100%
rename from detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml
rename to deprecated/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml
diff --git a/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml b/deprecated/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml
similarity index 100%
rename from detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml
rename to deprecated/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml
diff --git a/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml b/deprecated/detections/kubernetes_azure_detect_sensitive_object_access.yml
similarity index 100%
rename from detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml
rename to deprecated/detections/kubernetes_azure_detect_sensitive_object_access.yml
diff --git a/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml b/deprecated/detections/kubernetes_azure_detect_sensitive_role_access.yml
similarity index 100%
rename from detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml
rename to deprecated/detections/kubernetes_azure_detect_sensitive_role_access.yml
diff --git a/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml b/deprecated/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml
similarity index 100%
rename from detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml
rename to deprecated/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml
diff --git a/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml b/deprecated/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml
similarity index 100%
rename from detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml
rename to deprecated/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml
diff --git a/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml b/deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml
similarity index 100%
rename from detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml
rename to deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml
diff --git a/detections/deprecated/kubernetes_azure_scan_fingerprint.yml b/deprecated/detections/kubernetes_azure_scan_fingerprint.yml
similarity index 100%
rename from detections/deprecated/kubernetes_azure_scan_fingerprint.yml
rename to deprecated/detections/kubernetes_azure_scan_fingerprint.yml
diff --git a/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml b/deprecated/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml
similarity index 100%
rename from detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml
rename to deprecated/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml
diff --git a/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml b/deprecated/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml
similarity index 100%
rename from detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml
rename to deprecated/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml
diff --git a/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml b/deprecated/detections/kubernetes_gcp_detect_sensitive_object_access.yml
similarity index 100%
rename from detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml
rename to deprecated/detections/kubernetes_gcp_detect_sensitive_object_access.yml
diff --git a/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml b/deprecated/detections/kubernetes_gcp_detect_sensitive_role_access.yml
similarity index 100%
rename from detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml
rename to deprecated/detections/kubernetes_gcp_detect_sensitive_role_access.yml
diff --git a/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml b/deprecated/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml
similarity index 100%
rename from detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml
rename to deprecated/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml
diff --git a/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml b/deprecated/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml
similarity index 100%
rename from detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml
rename to deprecated/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml
diff --git a/detections/deprecated/linux_auditd_find_private_keys.yml b/deprecated/detections/linux_auditd_find_private_keys.yml
similarity index 100%
rename from detections/deprecated/linux_auditd_find_private_keys.yml
rename to deprecated/detections/linux_auditd_find_private_keys.yml
diff --git a/detections/deprecated/local_account_discovery_with_net.yml b/deprecated/detections/local_account_discovery_with_net.yml
similarity index 100%
rename from detections/deprecated/local_account_discovery_with_net.yml
rename to deprecated/detections/local_account_discovery_with_net.yml
diff --git a/detections/deprecated/monitor_dns_for_brand_abuse.yml b/deprecated/detections/monitor_dns_for_brand_abuse.yml
similarity index 100%
rename from detections/deprecated/monitor_dns_for_brand_abuse.yml
rename to deprecated/detections/monitor_dns_for_brand_abuse.yml
diff --git a/detections/deprecated/mshtml_module_load_in_office_product.yml b/deprecated/detections/mshtml_module_load_in_office_product.yml
similarity index 100%
rename from detections/deprecated/mshtml_module_load_in_office_product.yml
rename to deprecated/detections/mshtml_module_load_in_office_product.yml
diff --git a/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml b/deprecated/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml
similarity index 100%
rename from detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml
rename to deprecated/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml
diff --git a/detections/deprecated/net_localgroup_discovery.yml b/deprecated/detections/net_localgroup_discovery.yml
similarity index 100%
rename from detections/deprecated/net_localgroup_discovery.yml
rename to deprecated/detections/net_localgroup_discovery.yml
diff --git a/detections/deprecated/network_connection_discovery_with_net.yml b/deprecated/detections/network_connection_discovery_with_net.yml
similarity index 100%
rename from detections/deprecated/network_connection_discovery_with_net.yml
rename to deprecated/detections/network_connection_discovery_with_net.yml
diff --git a/detections/deprecated/o365_suspicious_admin_email_forwarding.yml b/deprecated/detections/o365_suspicious_admin_email_forwarding.yml
similarity index 100%
rename from detections/deprecated/o365_suspicious_admin_email_forwarding.yml
rename to deprecated/detections/o365_suspicious_admin_email_forwarding.yml
diff --git a/detections/deprecated/o365_suspicious_rights_delegation.yml b/deprecated/detections/o365_suspicious_rights_delegation.yml
similarity index 100%
rename from detections/deprecated/o365_suspicious_rights_delegation.yml
rename to deprecated/detections/o365_suspicious_rights_delegation.yml
diff --git a/detections/deprecated/o365_suspicious_user_email_forwarding.yml b/deprecated/detections/o365_suspicious_user_email_forwarding.yml
similarity index 100%
rename from detections/deprecated/o365_suspicious_user_email_forwarding.yml
rename to deprecated/detections/o365_suspicious_user_email_forwarding.yml
diff --git a/detections/deprecated/office_application_drop_executable.yml b/deprecated/detections/office_application_drop_executable.yml
similarity index 100%
rename from detections/deprecated/office_application_drop_executable.yml
rename to deprecated/detections/office_application_drop_executable.yml
diff --git a/detections/deprecated/office_application_spawn_regsvr32_process.yml b/deprecated/detections/office_application_spawn_regsvr32_process.yml
similarity index 100%
rename from detections/deprecated/office_application_spawn_regsvr32_process.yml
rename to deprecated/detections/office_application_spawn_regsvr32_process.yml
diff --git a/detections/deprecated/office_application_spawn_rundll32_process.yml b/deprecated/detections/office_application_spawn_rundll32_process.yml
similarity index 100%
rename from detections/deprecated/office_application_spawn_rundll32_process.yml
rename to deprecated/detections/office_application_spawn_rundll32_process.yml
diff --git a/detections/deprecated/office_document_creating_schedule_task.yml b/deprecated/detections/office_document_creating_schedule_task.yml
similarity index 100%
rename from detections/deprecated/office_document_creating_schedule_task.yml
rename to deprecated/detections/office_document_creating_schedule_task.yml
diff --git a/detections/deprecated/office_document_executing_macro_code.yml b/deprecated/detections/office_document_executing_macro_code.yml
similarity index 100%
rename from detections/deprecated/office_document_executing_macro_code.yml
rename to deprecated/detections/office_document_executing_macro_code.yml
diff --git a/detections/deprecated/office_document_spawned_child_process_to_download.yml b/deprecated/detections/office_document_spawned_child_process_to_download.yml
similarity index 100%
rename from detections/deprecated/office_document_spawned_child_process_to_download.yml
rename to deprecated/detections/office_document_spawned_child_process_to_download.yml
diff --git a/detections/deprecated/office_product_spawn_cmd_process.yml b/deprecated/detections/office_product_spawn_cmd_process.yml
similarity index 100%
rename from detections/deprecated/office_product_spawn_cmd_process.yml
rename to deprecated/detections/office_product_spawn_cmd_process.yml
diff --git a/detections/deprecated/office_product_spawning_bitsadmin.yml b/deprecated/detections/office_product_spawning_bitsadmin.yml
similarity index 100%
rename from detections/deprecated/office_product_spawning_bitsadmin.yml
rename to deprecated/detections/office_product_spawning_bitsadmin.yml
diff --git a/detections/deprecated/office_product_spawning_certutil.yml b/deprecated/detections/office_product_spawning_certutil.yml
similarity index 100%
rename from detections/deprecated/office_product_spawning_certutil.yml
rename to deprecated/detections/office_product_spawning_certutil.yml
diff --git a/detections/deprecated/office_product_spawning_mshta.yml b/deprecated/detections/office_product_spawning_mshta.yml
similarity index 100%
rename from detections/deprecated/office_product_spawning_mshta.yml
rename to deprecated/detections/office_product_spawning_mshta.yml
diff --git a/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml b/deprecated/detections/office_product_spawning_rundll32_with_no_dll.yml
similarity index 100%
rename from detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml
rename to deprecated/detections/office_product_spawning_rundll32_with_no_dll.yml
diff --git a/detections/deprecated/office_product_spawning_windows_script_host.yml b/deprecated/detections/office_product_spawning_windows_script_host.yml
similarity index 100%
rename from detections/deprecated/office_product_spawning_windows_script_host.yml
rename to deprecated/detections/office_product_spawning_windows_script_host.yml
diff --git a/detections/deprecated/office_product_spawning_wmic.yml b/deprecated/detections/office_product_spawning_wmic.yml
similarity index 100%
rename from detections/deprecated/office_product_spawning_wmic.yml
rename to deprecated/detections/office_product_spawning_wmic.yml
diff --git a/detections/deprecated/office_product_writing_cab_or_inf.yml b/deprecated/detections/office_product_writing_cab_or_inf.yml
similarity index 100%
rename from detections/deprecated/office_product_writing_cab_or_inf.yml
rename to deprecated/detections/office_product_writing_cab_or_inf.yml
diff --git a/detections/deprecated/office_spawning_control.yml b/deprecated/detections/office_spawning_control.yml
similarity index 100%
rename from detections/deprecated/office_spawning_control.yml
rename to deprecated/detections/office_spawning_control.yml
diff --git a/detections/deprecated/okta_account_locked_out.yml b/deprecated/detections/okta_account_locked_out.yml
similarity index 100%
rename from detections/deprecated/okta_account_locked_out.yml
rename to deprecated/detections/okta_account_locked_out.yml
diff --git a/detections/deprecated/okta_account_lockout_events.yml b/deprecated/detections/okta_account_lockout_events.yml
similarity index 100%
rename from detections/deprecated/okta_account_lockout_events.yml
rename to deprecated/detections/okta_account_lockout_events.yml
diff --git a/detections/deprecated/okta_failed_sso_attempts.yml b/deprecated/detections/okta_failed_sso_attempts.yml
similarity index 100%
rename from detections/deprecated/okta_failed_sso_attempts.yml
rename to deprecated/detections/okta_failed_sso_attempts.yml
diff --git a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml b/deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml
similarity index 100%
rename from detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml
rename to deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml
diff --git a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml b/deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml
similarity index 100%
rename from detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml
rename to deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml
diff --git a/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml b/deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml
similarity index 100%
rename from detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml
rename to deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml
diff --git a/detections/deprecated/osquery_pack___coldroot_detection.yml b/deprecated/detections/osquery_pack___coldroot_detection.yml
similarity index 100%
rename from detections/deprecated/osquery_pack___coldroot_detection.yml
rename to deprecated/detections/osquery_pack___coldroot_detection.yml
diff --git a/detections/deprecated/password_policy_discovery_with_net.yml b/deprecated/detections/password_policy_discovery_with_net.yml
similarity index 100%
rename from detections/deprecated/password_policy_discovery_with_net.yml
rename to deprecated/detections/password_policy_discovery_with_net.yml
diff --git a/detections/deprecated/processes_created_by_netsh.yml b/deprecated/detections/processes_created_by_netsh.yml
similarity index 100%
rename from detections/deprecated/processes_created_by_netsh.yml
rename to deprecated/detections/processes_created_by_netsh.yml
diff --git a/detections/deprecated/prohibited_software_on_endpoint.yml b/deprecated/detections/prohibited_software_on_endpoint.yml
similarity index 100%
rename from detections/deprecated/prohibited_software_on_endpoint.yml
rename to deprecated/detections/prohibited_software_on_endpoint.yml
diff --git a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml b/deprecated/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml
similarity index 100%
rename from detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml
rename to deprecated/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml
diff --git a/detections/deprecated/remote_registry_key_modifications.yml b/deprecated/detections/remote_registry_key_modifications.yml
similarity index 100%
rename from detections/deprecated/remote_registry_key_modifications.yml
rename to deprecated/detections/remote_registry_key_modifications.yml
diff --git a/detections/deprecated/remote_system_discovery_with_net.yml b/deprecated/detections/remote_system_discovery_with_net.yml
similarity index 100%
rename from detections/deprecated/remote_system_discovery_with_net.yml
rename to deprecated/detections/remote_system_discovery_with_net.yml
diff --git a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml b/deprecated/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml
similarity index 100%
rename from detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml
rename to deprecated/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml
diff --git a/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml b/deprecated/detections/spectre_and_meltdown_vulnerable_systems.yml
similarity index 100%
rename from detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml
rename to deprecated/detections/spectre_and_meltdown_vulnerable_systems.yml
diff --git a/detections/deprecated/suspicious_changes_to_file_associations.yml b/deprecated/detections/suspicious_changes_to_file_associations.yml
similarity index 100%
rename from detections/deprecated/suspicious_changes_to_file_associations.yml
rename to deprecated/detections/suspicious_changes_to_file_associations.yml
diff --git a/detections/deprecated/suspicious_email___uba_anomaly.yml b/deprecated/detections/suspicious_email___uba_anomaly.yml
similarity index 100%
rename from detections/deprecated/suspicious_email___uba_anomaly.yml
rename to deprecated/detections/suspicious_email___uba_anomaly.yml
diff --git a/detections/deprecated/suspicious_file_write.yml b/deprecated/detections/suspicious_file_write.yml
similarity index 100%
rename from detections/deprecated/suspicious_file_write.yml
rename to deprecated/detections/suspicious_file_write.yml
diff --git a/detections/deprecated/suspicious_powershell_command_line_arguments.yml b/deprecated/detections/suspicious_powershell_command_line_arguments.yml
similarity index 100%
rename from detections/deprecated/suspicious_powershell_command_line_arguments.yml
rename to deprecated/detections/suspicious_powershell_command_line_arguments.yml
diff --git a/detections/deprecated/suspicious_rundll32_rename.yml b/deprecated/detections/suspicious_rundll32_rename.yml
similarity index 100%
rename from detections/deprecated/suspicious_rundll32_rename.yml
rename to deprecated/detections/suspicious_rundll32_rename.yml
diff --git a/detections/deprecated/suspicious_writes_to_system_volume_information.yml b/deprecated/detections/suspicious_writes_to_system_volume_information.yml
similarity index 100%
rename from detections/deprecated/suspicious_writes_to_system_volume_information.yml
rename to deprecated/detections/suspicious_writes_to_system_volume_information.yml
diff --git a/detections/deprecated/uncommon_processes_on_endpoint.yml b/deprecated/detections/uncommon_processes_on_endpoint.yml
similarity index 100%
rename from detections/deprecated/uncommon_processes_on_endpoint.yml
rename to deprecated/detections/uncommon_processes_on_endpoint.yml
diff --git a/detections/deprecated/unsigned_image_loaded_by_lsass.yml b/deprecated/detections/unsigned_image_loaded_by_lsass.yml
similarity index 100%
rename from detections/deprecated/unsigned_image_loaded_by_lsass.yml
rename to deprecated/detections/unsigned_image_loaded_by_lsass.yml
diff --git a/detections/deprecated/unsuccessful_netbackup_backups.yml b/deprecated/detections/unsuccessful_netbackup_backups.yml
similarity index 100%
rename from detections/deprecated/unsuccessful_netbackup_backups.yml
rename to deprecated/detections/unsuccessful_netbackup_backups.yml
diff --git a/detections/deprecated/web_fraud___account_harvesting.yml b/deprecated/detections/web_fraud___account_harvesting.yml
similarity index 100%
rename from detections/deprecated/web_fraud___account_harvesting.yml
rename to deprecated/detections/web_fraud___account_harvesting.yml
diff --git a/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml b/deprecated/detections/web_fraud___anomalous_user_clickspeed.yml
similarity index 100%
rename from detections/deprecated/web_fraud___anomalous_user_clickspeed.yml
rename to deprecated/detections/web_fraud___anomalous_user_clickspeed.yml
diff --git a/detections/deprecated/web_fraud___password_sharing_across_accounts.yml b/deprecated/detections/web_fraud___password_sharing_across_accounts.yml
similarity index 100%
rename from detections/deprecated/web_fraud___password_sharing_across_accounts.yml
rename to deprecated/detections/web_fraud___password_sharing_across_accounts.yml
diff --git a/detections/deprecated/windows_command_shell_fetch_env_variables.yml b/deprecated/detections/windows_command_shell_fetch_env_variables.yml
similarity index 100%
rename from detections/deprecated/windows_command_shell_fetch_env_variables.yml
rename to deprecated/detections/windows_command_shell_fetch_env_variables.yml
diff --git a/detections/deprecated/windows_connhost_exe_started_forcefully.yml b/deprecated/detections/windows_connhost_exe_started_forcefully.yml
similarity index 100%
rename from detections/deprecated/windows_connhost_exe_started_forcefully.yml
rename to deprecated/detections/windows_connhost_exe_started_forcefully.yml
diff --git a/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml b/deprecated/detections/windows_dll_search_order_hijacking_hunt.yml
similarity index 100%
rename from detections/deprecated/windows_dll_search_order_hijacking_hunt.yml
rename to deprecated/detections/windows_dll_search_order_hijacking_hunt.yml
diff --git a/detections/deprecated/windows_hosts_file_modification.yml b/deprecated/detections/windows_hosts_file_modification.yml
similarity index 100%
rename from detections/deprecated/windows_hosts_file_modification.yml
rename to deprecated/detections/windows_hosts_file_modification.yml
diff --git a/detections/deprecated/windows_lateral_tool_transfer_remcom.yml b/deprecated/detections/windows_lateral_tool_transfer_remcom.yml
similarity index 100%
rename from detections/deprecated/windows_lateral_tool_transfer_remcom.yml
rename to deprecated/detections/windows_lateral_tool_transfer_remcom.yml
diff --git a/detections/deprecated/windows_modify_registry_reg_restore.yml b/deprecated/detections/windows_modify_registry_reg_restore.yml
similarity index 100%
rename from detections/deprecated/windows_modify_registry_reg_restore.yml
rename to deprecated/detections/windows_modify_registry_reg_restore.yml
diff --git a/detections/deprecated/windows_msiexec_with_network_connections.yml b/deprecated/detections/windows_msiexec_with_network_connections.yml
similarity index 100%
rename from detections/deprecated/windows_msiexec_with_network_connections.yml
rename to deprecated/detections/windows_msiexec_with_network_connections.yml
diff --git a/detections/deprecated/windows_network_share_interaction_with_net.yml b/deprecated/detections/windows_network_share_interaction_with_net.yml
similarity index 100%
rename from detections/deprecated/windows_network_share_interaction_with_net.yml
rename to deprecated/detections/windows_network_share_interaction_with_net.yml
diff --git a/detections/deprecated/windows_office_product_spawning_msdt.yml b/deprecated/detections/windows_office_product_spawning_msdt.yml
similarity index 100%
rename from detections/deprecated/windows_office_product_spawning_msdt.yml
rename to deprecated/detections/windows_office_product_spawning_msdt.yml
diff --git a/detections/deprecated/windows_query_registry_reg_save.yml b/deprecated/detections/windows_query_registry_reg_save.yml
similarity index 100%
rename from detections/deprecated/windows_query_registry_reg_save.yml
rename to deprecated/detections/windows_query_registry_reg_save.yml
diff --git a/detections/deprecated/windows_service_stop_via_net__and_sc_application.yml b/deprecated/detections/windows_service_stop_via_net__and_sc_application.yml
similarity index 100%
rename from detections/deprecated/windows_service_stop_via_net__and_sc_application.yml
rename to deprecated/detections/windows_service_stop_via_net__and_sc_application.yml
diff --git a/detections/deprecated/windows_valid_account_with_never_expires_password.yml b/deprecated/detections/windows_valid_account_with_never_expires_password.yml
similarity index 100%
rename from detections/deprecated/windows_valid_account_with_never_expires_password.yml
rename to deprecated/detections/windows_valid_account_with_never_expires_password.yml
diff --git a/detections/deprecated/winword_spawning_cmd.yml b/deprecated/detections/winword_spawning_cmd.yml
similarity index 100%
rename from detections/deprecated/winword_spawning_cmd.yml
rename to deprecated/detections/winword_spawning_cmd.yml
diff --git a/detections/deprecated/winword_spawning_powershell.yml b/deprecated/detections/winword_spawning_powershell.yml
similarity index 100%
rename from detections/deprecated/winword_spawning_powershell.yml
rename to deprecated/detections/winword_spawning_powershell.yml
diff --git a/detections/deprecated/winword_spawning_windows_script_host.yml b/deprecated/detections/winword_spawning_windows_script_host.yml
similarity index 100%
rename from detections/deprecated/winword_spawning_windows_script_host.yml
rename to deprecated/detections/winword_spawning_windows_script_host.yml
From d99e6ef75b7c1b311d0b89e606e470bbd474c1fa Mon Sep 17 00:00:00 2001
From: research-bot
Date: Wed, 26 Feb 2025 11:06:36 -0800
Subject: [PATCH 13/67] other objects
---
.../add_prohibited_processes_to_enterprise_security.yml | 0
.../baselines}/baseline_of_api_calls_per_user_arn.yml | 0
...aseline_of_excessive_aws_instances_launched_by_user___mltk.yml | 0
...eline_of_excessive_aws_instances_terminated_by_user___mltk.yml | 0
.../previously_seen_api_call_per_user_roles_in_cloudtrail.yml | 0
.../previously_seen_aws_provisioning_activity_sources.yml | 0
.../baselines}/previously_seen_ec2_amis.yml | 0
.../baselines}/previously_seen_ec2_instance_types.yml | 0
.../baselines}/previously_seen_ec2_launches_by_user.yml | 0
.../baselines}/previously_seen_users_in_cloudtrail.yml | 0
.../baselines}/update_previously_seen_users_in_cloudtrail.yml | 0
.../investigations}/all_backup_logs_for_host.yml | 0
.../investigations}/amazon_eks_kubernetes_activity_by_src_ip.yml | 0
.../aws_investigate_security_hub_alerts_by_dest.yml | 0
.../aws_investigate_user_activities_by_accesskeyid.yml | 0
.../investigations}/aws_investigate_user_activities_by_arn.yml | 0
.../investigations}/aws_network_acl_details_from_id.yml | 0
.../aws_network_interface_details_via_resourceid.yml | 0
.../investigations}/aws_s3_bucket_details_via_bucketname.yml | 0
.../investigations}/gcp_kubernetes_activity_by_src_ip.yml | 0
.../investigations}/get_all_aws_activity_from_city.yml | 0
.../investigations}/get_all_aws_activity_from_country.yml | 0
.../investigations}/get_all_aws_activity_from_ip_address.yml | 0
.../investigations}/get_all_aws_activity_from_region.yml | 0
.../investigations}/get_backup_logs_for_endpoint.yml | 0
.../investigations}/get_certificate_logs_for_a_domain.yml | 0
.../investigations}/get_dns_server_history_for_a_host.yml | 0
.../investigations}/get_dns_traffic_ratio.yml | 0
.../investigations}/get_ec2_instance_details_by_instanceid.yml | 0
.../investigations}/get_ec2_launch_details.yml | 0
{investigations => deprecated/investigations}/get_email_info.yml | 0
.../investigations}/get_emails_from_specific_sender.yml | 0
.../get_first_occurrence_and_last_occurrence_of_a_mac_address.yml | 0
.../investigations}/get_history_of_email_sources.yml | 0
.../get_logon_rights_modifications_for_endpoint.yml | 0
.../investigations}/get_logon_rights_modifications_for_user.yml | 0
.../investigations}/get_notable_history.yml | 0
.../get_outbound_emails_to_hidden_cobra_threat_actors.yml | 0
.../investigations}/get_parent_process_info.yml | 0
.../investigations}/get_process_file_activity.yml | 0
.../investigations}/get_process_info.yml | 0
.../investigations}/get_process_information_for_port_activity.yml | 0
.../get_process_responsible_for_the_dns_traffic.yml | 0
.../investigations}/get_sysmon_wmi_activity_for_host.yml | 0
.../get_web_session_information_via_session_id.yml | 0
.../investigate_aws_activities_via_region_name.yml | 0
.../investigate_aws_user_activities_by_user_field.yml | 0
.../investigate_failed_logins_for_multiple_destinations.yml | 0
.../investigations}/investigate_network_traffic_from_src_ip.yml | 0
.../investigations}/investigate_okta_activity_by_app.yml | 0
.../investigations}/investigate_okta_activity_by_ip_address.yml | 0
.../investigations}/investigate_pass_the_hash_attempts.yml | 0
.../investigations}/investigate_pass_the_ticket_attempts.yml | 0
.../investigations}/investigate_previous_unseen_user.yml | 0
.../investigate_successful_remote_desktop_authentications.yml | 0
.../investigate_suspicious_strings_in_http_header.yml | 0
.../investigations}/investigate_user_activities_in_okta.yml | 0
.../investigations}/investigate_web_posts_from_src.yml | 0
58 files changed, 0 insertions(+), 0 deletions(-)
rename {baselines/deprecated => deprecated/baselines}/add_prohibited_processes_to_enterprise_security.yml (100%)
rename {baselines/deprecated => deprecated/baselines}/baseline_of_api_calls_per_user_arn.yml (100%)
rename {baselines/deprecated => deprecated/baselines}/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml (100%)
rename {baselines/deprecated => deprecated/baselines}/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml (100%)
rename {baselines/deprecated => deprecated/baselines}/previously_seen_api_call_per_user_roles_in_cloudtrail.yml (100%)
rename {baselines/deprecated => deprecated/baselines}/previously_seen_aws_provisioning_activity_sources.yml (100%)
rename {baselines/deprecated => deprecated/baselines}/previously_seen_ec2_amis.yml (100%)
rename {baselines/deprecated => deprecated/baselines}/previously_seen_ec2_instance_types.yml (100%)
rename {baselines/deprecated => deprecated/baselines}/previously_seen_ec2_launches_by_user.yml (100%)
rename {baselines/deprecated => deprecated/baselines}/previously_seen_users_in_cloudtrail.yml (100%)
rename {baselines/deprecated => deprecated/baselines}/update_previously_seen_users_in_cloudtrail.yml (100%)
rename {investigations => deprecated/investigations}/all_backup_logs_for_host.yml (100%)
rename {investigations => deprecated/investigations}/amazon_eks_kubernetes_activity_by_src_ip.yml (100%)
rename {investigations => deprecated/investigations}/aws_investigate_security_hub_alerts_by_dest.yml (100%)
rename {investigations => deprecated/investigations}/aws_investigate_user_activities_by_accesskeyid.yml (100%)
rename {investigations => deprecated/investigations}/aws_investigate_user_activities_by_arn.yml (100%)
rename {investigations => deprecated/investigations}/aws_network_acl_details_from_id.yml (100%)
rename {investigations => deprecated/investigations}/aws_network_interface_details_via_resourceid.yml (100%)
rename {investigations => deprecated/investigations}/aws_s3_bucket_details_via_bucketname.yml (100%)
rename {investigations => deprecated/investigations}/gcp_kubernetes_activity_by_src_ip.yml (100%)
rename {investigations => deprecated/investigations}/get_all_aws_activity_from_city.yml (100%)
rename {investigations => deprecated/investigations}/get_all_aws_activity_from_country.yml (100%)
rename {investigations => deprecated/investigations}/get_all_aws_activity_from_ip_address.yml (100%)
rename {investigations => deprecated/investigations}/get_all_aws_activity_from_region.yml (100%)
rename {investigations => deprecated/investigations}/get_backup_logs_for_endpoint.yml (100%)
rename {investigations => deprecated/investigations}/get_certificate_logs_for_a_domain.yml (100%)
rename {investigations => deprecated/investigations}/get_dns_server_history_for_a_host.yml (100%)
rename {investigations => deprecated/investigations}/get_dns_traffic_ratio.yml (100%)
rename {investigations => deprecated/investigations}/get_ec2_instance_details_by_instanceid.yml (100%)
rename {investigations => deprecated/investigations}/get_ec2_launch_details.yml (100%)
rename {investigations => deprecated/investigations}/get_email_info.yml (100%)
rename {investigations => deprecated/investigations}/get_emails_from_specific_sender.yml (100%)
rename {investigations => deprecated/investigations}/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml (100%)
rename {investigations => deprecated/investigations}/get_history_of_email_sources.yml (100%)
rename {investigations => deprecated/investigations}/get_logon_rights_modifications_for_endpoint.yml (100%)
rename {investigations => deprecated/investigations}/get_logon_rights_modifications_for_user.yml (100%)
rename {investigations => deprecated/investigations}/get_notable_history.yml (100%)
rename {investigations => deprecated/investigations}/get_outbound_emails_to_hidden_cobra_threat_actors.yml (100%)
rename {investigations => deprecated/investigations}/get_parent_process_info.yml (100%)
rename {investigations => deprecated/investigations}/get_process_file_activity.yml (100%)
rename {investigations => deprecated/investigations}/get_process_info.yml (100%)
rename {investigations => deprecated/investigations}/get_process_information_for_port_activity.yml (100%)
rename {investigations => deprecated/investigations}/get_process_responsible_for_the_dns_traffic.yml (100%)
rename {investigations => deprecated/investigations}/get_sysmon_wmi_activity_for_host.yml (100%)
rename {investigations => deprecated/investigations}/get_web_session_information_via_session_id.yml (100%)
rename {investigations => deprecated/investigations}/investigate_aws_activities_via_region_name.yml (100%)
rename {investigations => deprecated/investigations}/investigate_aws_user_activities_by_user_field.yml (100%)
rename {investigations => deprecated/investigations}/investigate_failed_logins_for_multiple_destinations.yml (100%)
rename {investigations => deprecated/investigations}/investigate_network_traffic_from_src_ip.yml (100%)
rename {investigations => deprecated/investigations}/investigate_okta_activity_by_app.yml (100%)
rename {investigations => deprecated/investigations}/investigate_okta_activity_by_ip_address.yml (100%)
rename {investigations => deprecated/investigations}/investigate_pass_the_hash_attempts.yml (100%)
rename {investigations => deprecated/investigations}/investigate_pass_the_ticket_attempts.yml (100%)
rename {investigations => deprecated/investigations}/investigate_previous_unseen_user.yml (100%)
rename {investigations => deprecated/investigations}/investigate_successful_remote_desktop_authentications.yml (100%)
rename {investigations => deprecated/investigations}/investigate_suspicious_strings_in_http_header.yml (100%)
rename {investigations => deprecated/investigations}/investigate_user_activities_in_okta.yml (100%)
rename {investigations => deprecated/investigations}/investigate_web_posts_from_src.yml (100%)
diff --git a/baselines/deprecated/add_prohibited_processes_to_enterprise_security.yml b/deprecated/baselines/add_prohibited_processes_to_enterprise_security.yml
similarity index 100%
rename from baselines/deprecated/add_prohibited_processes_to_enterprise_security.yml
rename to deprecated/baselines/add_prohibited_processes_to_enterprise_security.yml
diff --git a/baselines/deprecated/baseline_of_api_calls_per_user_arn.yml b/deprecated/baselines/baseline_of_api_calls_per_user_arn.yml
similarity index 100%
rename from baselines/deprecated/baseline_of_api_calls_per_user_arn.yml
rename to deprecated/baselines/baseline_of_api_calls_per_user_arn.yml
diff --git a/baselines/deprecated/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml b/deprecated/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml
similarity index 100%
rename from baselines/deprecated/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml
rename to deprecated/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml
diff --git a/baselines/deprecated/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml b/deprecated/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml
similarity index 100%
rename from baselines/deprecated/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml
rename to deprecated/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml
diff --git a/baselines/deprecated/previously_seen_api_call_per_user_roles_in_cloudtrail.yml b/deprecated/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml
similarity index 100%
rename from baselines/deprecated/previously_seen_api_call_per_user_roles_in_cloudtrail.yml
rename to deprecated/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml
diff --git a/baselines/deprecated/previously_seen_aws_provisioning_activity_sources.yml b/deprecated/baselines/previously_seen_aws_provisioning_activity_sources.yml
similarity index 100%
rename from baselines/deprecated/previously_seen_aws_provisioning_activity_sources.yml
rename to deprecated/baselines/previously_seen_aws_provisioning_activity_sources.yml
diff --git a/baselines/deprecated/previously_seen_ec2_amis.yml b/deprecated/baselines/previously_seen_ec2_amis.yml
similarity index 100%
rename from baselines/deprecated/previously_seen_ec2_amis.yml
rename to deprecated/baselines/previously_seen_ec2_amis.yml
diff --git a/baselines/deprecated/previously_seen_ec2_instance_types.yml b/deprecated/baselines/previously_seen_ec2_instance_types.yml
similarity index 100%
rename from baselines/deprecated/previously_seen_ec2_instance_types.yml
rename to deprecated/baselines/previously_seen_ec2_instance_types.yml
diff --git a/baselines/deprecated/previously_seen_ec2_launches_by_user.yml b/deprecated/baselines/previously_seen_ec2_launches_by_user.yml
similarity index 100%
rename from baselines/deprecated/previously_seen_ec2_launches_by_user.yml
rename to deprecated/baselines/previously_seen_ec2_launches_by_user.yml
diff --git a/baselines/deprecated/previously_seen_users_in_cloudtrail.yml b/deprecated/baselines/previously_seen_users_in_cloudtrail.yml
similarity index 100%
rename from baselines/deprecated/previously_seen_users_in_cloudtrail.yml
rename to deprecated/baselines/previously_seen_users_in_cloudtrail.yml
diff --git a/baselines/deprecated/update_previously_seen_users_in_cloudtrail.yml b/deprecated/baselines/update_previously_seen_users_in_cloudtrail.yml
similarity index 100%
rename from baselines/deprecated/update_previously_seen_users_in_cloudtrail.yml
rename to deprecated/baselines/update_previously_seen_users_in_cloudtrail.yml
diff --git a/investigations/all_backup_logs_for_host.yml b/deprecated/investigations/all_backup_logs_for_host.yml
similarity index 100%
rename from investigations/all_backup_logs_for_host.yml
rename to deprecated/investigations/all_backup_logs_for_host.yml
diff --git a/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml b/deprecated/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml
similarity index 100%
rename from investigations/amazon_eks_kubernetes_activity_by_src_ip.yml
rename to deprecated/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml
diff --git a/investigations/aws_investigate_security_hub_alerts_by_dest.yml b/deprecated/investigations/aws_investigate_security_hub_alerts_by_dest.yml
similarity index 100%
rename from investigations/aws_investigate_security_hub_alerts_by_dest.yml
rename to deprecated/investigations/aws_investigate_security_hub_alerts_by_dest.yml
diff --git a/investigations/aws_investigate_user_activities_by_accesskeyid.yml b/deprecated/investigations/aws_investigate_user_activities_by_accesskeyid.yml
similarity index 100%
rename from investigations/aws_investigate_user_activities_by_accesskeyid.yml
rename to deprecated/investigations/aws_investigate_user_activities_by_accesskeyid.yml
diff --git a/investigations/aws_investigate_user_activities_by_arn.yml b/deprecated/investigations/aws_investigate_user_activities_by_arn.yml
similarity index 100%
rename from investigations/aws_investigate_user_activities_by_arn.yml
rename to deprecated/investigations/aws_investigate_user_activities_by_arn.yml
diff --git a/investigations/aws_network_acl_details_from_id.yml b/deprecated/investigations/aws_network_acl_details_from_id.yml
similarity index 100%
rename from investigations/aws_network_acl_details_from_id.yml
rename to deprecated/investigations/aws_network_acl_details_from_id.yml
diff --git a/investigations/aws_network_interface_details_via_resourceid.yml b/deprecated/investigations/aws_network_interface_details_via_resourceid.yml
similarity index 100%
rename from investigations/aws_network_interface_details_via_resourceid.yml
rename to deprecated/investigations/aws_network_interface_details_via_resourceid.yml
diff --git a/investigations/aws_s3_bucket_details_via_bucketname.yml b/deprecated/investigations/aws_s3_bucket_details_via_bucketname.yml
similarity index 100%
rename from investigations/aws_s3_bucket_details_via_bucketname.yml
rename to deprecated/investigations/aws_s3_bucket_details_via_bucketname.yml
diff --git a/investigations/gcp_kubernetes_activity_by_src_ip.yml b/deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml
similarity index 100%
rename from investigations/gcp_kubernetes_activity_by_src_ip.yml
rename to deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml
diff --git a/investigations/get_all_aws_activity_from_city.yml b/deprecated/investigations/get_all_aws_activity_from_city.yml
similarity index 100%
rename from investigations/get_all_aws_activity_from_city.yml
rename to deprecated/investigations/get_all_aws_activity_from_city.yml
diff --git a/investigations/get_all_aws_activity_from_country.yml b/deprecated/investigations/get_all_aws_activity_from_country.yml
similarity index 100%
rename from investigations/get_all_aws_activity_from_country.yml
rename to deprecated/investigations/get_all_aws_activity_from_country.yml
diff --git a/investigations/get_all_aws_activity_from_ip_address.yml b/deprecated/investigations/get_all_aws_activity_from_ip_address.yml
similarity index 100%
rename from investigations/get_all_aws_activity_from_ip_address.yml
rename to deprecated/investigations/get_all_aws_activity_from_ip_address.yml
diff --git a/investigations/get_all_aws_activity_from_region.yml b/deprecated/investigations/get_all_aws_activity_from_region.yml
similarity index 100%
rename from investigations/get_all_aws_activity_from_region.yml
rename to deprecated/investigations/get_all_aws_activity_from_region.yml
diff --git a/investigations/get_backup_logs_for_endpoint.yml b/deprecated/investigations/get_backup_logs_for_endpoint.yml
similarity index 100%
rename from investigations/get_backup_logs_for_endpoint.yml
rename to deprecated/investigations/get_backup_logs_for_endpoint.yml
diff --git a/investigations/get_certificate_logs_for_a_domain.yml b/deprecated/investigations/get_certificate_logs_for_a_domain.yml
similarity index 100%
rename from investigations/get_certificate_logs_for_a_domain.yml
rename to deprecated/investigations/get_certificate_logs_for_a_domain.yml
diff --git a/investigations/get_dns_server_history_for_a_host.yml b/deprecated/investigations/get_dns_server_history_for_a_host.yml
similarity index 100%
rename from investigations/get_dns_server_history_for_a_host.yml
rename to deprecated/investigations/get_dns_server_history_for_a_host.yml
diff --git a/investigations/get_dns_traffic_ratio.yml b/deprecated/investigations/get_dns_traffic_ratio.yml
similarity index 100%
rename from investigations/get_dns_traffic_ratio.yml
rename to deprecated/investigations/get_dns_traffic_ratio.yml
diff --git a/investigations/get_ec2_instance_details_by_instanceid.yml b/deprecated/investigations/get_ec2_instance_details_by_instanceid.yml
similarity index 100%
rename from investigations/get_ec2_instance_details_by_instanceid.yml
rename to deprecated/investigations/get_ec2_instance_details_by_instanceid.yml
diff --git a/investigations/get_ec2_launch_details.yml b/deprecated/investigations/get_ec2_launch_details.yml
similarity index 100%
rename from investigations/get_ec2_launch_details.yml
rename to deprecated/investigations/get_ec2_launch_details.yml
diff --git a/investigations/get_email_info.yml b/deprecated/investigations/get_email_info.yml
similarity index 100%
rename from investigations/get_email_info.yml
rename to deprecated/investigations/get_email_info.yml
diff --git a/investigations/get_emails_from_specific_sender.yml b/deprecated/investigations/get_emails_from_specific_sender.yml
similarity index 100%
rename from investigations/get_emails_from_specific_sender.yml
rename to deprecated/investigations/get_emails_from_specific_sender.yml
diff --git a/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml b/deprecated/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml
similarity index 100%
rename from investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml
rename to deprecated/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml
diff --git a/investigations/get_history_of_email_sources.yml b/deprecated/investigations/get_history_of_email_sources.yml
similarity index 100%
rename from investigations/get_history_of_email_sources.yml
rename to deprecated/investigations/get_history_of_email_sources.yml
diff --git a/investigations/get_logon_rights_modifications_for_endpoint.yml b/deprecated/investigations/get_logon_rights_modifications_for_endpoint.yml
similarity index 100%
rename from investigations/get_logon_rights_modifications_for_endpoint.yml
rename to deprecated/investigations/get_logon_rights_modifications_for_endpoint.yml
diff --git a/investigations/get_logon_rights_modifications_for_user.yml b/deprecated/investigations/get_logon_rights_modifications_for_user.yml
similarity index 100%
rename from investigations/get_logon_rights_modifications_for_user.yml
rename to deprecated/investigations/get_logon_rights_modifications_for_user.yml
diff --git a/investigations/get_notable_history.yml b/deprecated/investigations/get_notable_history.yml
similarity index 100%
rename from investigations/get_notable_history.yml
rename to deprecated/investigations/get_notable_history.yml
diff --git a/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml b/deprecated/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml
similarity index 100%
rename from investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml
rename to deprecated/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml
diff --git a/investigations/get_parent_process_info.yml b/deprecated/investigations/get_parent_process_info.yml
similarity index 100%
rename from investigations/get_parent_process_info.yml
rename to deprecated/investigations/get_parent_process_info.yml
diff --git a/investigations/get_process_file_activity.yml b/deprecated/investigations/get_process_file_activity.yml
similarity index 100%
rename from investigations/get_process_file_activity.yml
rename to deprecated/investigations/get_process_file_activity.yml
diff --git a/investigations/get_process_info.yml b/deprecated/investigations/get_process_info.yml
similarity index 100%
rename from investigations/get_process_info.yml
rename to deprecated/investigations/get_process_info.yml
diff --git a/investigations/get_process_information_for_port_activity.yml b/deprecated/investigations/get_process_information_for_port_activity.yml
similarity index 100%
rename from investigations/get_process_information_for_port_activity.yml
rename to deprecated/investigations/get_process_information_for_port_activity.yml
diff --git a/investigations/get_process_responsible_for_the_dns_traffic.yml b/deprecated/investigations/get_process_responsible_for_the_dns_traffic.yml
similarity index 100%
rename from investigations/get_process_responsible_for_the_dns_traffic.yml
rename to deprecated/investigations/get_process_responsible_for_the_dns_traffic.yml
diff --git a/investigations/get_sysmon_wmi_activity_for_host.yml b/deprecated/investigations/get_sysmon_wmi_activity_for_host.yml
similarity index 100%
rename from investigations/get_sysmon_wmi_activity_for_host.yml
rename to deprecated/investigations/get_sysmon_wmi_activity_for_host.yml
diff --git a/investigations/get_web_session_information_via_session_id.yml b/deprecated/investigations/get_web_session_information_via_session_id.yml
similarity index 100%
rename from investigations/get_web_session_information_via_session_id.yml
rename to deprecated/investigations/get_web_session_information_via_session_id.yml
diff --git a/investigations/investigate_aws_activities_via_region_name.yml b/deprecated/investigations/investigate_aws_activities_via_region_name.yml
similarity index 100%
rename from investigations/investigate_aws_activities_via_region_name.yml
rename to deprecated/investigations/investigate_aws_activities_via_region_name.yml
diff --git a/investigations/investigate_aws_user_activities_by_user_field.yml b/deprecated/investigations/investigate_aws_user_activities_by_user_field.yml
similarity index 100%
rename from investigations/investigate_aws_user_activities_by_user_field.yml
rename to deprecated/investigations/investigate_aws_user_activities_by_user_field.yml
diff --git a/investigations/investigate_failed_logins_for_multiple_destinations.yml b/deprecated/investigations/investigate_failed_logins_for_multiple_destinations.yml
similarity index 100%
rename from investigations/investigate_failed_logins_for_multiple_destinations.yml
rename to deprecated/investigations/investigate_failed_logins_for_multiple_destinations.yml
diff --git a/investigations/investigate_network_traffic_from_src_ip.yml b/deprecated/investigations/investigate_network_traffic_from_src_ip.yml
similarity index 100%
rename from investigations/investigate_network_traffic_from_src_ip.yml
rename to deprecated/investigations/investigate_network_traffic_from_src_ip.yml
diff --git a/investigations/investigate_okta_activity_by_app.yml b/deprecated/investigations/investigate_okta_activity_by_app.yml
similarity index 100%
rename from investigations/investigate_okta_activity_by_app.yml
rename to deprecated/investigations/investigate_okta_activity_by_app.yml
diff --git a/investigations/investigate_okta_activity_by_ip_address.yml b/deprecated/investigations/investigate_okta_activity_by_ip_address.yml
similarity index 100%
rename from investigations/investigate_okta_activity_by_ip_address.yml
rename to deprecated/investigations/investigate_okta_activity_by_ip_address.yml
diff --git a/investigations/investigate_pass_the_hash_attempts.yml b/deprecated/investigations/investigate_pass_the_hash_attempts.yml
similarity index 100%
rename from investigations/investigate_pass_the_hash_attempts.yml
rename to deprecated/investigations/investigate_pass_the_hash_attempts.yml
diff --git a/investigations/investigate_pass_the_ticket_attempts.yml b/deprecated/investigations/investigate_pass_the_ticket_attempts.yml
similarity index 100%
rename from investigations/investigate_pass_the_ticket_attempts.yml
rename to deprecated/investigations/investigate_pass_the_ticket_attempts.yml
diff --git a/investigations/investigate_previous_unseen_user.yml b/deprecated/investigations/investigate_previous_unseen_user.yml
similarity index 100%
rename from investigations/investigate_previous_unseen_user.yml
rename to deprecated/investigations/investigate_previous_unseen_user.yml
diff --git a/investigations/investigate_successful_remote_desktop_authentications.yml b/deprecated/investigations/investigate_successful_remote_desktop_authentications.yml
similarity index 100%
rename from investigations/investigate_successful_remote_desktop_authentications.yml
rename to deprecated/investigations/investigate_successful_remote_desktop_authentications.yml
diff --git a/investigations/investigate_suspicious_strings_in_http_header.yml b/deprecated/investigations/investigate_suspicious_strings_in_http_header.yml
similarity index 100%
rename from investigations/investigate_suspicious_strings_in_http_header.yml
rename to deprecated/investigations/investigate_suspicious_strings_in_http_header.yml
diff --git a/investigations/investigate_user_activities_in_okta.yml b/deprecated/investigations/investigate_user_activities_in_okta.yml
similarity index 100%
rename from investigations/investigate_user_activities_in_okta.yml
rename to deprecated/investigations/investigate_user_activities_in_okta.yml
diff --git a/investigations/investigate_web_posts_from_src.yml b/deprecated/investigations/investigate_web_posts_from_src.yml
similarity index 100%
rename from investigations/investigate_web_posts_from_src.yml
rename to deprecated/investigations/investigate_web_posts_from_src.yml
From 0ef5bfc0d26fb3452dddb4d57fa6817b895d2053 Mon Sep 17 00:00:00 2001
From: research-bot
Date: Wed, 26 Feb 2025 11:36:09 -0800
Subject: [PATCH 14/67] updating files after vaslidate
---
.../baselines}/monitor_successful_backups.yml | 6 +++---
.../baselines}/monitor_unsuccessful_backups.yml | 6 +++---
.../baselines}/previously_seen_aws_regions.yml | 6 +++---
.../previously_seen_ec2_modifications_by_user.yml | 6 +++---
.../systems_ready_for_spectre_meltdown_windows_patch.yml | 6 +++---
.../deprecated => deprecated/stories}/aws_cryptomining.yml | 0
.../stories}/aws_suspicious_provisioning_activities.yml | 0
.../stories}/common_phishing_frameworks.yml | 0
.../container_implantation_monitoring_and_investigation.yml | 0
.../deprecated => deprecated/stories}/host_redirection.yml | 0
.../stories}/kubernetes_sensitive_role_activity.yml | 0
.../deprecated => deprecated/stories}/lateral_movement.yml | 0
.../stories}/monitor_backup_solution.yml | 0
.../stories}/monitor_for_unauthorized_software.yml | 0
.../stories}/office_365_detections.yml | 0
.../stories}/spectre_and_meltdown_vulnerabilities.yml | 0
.../stories}/suspicious_aws_ec2_activities.yml | 0
.../stories}/unusual_aws_ec2_modifications.yml | 0
.../stories}/web_fraud_detection.yml | 0
detections/endpoint/attacker_tools_on_endpoint.yml | 3 +--
20 files changed, 16 insertions(+), 17 deletions(-)
rename {baselines => deprecated/baselines}/monitor_successful_backups.yml (94%)
rename {baselines => deprecated/baselines}/monitor_unsuccessful_backups.yml (94%)
rename {baselines => deprecated/baselines}/previously_seen_aws_regions.yml (95%)
rename {baselines => deprecated/baselines}/previously_seen_ec2_modifications_by_user.yml (95%)
rename {baselines => deprecated/baselines}/systems_ready_for_spectre_meltdown_windows_patch.yml (96%)
rename {stories/deprecated => deprecated/stories}/aws_cryptomining.yml (100%)
rename {stories/deprecated => deprecated/stories}/aws_suspicious_provisioning_activities.yml (100%)
rename {stories/deprecated => deprecated/stories}/common_phishing_frameworks.yml (100%)
rename {stories/deprecated => deprecated/stories}/container_implantation_monitoring_and_investigation.yml (100%)
rename {stories/deprecated => deprecated/stories}/host_redirection.yml (100%)
rename {stories/deprecated => deprecated/stories}/kubernetes_sensitive_role_activity.yml (100%)
rename {stories/deprecated => deprecated/stories}/lateral_movement.yml (100%)
rename {stories/deprecated => deprecated/stories}/monitor_backup_solution.yml (100%)
rename {stories/deprecated => deprecated/stories}/monitor_for_unauthorized_software.yml (100%)
rename {stories/deprecated => deprecated/stories}/office_365_detections.yml (100%)
rename {stories/deprecated => deprecated/stories}/spectre_and_meltdown_vulnerabilities.yml (100%)
rename {stories/deprecated => deprecated/stories}/suspicious_aws_ec2_activities.yml (100%)
rename {stories/deprecated => deprecated/stories}/unusual_aws_ec2_modifications.yml (100%)
rename {stories/deprecated => deprecated/stories}/web_fraud_detection.yml (100%)
diff --git a/baselines/monitor_successful_backups.yml b/deprecated/baselines/monitor_successful_backups.yml
similarity index 94%
rename from baselines/monitor_successful_backups.yml
rename to deprecated/baselines/monitor_successful_backups.yml
index fe0c140a5a..f178992d32 100644
--- a/baselines/monitor_successful_backups.yml
+++ b/deprecated/baselines/monitor_successful_backups.yml
@@ -1,10 +1,10 @@
name: Monitor Successful Backups
id: b4d0dfb2-2195-4f6e-93a3-48468ed9734e
-version: 1
-date: '2017-09-12'
+version: 2
+date: '2025-02-27'
author: David Dorsey, Splunk
type: Baseline
-status: production
+status: deprecated
description: This search is intended to give you a feel for how often successful backups
are conducted in your environment. Fluctuations in these numbers will allow you
to determine when you should investigate.
diff --git a/baselines/monitor_unsuccessful_backups.yml b/deprecated/baselines/monitor_unsuccessful_backups.yml
similarity index 94%
rename from baselines/monitor_unsuccessful_backups.yml
rename to deprecated/baselines/monitor_unsuccessful_backups.yml
index 83195cbae0..bd694ee2b0 100644
--- a/baselines/monitor_unsuccessful_backups.yml
+++ b/deprecated/baselines/monitor_unsuccessful_backups.yml
@@ -1,10 +1,10 @@
name: Monitor Unsuccessful Backups
id: b2178fed-592f-492b-b851-74161678aa56
-version: 1
-date: '2017-09-12'
+version: 2
+date: '2025-02-27'
author: David Dorsey, Splunk
type: Baseline
-status: production
+status: deprecated
description: This search is intended to give you a feel for how often backup failures
happen in your environments. Fluctuations in these numbers will allow you to determine
when you should investigate.
diff --git a/baselines/previously_seen_aws_regions.yml b/deprecated/baselines/previously_seen_aws_regions.yml
similarity index 95%
rename from baselines/previously_seen_aws_regions.yml
rename to deprecated/baselines/previously_seen_aws_regions.yml
index da7bd98582..24fd59423f 100644
--- a/baselines/previously_seen_aws_regions.yml
+++ b/deprecated/baselines/previously_seen_aws_regions.yml
@@ -1,10 +1,10 @@
name: Previously Seen AWS Regions
id: fc0edc95-ff2b-48b0-9f6f-63da3789fd63
-version: 1
-date: '2018-01-08'
+version: 2
+date: '2025-02-27'
author: Bhavin Patel, Splunk
type: Baseline
-status: production
+status: deprecated
description: This search looks for CloudTrail events where an AWS instance is started
and creates a baseline of most recent time (latest) and the first time (earliest)
we've seen this region in our dataset grouped by the value awsRegion for the last
diff --git a/baselines/previously_seen_ec2_modifications_by_user.yml b/deprecated/baselines/previously_seen_ec2_modifications_by_user.yml
similarity index 95%
rename from baselines/previously_seen_ec2_modifications_by_user.yml
rename to deprecated/baselines/previously_seen_ec2_modifications_by_user.yml
index fdf51c1460..426a1181ad 100644
--- a/baselines/previously_seen_ec2_modifications_by_user.yml
+++ b/deprecated/baselines/previously_seen_ec2_modifications_by_user.yml
@@ -1,10 +1,10 @@
name: Previously Seen EC2 Modifications By User
id: 4d69091b-d975-4267-85df-888bd41034eb
-version: 1
-date: '2018-04-05'
+version: 2
+date: '2025-02-27'
author: David Dorsey, Splunk
type: Baseline
-status: production
+status: deprecated
description: This search builds a table of previously seen ARNs that have launched
a EC2 instance.
search: '`cloudtrail` `ec2_modification_api_calls` errorCode=success | spath output=arn
diff --git a/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml b/deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml
similarity index 96%
rename from baselines/systems_ready_for_spectre_meltdown_windows_patch.yml
rename to deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml
index 7b26e9e44d..763652d0e0 100644
--- a/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml
+++ b/deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml
@@ -1,10 +1,10 @@
name: Systems Ready for Spectre-Meltdown Windows Patch
id: fc0edc95-ff2b-48b0-9f6f-63da3789fd61
-version: 1
-date: '2018-01-08'
+version: 2
+date: '2025-02-27'
author: David Dorsey, Splunk
type: Baseline
-status: production
+status: deprecated
description: Some AV applications can cause the Spectre/Meltdown patch for Windows
not to install successfully. This registry key is supposed to be created by the
AV engine when it has been patched to be able to handle the Windows patch. If this
diff --git a/stories/deprecated/aws_cryptomining.yml b/deprecated/stories/aws_cryptomining.yml
similarity index 100%
rename from stories/deprecated/aws_cryptomining.yml
rename to deprecated/stories/aws_cryptomining.yml
diff --git a/stories/deprecated/aws_suspicious_provisioning_activities.yml b/deprecated/stories/aws_suspicious_provisioning_activities.yml
similarity index 100%
rename from stories/deprecated/aws_suspicious_provisioning_activities.yml
rename to deprecated/stories/aws_suspicious_provisioning_activities.yml
diff --git a/stories/deprecated/common_phishing_frameworks.yml b/deprecated/stories/common_phishing_frameworks.yml
similarity index 100%
rename from stories/deprecated/common_phishing_frameworks.yml
rename to deprecated/stories/common_phishing_frameworks.yml
diff --git a/stories/deprecated/container_implantation_monitoring_and_investigation.yml b/deprecated/stories/container_implantation_monitoring_and_investigation.yml
similarity index 100%
rename from stories/deprecated/container_implantation_monitoring_and_investigation.yml
rename to deprecated/stories/container_implantation_monitoring_and_investigation.yml
diff --git a/stories/deprecated/host_redirection.yml b/deprecated/stories/host_redirection.yml
similarity index 100%
rename from stories/deprecated/host_redirection.yml
rename to deprecated/stories/host_redirection.yml
diff --git a/stories/deprecated/kubernetes_sensitive_role_activity.yml b/deprecated/stories/kubernetes_sensitive_role_activity.yml
similarity index 100%
rename from stories/deprecated/kubernetes_sensitive_role_activity.yml
rename to deprecated/stories/kubernetes_sensitive_role_activity.yml
diff --git a/stories/deprecated/lateral_movement.yml b/deprecated/stories/lateral_movement.yml
similarity index 100%
rename from stories/deprecated/lateral_movement.yml
rename to deprecated/stories/lateral_movement.yml
diff --git a/stories/deprecated/monitor_backup_solution.yml b/deprecated/stories/monitor_backup_solution.yml
similarity index 100%
rename from stories/deprecated/monitor_backup_solution.yml
rename to deprecated/stories/monitor_backup_solution.yml
diff --git a/stories/deprecated/monitor_for_unauthorized_software.yml b/deprecated/stories/monitor_for_unauthorized_software.yml
similarity index 100%
rename from stories/deprecated/monitor_for_unauthorized_software.yml
rename to deprecated/stories/monitor_for_unauthorized_software.yml
diff --git a/stories/deprecated/office_365_detections.yml b/deprecated/stories/office_365_detections.yml
similarity index 100%
rename from stories/deprecated/office_365_detections.yml
rename to deprecated/stories/office_365_detections.yml
diff --git a/stories/deprecated/spectre_and_meltdown_vulnerabilities.yml b/deprecated/stories/spectre_and_meltdown_vulnerabilities.yml
similarity index 100%
rename from stories/deprecated/spectre_and_meltdown_vulnerabilities.yml
rename to deprecated/stories/spectre_and_meltdown_vulnerabilities.yml
diff --git a/stories/deprecated/suspicious_aws_ec2_activities.yml b/deprecated/stories/suspicious_aws_ec2_activities.yml
similarity index 100%
rename from stories/deprecated/suspicious_aws_ec2_activities.yml
rename to deprecated/stories/suspicious_aws_ec2_activities.yml
diff --git a/stories/deprecated/unusual_aws_ec2_modifications.yml b/deprecated/stories/unusual_aws_ec2_modifications.yml
similarity index 100%
rename from stories/deprecated/unusual_aws_ec2_modifications.yml
rename to deprecated/stories/unusual_aws_ec2_modifications.yml
diff --git a/stories/deprecated/web_fraud_detection.yml b/deprecated/stories/web_fraud_detection.yml
similarity index 100%
rename from stories/deprecated/web_fraud_detection.yml
rename to deprecated/stories/web_fraud_detection.yml
diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml
index a983aeb31d..4608e0a6da 100644
--- a/detections/endpoint/attacker_tools_on_endpoint.yml
+++ b/detections/endpoint/attacker_tools_on_endpoint.yml
@@ -1,7 +1,7 @@
name: Attacker Tools On Endpoint
id: a51bfe1a-94f0-48cc-b4e4-16a110145893
version: 8
-date: '2025-02-10'
+date: '2025-02-27'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -66,7 +66,6 @@ rba:
tags:
analytic_story:
- XMRig
- - Monitor for Unauthorized Software
- Unusual Processes
- SamSam Ransomware
- CISA AA22-264A
From b70a4740a17d5de4d92d0aaa31dc47e938c082fd Mon Sep 17 00:00:00 2001
From: research-bot
Date: Wed, 26 Feb 2025 11:40:03 -0800
Subject: [PATCH 15/67] updating version
---
detections/endpoint/attacker_tools_on_endpoint.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml
index 4608e0a6da..b4a9c676c9 100644
--- a/detections/endpoint/attacker_tools_on_endpoint.yml
+++ b/detections/endpoint/attacker_tools_on_endpoint.yml
@@ -1,6 +1,6 @@
name: Attacker Tools On Endpoint
id: a51bfe1a-94f0-48cc-b4e4-16a110145893
-version: 8
+version: 9
date: '2025-02-27'
author: Bhavin Patel, Splunk
status: production
From 098daaf4405ff4222754533e82f86b9a5f7db288 Mon Sep 17 00:00:00 2001
From: Steven Dick <38897662+nterl0k@users.noreply.github.com>
Date: Thu, 27 Feb 2025 10:43:47 -0500
Subject: [PATCH 16/67] Update o365_sharepoint_suspicious_search_behavior.yml
---
..._sharepoint_suspicious_search_behavior.yml | 31 ++++++++++---------
1 file changed, 17 insertions(+), 14 deletions(-)
diff --git a/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml b/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml
index 52449ed52b..8ab7ecfb4f 100644
--- a/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml
+++ b/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml
@@ -1,7 +1,7 @@
name: O365 SharePoint Suspicious Search Behavior
id: 6ca919db-52f3-4c95-a4e9-7b189e8a043d
-version: 1
-date: '2025-01-08'
+version: 2
+date: '2025-02-27'
author: Steven Dick
status: production
type: Anomaly
@@ -9,18 +9,20 @@ description: The following analytic identifies when the O365 SharePoint users se
data_source:
- Office 365 Universal Audit Log
search: |-
- `o365_management_activity` Workload=SharePoint Operation="SearchQueryPerformed" SearchQueryText=* EventData=*search*
- | where NOT (match(SearchQueryText, "\*") OR match(SearchQueryText,"(\*)"))
- | eval signature_id = CorrelationId, signature=Operation, src = ClientIP, user = UserId, object_name=EventData, command = SearchQueryText, -time = _time
- | bin _time span=1hr
- | stats values(object_name) as object_name values(command) as command, values(src) as src, dc(command) as count, min(-time) as firstTime, max(-time) as lastTime by user,signature,_time
- | where count > 20 OR match(command, "(?i)password|credential|passwd|shadow|active directory|account|username|network|computer|access|MFA|bank|deposit|payroll|EFT|Electonic Funds|routing")
- | `security_content_ctime(firstTime)`
- | `security_content_ctime(lastTime)`
+ `o365_management_activity` (Workload=SharePoint Operation="SearchQueryPerformed" SearchQueryText=* EventData=*search*) OR Operation=SearchQueryInitiatedSharepoint
+ | eval command = case(Operation=="SearchQueryPerformed",SearchQueryText,true(),QueryText), UserId = lower(UserId), signature_id = CorrelationId, signature=Operation, src = ClientIP, user = lower(UserId), object_name=case(Operation=="SearchQueryPerformed",'EventData',true(),QuerySource), -time = _time, suspect_terms = case(match(command, `o365_suspect_search_terms_regex`),command,true(),null())
+ | where command != "*" AND command != "(*)"
+ | bin _time span=1hr
| `o365_sharepoint_suspicious_search_behavior_filter`
+ | stats values(ScenarioName) as app, values(object_name) as object_name values(command) as command, values(suspect_terms) as suspect_terms, values(src) as src, dc(suspect_terms) as suspect_terms_count, dc(command) as count, min(-time) as firstTime, max(-time) as lastTime by user,signature,_time
+ | where count > 20 OR suspect_terms_count >= 2
+ | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest Office 365 management activity events. The thresholds and match terms set within the analytic are initial guidelines and should be customized based on the organization's user behavior and risk profile. Security teams are encouraged to adjust these thresholds to optimize the balance between detecting genuine threats and minimizing false positives, ensuring the detection is tailored to their specific environment.
known_false_positives: Users searching excessively or possible false positives related to matching conditions.
references:
+- https://learn.microsoft.com/en-us/purview/audit-get-started#step-3-enable-searchqueryinitiated-events
+- https://www.cisa.gov/sites/default/files/2025-01/microsoft-expanded-cloud-logs-implementation-playbook-508c.pdf
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a
- https://attack.mitre.org/techniques/T1213/002/
drilldown_searches:
@@ -33,22 +35,23 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: Investigate search behavior by $user$
- search: '`o365_management_activity` Workload=SharePoint Operation="SearchQueryPerformed" SearchQueryText=* EventData=*search* AND UserId = "$user$"'
+ search: '`o365_management_activity` (Workload=SharePoint Operation="SearchQueryPerformed" SearchQueryText=* EventData=*search* AND UserId = "$user$") OR (OR Operation=SearchQueryInitiatedSharepoint AND UserId = "$user$")'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
- message: The SharePoint Online was searched suspiciously by $user$
+ message: The user $user$ searched SharePoint suspiciously, $count$ unique terms and $suspect_terms_count$ suspect terms were searched within a limited timeframe.
risk_objects:
- field: user
type: user
- score: 25
+ score: 35
threat_objects:
- field: src
type: ip_address
tags:
analytic_story:
- - Azure Active Directory Persistence
- Office 365 Account Takeover
+ - Office 365 Collection Techniques
+ - Compromised User Account
- CISA AA22-320A
asset_type: O365 Tenant
mitre_attack_id:
From a500515a33addfbad1aebd23061f5a6b22a35798 Mon Sep 17 00:00:00 2001
From: Steven Dick <38897662+nterl0k@users.noreply.github.com>
Date: Thu, 27 Feb 2025 10:52:01 -0500
Subject: [PATCH 17/67] Add files via upload
---
macros/o365_suspect_search_terms_regex.yml | 3 +++
1 file changed, 3 insertions(+)
create mode 100644 macros/o365_suspect_search_terms_regex.yml
diff --git a/macros/o365_suspect_search_terms_regex.yml b/macros/o365_suspect_search_terms_regex.yml
new file mode 100644
index 0000000000..b1dbd9fe3d
--- /dev/null
+++ b/macros/o365_suspect_search_terms_regex.yml
@@ -0,0 +1,3 @@
+definition: "(?i)password|credential$|credentials$|login|passwd|shadow|active directory|account|username|network|computer|access|MFA|bank|deposit|payroll|EFT|Electonic Funds|routing"
+description: A regex used with match statements preloaded with generic suspicious terms or phrases. Is used to detect malicious actor or insider threat searches, replace/modify these terms to suit your organization.
+name: o365_suspect_search_terms_regex
\ No newline at end of file
From 6961c6ced2a58020ca74d5a96b5e0c443065fafb Mon Sep 17 00:00:00 2001
From: Steven Dick <38897662+nterl0k@users.noreply.github.com>
Date: Thu, 27 Feb 2025 11:43:30 -0500
Subject: [PATCH 18/67] Add files via upload
---
.../o365_email_suspicious_search_behavior.yml | 70 +++++++++++++++++++
1 file changed, 70 insertions(+)
create mode 100644 detections/cloud/o365_email_suspicious_search_behavior.yml
diff --git a/detections/cloud/o365_email_suspicious_search_behavior.yml b/detections/cloud/o365_email_suspicious_search_behavior.yml
new file mode 100644
index 0000000000..5d67c47519
--- /dev/null
+++ b/detections/cloud/o365_email_suspicious_search_behavior.yml
@@ -0,0 +1,70 @@
+name: O365 Email Suspicious Search Behavior
+id: 3b6e1d36-6916-4eec-a7d5-bc98953ba595
+version: 1
+date: '2025-02-27'
+author: Steven Dick
+status: production
+type: Anamoly
+description: The following analytic identifies when Office 365 users search for suspicious keywords or have an excessive number of queries to a mailbox within a limited timeframe. This behavior may indicate that a malicious actor has gained control of a mailbox and is conducting discovery or enumeration activities.
+data_source:
+- Office 365 Universal Audit Log
+search: |-
+ `o365_management_activity` Operation=SearchQueryInitiatedExchange
+ | eval command = case(Operation=="SearchQueryPerformed",SearchQueryText,true(),QueryText), UserId = lower(UserId), signature_id = CorrelationId, signature=Operation, src = ClientIP, user = lower(UserId), object_name=case(Operation=="SearchQueryPerformed",'EventData',true(),QuerySource), -time = _time, suspect_terms = case(match(command, `o365_suspect_search_terms_regex`),command,true(),null())
+ | where command != "*" AND command != "(*)"
+ | bin _time span=1hr
+ | `o365_email_suspicious_search_behavior_filter`
+ | stats values(ScenarioName) as app, values(object_name) as object_name values(command) as command, values(suspect_terms) as suspect_terms, values(src) as src, dc(suspect_terms) as suspect_terms_count, dc(command) as count, min(-time) as firstTime, max(-time) as lastTime by user,signature,_time
+ | where count > 20 OR suspect_terms_count >= 2
+ | `security_content_ctime(firstTime)`
+ | `security_content_ctime(lastTime)`
+how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest Office 365 management activity events. You must also enable SearchQueryInitiated category as part of your organizations mailbox audit logging policy. The thresholds and match terms set within the analytic are initial guidelines and should be customized based on the organization's user behavior and risk profile. Security teams are encouraged to adjust these thresholds to optimize the balance between detecting genuine threats and minimizing false positives, ensuring the detection is tailored to their specific environment.
+known_false_positives: Users searching excessively or possible false positives related to matching conditions.
+references:
+- https://learn.microsoft.com/en-us/purview/audit-get-started#step-3-enable-searchqueryinitiated-events
+- https://www.cisa.gov/sites/default/files/2025-01/microsoft-expanded-cloud-logs-implementation-playbook-508c.pdf
+- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a
+- https://attack.mitre.org/techniques/T1114/002/
+drilldown_searches:
+- name: View the detection results for - "$user$"
+ search: '%original_detection_search% | search user = "$user$"'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: View risk events for the last 7 days for - "$user$"
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+- name: Investigate search behavior by $user$
+ search: '`o365_management_activity` AND Operation=SearchQueryInitiatedExchange AND UserId = "$user$"'
+ earliest_offset: $info_min_time$
+ latest_offset: $info_max_time$
+rba:
+ message: The user $user$ searched email suspiciously, $count$ unique terms and $suspect_terms_count$ suspect terms were searched within a limited timeframe.
+ risk_objects:
+ - field: user
+ type: user
+ score: 35
+ threat_objects:
+ - field: src
+ type: ip_address
+tags:
+ analytic_story:
+ - Office 365 Account Takeover
+ - Office 365 Collection Techniques
+ - Compromised User Account
+ - CISA AA22-320A
+ asset_type: O365 Tenant
+ mitre_attack_id:
+ - T1114.002
+ - T1552
+ product:
+ - Splunk Enterprise
+ - Splunk Enterprise Security
+ - Splunk Cloud
+ security_domain: threat
+tests:
+- name: True Positive Test
+ attack_data:
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1213.002/o365_sus_sharepoint_search/o365_sus_sharepoint_search.log
+ source: o365
+ sourcetype: o365:management:activity
\ No newline at end of file
From 9ca556447582afc26cac9530425b9613b6d22133 Mon Sep 17 00:00:00 2001
From: Steven Dick <38897662+nterl0k@users.noreply.github.com>
Date: Thu, 27 Feb 2025 12:05:57 -0500
Subject: [PATCH 19/67] Update o365_email_suspicious_search_behavior.yml
---
detections/cloud/o365_email_suspicious_search_behavior.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/detections/cloud/o365_email_suspicious_search_behavior.yml b/detections/cloud/o365_email_suspicious_search_behavior.yml
index 5d67c47519..f9ae1c57ab 100644
--- a/detections/cloud/o365_email_suspicious_search_behavior.yml
+++ b/detections/cloud/o365_email_suspicious_search_behavior.yml
@@ -67,4 +67,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1213.002/o365_sus_sharepoint_search/o365_sus_sharepoint_search.log
source: o365
- sourcetype: o365:management:activity
\ No newline at end of file
+ sourcetype: o365:management:activity
From 65c66a4270c1116ad0ab810c35965559ce96cb90 Mon Sep 17 00:00:00 2001
From: Steven Dick <38897662+nterl0k@users.noreply.github.com>
Date: Thu, 27 Feb 2025 12:07:13 -0500
Subject: [PATCH 20/67] Update o365_sharepoint_suspicious_search_behavior.yml
---
detections/cloud/o365_sharepoint_suspicious_search_behavior.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml b/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml
index 8ab7ecfb4f..87ef5a4414 100644
--- a/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml
+++ b/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml
@@ -5,7 +5,7 @@ date: '2025-02-27'
author: Steven Dick
status: production
type: Anomaly
-description: The following analytic identifies when the O365 SharePoint users search for suspicious keywords or have an excessive number of queries within a limited timeframe. This behavior may indicate malicious actor enumeration of SharePoint based data within O365.
+description: The following analytic identifies when Office 365 users search for suspicious keywords or have an excessive number of queries to a SharePoint site within a limited timeframe. This behavior may indicate that a malicious actor has gained control of a user account and is conducting discovery or enumeration activities.
data_source:
- Office 365 Universal Audit Log
search: |-
From 1e9a8c8f2017ad27ed2a84e0635dbb50526d81f0 Mon Sep 17 00:00:00 2001
From: Steven Dick <38897662+nterl0k@users.noreply.github.com>
Date: Thu, 27 Feb 2025 12:10:30 -0500
Subject: [PATCH 21/67] Update o365_email_suspicious_search_behavior.yml
---
detections/cloud/o365_email_suspicious_search_behavior.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/detections/cloud/o365_email_suspicious_search_behavior.yml b/detections/cloud/o365_email_suspicious_search_behavior.yml
index f9ae1c57ab..f94970bf6b 100644
--- a/detections/cloud/o365_email_suspicious_search_behavior.yml
+++ b/detections/cloud/o365_email_suspicious_search_behavior.yml
@@ -4,7 +4,7 @@ version: 1
date: '2025-02-27'
author: Steven Dick
status: production
-type: Anamoly
+type: Anomaly
description: The following analytic identifies when Office 365 users search for suspicious keywords or have an excessive number of queries to a mailbox within a limited timeframe. This behavior may indicate that a malicious actor has gained control of a mailbox and is conducting discovery or enumeration activities.
data_source:
- Office 365 Universal Audit Log
From 7489993e96b541ac890fb966024f23011eec6cfc Mon Sep 17 00:00:00 2001
From: Teoderick Contreras
Date: Fri, 28 Feb 2025 11:44:04 +0100
Subject: [PATCH 22/67] systembc
---
..._or_script_creation_in_suspicious_path.yml | 5 +--
.../endpoint/powershell_4104_hunting.yml | 5 +--
.../registry_keys_used_for_persistence.yml | 5 +--
...ution_policy_to_unrestricted_or_bypass.yml | 5 +--
.../windows_suspicious_process_file_path.yml | 5 +--
..._scheduled_task_created_to_spawn_shell.yml | 5 +--
...eduled_task_created_within_public_path.yml | 5 +--
...ws_task_scheduler_event_action_started.yml | 5 +--
stories/systembc.yml | 35 +++++++++++++++++++
9 files changed, 59 insertions(+), 16 deletions(-)
create mode 100644 stories/systembc.yml
diff --git a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml
index 741c492268..6cc1ec1a85 100644
--- a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml
+++ b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml
@@ -1,7 +1,7 @@
name: Executables Or Script Creation In Suspicious Path
id: a7e3f0f0-ae42-11eb-b245-acde48001122
-version: '11'
-date: '2025-02-24'
+version: '12'
+date: '2025-02-28'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -101,6 +101,7 @@ tags:
- Data Destruction
- Amadey
- WhisperGate
+ - SystemBC
asset_type: Endpoint
mitre_attack_id:
- T1036
diff --git a/detections/endpoint/powershell_4104_hunting.yml b/detections/endpoint/powershell_4104_hunting.yml
index d4a20fcd06..d03afb46b9 100644
--- a/detections/endpoint/powershell_4104_hunting.yml
+++ b/detections/endpoint/powershell_4104_hunting.yml
@@ -1,7 +1,7 @@
name: PowerShell 4104 Hunting
id: d6f2b006-0041-11ec-8885-acde48001122
-version: '12'
-date: '2025-02-24'
+version: '13'
+date: '2025-02-28'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -72,6 +72,7 @@ tags:
- Rhysida Ransomware
- Data Destruction
- Hermetic Wiper
+ - SystemBC
asset_type: Endpoint
mitre_attack_id:
- T1059.001
diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml
index 968c76a2f3..af322ef9b3 100644
--- a/detections/endpoint/registry_keys_used_for_persistence.yml
+++ b/detections/endpoint/registry_keys_used_for_persistence.yml
@@ -1,7 +1,7 @@
name: Registry Keys Used For Persistence
id: f5f6af30-7aa7-4295-bfe9-07fe87c01a4b
-version: '17'
-date: '2025-02-24'
+version: '18'
+date: '2025-02-28'
author: Jose Hernandez, David Dorsey, Teoderick Contreras, Rod Soto, Splunk
status: production
type: TTP
@@ -105,6 +105,7 @@ tags:
- DarkGate Malware
- Azorult
- Amadey
+ - SystemBC
asset_type: Endpoint
mitre_attack_id:
- T1547.001
diff --git a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml
index 00822bc0c3..071b4ea163 100644
--- a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml
+++ b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml
@@ -1,7 +1,7 @@
name: Set Default PowerShell Execution Policy To Unrestricted or Bypass
id: c2590137-0b08-4985-9ec5-6ae23d92f63d
-version: 13
-date: '2025-02-10'
+version: 14
+date: '2025-02-28'
author: Steven Dick, Patrick Bareiss, Splunk
status: production
type: TTP
@@ -77,6 +77,7 @@ tags:
- Malicious PowerShell
- Data Destruction
- DarkGate Malware
+ - SystemBC
asset_type: Endpoint
mitre_attack_id:
- T1059.001
diff --git a/detections/endpoint/windows_suspicious_process_file_path.yml b/detections/endpoint/windows_suspicious_process_file_path.yml
index 0675251a94..2c05ad3d0c 100644
--- a/detections/endpoint/windows_suspicious_process_file_path.yml
+++ b/detections/endpoint/windows_suspicious_process_file_path.yml
@@ -1,7 +1,7 @@
name: Windows Suspicious Process File Path
id: ecddae4e-3d4b-41e2-b3df-e46a88b38521
-version: 7
-date: '2025-02-10'
+version: 8
+date: '2025-02-28'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -103,6 +103,7 @@ tags:
- MoonPeak
- ValleyRAT
- Meduza Stealer
+ - SystemBC
asset_type: Endpoint
mitre_attack_id:
- T1543
diff --git a/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml b/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml
index eb98f737e4..515bdb1768 100644
--- a/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml
+++ b/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml
@@ -1,7 +1,7 @@
name: WinEvent Scheduled Task Created to Spawn Shell
id: 203ef0ea-9bd8-11eb-8201-acde48001122
-version: '10'
-date: '2025-02-24'
+version: '11'
+date: '2025-02-25'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -64,6 +64,7 @@ tags:
- Scheduled Tasks
- Earth Estries
- Winter Vivern
+ - SystemBC
asset_type: Endpoint
mitre_attack_id:
- T1053.005
diff --git a/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml b/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml
index f464f02690..142adf55be 100644
--- a/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml
+++ b/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml
@@ -1,7 +1,7 @@
name: WinEvent Scheduled Task Created Within Public Path
id: 5d9c6eee-988c-11eb-8253-acde48001122
-version: '10'
-date: '2025-02-24'
+version: '11'
+date: '2025-02-28'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -70,6 +70,7 @@ tags:
- Scheduled Tasks
- Data Destruction
- Winter Vivern
+ - SystemBC
asset_type: Endpoint
mitre_attack_id:
- T1053.005
diff --git a/detections/endpoint/winevent_windows_task_scheduler_event_action_started.yml b/detections/endpoint/winevent_windows_task_scheduler_event_action_started.yml
index f20cf4265e..040059360b 100644
--- a/detections/endpoint/winevent_windows_task_scheduler_event_action_started.yml
+++ b/detections/endpoint/winevent_windows_task_scheduler_event_action_started.yml
@@ -1,7 +1,7 @@
name: WinEvent Windows Task Scheduler Event Action Started
id: b3632472-310b-11ec-9aab-acde48001122
-version: 6
-date: '2024-11-13'
+version: 7
+date: '2025-02-28'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -47,6 +47,7 @@ tags:
- CISA AA24-241A
- BlackSuit Ransomware
- ValleyRAT
+ - SystemBC
asset_type: Endpoint
mitre_attack_id:
- T1053.005
diff --git a/stories/systembc.yml b/stories/systembc.yml
new file mode 100644
index 0000000000..5b02eae405
--- /dev/null
+++ b/stories/systembc.yml
@@ -0,0 +1,35 @@
+name: SystemBC
+id:
+version: 1
+date: '2025-02-28'
+author: Teoderick Contreras, Splunk
+status: production
+description: Leverage searches for Dropped Files anomalies, and registry modification to detect SystemBC malware.
+ This threat acts as a backdoor proxy that enables attackers to maintain persistence, evade detection, and facilitate ransomware operations.
+ It often uses SOCKS5 proxies to disguise malicious traffic, making traditional network monitoring less effective.
+ Look for unusual outbound connections, especially to known threat actor infrastructure. Additionally, analyze PowerShell scripts,
+ scheduled tasks, and process injections that may indicate SystemBC deployment. Proactive threat hunting and endpoint monitoring are
+ essential to detecting and mitigating this malware.
+narrative: SystemBC is a stealthy malware strain known for its proxy and backdoor capabilities,
+ often used by cybercriminals to facilitate ransomware attacks. First reported in 2019, it operates as a SOCKS5 proxy,
+ allowing attackers to route malicious traffic through infected systems while evading detection.
+ The malware is typically delivered via exploit kits, phishing emails, or secondary payloads from other malware families.
+ It enables persistent remote access, executes encrypted commands from a C2 server, and helps adversaries maintain control
+ over compromised networks. SystemBC has been linked to major ransomware operations, making it a significant threat in modern cyberattacks.
+references:
+- https://malpedia.caad.fkie.fraunhofer.de/details/win.systembc
+- https://thedfirreport.com/2025/01/27/cobalt-strike-and-a-pair-of-socks-lead-to-lockbit-ransomware/
+- https://hackread.com/systembc-rat-targets-linux-ransomware-infostealers/
+- https://hackread.com/infostealers-breach-us-security-military-fbi-hit/
+- https://www.kroll.com/en/insights/publications/cyber/inside-the-systembc-malware-server
+- https://medium.com/walmartglobaltech/systembc-powershell-version-68c9aad0f85c
+- https://securelist.com/focus-on-droxidat-systembc/110302/
+- https://blogs.blackberry.com/en/2021/06/threat-thursday-systembc-a-rat-in-the-pipeline
+tags:
+ category:
+ - Malware
+ product:
+ - Splunk Enterprise
+ - Splunk Enterprise Security
+ - Splunk Cloud
+ usecase: Advanced Threat Detection
\ No newline at end of file
From 95384fcf0561680e7ad03ae0222c9c13a58e9ead Mon Sep 17 00:00:00 2001
From: Teoderick Contreras
Date: Fri, 28 Feb 2025 12:00:07 +0100
Subject: [PATCH 23/67] systembc
---
stories/systembc.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/stories/systembc.yml b/stories/systembc.yml
index 5b02eae405..e25c032ccd 100644
--- a/stories/systembc.yml
+++ b/stories/systembc.yml
@@ -1,5 +1,5 @@
name: SystemBC
-id:
+id: ddc2801b-a881-4458-8f9d-c20e95daebea
version: 1
date: '2025-02-28'
author: Teoderick Contreras, Splunk
From c8087bc330e607c086ee2d7f71919aa970601478 Mon Sep 17 00:00:00 2001
From: Teoderick Contreras
Date: Mon, 3 Mar 2025 14:12:55 +0100
Subject: [PATCH 24/67] systembc
---
...dedit_command_back_to_normal_mode_boot.yml | 8 +++---
...hange_to_safe_mode_with_network_config.yml | 8 +++---
.../endpoint/common_ransomware_extensions.yml | 28 ++++++++++---------
.../endpoint/common_ransomware_notes.yml | 20 ++++++-------
.../endpoint/deleting_shadow_copies.yml | 18 ++++++------
.../detect_rclone_command_line_usage.yml | 8 +++---
detections/endpoint/detect_renamed_rclone.yml | 8 +++---
.../disable_defender_antivirus_registry.yml | 10 +++----
.../disable_windows_behavior_monitoring.yml | 16 +++++------
.../endpoint/modification_of_wallpaper.yml | 18 ++++++------
.../print_spooler_adding_a_printer_driver.yml | 8 +++---
...print_spooler_failed_to_load_a_plug_in.yml | 8 +++---
.../ransomware_notes_bulk_creation.yml | 18 ++++++------
.../endpoint/spoolsv_spawning_rundll32.yml | 8 +++---
.../spoolsv_suspicious_loaded_modules.yml | 8 +++---
.../spoolsv_suspicious_process_access.yml | 8 +++---
detections/endpoint/spoolsv_writing_a_dll.yml | 8 +++---
.../spoolsv_writing_a_dll___sysmon.yml | 8 +++---
...ndows_curl_download_to_suspicious_path.yml | 7 +++--
.../windows_high_file_deletion_frequency.yml | 16 +++++------
.../network/detect_zerologon_via_zeek.yml | 11 ++++----
lookups/ransomware_extensions_lookup.csv | 3 +-
stories/black_basta_ransomware.yml | 18 ++++++++++++
23 files changed, 147 insertions(+), 124 deletions(-)
create mode 100644 stories/black_basta_ransomware.yml
diff --git a/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml b/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml
index 0b6dcac7d9..d8c602f6b4 100644
--- a/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml
+++ b/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml
@@ -1,7 +1,7 @@
name: Bcdedit Command Back To Normal Mode Boot
id: dc7a8004-0f18-11ec-8c54-acde48001122
-version: 4
-date: '2024-11-13'
+version: '5'
+date: '2025-03-03'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -62,6 +62,7 @@ rba:
threat_objects: []
tags:
analytic_story:
+ - Black Basta Ransomware
- BlackMatter Ransomware
asset_type: Endpoint
mitre_attack_id:
@@ -74,7 +75,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/change_to_safe_mode_with_network_config.yml b/detections/endpoint/change_to_safe_mode_with_network_config.yml
index 6d8c2aa9ec..75247f707c 100644
--- a/detections/endpoint/change_to_safe_mode_with_network_config.yml
+++ b/detections/endpoint/change_to_safe_mode_with_network_config.yml
@@ -1,7 +1,7 @@
name: Change To Safe Mode With Network Config
id: 81f1dce0-0f18-11ec-a5d7-acde48001122
-version: 4
-date: '2024-11-13'
+version: '5'
+date: '2025-03-03'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -61,6 +61,7 @@ rba:
threat_objects: []
tags:
analytic_story:
+ - Black Basta Ransomware
- BlackMatter Ransomware
asset_type: Endpoint
mitre_attack_id:
@@ -73,7 +74,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/common_ransomware_extensions.yml b/detections/endpoint/common_ransomware_extensions.yml
index b7dbef7eb3..079d11de57 100644
--- a/detections/endpoint/common_ransomware_extensions.yml
+++ b/detections/endpoint/common_ransomware_extensions.yml
@@ -1,7 +1,7 @@
name: Common Ransomware Extensions
id: a9e5c5db-db11-43ca-86a8-c852d1b2c0ec
-version: 11
-date: '2025-01-07'
+version: '12'
+date: '2025-03-03'
author: David Dorsey, Michael Haag, Splunk, Steven Dick
status: production
type: TTP
@@ -24,10 +24,10 @@ search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_
path_count dc(file_name) as file_count latest(true_file_path) as file_path by dest
file_name | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)`
| `ransomware_extensions` | where path_count > 1 OR file_count > 20 | `common_ransomware_extensions_filter`'
-how_to_implement: 'You must be ingesting data that records the filesystem activity
+how_to_implement: You must be ingesting data that records the filesystem activity
from your hosts to populate the Endpoint Filesystem data model node. To see the
additional metadata, add the following fields, if not already present, please review
- the detailed documentation on how to create a new field within Incident Review'
+ the detailed documentation on how to create a new field within Incident Review
known_false_positives: It is possible for a legitimate file with these extensions
to be created. If this is a true ransomware attack, there will be a large number
of files created with these extensions.
@@ -47,8 +47,10 @@ drilldown_searches:
| `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
-rba:
- message: The device $dest$ wrote $file_count$ files to $path_count$ path(s) with the $Extensions$ extension. This extension and behavior may indicate a $Name$ ransomware attack.
+rba:
+ message: The device $dest$ wrote $file_count$ files to $path_count$ path(s) with
+ the $Extensions$ extension. This extension and behavior may indicate a $Name$
+ ransomware attack.
risk_objects:
- field: user
type: user
@@ -59,13 +61,14 @@ rba:
threat_objects: []
tags:
analytic_story:
- - SamSam Ransomware
- - Ryuk Ransomware
- - Ransomware
- - Clop Ransomware
+ - Rhysida Ransomware
- Prestige Ransomware
- LockBit Ransomware
- - Rhysida Ransomware
+ - Ryuk Ransomware
+ - SamSam Ransomware
+ - Black Basta Ransomware
+ - Ransomware
+ - Clop Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1485
@@ -77,7 +80,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_notes/ransom-sysmon.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_notes/ransom-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/common_ransomware_notes.yml b/detections/endpoint/common_ransomware_notes.yml
index 2535f7533b..069996fda3 100644
--- a/detections/endpoint/common_ransomware_notes.yml
+++ b/detections/endpoint/common_ransomware_notes.yml
@@ -1,7 +1,7 @@
name: Common Ransomware Notes
id: ada0f478-84a8-4641-a3f1-d82362d6bd71
-version: 7
-date: '2024-11-13'
+version: '8'
+date: '2025-03-03'
author: David Dorsey, Splunk
status: production
type: Hunting
@@ -29,13 +29,14 @@ known_false_positives: It's possible that a legitimate file could be created wit
references: []
tags:
analytic_story:
- - SamSam Ransomware
- - Ransomware
- - Ryuk Ransomware
- - Clop Ransomware
- - Chaos Ransomware
- - LockBit Ransomware
- Rhysida Ransomware
+ - LockBit Ransomware
+ - Ryuk Ransomware
+ - SamSam Ransomware
+ - Chaos Ransomware
+ - Black Basta Ransomware
+ - Ransomware
+ - Clop Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1485
@@ -47,7 +48,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_notes/windows-sysmon.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_notes/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/deleting_shadow_copies.yml b/detections/endpoint/deleting_shadow_copies.yml
index 89b5ebed9b..ed825e84fd 100644
--- a/detections/endpoint/deleting_shadow_copies.yml
+++ b/detections/endpoint/deleting_shadow_copies.yml
@@ -1,7 +1,7 @@
name: Deleting Shadow Copies
id: b89919ed-ee5f-492c-b139-95dbb162039e
-version: 10
-date: '2024-12-10'
+version: '11'
+date: '2025-03-03'
author: David Dorsey, Splunk
status: production
type: TTP
@@ -69,15 +69,16 @@ rba:
type: process_name
tags:
analytic_story:
- - Chaos Ransomware
- Rhysida Ransomware
- - Windows Log Manipulation
- Prestige Ransomware
- - Ransomware
- - SamSam Ransomware
- CISA AA22-264A
- - DarkGate Malware
- LockBit Ransomware
+ - SamSam Ransomware
+ - Chaos Ransomware
+ - Black Basta Ransomware
+ - DarkGate Malware
+ - Ransomware
+ - Windows Log Manipulation
- Compromised Windows Host
- Clop Ransomware
asset_type: Endpoint
@@ -91,7 +92,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/detect_rclone_command_line_usage.yml b/detections/endpoint/detect_rclone_command_line_usage.yml
index a36e49cace..d5dae5c8af 100644
--- a/detections/endpoint/detect_rclone_command_line_usage.yml
+++ b/detections/endpoint/detect_rclone_command_line_usage.yml
@@ -1,7 +1,7 @@
name: Detect RClone Command-Line Usage
id: 32e0baea-b3f1-11eb-a2ce-acde48001122
-version: 7
-date: '2024-11-13'
+version: '8'
+date: '2025-03-03'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -75,6 +75,7 @@ tags:
analytic_story:
- DarkSide Ransomware
- Ransomware
+ - Black Basta Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1020
@@ -86,7 +87,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/detect_renamed_rclone.yml b/detections/endpoint/detect_renamed_rclone.yml
index 04c0a7e651..8d842c1444 100644
--- a/detections/endpoint/detect_renamed_rclone.yml
+++ b/detections/endpoint/detect_renamed_rclone.yml
@@ -1,7 +1,7 @@
name: Detect Renamed RClone
id: 6dca1124-b3ec-11eb-9328-acde48001122
-version: 6
-date: '2024-11-13'
+version: '7'
+date: '2025-03-03'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -42,6 +42,7 @@ tags:
analytic_story:
- DarkSide Ransomware
- Ransomware
+ - Black Basta Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1020
@@ -53,7 +54,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/disable_defender_antivirus_registry.yml b/detections/endpoint/disable_defender_antivirus_registry.yml
index 6aca910525..d7b9f60813 100644
--- a/detections/endpoint/disable_defender_antivirus_registry.yml
+++ b/detections/endpoint/disable_defender_antivirus_registry.yml
@@ -1,7 +1,7 @@
name: Disable Defender AntiVirus Registry
id: aa4f695a-3024-11ec-9987-acde48001122
-version: 9
-date: '2025-02-10'
+version: '10'
+date: '2025-03-03'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -56,9 +56,10 @@ rba:
threat_objects: []
tags:
analytic_story:
- - IcedID
- Windows Registry Abuse
- CISA AA24-241A
+ - IcedID
+ - Black Basta Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1562.001
@@ -70,7 +71,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/disable_windows_behavior_monitoring.yml b/detections/endpoint/disable_windows_behavior_monitoring.yml
index 1fd00e8d98..2e0c1f7cd4 100644
--- a/detections/endpoint/disable_windows_behavior_monitoring.yml
+++ b/detections/endpoint/disable_windows_behavior_monitoring.yml
@@ -1,7 +1,7 @@
name: Disable Windows Behavior Monitoring
id: 79439cae-9200-11eb-a4d3-acde48001122
-version: 11
-date: '2025-02-10'
+version: '12'
+date: '2025-03-03'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -58,13 +58,14 @@ rba:
threat_objects: []
tags:
analytic_story:
- - Azorult
- - Ransomware
- - Windows Registry Abuse
- - RedLine Stealer
- Windows Defense Evasion Tactics
- CISA AA23-347A
- Revil Ransomware
+ - Azorult
+ - Windows Registry Abuse
+ - Black Basta Ransomware
+ - Ransomware
+ - RedLine Stealer
asset_type: Endpoint
mitre_attack_id:
- T1562.001
@@ -76,7 +77,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/modification_of_wallpaper.yml b/detections/endpoint/modification_of_wallpaper.yml
index e51be7f390..fcb014d2a1 100644
--- a/detections/endpoint/modification_of_wallpaper.yml
+++ b/detections/endpoint/modification_of_wallpaper.yml
@@ -1,7 +1,7 @@
name: Modification Of Wallpaper
id: accb0712-c381-11eb-8e5b-acde48001122
-version: 4
-date: '2024-11-13'
+version: '5'
+date: '2025-03-03'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -54,13 +54,14 @@ rba:
threat_objects: []
tags:
analytic_story:
- - Ransomware
- Revil Ransomware
- - BlackMatter Ransomware
- - Windows Registry Abuse
- - Brute Ratel C4
- - LockBit Ransomware
- Rhysida Ransomware
+ - LockBit Ransomware
+ - BlackMatter Ransomware
+ - Brute Ratel C4
+ - Windows Registry Abuse
+ - Black Basta Ransomware
+ - Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1491
@@ -72,7 +73,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-sysmon.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/print_spooler_adding_a_printer_driver.yml b/detections/endpoint/print_spooler_adding_a_printer_driver.yml
index 8afd39363a..3f642c1daf 100644
--- a/detections/endpoint/print_spooler_adding_a_printer_driver.yml
+++ b/detections/endpoint/print_spooler_adding_a_printer_driver.yml
@@ -1,7 +1,7 @@
name: Print Spooler Adding A Printer Driver
id: 313681a2-da8e-11eb-adad-acde48001122
-version: 5
-date: '2025-02-10'
+version: '6'
+date: '2025-03-03'
author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk
status: production
type: TTP
@@ -52,6 +52,7 @@ rba:
tags:
analytic_story:
- PrintNightmare CVE-2021-34527
+ - Black Basta Ransomware
asset_type: Endpoint
cve:
- CVE-2021-34527
@@ -66,7 +67,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-printservice_operational.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-printservice_operational.log
source: WinEventLog:Microsoft-Windows-PrintService/Operational
sourcetype: WinEventLog
diff --git a/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml b/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml
index 7ad22f6b32..505ec33faf 100644
--- a/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml
+++ b/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml
@@ -1,7 +1,7 @@
name: Print Spooler Failed to Load a Plug-in
id: 1adc9548-da7c-11eb-8f13-acde48001122
-version: 5
-date: '2025-02-10'
+version: '6'
+date: '2025-03-03'
author: Mauricio Velazco, Michael Haag, Splunk
status: production
type: TTP
@@ -53,6 +53,7 @@ rba:
tags:
analytic_story:
- PrintNightmare CVE-2021-34527
+ - Black Basta Ransomware
asset_type: Endpoint
cve:
- CVE-2021-34527
@@ -67,7 +68,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-printservice_admin.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-printservice_admin.log
source: WinEventLog:Microsoft-Windows-PrintService/Admin
sourcetype: WinEventLog
diff --git a/detections/endpoint/ransomware_notes_bulk_creation.yml b/detections/endpoint/ransomware_notes_bulk_creation.yml
index 61d4c21f17..631b0fc764 100644
--- a/detections/endpoint/ransomware_notes_bulk_creation.yml
+++ b/detections/endpoint/ransomware_notes_bulk_creation.yml
@@ -1,7 +1,7 @@
name: Ransomware Notes bulk creation
id: eff7919a-8330-11eb-83f8-acde48001122
-version: 4
-date: '2024-11-13'
+version: '5'
+date: '2025-03-03'
author: Teoderick Contreras
status: production
type: Anomaly
@@ -51,12 +51,13 @@ rba:
threat_objects: []
tags:
analytic_story:
- - Clop Ransomware
- - DarkSide Ransomware
- - BlackMatter Ransomware
- - Chaos Ransomware
- - LockBit Ransomware
- Rhysida Ransomware
+ - LockBit Ransomware
+ - BlackMatter Ransomware
+ - DarkSide Ransomware
+ - Chaos Ransomware
+ - Black Basta Ransomware
+ - Clop Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1486
@@ -68,7 +69,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/spoolsv_spawning_rundll32.yml b/detections/endpoint/spoolsv_spawning_rundll32.yml
index 70da48f52e..e65d63e295 100644
--- a/detections/endpoint/spoolsv_spawning_rundll32.yml
+++ b/detections/endpoint/spoolsv_spawning_rundll32.yml
@@ -1,7 +1,7 @@
name: Spoolsv Spawning Rundll32
id: 15d905f6-da6b-11eb-ab82-acde48001122
-version: 7
-date: '2025-02-10'
+version: '8'
+date: '2025-03-03'
author: Mauricio Velazco, Michael Haag, Splunk
status: production
type: TTP
@@ -67,6 +67,7 @@ tags:
analytic_story:
- PrintNightmare CVE-2021-34527
- Compromised Windows Host
+ - Black Basta Ransomware
asset_type: Endpoint
cve:
- CVE-2021-34527
@@ -80,7 +81,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/spoolsv_suspicious_loaded_modules.yml b/detections/endpoint/spoolsv_suspicious_loaded_modules.yml
index 07a521d03e..fa3847f8b0 100644
--- a/detections/endpoint/spoolsv_suspicious_loaded_modules.yml
+++ b/detections/endpoint/spoolsv_suspicious_loaded_modules.yml
@@ -1,7 +1,7 @@
name: Spoolsv Suspicious Loaded Modules
id: a5e451f8-da81-11eb-b245-acde48001122
-version: 6
-date: '2025-02-10'
+version: '7'
+date: '2025-03-03'
author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk
status: production
type: TTP
@@ -50,6 +50,7 @@ rba:
tags:
analytic_story:
- PrintNightmare CVE-2021-34527
+ - Black Basta Ransomware
asset_type: Endpoint
cve:
- CVE-2021-34527
@@ -63,7 +64,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/spoolsv_suspicious_process_access.yml b/detections/endpoint/spoolsv_suspicious_process_access.yml
index a41111a7b1..3b7ec83687 100644
--- a/detections/endpoint/spoolsv_suspicious_process_access.yml
+++ b/detections/endpoint/spoolsv_suspicious_process_access.yml
@@ -1,7 +1,7 @@
name: Spoolsv Suspicious Process Access
id: 799b606e-da81-11eb-93f8-acde48001122
-version: 6
-date: '2024-11-13'
+version: '7'
+date: '2025-03-03'
author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk
status: production
type: TTP
@@ -59,6 +59,7 @@ rba:
tags:
analytic_story:
- PrintNightmare CVE-2021-34527
+ - Black Basta Ransomware
asset_type: Endpoint
cve:
- CVE-2021-34527
@@ -72,7 +73,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/spoolsv_writing_a_dll.yml b/detections/endpoint/spoolsv_writing_a_dll.yml
index 3111e77d23..a8fab8f7b0 100644
--- a/detections/endpoint/spoolsv_writing_a_dll.yml
+++ b/detections/endpoint/spoolsv_writing_a_dll.yml
@@ -1,7 +1,7 @@
name: Spoolsv Writing a DLL
id: d5bf5cf2-da71-11eb-92c2-acde48001122
-version: 7
-date: '2025-02-10'
+version: '8'
+date: '2025-03-03'
author: Mauricio Velazco, Michael Haag, Splunk
status: production
type: TTP
@@ -65,6 +65,7 @@ tags:
analytic_story:
- PrintNightmare CVE-2021-34527
- Compromised Windows Host
+ - Black Basta Ransomware
asset_type: Endpoint
cve:
- CVE-2021-34527
@@ -78,7 +79,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml b/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml
index de8fec23dd..3fce3b68aa 100644
--- a/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml
+++ b/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml
@@ -1,7 +1,7 @@
name: Spoolsv Writing a DLL - Sysmon
id: 347fd388-da87-11eb-836d-acde48001122
-version: 5
-date: '2025-02-10'
+version: '6'
+date: '2025-03-03'
author: Mauricio Velazco, Michael Haag, Splunk
status: production
type: TTP
@@ -58,6 +58,7 @@ rba:
tags:
analytic_story:
- PrintNightmare CVE-2021-34527
+ - Black Basta Ransomware
asset_type: Endpoint
cve:
- CVE-2021-34527
@@ -71,7 +72,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/endpoint/windows_curl_download_to_suspicious_path.yml b/detections/endpoint/windows_curl_download_to_suspicious_path.yml
index aa27afdfc7..95fd1c0638 100644
--- a/detections/endpoint/windows_curl_download_to_suspicious_path.yml
+++ b/detections/endpoint/windows_curl_download_to_suspicious_path.yml
@@ -1,7 +1,7 @@
name: Windows Curl Download to Suspicious Path
id: c32f091e-30db-11ec-8738-acde48001122
-version: '9'
-date: '2025-02-24'
+version: '11'
+date: '2025-03-03'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -70,11 +70,12 @@ rba:
type: process_name
tags:
analytic_story:
- - Ingress Tool Transfer
- China-Nexus Threat Activity
+ - Ingress Tool Transfer
- IcedID
- Forest Blizzard
- Earth Estries
+ - Black Basta Ransomware
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
diff --git a/detections/endpoint/windows_high_file_deletion_frequency.yml b/detections/endpoint/windows_high_file_deletion_frequency.yml
index 7c18190d62..93778f82a0 100644
--- a/detections/endpoint/windows_high_file_deletion_frequency.yml
+++ b/detections/endpoint/windows_high_file_deletion_frequency.yml
@@ -1,7 +1,7 @@
name: Windows High File Deletion Frequency
id: 45b125c4-866f-11eb-a95a-acde48001122
-version: 5
-date: '2024-11-13'
+version: '6'
+date: '2025-03-03'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: Anomaly
@@ -65,13 +65,14 @@ rba:
type: process_name
tags:
analytic_story:
- - Clop Ransomware
+ - Handala Wiper
- DarkCrystal RAT
- - Swift Slicer
- - Data Destruction
- WhisperGate
- Sandworm Tools
- - Handala Wiper
+ - Black Basta Ransomware
+ - Swift Slicer
+ - Data Destruction
+ - Clop Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1485
@@ -83,7 +84,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- - data:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
diff --git a/detections/network/detect_zerologon_via_zeek.yml b/detections/network/detect_zerologon_via_zeek.yml
index 94fadd635c..33000d7d6b 100644
--- a/detections/network/detect_zerologon_via_zeek.yml
+++ b/detections/network/detect_zerologon_via_zeek.yml
@@ -1,18 +1,18 @@
name: Detect Zerologon via Zeek
id: bf7a06ec-f703-11ea-adc1-0242ac120002
-version: 4
-date: '2024-11-15'
+version: '5'
+date: '2025-03-03'
author: Shannon Davis, Splunk
status: experimental
type: TTP
-description: "The following analytic detects attempts to exploit the Zerologon CVE-2020-1472
+description: 'The following analytic detects attempts to exploit the Zerologon CVE-2020-1472
vulnerability via Zeek RPC. It leverages Zeek DCE-RPC data to identify specific
operations: NetrServerPasswordSet2, NetrServerReqChallenge, and NetrServerAuthenticate3.
This activity is significant because it indicates an attempt to gain unauthorized
access to a domain controller, potentially leading to a complete takeover of an
- organization's IT infrastructure. If confirmed malicious, the impact could be severe,
+ organization''s IT infrastructure. If confirmed malicious, the impact could be severe,
including data theft, ransomware deployment, or other devastating outcomes. Immediate
- investigation of the identified IP addresses and RPC operations is crucial."
+ investigation of the identified IP addresses and RPC operations is crucial.'
data_source: []
search: '`zeek_rpc` operation IN (NetrServerPasswordSet2,NetrServerReqChallenge,NetrServerAuthenticate3)
| bin span=5m _time | stats values(operation) dc(operation) as opscount count(eval(operation=="NetrServerReqChallenge"))
@@ -40,6 +40,7 @@ tags:
analytic_story:
- Detect Zerologon Attack
- Rhysida Ransomware
+ - Black Basta Ransomware
asset_type: Network
cve:
- CVE-2020-1472
diff --git a/lookups/ransomware_extensions_lookup.csv b/lookups/ransomware_extensions_lookup.csv
index 38cca70a09..c6cb398475 100644
--- a/lookups/ransomware_extensions_lookup.csv
+++ b/lookups/ransomware_extensions_lookup.csv
@@ -300,4 +300,5 @@ Extensions,Name
*.GANGBANG,Gangbang
*.reddot,RedDot
*.MEDUSA,Medusa
-*.rhysida,Rhysida
\ No newline at end of file
+*.rhysida,Rhysida
+*.basta, BlackBasta
\ No newline at end of file
diff --git a/stories/black_basta_ransomware.yml b/stories/black_basta_ransomware.yml
new file mode 100644
index 0000000000..d58f9bc49c
--- /dev/null
+++ b/stories/black_basta_ransomware.yml
@@ -0,0 +1,18 @@
+name: Black Basta Ransomware
+id: b543afc8-2b65-49d7-8325-a9bca4fd65c8
+version: 1
+date: '2025-02-03'
+author: Teoderick Contreras, Splunk
+status: production
+description: Leverage searches for suspicious behaviors associated with Black Basta ransomware, focusing on key indicators such as process execution, registry modifications, and network activity. Monitor for unusual file encryption patterns, particularly involving cmd.exe, powershell.exe, or wmic.exe executing with arguments linked to volume shadow copy deletion (vssadmin delete shadows). Look for registry changes disabling security features or altering startup configurations. Track high-volume file modifications in rapid succession, indicative of ransomware encryption. Additionally, unauthorized remote service executions. Cross-reference endpoint logs, EDR alerts, and SIEM detections to correlate malicious activity. Behavioral analytics and heuristic-based detections can enhance visibility into evolving tactics. Implement robust monitoring and response mechanisms to mitigate Black Basta’s impact effectively.
+narrative: Black Basta ransomware is a highly sophisticated and fast-moving threat that has been targeting organizations worldwide, often disrupting critical operations and demanding hefty ransoms. It operates as a double extortion ransomware, encrypting victim data while simultaneously exfiltrating it to pressure victims into paying. The attack typically begins with initial access via phishing emails, compromised credentials, or exploitation of vulnerabilities in remote desktop services. Once inside, attackers escalate privileges, disable security defenses, and deploy the ransomware payload. The malware rapidly encrypts files across local and networked drives, deleting shadow copies to prevent recovery. It often abuses legitimate system tools like wmic.exe and rundll32.exe, to evade detection. Simultaneously, it establishes command-and-control (C2) connections to exfiltrate sensitive data. The impact is severe—disrupting business operations, exposing confidential information, and leaving organizations with few options for recovery. Early detection, network segmentation, and strong endpoint defenses are crucial to mitigating the risk posed by Black Basta.
+references:
+- https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a
+tags:
+ category:
+ - Malware
+ product:
+ - Splunk Enterprise
+ - Splunk Enterprise Security
+ - Splunk Cloud
+ usecase: Advanced Threat Detection
From d87b3f6a48ffb3e2647507e6cbdf36f77630a0f4 Mon Sep 17 00:00:00 2001
From: Teoderick Contreras
Date: Mon, 3 Mar 2025 15:10:33 +0100
Subject: [PATCH 25/67] systembc
---
lookups/ransomware_notes_lookup.yml | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/lookups/ransomware_notes_lookup.yml b/lookups/ransomware_notes_lookup.yml
index e36d441ec7..21ec31a3bf 100644
--- a/lookups/ransomware_notes_lookup.yml
+++ b/lookups/ransomware_notes_lookup.yml
@@ -1,6 +1,6 @@
name: ransomware_notes_lookup
-date: 2024-12-23
-version: 2
+date: 2025-03-03
+version: 3
id: 93d9fb06-035e-496c-91d5-7a79543ce1e1
author: Splunk Threat Research Team
lookup_type: csv
From 4f4f87af9ffc2103eec27d2022cd74728c1e42fd Mon Sep 17 00:00:00 2001
From: pyth0n1c
Date: Tue, 4 Mar 2025 13:42:37 -0800
Subject: [PATCH 26/67] Add baselines, stories, and investigations to
deprecation yml.
---
deprecated/deprecated_detection_mapping.yml | 426 +++++++++++++++++++-
1 file changed, 423 insertions(+), 3 deletions(-)
diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml
index 322dea112d..48f6c3f118 100644
--- a/deprecated/deprecated_detection_mapping.yml
+++ b/deprecated/deprecated_detection_mapping.yml
@@ -897,6 +897,426 @@ detections:
TA update
replacement_content:
- Okta Multiple Failed MFA Requests For User
-baselines: []
-investigations: []
-stories: []
\ No newline at end of file
+ - deprecated_content: Excel Spawning Windows Script Host
+ deprecated_in_version: 5.3.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: GitHub Actions Disable Security Workflow
+ deprecated_in_version: 5.3.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Github Commit Changes In Master
+ deprecated_in_version: 5.3.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Github Commit In Develop
+ deprecated_in_version: 5.3.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: GitHub Dependabot Alert
+ deprecated_in_version: 5.3.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: GitHub Pull Request from Unknown User
+ deprecated_in_version: 5.3.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Known Services Killed by Ransomware
+ deprecated_in_version: 5.3.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Remote Desktop Network Bruteforce
+ deprecated_in_version: 5.3.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Suspicious Driver Loaded Path
+ deprecated_in_version: 5.3.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Suspicious Event Log Service Behavior
+ deprecated_in_version: 5.3.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Suspicious Process File Path
+ deprecated_in_version: 5.3.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Windows Service Stop Via Net and SC Application
+ deprecated_in_version: 5.3.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+baselines:
+ - deprecated_content: Add Prohibited Processes to Enterprise Security
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Baseline of API Calls per User ARN
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Baseline of Excessive AWS Instances Launched by User - MLTK
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Baseline of Excessive AWS Instances Terminated by User - MLTK
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Previously seen API call per user roles in CloudTrail
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Previously Seen AWS Provisioning Activity Sources
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Previously Seen EC2 AMIs
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Previously Seen EC2 Instance Types
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Previously Seen EC2 Launches By User
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Previously seen users in CloudTrail
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Update previously seen users in CloudTrail
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+investigations:
+ - deprecated_content: All backup logs for host
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Amazon EKS Kubernetes activity by src ip
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: AWS Investigate Security Hub alerts by dest
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: AWS Investigate User Activities By AccessKeyId
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: AWS Investigate User Activities By ARN
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: AWS Network ACL Details from ID
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: AWS Network Interface details via resourceId
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: AWS S3 Bucket details via bucketName
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: GCP Kubernetes activity by src ip
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get All AWS Activity From City
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get All AWS Activity From Country
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get All AWS Activity From IP Address
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get All AWS Activity From Region
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Backup Logs For Endpoint
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Certificate logs for a domain
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get DNS Server History for a host
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get DNS traffic ratio
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get EC2 Instance Details by instanceId
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get EC2 Launch Details
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Email Info
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Emails From Specific Sender
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get First Occurrence and Last Occurrence of a MAC Address
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get History Of Email Sources
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Logon Rights Modifications For Endpoint
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Logon Rights Modifications For User
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Notable History
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Outbound Emails to Hidden Cobra Threat Actors
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Parent Process Info
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Process File Activity
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Process Info
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Process Information For Port Activity
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Process Responsible For The DNS Traffic
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Sysmon WMI Activity for Host
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Web Session Information via session id
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate AWS activities via region name
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate AWS User Activities by user field
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Failed Logins for Multiple Destinations
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Network Traffic From src ip
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Okta Activity by app
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Okta Activity by IP Address
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Pass the Hash Attempts
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Pass the Ticket Attempts
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Previous Unseen User
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Successful Remote Desktop Authentications
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Suspicious Strings in HTTP Header
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate User Activities In Okta
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Web POSTs From src
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+stories:
+ - deprecated_content: AWS Cryptomining
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: AWS Suspicious Provisioning Activities
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Common Phishing Frameworks
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Container Implantation Monitoring and Investigation
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Host Redirection
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Kubernetes Sensitive Role Activity
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Lateral Movement
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Monitor Backup Solution
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Monitor for Unauthorized Software
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Office 365 Detections
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Spectre And Meltdown Vulnerabilities
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Suspicious AWS EC2 Activities
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Unusual AWS EC2 Modifications
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Web Fraud Detection
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
From 78cc0c0f1793cf01227fb95cbccf499161b200d6 Mon Sep 17 00:00:00 2001
From: pyth0n1c
Date: Wed, 5 Mar 2025 14:24:11 -0800
Subject: [PATCH 27/67] updated deprecation mapping again
---
deprecated/deprecated_detection_mapping.yml | 729 ++++++++++----------
1 file changed, 366 insertions(+), 363 deletions(-)
diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml
index 48f6c3f118..1e7efff47c 100644
--- a/deprecated/deprecated_detection_mapping.yml
+++ b/deprecated/deprecated_detection_mapping.yml
@@ -957,366 +957,369 @@ detections:
deprecated_date: 2025-03-12
reason: ''
replacement_content: []
-baselines:
- - deprecated_content: Add Prohibited Processes to Enterprise Security
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- - deprecated_content: Baseline of API Calls per User ARN
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- - deprecated_content: Baseline of Excessive AWS Instances Launched by User - MLTK
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- - deprecated_content: Baseline of Excessive AWS Instances Terminated by User - MLTK
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- - deprecated_content: Previously seen API call per user roles in CloudTrail
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- - deprecated_content: Previously Seen AWS Provisioning Activity Sources
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- - deprecated_content: Previously Seen EC2 AMIs
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- - deprecated_content: Previously Seen EC2 Instance Types
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- - deprecated_content: Previously Seen EC2 Launches By User
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- - deprecated_content: Previously seen users in CloudTrail
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- - deprecated_content: Update previously seen users in CloudTrail
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
-investigations:
- - deprecated_content: All backup logs for host
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Amazon EKS Kubernetes activity by src ip
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: AWS Investigate Security Hub alerts by dest
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: AWS Investigate User Activities By AccessKeyId
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: AWS Investigate User Activities By ARN
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: AWS Network ACL Details from ID
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: AWS Network Interface details via resourceId
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: AWS S3 Bucket details via bucketName
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: GCP Kubernetes activity by src ip
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get All AWS Activity From City
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get All AWS Activity From Country
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get All AWS Activity From IP Address
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get All AWS Activity From Region
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get Backup Logs For Endpoint
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get Certificate logs for a domain
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get DNS Server History for a host
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get DNS traffic ratio
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get EC2 Instance Details by instanceId
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get EC2 Launch Details
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get Email Info
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get Emails From Specific Sender
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get First Occurrence and Last Occurrence of a MAC Address
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get History Of Email Sources
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get Logon Rights Modifications For Endpoint
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get Logon Rights Modifications For User
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get Notable History
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get Outbound Emails to Hidden Cobra Threat Actors
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get Parent Process Info
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get Process File Activity
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get Process Info
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get Process Information For Port Activity
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get Process Responsible For The DNS Traffic
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get Sysmon WMI Activity for Host
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Get Web Session Information via session id
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Investigate AWS activities via region name
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Investigate AWS User Activities by user field
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Investigate Failed Logins for Multiple Destinations
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Investigate Network Traffic From src ip
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Investigate Okta Activity by app
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Investigate Okta Activity by IP Address
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Investigate Pass the Hash Attempts
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Investigate Pass the Ticket Attempts
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Investigate Previous Unseen User
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Investigate Successful Remote Desktop Authentications
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Investigate Suspicious Strings in HTTP Header
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Investigate User Activities In Okta
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- - deprecated_content: Investigate Web POSTs From src
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
-stories:
- - deprecated_content: AWS Cryptomining
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: AWS Suspicious Provisioning Activities
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Common Phishing Frameworks
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Container Implantation Monitoring and Investigation
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Host Redirection
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Kubernetes Sensitive Role Activity
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Lateral Movement
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Monitor Backup Solution
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Monitor for Unauthorized Software
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Office 365 Detections
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Spectre And Meltdown Vulnerabilities
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Suspicious AWS EC2 Activities
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Unusual AWS EC2 Modifications
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
- - deprecated_content: Web Fraud Detection
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: ''
- replacement_content: []
+baselines: []
+investigations: []
+stories: []
+# baselines:
+# - deprecated_content: Add Prohibited Processes to Enterprise Security
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+# replacement_content: []
+# - deprecated_content: Baseline of API Calls per User ARN
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+# replacement_content: []
+# - deprecated_content: Baseline of Excessive AWS Instances Launched by User - MLTK
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+# replacement_content: []
+# - deprecated_content: Baseline of Excessive AWS Instances Terminated by User - MLTK
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+# replacement_content: []
+# - deprecated_content: Previously seen API call per user roles in CloudTrail
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+# replacement_content: []
+# - deprecated_content: Previously Seen AWS Provisioning Activity Sources
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+# replacement_content: []
+# - deprecated_content: Previously Seen EC2 AMIs
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+# replacement_content: []
+# - deprecated_content: Previously Seen EC2 Instance Types
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+# replacement_content: []
+# - deprecated_content: Previously Seen EC2 Launches By User
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+# replacement_content: []
+# - deprecated_content: Previously seen users in CloudTrail
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+# replacement_content: []
+# - deprecated_content: Update previously seen users in CloudTrail
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+# replacement_content: []
+# investigations:
+# - deprecated_content: All backup logs for host
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Amazon EKS Kubernetes activity by src ip
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: AWS Investigate Security Hub alerts by dest
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: AWS Investigate User Activities By AccessKeyId
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: AWS Investigate User Activities By ARN
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: AWS Network ACL Details from ID
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: AWS Network Interface details via resourceId
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: AWS S3 Bucket details via bucketName
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: GCP Kubernetes activity by src ip
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get All AWS Activity From City
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get All AWS Activity From Country
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get All AWS Activity From IP Address
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get All AWS Activity From Region
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get Backup Logs For Endpoint
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get Certificate logs for a domain
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get DNS Server History for a host
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get DNS traffic ratio
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get EC2 Instance Details by instanceId
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get EC2 Launch Details
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get Email Info
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get Emails From Specific Sender
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get First Occurrence and Last Occurrence of a MAC Address
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get History Of Email Sources
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get Logon Rights Modifications For Endpoint
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get Logon Rights Modifications For User
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get Notable History
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get Outbound Emails to Hidden Cobra Threat Actors
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get Parent Process Info
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get Process File Activity
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get Process Info
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get Process Information For Port Activity
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get Process Responsible For The DNS Traffic
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get Sysmon WMI Activity for Host
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Get Web Session Information via session id
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Investigate AWS activities via region name
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Investigate AWS User Activities by user field
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Investigate Failed Logins for Multiple Destinations
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Investigate Network Traffic From src ip
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Investigate Okta Activity by app
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Investigate Okta Activity by IP Address
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Investigate Pass the Hash Attempts
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Investigate Pass the Ticket Attempts
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Investigate Previous Unseen User
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Investigate Successful Remote Desktop Authentications
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Investigate Suspicious Strings in HTTP Header
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Investigate User Activities In Okta
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# - deprecated_content: Investigate Web POSTs From src
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+# replacement_content: []
+# stories:
+# - deprecated_content: AWS Cryptomining
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: ''
+# replacement_content: []
+# - deprecated_content: AWS Suspicious Provisioning Activities
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: ''
+# replacement_content: []
+# - deprecated_content: Common Phishing Frameworks
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: ''
+# replacement_content: []
+# - deprecated_content: Container Implantation Monitoring and Investigation
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: ''
+# replacement_content: []
+# - deprecated_content: Host Redirection
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: ''
+# replacement_content: []
+# - deprecated_content: Kubernetes Sensitive Role Activity
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: ''
+# replacement_content: []
+# - deprecated_content: Lateral Movement
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: ''
+# replacement_content: []
+# - deprecated_content: Monitor Backup Solution
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: ''
+# replacement_content: []
+# - deprecated_content: Monitor for Unauthorized Software
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: ''
+# replacement_content: []
+# - deprecated_content: Office 365 Detections
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: ''
+# replacement_content: []
+# - deprecated_content: Spectre And Meltdown Vulnerabilities
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: ''
+# replacement_content: []
+# - deprecated_content: Suspicious AWS EC2 Activities
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: ''
+# replacement_content: []
+# - deprecated_content: Unusual AWS EC2 Modifications
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: ''
+# replacement_content: []
+# - deprecated_content: Web Fraud Detection
+# deprecated_in_version: 5.2.0
+# deprecated_date: 2025-03-12
+# reason: ''
+# replacement_content: []
From d86e7667205765e76d6f7e0e8f7272a60a399452 Mon Sep 17 00:00:00 2001
From: pyth0n1c
Date: Thu, 6 Mar 2025 13:16:16 -0800
Subject: [PATCH 28/67] updated with missing content
---
deprecated/deprecated_detection_mapping.yml | 729 ++++++++++----------
1 file changed, 363 insertions(+), 366 deletions(-)
diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml
index 1e7efff47c..48f6c3f118 100644
--- a/deprecated/deprecated_detection_mapping.yml
+++ b/deprecated/deprecated_detection_mapping.yml
@@ -957,369 +957,366 @@ detections:
deprecated_date: 2025-03-12
reason: ''
replacement_content: []
-baselines: []
-investigations: []
-stories: []
-# baselines:
-# - deprecated_content: Add Prohibited Processes to Enterprise Security
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
-# replacement_content: []
-# - deprecated_content: Baseline of API Calls per User ARN
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
-# replacement_content: []
-# - deprecated_content: Baseline of Excessive AWS Instances Launched by User - MLTK
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
-# replacement_content: []
-# - deprecated_content: Baseline of Excessive AWS Instances Terminated by User - MLTK
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
-# replacement_content: []
-# - deprecated_content: Previously seen API call per user roles in CloudTrail
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
-# replacement_content: []
-# - deprecated_content: Previously Seen AWS Provisioning Activity Sources
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
-# replacement_content: []
-# - deprecated_content: Previously Seen EC2 AMIs
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
-# replacement_content: []
-# - deprecated_content: Previously Seen EC2 Instance Types
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
-# replacement_content: []
-# - deprecated_content: Previously Seen EC2 Launches By User
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
-# replacement_content: []
-# - deprecated_content: Previously seen users in CloudTrail
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
-# replacement_content: []
-# - deprecated_content: Update previously seen users in CloudTrail
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
-# replacement_content: []
-# investigations:
-# - deprecated_content: All backup logs for host
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Amazon EKS Kubernetes activity by src ip
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: AWS Investigate Security Hub alerts by dest
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: AWS Investigate User Activities By AccessKeyId
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: AWS Investigate User Activities By ARN
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: AWS Network ACL Details from ID
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: AWS Network Interface details via resourceId
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: AWS S3 Bucket details via bucketName
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: GCP Kubernetes activity by src ip
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get All AWS Activity From City
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get All AWS Activity From Country
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get All AWS Activity From IP Address
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get All AWS Activity From Region
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get Backup Logs For Endpoint
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get Certificate logs for a domain
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get DNS Server History for a host
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get DNS traffic ratio
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get EC2 Instance Details by instanceId
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get EC2 Launch Details
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get Email Info
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get Emails From Specific Sender
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get First Occurrence and Last Occurrence of a MAC Address
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get History Of Email Sources
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get Logon Rights Modifications For Endpoint
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get Logon Rights Modifications For User
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get Notable History
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get Outbound Emails to Hidden Cobra Threat Actors
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get Parent Process Info
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get Process File Activity
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get Process Info
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get Process Information For Port Activity
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get Process Responsible For The DNS Traffic
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get Sysmon WMI Activity for Host
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Get Web Session Information via session id
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Investigate AWS activities via region name
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Investigate AWS User Activities by user field
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Investigate Failed Logins for Multiple Destinations
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Investigate Network Traffic From src ip
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Investigate Okta Activity by app
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Investigate Okta Activity by IP Address
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Investigate Pass the Hash Attempts
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Investigate Pass the Ticket Attempts
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Investigate Previous Unseen User
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Investigate Successful Remote Desktop Authentications
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Investigate Suspicious Strings in HTTP Header
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Investigate User Activities In Okta
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# - deprecated_content: Investigate Web POSTs From src
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
-# replacement_content: []
-# stories:
-# - deprecated_content: AWS Cryptomining
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: ''
-# replacement_content: []
-# - deprecated_content: AWS Suspicious Provisioning Activities
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: ''
-# replacement_content: []
-# - deprecated_content: Common Phishing Frameworks
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: ''
-# replacement_content: []
-# - deprecated_content: Container Implantation Monitoring and Investigation
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: ''
-# replacement_content: []
-# - deprecated_content: Host Redirection
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: ''
-# replacement_content: []
-# - deprecated_content: Kubernetes Sensitive Role Activity
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: ''
-# replacement_content: []
-# - deprecated_content: Lateral Movement
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: ''
-# replacement_content: []
-# - deprecated_content: Monitor Backup Solution
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: ''
-# replacement_content: []
-# - deprecated_content: Monitor for Unauthorized Software
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: ''
-# replacement_content: []
-# - deprecated_content: Office 365 Detections
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: ''
-# replacement_content: []
-# - deprecated_content: Spectre And Meltdown Vulnerabilities
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: ''
-# replacement_content: []
-# - deprecated_content: Suspicious AWS EC2 Activities
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: ''
-# replacement_content: []
-# - deprecated_content: Unusual AWS EC2 Modifications
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: ''
-# replacement_content: []
-# - deprecated_content: Web Fraud Detection
-# deprecated_in_version: 5.2.0
-# deprecated_date: 2025-03-12
-# reason: ''
-# replacement_content: []
+baselines:
+ - deprecated_content: Add Prohibited Processes to Enterprise Security
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Baseline of API Calls per User ARN
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Baseline of Excessive AWS Instances Launched by User - MLTK
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Baseline of Excessive AWS Instances Terminated by User - MLTK
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Previously seen API call per user roles in CloudTrail
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Previously Seen AWS Provisioning Activity Sources
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Previously Seen EC2 AMIs
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Previously Seen EC2 Instance Types
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Previously Seen EC2 Launches By User
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Previously seen users in CloudTrail
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+ - deprecated_content: Update previously seen users in CloudTrail
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ replacement_content: []
+investigations:
+ - deprecated_content: All backup logs for host
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Amazon EKS Kubernetes activity by src ip
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: AWS Investigate Security Hub alerts by dest
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: AWS Investigate User Activities By AccessKeyId
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: AWS Investigate User Activities By ARN
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: AWS Network ACL Details from ID
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: AWS Network Interface details via resourceId
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: AWS S3 Bucket details via bucketName
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: GCP Kubernetes activity by src ip
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get All AWS Activity From City
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get All AWS Activity From Country
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get All AWS Activity From IP Address
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get All AWS Activity From Region
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Backup Logs For Endpoint
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Certificate logs for a domain
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get DNS Server History for a host
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get DNS traffic ratio
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get EC2 Instance Details by instanceId
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get EC2 Launch Details
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Email Info
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Emails From Specific Sender
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get First Occurrence and Last Occurrence of a MAC Address
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get History Of Email Sources
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Logon Rights Modifications For Endpoint
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Logon Rights Modifications For User
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Notable History
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Outbound Emails to Hidden Cobra Threat Actors
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Parent Process Info
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Process File Activity
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Process Info
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Process Information For Port Activity
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Process Responsible For The DNS Traffic
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Sysmon WMI Activity for Host
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Get Web Session Information via session id
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate AWS activities via region name
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate AWS User Activities by user field
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Failed Logins for Multiple Destinations
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Network Traffic From src ip
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Okta Activity by app
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Okta Activity by IP Address
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Pass the Hash Attempts
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Pass the Ticket Attempts
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Previous Unseen User
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Successful Remote Desktop Authentications
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Suspicious Strings in HTTP Header
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate User Activities In Okta
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+ - deprecated_content: Investigate Web POSTs From src
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
+ replacement_content: []
+stories:
+ - deprecated_content: AWS Cryptomining
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: AWS Suspicious Provisioning Activities
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Common Phishing Frameworks
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Container Implantation Monitoring and Investigation
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Host Redirection
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Kubernetes Sensitive Role Activity
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Lateral Movement
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Monitor Backup Solution
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Monitor for Unauthorized Software
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Office 365 Detections
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Spectre And Meltdown Vulnerabilities
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Suspicious AWS EC2 Activities
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Unusual AWS EC2 Modifications
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
+ - deprecated_content: Web Fraud Detection
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: ''
+ replacement_content: []
From 726dd930598ee95c7e3d4405329eaeb267bb2b19 Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Tue, 11 Mar 2025 17:20:32 -0700
Subject: [PATCH 29/67] adding a reason for empty detections
---
deprecated/deprecated_detection_mapping.yml | 200 ++++++++++----------
1 file changed, 100 insertions(+), 100 deletions(-)
diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml
index 48f6c3f118..7990514343 100644
--- a/deprecated/deprecated_detection_mapping.yml
+++ b/deprecated/deprecated_detection_mapping.yml
@@ -2,7 +2,7 @@ detections:
- deprecated_content: ASL AWS Excessive Security Scanning
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: AWS Cloud Provisioning From Previously Unseen Region
deprecated_in_version: 5.2.0
@@ -14,27 +14,27 @@ detections:
- deprecated_content: First time seen command line argument
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Windows connhost exe started forcefully
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Detect Mimikatz Using Loaded Images
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Kubernetes Azure detect sensitive role access
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Web Fraud - Anomalous User Clickspeed
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: EC2 Instance Started With Previously Unseen Instance Type
deprecated_in_version: 5.2.0
@@ -53,13 +53,13 @@ detections:
- deprecated_content: Domain Group Discovery With Net
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content:
- Windows Group Discovery Via Net
- deprecated_content: Kubernetes AWS detect sensitive role access
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Winword Spawning Windows Script Host
deprecated_in_version: 5.2.0
@@ -73,7 +73,7 @@ detections:
- deprecated_content: Winword Spawning PowerShell
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Attempted Credential Dump From Registry via Reg exe
@@ -131,27 +131,27 @@ detections:
- deprecated_content: Detect AWS API Activities From Unapproved Accounts
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Monitor DNS For Brand Abuse
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Kubernetes GCP detect sensitive object access
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Kubernetes Azure scan fingerprint
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: ASL AWS Password Policy Changes
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: O365 Suspicious Admin Email Forwarding
deprecated_in_version: 5.2.0
@@ -170,12 +170,12 @@ detections:
- deprecated_content: Kubernetes AWS detect service accounts forbidden failure access
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Osquery pack - ColdRoot detection
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Windows Modify Registry Reg Restore
deprecated_in_version: 5.2.0
@@ -186,7 +186,7 @@ detections:
- deprecated_content: Kubernetes GCP detect most active service accounts by pod
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Scheduled tasks used in BadRabbit ransomware
deprecated_in_version: 5.2.0
@@ -197,7 +197,7 @@ detections:
- deprecated_content: Suspicious Rundll32 Rename
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Remote System Discovery with Net
deprecated_in_version: 5.2.0
@@ -211,23 +211,23 @@ detections:
- deprecated_content: Remote System Discovery with Net
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content:
- Windows Sensitive Group Discovery With Net
- deprecated_content: DNS Query Requests Resolved by Unauthorized DNS Servers
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Suspicious Changes to File Associations
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: GCP Detect high risk permissions by resource and account
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Office Product Writing cab or inf
deprecated_in_version: 5.2.0
@@ -238,12 +238,12 @@ detections:
- deprecated_content: Identify New User Accounts
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Office Product Spawn CMD Process
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Windows DLL Search Order Hijacking Hunt
@@ -263,7 +263,7 @@ detections:
- deprecated_content: Okta ThreatInsight Login Failure with High Unknown users
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Detect Spike in Security Group Activity
deprecated_in_version: 5.2.0
@@ -275,7 +275,7 @@ detections:
- deprecated_content: Office Product Spawning BITSAdmin
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Create local admin accounts using net exe
@@ -287,7 +287,7 @@ detections:
- deprecated_content: Abnormally High AWS Instances Terminated by User - MLTK
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Windows Office Product Spawning MSDT
deprecated_in_version: 5.2.0
@@ -298,18 +298,18 @@ detections:
- deprecated_content: Detect Spike in AWS API Activity
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Office Product Spawning Windows Script Host
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Prohibited Software On Endpoint
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content:
- Attacker Tools On Endpoint
- deprecated_content: AWS Cloud Provisioning From Previously Unseen Country
@@ -332,19 +332,19 @@ detections:
- deprecated_content: Detect Critical Alerts from Security Tools
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content:
- Microsoft Defender Incident Alerts
- deprecated_content: Excel Spawning PowerShell
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Office Application Spawn rundll32 process
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Excessive Usage Of Net App
@@ -374,7 +374,7 @@ detections:
- deprecated_content: Suspicious Email - UBA Anomaly
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Detect web traffic to dynamic domain providers
deprecated_in_version: 5.2.0
@@ -392,17 +392,17 @@ detections:
- deprecated_content: Kubernetes AWS detect RBAC authorization by account
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Kubernetes Azure detect service accounts forbidden failure access
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Remote Registry Key modifications
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: O365 Suspicious User Email Forwarding
deprecated_in_version: 5.2.0
@@ -414,13 +414,13 @@ detections:
- deprecated_content: Office Product Spawning MSHTA
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Kubernetes AWS detect most active service accounts by pod
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Correlation by Repository and Risk
deprecated_in_version: 5.2.0
@@ -431,12 +431,12 @@ detections:
- deprecated_content: Kubernetes Azure detect RBAC authorization by account
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Clients Connecting to Multiple DNS Servers
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Excessive Service Stop Attempt
deprecated_in_version: 5.2.0
@@ -454,7 +454,7 @@ detections:
- deprecated_content: Suspicious writes to System Volume Information
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Detect new user AWS Console Login
deprecated_in_version: 5.2.0
@@ -475,12 +475,12 @@ detections:
- deprecated_content: Detection of DNS Tunnels
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Detect DNS requests to Phishing Sites leveraging EvilGinx2
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Office Document Creating Schedule Task
deprecated_in_version: 5.2.0
@@ -498,7 +498,7 @@ detections:
- deprecated_content: Unsuccessful Netbackup backups
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Detect Mimikatz Via PowerShell And EventCode 4703
deprecated_in_version: 5.2.0
@@ -509,7 +509,7 @@ detections:
- deprecated_content: Winword Spawning Cmd
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: GCP Kubernetes cluster scan detection
@@ -522,12 +522,12 @@ detections:
- deprecated_content: Kubernetes GCP detect suspicious kubectl calls
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: gcp detect oauth token abuse
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Correlation by User and Risk
deprecated_in_version: 5.2.0
@@ -544,7 +544,7 @@ detections:
- deprecated_content: Office Product Spawning Wmic
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Extraction of Registry Hives
@@ -588,17 +588,17 @@ detections:
- deprecated_content: Abnormally High AWS Instances Launched by User - MLTK
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Reg exe used to hide files directories via registry keys
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Detect Long DNS TXT Record Response
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Password Policy Discovery with Net
deprecated_in_version: 5.2.0
@@ -622,12 +622,12 @@ detections:
- deprecated_content: Kubernetes Azure detect suspicious kubectl calls
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Kubernetes GCP detect sensitive role access
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Detect Webshell Exploit Behavior
deprecated_in_version: 5.2.0
@@ -638,17 +638,17 @@ detections:
- deprecated_content: DNS record changed
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Unsigned Image Loaded by LSASS
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Detect USB device insertion
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Windows Network Share Interaction With Net
deprecated_in_version: 5.2.0
@@ -713,7 +713,7 @@ detections:
- deprecated_content: Windows hosts file modification
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: MSHTML Module Load in Office Product
deprecated_in_version: 5.2.0
@@ -731,7 +731,7 @@ detections:
- deprecated_content: Web Fraud - Account Harvesting
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Office Spawning Control
deprecated_in_version: 5.2.0
@@ -742,7 +742,7 @@ detections:
- deprecated_content: Detect Activity Related to Pass the Hash Attacks
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Deleting Of Net Users
deprecated_in_version: 5.2.0
@@ -753,7 +753,7 @@ detections:
- deprecated_content: Suspicious File Write
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: AWS EKS Kubernetes cluster sensitive object access
deprecated_in_version: 5.2.0
@@ -765,7 +765,7 @@ detections:
- deprecated_content: Spectre and Meltdown Vulnerable Systems
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: EC2 Instance Started With Previously Unseen User
deprecated_in_version: 5.2.0
@@ -777,13 +777,13 @@ detections:
- deprecated_content: Office Product Spawning CertUtil
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Kubernetes GCP detect RBAC authorizations by account
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Office Application Drop Executable
deprecated_in_version: 5.2.0
@@ -794,12 +794,12 @@ detections:
- deprecated_content: Kubernetes Azure active service accounts by pod namespace
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Kubernetes Azure pod scan fingerprint
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Detect Spike in Network ACL Activity
deprecated_in_version: 5.2.0
@@ -811,13 +811,13 @@ detections:
- deprecated_content: Suspicious Powershell Command-Line Arguments
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content:
- Malicious PowerShell Process - Encoded Command
- deprecated_content: Office Application Spawn Regsvr32 process
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Detect API activity from users without MFA
@@ -830,12 +830,12 @@ detections:
- deprecated_content: Kubernetes Azure detect sensitive object access
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Web Fraud - Password Sharing Across Accounts
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Disabling Net User Account
deprecated_in_version: 5.2.0
@@ -846,17 +846,17 @@ detections:
- deprecated_content: GCP Detect accounts with high risk roles by project
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Kubernetes GCP detect service accounts forbidden failure access
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Extended Period Without Successful Netbackup Backups
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Office Product Spawning Rundll32 with no DLL
deprecated_in_version: 5.2.0
@@ -881,7 +881,7 @@ detections:
- deprecated_content: Uncommon Processes On Endpoint
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content:
- Attacker Tools On Endpoint
- deprecated_content: Dump LSASS via procdump Rename
@@ -900,62 +900,62 @@ detections:
- deprecated_content: Excel Spawning Windows Script Host
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: GitHub Actions Disable Security Workflow
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Github Commit Changes In Master
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Github Commit In Develop
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: GitHub Dependabot Alert
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: GitHub Pull Request from Unknown User
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Known Services Killed by Ransomware
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Remote Desktop Network Bruteforce
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Suspicious Driver Loaded Path
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Suspicious Event Log Service Behavior
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Suspicious Process File Path
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Windows Service Stop Via Net and SC Application
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
baselines:
- deprecated_content: Add Prohibited Processes to Enterprise Security
@@ -1253,70 +1253,70 @@ stories:
- deprecated_content: AWS Cryptomining
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: AWS Suspicious Provisioning Activities
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Common Phishing Frameworks
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Container Implantation Monitoring and Investigation
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Host Redirection
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Kubernetes Sensitive Role Activity
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Lateral Movement
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Monitor Backup Solution
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Monitor for Unauthorized Software
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Office 365 Detections
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Spectre And Meltdown Vulnerabilities
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Suspicious AWS EC2 Activities
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Unusual AWS EC2 Modifications
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
- deprecated_content: Web Fraud Detection
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: ''
+ reason: The detection does not work as expected and is now deprecated
replacement_content: []
From 2445b44357cbe25cc501d3a303bfa349b5243ed3 Mon Sep 17 00:00:00 2001
From: Steven Dick <38897662+nterl0k@users.noreply.github.com>
Date: Wed, 12 Mar 2025 07:32:14 -0400
Subject: [PATCH 30/67] Update o365_suspect_search_terms_regex.yml
removing regex using $ because ContentCTL is being dumb and thinks it's a variable.
---
macros/o365_suspect_search_terms_regex.yml | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/macros/o365_suspect_search_terms_regex.yml b/macros/o365_suspect_search_terms_regex.yml
index b1dbd9fe3d..e5190a3cb3 100644
--- a/macros/o365_suspect_search_terms_regex.yml
+++ b/macros/o365_suspect_search_terms_regex.yml
@@ -1,3 +1,3 @@
-definition: "(?i)password|credential$|credentials$|login|passwd|shadow|active directory|account|username|network|computer|access|MFA|bank|deposit|payroll|EFT|Electonic Funds|routing"
+definition: "(?i)password|credential|login|passwd|shadow|active directory|account|username|network|computer|access|MFA|bank|deposit|payroll|EFT|Electonic Funds|routing"
description: A regex used with match statements preloaded with generic suspicious terms or phrases. Is used to detect malicious actor or insider threat searches, replace/modify these terms to suit your organization.
-name: o365_suspect_search_terms_regex
\ No newline at end of file
+name: o365_suspect_search_terms_regex
From 5e02c6b38cb09b64ccbe7fa04ca160245c220c69 Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Wed, 12 Mar 2025 14:25:10 -0700
Subject: [PATCH 31/67] updating for nexus
---
deprecated/deprecated_detection_mapping.yml | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml
index 7990514343..1c79dd2c27 100644
--- a/deprecated/deprecated_detection_mapping.yml
+++ b/deprecated/deprecated_detection_mapping.yml
@@ -1320,3 +1320,8 @@ stories:
deprecated_date: 2025-03-12
reason: The detection does not work as expected and is now deprecated
replacement_content: []
+ - deprecated_content: Nexus APT Threat Activity
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: The detection does not work as expected and is now deprecated
+ replacement_content: []
From 97395878e97777cc96786c92db47ad574c6d59a6 Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Thu, 13 Mar 2025 17:42:27 -0700
Subject: [PATCH 32/67] updating text
---
deprecated/deprecated_detection_mapping.yml | 322 ++++++++++----------
1 file changed, 161 insertions(+), 161 deletions(-)
diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml
index 1c79dd2c27..c5d72406cb 100644
--- a/deprecated/deprecated_detection_mapping.yml
+++ b/deprecated/deprecated_detection_mapping.yml
@@ -2,7 +2,7 @@ detections:
- deprecated_content: ASL AWS Excessive Security Scanning
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: AWS Cloud Provisioning From Previously Unseen Region
deprecated_in_version: 5.2.0
@@ -14,27 +14,27 @@ detections:
- deprecated_content: First time seen command line argument
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Windows connhost exe started forcefully
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Detect Mimikatz Using Loaded Images
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Kubernetes Azure detect sensitive role access
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Web Fraud - Anomalous User Clickspeed
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: EC2 Instance Started With Previously Unseen Instance Type
deprecated_in_version: 5.2.0
@@ -53,13 +53,13 @@ detections:
- deprecated_content: Domain Group Discovery With Net
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Group Discovery Via Net
- deprecated_content: Kubernetes AWS detect sensitive role access
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Winword Spawning Windows Script Host
deprecated_in_version: 5.2.0
@@ -73,7 +73,7 @@ detections:
- deprecated_content: Winword Spawning PowerShell
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Attempted Credential Dump From Registry via Reg exe
@@ -131,27 +131,27 @@ detections:
- deprecated_content: Detect AWS API Activities From Unapproved Accounts
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Monitor DNS For Brand Abuse
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Kubernetes GCP detect sensitive object access
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Kubernetes Azure scan fingerprint
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: ASL AWS Password Policy Changes
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: O365 Suspicious Admin Email Forwarding
deprecated_in_version: 5.2.0
@@ -170,12 +170,12 @@ detections:
- deprecated_content: Kubernetes AWS detect service accounts forbidden failure access
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Osquery pack - ColdRoot detection
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Windows Modify Registry Reg Restore
deprecated_in_version: 5.2.0
@@ -186,7 +186,7 @@ detections:
- deprecated_content: Kubernetes GCP detect most active service accounts by pod
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Scheduled tasks used in BadRabbit ransomware
deprecated_in_version: 5.2.0
@@ -197,7 +197,7 @@ detections:
- deprecated_content: Suspicious Rundll32 Rename
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Remote System Discovery with Net
deprecated_in_version: 5.2.0
@@ -211,23 +211,23 @@ detections:
- deprecated_content: Remote System Discovery with Net
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Sensitive Group Discovery With Net
- deprecated_content: DNS Query Requests Resolved by Unauthorized DNS Servers
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Suspicious Changes to File Associations
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: GCP Detect high risk permissions by resource and account
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Office Product Writing cab or inf
deprecated_in_version: 5.2.0
@@ -238,12 +238,12 @@ detections:
- deprecated_content: Identify New User Accounts
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Office Product Spawn CMD Process
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Windows DLL Search Order Hijacking Hunt
@@ -263,7 +263,7 @@ detections:
- deprecated_content: Okta ThreatInsight Login Failure with High Unknown users
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Detect Spike in Security Group Activity
deprecated_in_version: 5.2.0
@@ -275,7 +275,7 @@ detections:
- deprecated_content: Office Product Spawning BITSAdmin
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Create local admin accounts using net exe
@@ -287,7 +287,7 @@ detections:
- deprecated_content: Abnormally High AWS Instances Terminated by User - MLTK
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Windows Office Product Spawning MSDT
deprecated_in_version: 5.2.0
@@ -298,18 +298,18 @@ detections:
- deprecated_content: Detect Spike in AWS API Activity
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Office Product Spawning Windows Script Host
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Prohibited Software On Endpoint
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Attacker Tools On Endpoint
- deprecated_content: AWS Cloud Provisioning From Previously Unseen Country
@@ -332,19 +332,19 @@ detections:
- deprecated_content: Detect Critical Alerts from Security Tools
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Microsoft Defender Incident Alerts
- deprecated_content: Excel Spawning PowerShell
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Office Application Spawn rundll32 process
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Excessive Usage Of Net App
@@ -374,7 +374,7 @@ detections:
- deprecated_content: Suspicious Email - UBA Anomaly
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Detect web traffic to dynamic domain providers
deprecated_in_version: 5.2.0
@@ -392,17 +392,17 @@ detections:
- deprecated_content: Kubernetes AWS detect RBAC authorization by account
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Kubernetes Azure detect service accounts forbidden failure access
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Remote Registry Key modifications
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: O365 Suspicious User Email Forwarding
deprecated_in_version: 5.2.0
@@ -414,13 +414,13 @@ detections:
- deprecated_content: Office Product Spawning MSHTA
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Kubernetes AWS detect most active service accounts by pod
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Correlation by Repository and Risk
deprecated_in_version: 5.2.0
@@ -431,12 +431,12 @@ detections:
- deprecated_content: Kubernetes Azure detect RBAC authorization by account
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Clients Connecting to Multiple DNS Servers
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Excessive Service Stop Attempt
deprecated_in_version: 5.2.0
@@ -454,7 +454,7 @@ detections:
- deprecated_content: Suspicious writes to System Volume Information
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Detect new user AWS Console Login
deprecated_in_version: 5.2.0
@@ -475,12 +475,12 @@ detections:
- deprecated_content: Detection of DNS Tunnels
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Detect DNS requests to Phishing Sites leveraging EvilGinx2
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Office Document Creating Schedule Task
deprecated_in_version: 5.2.0
@@ -498,7 +498,7 @@ detections:
- deprecated_content: Unsuccessful Netbackup backups
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Detect Mimikatz Via PowerShell And EventCode 4703
deprecated_in_version: 5.2.0
@@ -509,7 +509,7 @@ detections:
- deprecated_content: Winword Spawning Cmd
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: GCP Kubernetes cluster scan detection
@@ -522,12 +522,12 @@ detections:
- deprecated_content: Kubernetes GCP detect suspicious kubectl calls
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: gcp detect oauth token abuse
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Correlation by User and Risk
deprecated_in_version: 5.2.0
@@ -544,7 +544,7 @@ detections:
- deprecated_content: Office Product Spawning Wmic
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Extraction of Registry Hives
@@ -588,17 +588,17 @@ detections:
- deprecated_content: Abnormally High AWS Instances Launched by User - MLTK
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Reg exe used to hide files directories via registry keys
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Detect Long DNS TXT Record Response
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Password Policy Discovery with Net
deprecated_in_version: 5.2.0
@@ -622,12 +622,12 @@ detections:
- deprecated_content: Kubernetes Azure detect suspicious kubectl calls
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Kubernetes GCP detect sensitive role access
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Detect Webshell Exploit Behavior
deprecated_in_version: 5.2.0
@@ -638,17 +638,17 @@ detections:
- deprecated_content: DNS record changed
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Unsigned Image Loaded by LSASS
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Detect USB device insertion
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Windows Network Share Interaction With Net
deprecated_in_version: 5.2.0
@@ -713,7 +713,7 @@ detections:
- deprecated_content: Windows hosts file modification
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: MSHTML Module Load in Office Product
deprecated_in_version: 5.2.0
@@ -731,7 +731,7 @@ detections:
- deprecated_content: Web Fraud - Account Harvesting
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Office Spawning Control
deprecated_in_version: 5.2.0
@@ -742,7 +742,7 @@ detections:
- deprecated_content: Detect Activity Related to Pass the Hash Attacks
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Deleting Of Net Users
deprecated_in_version: 5.2.0
@@ -753,7 +753,7 @@ detections:
- deprecated_content: Suspicious File Write
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: AWS EKS Kubernetes cluster sensitive object access
deprecated_in_version: 5.2.0
@@ -765,7 +765,7 @@ detections:
- deprecated_content: Spectre and Meltdown Vulnerable Systems
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: EC2 Instance Started With Previously Unseen User
deprecated_in_version: 5.2.0
@@ -777,13 +777,13 @@ detections:
- deprecated_content: Office Product Spawning CertUtil
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Kubernetes GCP detect RBAC authorizations by account
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Office Application Drop Executable
deprecated_in_version: 5.2.0
@@ -794,12 +794,12 @@ detections:
- deprecated_content: Kubernetes Azure active service accounts by pod namespace
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Kubernetes Azure pod scan fingerprint
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Detect Spike in Network ACL Activity
deprecated_in_version: 5.2.0
@@ -811,13 +811,13 @@ detections:
- deprecated_content: Suspicious Powershell Command-Line Arguments
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Malicious PowerShell Process - Encoded Command
- deprecated_content: Office Application Spawn Regsvr32 process
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Detect API activity from users without MFA
@@ -830,12 +830,12 @@ detections:
- deprecated_content: Kubernetes Azure detect sensitive object access
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Web Fraud - Password Sharing Across Accounts
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Disabling Net User Account
deprecated_in_version: 5.2.0
@@ -846,17 +846,17 @@ detections:
- deprecated_content: GCP Detect accounts with high risk roles by project
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Kubernetes GCP detect service accounts forbidden failure access
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Extended Period Without Successful Netbackup Backups
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Office Product Spawning Rundll32 with no DLL
deprecated_in_version: 5.2.0
@@ -881,7 +881,7 @@ detections:
- deprecated_content: Uncommon Processes On Endpoint
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Attacker Tools On Endpoint
- deprecated_content: Dump LSASS via procdump Rename
@@ -900,62 +900,62 @@ detections:
- deprecated_content: Excel Spawning Windows Script Host
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: GitHub Actions Disable Security Workflow
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Github Commit Changes In Master
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Github Commit In Develop
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: GitHub Dependabot Alert
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: GitHub Pull Request from Unknown User
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Known Services Killed by Ransomware
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Remote Desktop Network Bruteforce
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Suspicious Driver Loaded Path
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Suspicious Event Log Service Behavior
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Suspicious Process File Path
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Windows Service Stop Via Net and SC Application
deprecated_in_version: 5.3.0
deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
baselines:
- deprecated_content: Add Prohibited Processes to Enterprise Security
@@ -1250,78 +1250,78 @@ investigations:
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
replacement_content: []
stories:
- - deprecated_content: AWS Cryptomining
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
- replacement_content: []
- - deprecated_content: AWS Suspicious Provisioning Activities
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
- replacement_content: []
- - deprecated_content: Common Phishing Frameworks
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
- replacement_content: []
- - deprecated_content: Container Implantation Monitoring and Investigation
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
- replacement_content: []
- - deprecated_content: Host Redirection
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
- replacement_content: []
- - deprecated_content: Kubernetes Sensitive Role Activity
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
- replacement_content: []
- - deprecated_content: Lateral Movement
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
- replacement_content: []
- - deprecated_content: Monitor Backup Solution
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
- replacement_content: []
- - deprecated_content: Monitor for Unauthorized Software
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
- replacement_content: []
- - deprecated_content: Office 365 Detections
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
- replacement_content: []
- - deprecated_content: Spectre And Meltdown Vulnerabilities
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
- replacement_content: []
- - deprecated_content: Suspicious AWS EC2 Activities
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
- replacement_content: []
- - deprecated_content: Unusual AWS EC2 Modifications
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
- replacement_content: []
- - deprecated_content: Web Fraud Detection
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
- replacement_content: []
- - deprecated_content: Nexus APT Threat Activity
- deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: The detection does not work as expected and is now deprecated
- replacement_content: []
+ - deprecated_content: AWS Cryptomining
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content: []
+ - deprecated_content: AWS Suspicious Provisioning Activities
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content: []
+ - deprecated_content: Common Phishing Frameworks
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content: []
+ - deprecated_content: Container Implantation Monitoring and Investigation
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content: []
+ - deprecated_content: Host Redirection
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content: []
+ - deprecated_content: Kubernetes Sensitive Role Activity
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content: []
+ - deprecated_content: Lateral Movement
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content: []
+ - deprecated_content: Monitor Backup Solution
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content: []
+ - deprecated_content: Monitor for Unauthorized Software
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content: []
+ - deprecated_content: Office 365 Detections
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content: []
+ - deprecated_content: Spectre And Meltdown Vulnerabilities
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content: []
+ - deprecated_content: Suspicious AWS EC2 Activities
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content: []
+ - deprecated_content: Unusual AWS EC2 Modifications
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content: []
+ - deprecated_content: Web Fraud Detection
+ deprecated_in_version: 5.2.0
+ deprecated_date: 2025-03-12
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content: []
+ - deprecated_content: Nexus APT Threat Activity
+ deprecated_in_version: 5.4.0
+ deprecated_date: 2025-03-12
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content: []
\ No newline at end of file
From bebfe2e13e2d5b89afd5fd7514794dbcef7a9ea5 Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Thu, 13 Mar 2025 18:12:45 -0700
Subject: [PATCH 33/67] updating lookups from latest mapping
---
lookups/deprecation_info.csv | 195 +++++++++++++++++++++++++++++++++++
lookups/deprecation_info.yml | 9 ++
2 files changed, 204 insertions(+)
create mode 100644 lookups/deprecation_info.csv
create mode 100644 lookups/deprecation_info.yml
diff --git a/lookups/deprecation_info.csv b/lookups/deprecation_info.csv
new file mode 100644
index 0000000000..ca41e89981
--- /dev/null
+++ b/lookups/deprecation_info.csv
@@ -0,0 +1,195 @@
+Name,Content Type,Deprecated in Version,Reason,Migration Guide,Replacement Content
+ESCU - ASL AWS Excessive Security Scanning - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - AWS Cloud Provisioning From Previously Unseen Region - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5aba1860-9617-4af9-b19d-aecac16fe4f2
+ESCU - First time seen command line argument - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Windows connhost exe started forcefully - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Detect Mimikatz Using Loaded Images - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Kubernetes Azure detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Web Fraud - Anomalous User Clickspeed - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - EC2 Instance Started With Previously Unseen Instance Type - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c6ddbf53-9715-49f3-bb4c-fb2e8a309cda
+ESCU - EC2 Instance Started With Previously Unseen AMI - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/bc24922d-987c-4645-b288-f8c73ec194c4
+ESCU - Domain Group Discovery With Net - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c5c8e0f3-147a-43da-bf04-4cfaec27dc44
+ESCU - Kubernetes AWS detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Winword Spawning Windows Script Host - Rule,Detection,5.2.0,"The following analytics was deprecated in favour of a more generic approach. Where instead of creating specific analytic for every potentially suspicious child of an office product. We group them by threat level.
+This would ease management and false positives tuning.",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Winword Spawning PowerShell - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Attempted Credential Dump From Registry via Reg exe - Rule,Detection,5.2.0,"This analytic had some overlap with another one, hence the deprecation. It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry Hive Dump Via CommandLine",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5aaff29d-0cce-405b-9ee8-5d06b49d045e
+ESCU - Detect processes used for System Network Configuration Discovery - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/3f0b95e3-3195-46ac-bea3-84fb59e7fac5
+ESCU - Execution of File With Spaces Before Extension - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b06a555e-dce0-417d-a2eb-28a5d8d66ef7
+ESCU - EC2 Instance Started In Previously Unseen Region - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/fa4089e2-50e3-40f7-8469-d2cc1564ca59
+ESCU - Office Document Spawned Child Process To Download - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f02b64b8-cbea-4f75-bf77-7a05111566b1
+ESCU - Detect new API calls from user roles - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2181ad1f-1e73-4d0c-9780-e8880482a08f
+ESCU - Cmdline Tool Not Executed In CMD Shell - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2afa393f-b88d-41b7-9793-623c93a2dfde
+ESCU - Linux Auditd Find Private Keys - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/892eb674-3344-4143-8e52-4775b1daf3f1
+ESCU - Detect AWS API Activities From Unapproved Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Monitor DNS For Brand Abuse - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Kubernetes GCP detect sensitive object access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Kubernetes Azure scan fingerprint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - ASL AWS Password Policy Changes - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - O365 Suspicious Admin Email Forwarding - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/0b6bc75c-05d1-4101-9fc3-97e706168f24
+ESCU - AWS Cloud Provisioning From Previously Unseen City - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/e7ecc5e0-88df-48b9-91af-51104c68f02f
+ESCU - Kubernetes AWS detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Osquery pack - ColdRoot detection - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Windows Modify Registry Reg Restore - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a17af481-e2ad-494c-9da6-afb4d243a019
+ESCU - Kubernetes GCP detect most active service accounts by pod - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Scheduled tasks used in BadRabbit ransomware - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d5af132c-7c17-439c-9d31-13d55340f36c
+ESCU - Suspicious Rundll32 Rename - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Remote System Discovery with Net - Rule,Detection,5.2.0,"This analytic was focusing on 2 separate and unrelated type of threats or actions. It was split into other analytics, namely:
+
+Windows Network Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277
+Windows Sensitive Group Discovery With Net / a23a0e20-0b1b-4a07-82e5-ec5f70811e7a",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/4dc3951f-b3f8-4f46-b412-76a483f72277
+ESCU - Remote System Discovery with Net - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d9eb7cda-5622-4722-bc88-7f2442f4b5af
+ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Suspicious Changes to File Associations - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - GCP Detect high risk permissions by resource and account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Office Product Writing cab or inf - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/dbdd251e-dd45-4ec9-a555-f5e151391746
+ESCU - Identify New User Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Office Product Spawn CMD Process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Windows DLL Search Order Hijacking Hunt - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/79c7d1fc-64c7-91be-a616-ccda752efe81
+ESCU - ASL AWS CreateAccessKey - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/81a9f2fe-1697-473c-af1d-086b0d8b63c8
+ESCU - Okta ThreatInsight Login Failure with High Unknown users - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Detect Spike in Security Group Activity - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d4dfb7f3-7a37-498a-b5df-f19334e871af
+ESCU - Office Product Spawning BITSAdmin - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Create local admin accounts using net exe - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2c568c34-bb57-4b43-9d75-19c605b98e70
+ESCU - Abnormally High AWS Instances Terminated by User - MLTK - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Windows Office Product Spawning MSDT - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a3148fad-3734-4b7f-9a71-62f08d39fab1
+ESCU - Detect Spike in AWS API Activity - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Office Product Spawning Windows Script Host - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Prohibited Software On Endpoint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a51bfe1a-94f0-48cc-b4e4-16a110145893
+ESCU - AWS Cloud Provisioning From Previously Unseen Country - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/94994255-3acf-4213-9b3f-0494df03bb31
+ESCU - Detect Critical Alerts from Security Tools - Rule,Detection,5.2.0,"As discussed internally, this analytic was too generic for an analyst to do anything with it. It was deprecated in favor of the more specific approach provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender Incident Alerts. Going forward analytics from leveraging alerts from vendors will have their specific analytics.",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/38f034ed-1598-46c8-95e8-14edf05fdf5d
+ESCU - Detect Critical Alerts from Security Tools - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/13435b55-afd8-46d4-9045-7d5457f430a5
+ESCU - Excel Spawning PowerShell - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Office Application Spawn rundll32 process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Excessive Usage Of Net App - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/355ba810-0a20-4215-8485-9ce3f87f2e38
+ESCU - Elevated Group Discovery With Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d9eb7cda-5622-4722-bc88-7f2442f4b5af
+ESCU - Local Account Discovery with Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7742987e-88c1-476b-a626-a869e088ab72
+ESCU - Windows Command Shell Fetch Env Variables - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/aec157f4-8783-4584-aca6-754c4dc7fba9
+ESCU - Suspicious Email - UBA Anomaly - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Detect web traffic to dynamic domain providers - Rule,Detection,5.2.0,Updated to use a different log source,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a1e761ac-1344-4dbd-88b2-3f34c912d359
+ESCU - Okta Failed SSO Attempts - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5f661629-9750-4cb9-897c-1f05d6db8727
+ESCU - Kubernetes AWS detect RBAC authorization by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Kubernetes Azure detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Remote Registry Key modifications - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - O365 Suspicious User Email Forwarding - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/0b6bc75c-05d1-4101-9fc3-97e706168f24
+ESCU - Office Product Spawning MSHTA - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Kubernetes AWS detect most active service accounts by pod - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Correlation by Repository and Risk - Rule,Detection,5.2.0,Detections updated to use the datamodel,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/161bc0ca-4651-4c13-9c27-27770660cf67
+ESCU - Kubernetes Azure detect RBAC authorization by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Clients Connecting to Multiple DNS Servers - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Excessive Service Stop Attempt - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/8f3a614f-6b98-4f7d-82dd-d0df38452a8b
+ESCU - Multiple Okta Users With Invalid Credentials From The Same IP - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/de365ffa-42f5-46b5-b43f-fa72290b8218
+ESCU - Suspicious writes to System Volume Information - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Detect new user AWS Console Login - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/bc91a8cd-35e7-4bb2-6140-e756cc46fd71
+ESCU - Domain Account Discovery With Net App - Rule,Detection,5.2.0,"This analytic was a TTP that looked only for commands that tries to query info about the users via net user /do. This had a couple of issues, such as triggering on creation of users via the /add flag etc..
+It was deprecated in favor of a more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7742987e-88c1-476b-a626-a869e088ab72
+ESCU - Detection of DNS Tunnels - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Detect DNS requests to Phishing Sites leveraging EvilGinx2 - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Office Document Creating Schedule Task - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d7297cfa-1f04-4714-bfbe-3679e0666959
+ESCU - Okta Account Locked Out - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a511426e-184f-4de6-8711-cfd2af29d1e1
+ESCU - Unsuccessful Netbackup backups - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Detect Mimikatz Via PowerShell And EventCode 4703 - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/8148c29c-c952-11eb-9255-acde48001122
+ESCU - Winword Spawning Cmd - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - GCP Kubernetes cluster scan detection - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f9cadf4e-df22-4f4e-a08f-9d3344c2165d
+ESCU - Kubernetes GCP detect suspicious kubectl calls - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - gcp detect oauth token abuse - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Correlation by User and Risk - Rule,Detection,5.2.0,Detections updated to use the datamodel,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/161bc0ca-4651-4c13-9c27-27770660cf67
+ESCU - Processes created by netsh - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b89919ed-fe5f-492c-b139-95dbb162040e
+ESCU - Office Product Spawning Wmic - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Extraction of Registry Hives - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5aaff29d-0cce-405b-9ee8-5d06b49d045e
+ESCU - Attempt To Stop Security Service - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/9ed27cea-4e27-4eff-b2c6-aac9e78a7517
+ESCU - Windows MSIExec With Network Connections - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b0fd38c7-f71a-43a2-870e-f3ca06bcdd99
+ESCU - Windows Query Registry Reg Save - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/466379bc-0f47-476c-8202-16ef38112e0d
+ESCU - Cloud Network Access Control List Deleted - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/ada0f478-84a8-4641-a3f1-d82362d6fd75
+ESCU - O365 Suspicious Rights Delegation - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2246c142-a678-45f8-8546-aaed7e0efd30
+ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Reg exe used to hide files directories via registry keys - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Detect Long DNS TXT Record Response - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Password Policy Discovery with Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/e52f7865-be78-46bf-b7ed-150fbe447613
+ESCU - AWS Cloud Provisioning From Previously Unseen IP Address - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f86a8ec9-b042-45eb-92f4-e9ed1d781078
+ESCU - Network Connection Discovery With Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/86a5b949-679b-4197-8d4c-9c180a818c45
+ESCU - Kubernetes Azure detect suspicious kubectl calls - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Kubernetes GCP detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Detect Webshell Exploit Behavior - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2d4470ef-7158-4b47-b68b-1f7f16382156
+ESCU - DNS record changed - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Unsigned Image Loaded by LSASS - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Detect USB device insertion - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Windows Network Share Interaction With Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/e51fbdb0-0be0-474f-92ea-d289f71a695e
+ESCU - Account Discovery With Net App - Rule,Detection,5.2.0,"This analytic was a TTP that focused on unrelated things and called account discovery. Since there were other detection that overlapped with it. I choose to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 / Windows Excessive Usage Of Net App.",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/355ba810-0a20-4215-8485-9ce3f87f2e38
+ESCU - Change Default File Association - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7d1f031f-f1c9-43be-8b0b-c4e3e8a8928a
+ESCU - Windows Lateral Tool Transfer RemCom - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7e3d68db-ea4d-419b-adbd-e14a525ecf09
+ESCU - Office Document Executing Macro Code - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7cfec906-2697-43f7-898b-83634a051d9a
+ESCU - Okta Account Lockout Events - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a511426e-184f-4de6-8711-cfd2af29d1e1
+ESCU - Abnormally High AWS Instances Launched by User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f2361e9f-3928-496c-a556-120cd4223a65
+ESCU - EC2 Instance Modified With Previously Unseen User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2181ad1f-1e73-4d0c-9780-e8880482a08f
+ESCU - Windows Valid Account With Never Expires Password - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/11f93009-8083-43fd-82a7-821fcbdc8342
+ESCU - Windows hosts file modification - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - MSHTML Module Load in Office Product - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/4cc015c9-687c-40d2-adcc-46350f66e10c
+ESCU - Abnormally High AWS Instances Terminated by User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/ef629fc9-1583-4590-b62a-f2247fbf7bbf
+ESCU - Web Fraud - Account Harvesting - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Office Spawning Control - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/081c485d-ac8d-4bee-ad4c-525772fead4d
+ESCU - Detect Activity Related to Pass the Hash Attacks - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Deleting Of Net Users - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b0b6fd2c-8953-4d1b-8f7b-56075ea6ab3e
+ESCU - Suspicious File Write - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - AWS EKS Kubernetes cluster sensitive object access - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/40a064c1-4ec1-4381-9e35-61192ba8ef82
+ESCU - Spectre and Meltdown Vulnerable Systems - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - EC2 Instance Started With Previously Unseen User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/37a0ec8d-827e-4d6d-8025-cedf31f3a149
+ESCU - Office Product Spawning CertUtil - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Kubernetes GCP detect RBAC authorizations by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Office Application Drop Executable - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7ac0fced-9eae-4381-a748-90dcd1aa9393
+ESCU - Kubernetes Azure active service accounts by pod namespace - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Kubernetes Azure pod scan fingerprint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Detect Spike in Network ACL Activity - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/0840ddf1-8c89-46ff-b730-c8d6722478c0
+ESCU - Suspicious Powershell Command-Line Arguments - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c4db14d9-7909-48b4-a054-aa14d89dbb19
+ESCU - Office Application Spawn Regsvr32 process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Detect API activity from users without MFA - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a520b1fe-cc9e-4f56-b762-18354594c52f
+ESCU - Kubernetes Azure detect sensitive object access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Web Fraud - Password Sharing Across Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Disabling Net User Account - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b0359e05-c87b-4354-83d8-aee0d890243f
+ESCU - GCP Detect accounts with high risk roles by project - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Kubernetes GCP detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Extended Period Without Successful Netbackup Backups - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Office Product Spawning Rundll32 with no DLL - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f28e787e-69ca-480e-9f98-ab970e6d4bcc
+ESCU - Okta ThreatInsight Suspected PasswordSpray Attack - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/140504ae-5fe2-4d65-b2bc-a211813fbca6
+ESCU - Net Localgroup Discovery - Rule,Detection,5.2.0,Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 / Windows Group Discovery Via Net,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c5c8e0f3-147a-43da-bf04-4cfaec27dc44
+ESCU - Uncommon Processes On Endpoint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a51bfe1a-94f0-48cc-b4e4-16a110145893
+ESCU - Dump LSASS via procdump Rename - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/3742ebfe-64c2-11eb-ae93-0242ac130002
+ESCU - Okta Two or More Rejected Okta Pushes - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/826dbaae-a1e6-4c8c-b384-d16898956e73
+ESCU - Excel Spawning Windows Script Host - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - GitHub Actions Disable Security Workflow - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Github Commit Changes In Master - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Github Commit In Develop - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - GitHub Dependabot Alert - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - GitHub Pull Request from Unknown User - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Known Services Killed by Ransomware - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Remote Desktop Network Bruteforce - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Suspicious Driver Loaded Path - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Suspicious Event Log Service Behavior - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Suspicious Process File Path - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Windows Service Stop Via Net and SC Application - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+ESCU - Add Prohibited Processes to Enterprise Security,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
+ESCU - Baseline of API Calls per User ARN,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
+ESCU - Baseline of Excessive AWS Instances Launched by User - MLTK,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
+ESCU - Baseline of Excessive AWS Instances Terminated by User - MLTK,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
+ESCU - Previously seen API call per user roles in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
+ESCU - Previously Seen AWS Provisioning Activity Sources,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
+ESCU - Previously Seen EC2 AMIs,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
+ESCU - Previously Seen EC2 Instance Types,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
+ESCU - Previously Seen EC2 Launches By User,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
+ESCU - Previously seen users in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
+ESCU - Update previously seen users in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
+AWS Cryptomining,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+AWS Suspicious Provisioning Activities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+Common Phishing Frameworks,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+Container Implantation Monitoring and Investigation,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+Host Redirection,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+Kubernetes Sensitive Role Activity,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+Lateral Movement,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+Monitor Backup Solution,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+Monitor for Unauthorized Software,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+Office 365 Detections,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+Spectre And Meltdown Vulnerabilities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+Suspicious AWS EC2 Activities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+Unusual AWS EC2 Modifications,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+Web Fraud Detection,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+Nexus APT Threat Activity,Story,5.4.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
diff --git a/lookups/deprecation_info.yml b/lookups/deprecation_info.yml
new file mode 100644
index 0000000000..dab74f8b34
--- /dev/null
+++ b/lookups/deprecation_info.yml
@@ -0,0 +1,9 @@
+name: deprecation_info
+date: 2025-03-14
+version: 1
+id: d83dad4f-7bce-4979-bf07-a88c610da5f6
+author: Splunk Threat Research Team
+lookup_type: csv
+default_match: false
+description: A lookup file for deprecation information
+min_matches: 1
From 09d1d1c02f82330eace98f878b6c29f1785449d6 Mon Sep 17 00:00:00 2001
From: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
Date: Fri, 14 Mar 2025 06:57:50 +0000
Subject: [PATCH 34/67] Updated TAs
---
contentctl.yml | 4 ++--
.../cisco_secure_application_appdynamics_alerts.yml | 11 +++++++++--
data_sources/linux_secure.yml | 2 +-
3 files changed, 12 insertions(+), 5 deletions(-)
diff --git a/contentctl.yml b/contentctl.yml
index 401119b03c..b17f8ecc0c 100644
--- a/contentctl.yml
+++ b/contentctl.yml
@@ -221,8 +221,8 @@ apps:
- uid: 2882
title: Splunk Add-on for AppDynamics
appid: Splunk_TA_AppDynamics
- version: 3.1.0
+ version: 3.0.0
description: The Splunk Add-on for AppDynamics enables you to easily configure data
inputs to pull data from AppDynamics' REST APIs
- hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-splunk-add-on-for-appdynamics_310.tgz
+ hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-splunk-add-on-for-appdynamics_300.tgz
githash: d6fac80e6d50ae06b40f91519a98489d4ce3a3fd
diff --git a/data_sources/cisco_secure_application_appdynamics_alerts.yml b/data_sources/cisco_secure_application_appdynamics_alerts.yml
index d4a59e0eb7..cdd022fe72 100644
--- a/data_sources/cisco_secure_application_appdynamics_alerts.yml
+++ b/data_sources/cisco_secure_application_appdynamics_alerts.yml
@@ -9,7 +9,7 @@ sourcetype: appdynamics_security
supported_TA:
- name: Splunk Add-on for AppDynamics
url: https://splunkbase.splunk.com/app/3471
- version: 3.1.0
+ version: 3.0.0
fields:
- SourceType
- apiServerExternal
@@ -133,4 +133,11 @@ fields:
- _si
- _sourcetype
- _time
-example_log: '{ "SourceType": "secure_app_attacks", "attackId": "24815279", "attackSource": "EXTERNAL", "attackOutcome": "EXPLOITED", "attackTypes": "{SSRF}", "attackEventTrigger": "", "application": "AD-Ecommerce", "tier": "Order-Processing-Services", "businessTransaction": "Checkout", "attackStatus": "OPEN", "attackLastDetected": "2025-01-31 12:30:22 +0000 UTC", "attackEvents": [{"attackOutcome":"EXPLOITED","eventType":"SOCKET_RESOLVE","attackTypes":"SSRF","timestamp":"2025-01-31T12:30:22Z","applicationName":"AD-Ecommerce","tierName":"Order-Processing-Services","maliciousIpOut":"","maliciousIpSourceOut":"","detailJson":{"classname":"java.net.SocketPermission","ptype":"SOCKET","socketOut":"www.cisco.com","hostContext":"www.cisco.com","methodName":"sun.net.www.http.HttpClient.openServer","apiServerExternal":true,"apiServerInUrl":true},"blocked":false,"blockedReason":"","vulnerableMethod":"org.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:868)","matchedCveName":"CVE-2020-13934","keyInfo":"","cveId":"a21931cd-52fa-11ec-a8b2-8e3051145156","stackTrace":"java.lang.SecurityManager.checkConnect(SecurityManager.java:1051)\nsun.net.www.http.HttpClient.openServer(HttpClient.java:510)\nsun.net.www.protocol.https.HttpsClient.\u003cinit\u003e(HttpsClient.java:264)\nsun.net.www.protocol.https.HttpsClient.New(HttpsClient.java:367)\nsun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.getNewHttpClient(AbstractDelegateHttpsURLConnection.java:191)\norg.apache.activemq.artemis.spi.core.security.jaas.LDAPLoginModule.login(SomeFile.java:12)\nsun.net.www.protocol.http.HttpURLConnection.plainConnect0(HttpURLConnection.java:1138)\nsun.net.www.protocol.http.HttpURLConnection$6.run(HttpURLConnection.java:1022)\nsun.net.www.protocol.http.HttpURLConnection$6.run(HttpURLConnection.java:1020)\njava.security.AccessController.doPrivileged(Native Method)\njava.security.AccessController.doPrivilegedWithCombiner(AccessController.java:782)\nsun.net.www.protocol.http.HttpURLConnection.plainConnect(HttpURLConnection.java:1019)\nsun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.connect(AbstractDelegateHttpsURLConnection.java:177)\nsun.net.www.protocol.http.HttpURLConnection.getInputStream0(HttpURLConnection.java:1546)\nsun.net.www.protocol.http.HttpURLConnection.access$200(HttpURLConnection.java:91)\nsun.net.www.protocol.http.HttpURLConnection$9.run(HttpURLConnection.java:1466)\nsun.net.www.protocol.http.HttpURLConnection$9.run(HttpURLConnection.java:1464)\njava.security.AccessController.doPrivileged(Native Method)\njava.security.AccessController.doPrivilegedWithCombiner(AccessController.java:782)\nsun.net.www.protocol.http.HttpURLConnection.getInputStream(HttpURLConnection.java:1463)\nsun.net.www.protocol.https.HttpsURLConnectionImpl.getInputStream(HttpsURLConnectionImpl.java:254)\nservlet.ArgentoDemoApp$GenericExecution._executeServletCommand(ArgentoDemoApp.java:850)\nservlet.ArgentoDemoApp$GenericExecution.executeServletCommand(ArgentoDemoApp.java:778)\nservlet.ArgentoDemoApp$MyApplicationExecution.executeServletCommand(ArgentoDemoApp.java:718)\nservlet.ArgentoDemoApp._doGet(ArgentoDemoApp.java:441)\nservlet.ArgentoDemoApp.doGet(ArgentoDemoApp.java:376)\njavax.servlet.http.HttpServlet.service(HttpServlet.java:634)\njavax.servlet.http.HttpServlet.service(HttpServlet.java:741)\norg.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:231)\norg.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)\norg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:53)\norg.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)\norg.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)\norg.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:202)\norg.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:96)\norg.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:541)\norg.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:139)\norg.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:92)\norg.apache.catalina.valves.AbstractAccessLogValve.invoke(AbstractAccessLogValve.java:690)\norg.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:74)\norg.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:343)\norg.apache.coyote.http11.Http11Processor.service(Http11Processor.java:373)\norg.apache.coyote.AbstractProcessorLight.process(AbstractProcessorLight.java:65)\norg.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:868)\norg.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1590)\norg.apache.tomcat.util.net.SocketProcessorBase.run(SocketProcessorBase.java:49)\njava.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142)\njava.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617)\norg.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)\njava.lang.Thread.run(Thread.java:745)\n","jvmId":"EEcommerce_MS_NODE","maliciousIpSource":"","webTransactionUrl":"https://localhost:8088/argentoDemoApp/execute?upload=https://www.cisco.com/c/dam/cdc/t/ctm-core.js","clientAddressType":4,"clientAddress":"218.132.217.179","serverPort":"1047","serverAddress":"75.155.150.130","clientPort":"68389","serverName":"/usr/src/argento/prod/demo-run/tomcat-demo-app/webapps/argentoDemoApp/","vulnerabilityInfo":{"cvePublishDate":"2020-07-15T16:40:14.601976Z","cvssScore":5.3,"cvssSeverity":"MEDIUM","cveNvdUrl":"https://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-584427","incidentFirstDetected":"2020-07-15T16:40:14.601976Z","kennaScore":53.0971,"library":"org.apache.tomcat.embed:tomcat-embed-core","title":"Denial of Service (DoS)","type":"java","kennaActiveInternetBreach":false,"kennaEasilyExploitable":false,"kennaMalwareExploitable":false,"kennaPredictedExploitable":true,"kennaPopularTarget":false}}]}'
+example_log: '{ "SourceType": "secure_app_attacks", "attackId": "24815279", "attackSource":
+ "EXTERNAL", "attackOutcome": "EXPLOITED", "attackTypes": "{SSRF}", "attackEventTrigger":
+ "", "application": "AD-Ecommerce", "tier": "Order-Processing-Services", "businessTransaction":
+ "Checkout", "attackStatus": "OPEN", "attackLastDetected": "2025-01-31 12:30:22
+ +0000 UTC", "attackEvents": [{"attackOutcome":"EXPLOITED","eventType":"SOCKET_RESOLVE","attackTypes":"SSRF","timestamp":"2025-01-31T12:30:22Z","applicationName":"AD-Ecommerce","tierName":"Order-Processing-Services","maliciousIpOut":"","maliciousIpSourceOut":"","detailJson":{"classname":"java.net.SocketPermission","ptype":"SOCKET","socketOut":"www.cisco.com","hostContext":"www.cisco.com","methodName":"sun.net.www.http.HttpClient.openServer","apiServerExternal":true,"apiServerInUrl":true},"blocked":false,"blockedReason":"","vulnerableMethod":"org.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:868)","matchedCveName":"CVE-2020-13934","keyInfo":"","cveId":"a21931cd-52fa-11ec-a8b2-8e3051145156","stackTrace":"java.lang.SecurityManager.checkConnect(SecurityManager.java:1051)\nsun.net.www.http.HttpClient.openServer(HttpClient.java:510)\nsun.net.www.protocol.https.HttpsClient.\u003cinit\u003e(HttpsClient.java:264)\nsun.net.www.protocol.https.HttpsClient.New(HttpsClient.java:367)\nsun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.getNewHttpClient(AbstractDelegateHttpsURLConnection.java:191)\norg.apache.activemq.artemis.spi.core.security.jaas.LDAPLoginModule.login(SomeFile.java:12)\nsun.net.www.protocol.http.HttpURLConnection.plainConnect0(HttpURLConnection.java:1138)\nsun.net.www.protocol.http.HttpURLConnection$6.run(HttpURLConnection.java:1022)\nsun.net.www.protocol.http.HttpURLConnection$6.run(HttpURLConnection.java:1020)\njava.security.AccessController.doPrivileged(Native
+ Method)\njava.security.AccessController.doPrivilegedWithCombiner(AccessController.java:782)\nsun.net.www.protocol.http.HttpURLConnection.plainConnect(HttpURLConnection.java:1019)\nsun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.connect(AbstractDelegateHttpsURLConnection.java:177)\nsun.net.www.protocol.http.HttpURLConnection.getInputStream0(HttpURLConnection.java:1546)\nsun.net.www.protocol.http.HttpURLConnection.access$200(HttpURLConnection.java:91)\nsun.net.www.protocol.http.HttpURLConnection$9.run(HttpURLConnection.java:1466)\nsun.net.www.protocol.http.HttpURLConnection$9.run(HttpURLConnection.java:1464)\njava.security.AccessController.doPrivileged(Native
+ Method)\njava.security.AccessController.doPrivilegedWithCombiner(AccessController.java:782)\nsun.net.www.protocol.http.HttpURLConnection.getInputStream(HttpURLConnection.java:1463)\nsun.net.www.protocol.https.HttpsURLConnectionImpl.getInputStream(HttpsURLConnectionImpl.java:254)\nservlet.ArgentoDemoApp$GenericExecution._executeServletCommand(ArgentoDemoApp.java:850)\nservlet.ArgentoDemoApp$GenericExecution.executeServletCommand(ArgentoDemoApp.java:778)\nservlet.ArgentoDemoApp$MyApplicationExecution.executeServletCommand(ArgentoDemoApp.java:718)\nservlet.ArgentoDemoApp._doGet(ArgentoDemoApp.java:441)\nservlet.ArgentoDemoApp.doGet(ArgentoDemoApp.java:376)\njavax.servlet.http.HttpServlet.service(HttpServlet.java:634)\njavax.servlet.http.HttpServlet.service(HttpServlet.java:741)\norg.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:231)\norg.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)\norg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:53)\norg.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)\norg.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)\norg.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:202)\norg.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:96)\norg.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:541)\norg.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:139)\norg.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:92)\norg.apache.catalina.valves.AbstractAccessLogValve.invoke(AbstractAccessLogValve.java:690)\norg.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:74)\norg.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:343)\norg.apache.coyote.http11.Http11Processor.service(Http11Processor.java:373)\norg.apache.coyote.AbstractProcessorLight.process(AbstractProcessorLight.java:65)\norg.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:868)\norg.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1590)\norg.apache.tomcat.util.net.SocketProcessorBase.run(SocketProcessorBase.java:49)\njava.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142)\njava.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617)\norg.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)\njava.lang.Thread.run(Thread.java:745)\n","jvmId":"EEcommerce_MS_NODE","maliciousIpSource":"","webTransactionUrl":"https://localhost:8088/argentoDemoApp/execute?upload=https://www.cisco.com/c/dam/cdc/t/ctm-core.js","clientAddressType":4,"clientAddress":"218.132.217.179","serverPort":"1047","serverAddress":"75.155.150.130","clientPort":"68389","serverName":"/usr/src/argento/prod/demo-run/tomcat-demo-app/webapps/argentoDemoApp/","vulnerabilityInfo":{"cvePublishDate":"2020-07-15T16:40:14.601976Z","cvssScore":5.3,"cvssSeverity":"MEDIUM","cveNvdUrl":"https://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-584427","incidentFirstDetected":"2020-07-15T16:40:14.601976Z","kennaScore":53.0971,"library":"org.apache.tomcat.embed:tomcat-embed-core","title":"Denial
+ of Service (DoS)","type":"java","kennaActiveInternetBreach":false,"kennaEasilyExploitable":false,"kennaMalwareExploitable":false,"kennaPredictedExploitable":true,"kennaPopularTarget":false}}]}'
diff --git a/data_sources/linux_secure.yml b/data_sources/linux_secure.yml
index 468d387446..c3bb4697bb 100644
--- a/data_sources/linux_secure.yml
+++ b/data_sources/linux_secure.yml
@@ -9,7 +9,7 @@ sourcetype: linux_secure
supported_TA:
- name: Splunk Add-on for Unix and Linux
url: https://splunkbase.splunk.com/app/833
- version: 9.2.0
+ version: 10.0.0
fields:
- _time
- action
From e49f84d06dcf4b6104b84cc9248dcef2e00958d0 Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Fri, 14 Mar 2025 09:47:06 -0700
Subject: [PATCH 35/67] fixes
---
contentctl.yml | 2 +-
data_sources/linux_secure.yml | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/contentctl.yml b/contentctl.yml
index b17f8ecc0c..0fcd575b4a 100644
--- a/contentctl.yml
+++ b/contentctl.yml
@@ -218,7 +218,7 @@ apps:
version: 3.1.0
description: description of app
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-github_310.tgz
-- uid: 2882
+- uid: 3471
title: Splunk Add-on for AppDynamics
appid: Splunk_TA_AppDynamics
version: 3.0.0
diff --git a/data_sources/linux_secure.yml b/data_sources/linux_secure.yml
index c3bb4697bb..468d387446 100644
--- a/data_sources/linux_secure.yml
+++ b/data_sources/linux_secure.yml
@@ -9,7 +9,7 @@ sourcetype: linux_secure
supported_TA:
- name: Splunk Add-on for Unix and Linux
url: https://splunkbase.splunk.com/app/833
- version: 10.0.0
+ version: 9.2.0
fields:
- _time
- action
From 1120cea9a0f8b9ab6d1bf17e53debd79789a4446 Mon Sep 17 00:00:00 2001
From: Patrick Bareiss
Date: Mon, 17 Mar 2025 12:24:08 +0100
Subject: [PATCH 36/67] Improve data source validation
---
data_sources/asl_aws_cloudtrail.yml | 1 -
data_sources/aws_cloudtrail.yml | 9 --------
...s_multi_factor_authentication_disabled.yml | 6 +++---
...mber_of_failed_authentications_from_ip.yml | 7 ++++---
detections/cloud/aws_updateloginprofile.yml | 21 ++++++++++---------
5 files changed, 18 insertions(+), 26 deletions(-)
diff --git a/data_sources/asl_aws_cloudtrail.yml b/data_sources/asl_aws_cloudtrail.yml
index edd56c9a67..32818e97f8 100644
--- a/data_sources/asl_aws_cloudtrail.yml
+++ b/data_sources/asl_aws_cloudtrail.yml
@@ -16,7 +16,6 @@ output_fields:
- dest
- user
- user_agent
-- status
- src
- vendor_account
- vendor_region
diff --git a/data_sources/aws_cloudtrail.yml b/data_sources/aws_cloudtrail.yml
index 560f4ec819..e2734eacfe 100644
--- a/data_sources/aws_cloudtrail.yml
+++ b/data_sources/aws_cloudtrail.yml
@@ -11,12 +11,3 @@ supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.9.1
-output_fields:
-- action
-- dest
-- user
-- user_agent
-- src
-- vendor_account
-- vendor_region
-- vendor_product
diff --git a/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml b/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml
index 9f331adb00..916df22a3a 100644
--- a/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml
+++ b/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml
@@ -17,8 +17,8 @@ data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` (api.operation=DeleteVirtualMFADevice OR api.operation=DeactivateMFADevice)
| fillnull
- | stats count min(_time) as firstTime max(_time) as lastTime by actor.user.uid api.operation actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region
- | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent
+ | stats count min(_time) as firstTime max(_time) as lastTime by actor.user.uid api.operation api.service.name http_request.user_agent src_endpoint.ip actor.user.account.uid cloud.provider cloud.region
+ | rename actor.user.uid as user api.operation as action api.service.name as dest http_request.user_agent as user_agent src_endpoint.ip as src actor.user.account.uid as vendor_account cloud.provider as vendor_product cloud.region as vendor_region
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `asl_aws_multi_factor_authentication_disabled_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
@@ -47,7 +47,7 @@ rba:
type: user
score: 64
threat_objects:
- - field: src_ip
+ - field: src
type: ip_address
tags:
analytic_story:
diff --git a/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml b/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml
index 81255cca76..97241dc694 100644
--- a/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml
+++ b/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml
@@ -16,7 +16,8 @@ data_source:
- AWS CloudTrail ConsoleLogin
search: '`cloudtrail` eventName=ConsoleLogin action=failure
| bucket span=10m _time
- | stats dc(_raw) AS distinct_attempts values(user_name) as tried_accounts by _time, src_ip
+ | stats dc(_raw) AS distinct_attempts values(user_name) as tried_accounts values(action) as action values(dest) as dest
+ values(vendor_account) as vendor_account values(vendor_region) as vendor_region values(vendor_product) as vendor_product values(user_agent) as user_agent by _time, src_ip
| eventstats avg(distinct_attempts) as avg_attempts , stdev(distinct_attempts) as ip_std by _time
| eval upperBound=(avg_attempts+ip_std*3)
| eval isOutlier=if(distinct_attempts > 10 and distinct_attempts >= upperBound, 1, 0)
@@ -47,13 +48,13 @@ drilldown_searches:
latest_offset: $info_max_time$
rba:
message: 'Unusual number of failed console login attempts (Count: $distinct_attempts$)
- against users from IP Address - $src_ip$'
+ against users from IP Address - $src$'
risk_objects:
- field: tried_accounts
type: user
score: 54
threat_objects:
- - field: src_ip
+ - field: src
type: ip_address
tags:
analytic_story:
diff --git a/detections/cloud/aws_updateloginprofile.yml b/detections/cloud/aws_updateloginprofile.yml
index c90f5d742a..6c831b3172 100644
--- a/detections/cloud/aws_updateloginprofile.yml
+++ b/detections/cloud/aws_updateloginprofile.yml
@@ -17,9 +17,10 @@ data_source:
- AWS CloudTrail UpdateLoginProfile
search: '`cloudtrail` eventName = UpdateLoginProfile userAgent !=console.amazonaws.com
errorCode = success | eval match=if(match(userIdentity.userName,requestParameters.userName),
- 1,0) | search match=0 | stats count min(_time) as firstTime max(_time) as lastTime
- by requestParameters.userName src eventName eventSource aws_account_id errorCode
- userAgent eventID awsRegion userIdentity.userName user_arn | `security_content_ctime(firstTime)`
+ 1,0) | search match=0
+ | stats count min(_time) as firstTime max(_time) as lastTime by actor.user.uid api.operation api.service.name http_request.user_agent src_endpoint.ip actor.user.account.uid cloud.provider cloud.region
+ | rename actor.user.uid as user api.operation as action api.service.name as dest http_request.user_agent as user_agent src_endpoint.ip as src actor.user.account.uid as vendor_account cloud.provider as vendor_product cloud.region as vendor_region
+ | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `aws_updateloginprofile_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
@@ -29,12 +30,12 @@ references:
- https://bishopfox.com/blog/privilege-escalation-in-aws
- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/
drilldown_searches:
-- name: View the detection results for - "$user_arn$"
- search: '%original_detection_search% | search user_arn = "$user_arn$"'
+- name: View the detection results for - "$user$"
+ search: '%original_detection_search% | search user = "$user$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
-- name: View risk events for the last 7 days for - "$user_arn$"
- search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user_arn$")
+- name: View risk events for the last 7 days for - "$user$"
+ search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
@@ -43,11 +44,11 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
- message: From IP address $src$, user agent $userAgent$ has trigged an event $eventName$
- for updating the existing login profile, potentially giving user $user_arn$ more
+ message: From IP address $src$, user agent $userAgent$ has trigged an event UpdateLoginProfile
+ for updating the existing login profile, potentially giving user $user$ more
access privilleges
risk_objects:
- - field: user_arn
+ - field: user
type: user
score: 30
threat_objects:
From 13f692c0521323a3126830254eef7568e10979e6 Mon Sep 17 00:00:00 2001
From: Patrick Bareiss
Date: Mon, 17 Mar 2025 12:28:56 +0100
Subject: [PATCH 37/67] version bump
---
detections/cloud/aws_updateloginprofile.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/detections/cloud/aws_updateloginprofile.yml b/detections/cloud/aws_updateloginprofile.yml
index 6c831b3172..2c2f4f835b 100644
--- a/detections/cloud/aws_updateloginprofile.yml
+++ b/detections/cloud/aws_updateloginprofile.yml
@@ -1,6 +1,6 @@
name: AWS UpdateLoginProfile
id: 2a9b80d3-6a40-4115-11ad-212bf3d0d111
-version: 8
+version: 9
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
From 850a172af4b9fc2c1fbf64f52405a64a77615246 Mon Sep 17 00:00:00 2001
From: Patrick Bareiss
Date: Mon, 17 Mar 2025 13:02:18 +0100
Subject: [PATCH 38/67] bug fix
---
.../aws_unusual_number_of_failed_authentications_from_ip.yml | 2 +-
detections/cloud/aws_updateloginprofile.yml | 5 +++--
2 files changed, 4 insertions(+), 3 deletions(-)
diff --git a/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml b/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml
index 97241dc694..4c59fbe732 100644
--- a/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml
+++ b/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml
@@ -17,7 +17,7 @@ data_source:
search: '`cloudtrail` eventName=ConsoleLogin action=failure
| bucket span=10m _time
| stats dc(_raw) AS distinct_attempts values(user_name) as tried_accounts values(action) as action values(dest) as dest
- values(vendor_account) as vendor_account values(vendor_region) as vendor_region values(vendor_product) as vendor_product values(user_agent) as user_agent by _time, src_ip
+ values(vendor_account) as vendor_account values(vendor_region) as vendor_region values(vendor_product) as vendor_product values(user_agent) as user_agent by _time, src
| eventstats avg(distinct_attempts) as avg_attempts , stdev(distinct_attempts) as ip_std by _time
| eval upperBound=(avg_attempts+ip_std*3)
| eval isOutlier=if(distinct_attempts > 10 and distinct_attempts >= upperBound, 1, 0)
diff --git a/detections/cloud/aws_updateloginprofile.yml b/detections/cloud/aws_updateloginprofile.yml
index 2c2f4f835b..0534a0819d 100644
--- a/detections/cloud/aws_updateloginprofile.yml
+++ b/detections/cloud/aws_updateloginprofile.yml
@@ -18,8 +18,9 @@ data_source:
search: '`cloudtrail` eventName = UpdateLoginProfile userAgent !=console.amazonaws.com
errorCode = success | eval match=if(match(userIdentity.userName,requestParameters.userName),
1,0) | search match=0
- | stats count min(_time) as firstTime max(_time) as lastTime by actor.user.uid api.operation api.service.name http_request.user_agent src_endpoint.ip actor.user.account.uid cloud.provider cloud.region
- | rename actor.user.uid as user api.operation as action api.service.name as dest http_request.user_agent as user_agent src_endpoint.ip as src actor.user.account.uid as vendor_account cloud.provider as vendor_product cloud.region as vendor_region
+ | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
+ | eval vendor_product = "AWS"
+ | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `aws_updateloginprofile_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
From b3a3caeccae9f864c59b332b015437862ab8ac96 Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Mon, 17 Mar 2025 09:53:18 -0700
Subject: [PATCH 39/67] updating for manual test
---
.../endpoint/windows_sql_server_critical_procedures_enabled.yml | 1 +
detections/endpoint/windows_sql_server_startup_procedure.yml | 1 +
.../endpoint/windows_sql_server_xp_cmdshell_config_change.yml | 1 +
3 files changed, 3 insertions(+)
diff --git a/detections/endpoint/windows_sql_server_critical_procedures_enabled.yml b/detections/endpoint/windows_sql_server_critical_procedures_enabled.yml
index 9fed3fb897..fde5c9f7ef 100644
--- a/detections/endpoint/windows_sql_server_critical_procedures_enabled.yml
+++ b/detections/endpoint/windows_sql_server_critical_procedures_enabled.yml
@@ -71,6 +71,7 @@ tags:
- Splunk Enterprise Security
- Splunk Cloud
security_domain: endpoint
+ manual_test: The risk message is dynamically generated in the SPL and it needs to be manually tested for integration testing.
tests:
- name: True Positive Test
attack_data:
diff --git a/detections/endpoint/windows_sql_server_startup_procedure.yml b/detections/endpoint/windows_sql_server_startup_procedure.yml
index f229b0bd3b..ec7dcaeca4 100644
--- a/detections/endpoint/windows_sql_server_startup_procedure.yml
+++ b/detections/endpoint/windows_sql_server_startup_procedure.yml
@@ -60,6 +60,7 @@ tags:
- Splunk Enterprise Security
- Splunk Cloud
security_domain: endpoint
+ manual_test: The risk message is dynamically generated in the SPL and it needs to be manually tested for integration testing.
tests:
- name: True Positive Test
attack_data:
diff --git a/detections/endpoint/windows_sql_server_xp_cmdshell_config_change.yml b/detections/endpoint/windows_sql_server_xp_cmdshell_config_change.yml
index aa9f81c6e3..a99a2646dd 100644
--- a/detections/endpoint/windows_sql_server_xp_cmdshell_config_change.yml
+++ b/detections/endpoint/windows_sql_server_xp_cmdshell_config_change.yml
@@ -72,6 +72,7 @@ tags:
- Splunk Enterprise Security
- Splunk Cloud
security_domain: endpoint
+ manual_test: The risk message is dynamically generated in the SPL and it needs to be manually tested for integration testing.
tests:
- name: True Positive Test
attack_data:
From 58d7d6052c9bc8788b658e3344932424b10b6205 Mon Sep 17 00:00:00 2001
From: Michael Haag <5632822+MHaggis@users.noreply.github.com>
Date: Mon, 17 Mar 2025 13:25:49 -0600
Subject: [PATCH 40/67] version updates
---
detections/endpoint/any_powershell_downloadstring.yml | 2 +-
detections/endpoint/attacker_tools_on_endpoint.yml | 2 +-
.../endpoint/detect_regsvr32_application_control_bypass.yml | 2 +-
.../endpoint/powershell_webrequest_using_memory_stream.yml | 2 +-
detections/endpoint/system_user_discovery_with_whoami.yml | 2 +-
detections/endpoint/w3wp_spawning_shell.yml | 2 +-
.../windows_process_writing_file_to_world_writable_path.yml | 2 +-
7 files changed, 7 insertions(+), 7 deletions(-)
diff --git a/detections/endpoint/any_powershell_downloadstring.yml b/detections/endpoint/any_powershell_downloadstring.yml
index 7f516361ff..3974f041fa 100644
--- a/detections/endpoint/any_powershell_downloadstring.yml
+++ b/detections/endpoint/any_powershell_downloadstring.yml
@@ -1,6 +1,6 @@
name: Any Powershell DownloadString
id: 4d015ef2-7adf-11eb-95da-acde48001122
-version: 9
+version: 10
date: '2025-02-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml
index a983aeb31d..9838d2984e 100644
--- a/detections/endpoint/attacker_tools_on_endpoint.yml
+++ b/detections/endpoint/attacker_tools_on_endpoint.yml
@@ -1,6 +1,6 @@
name: Attacker Tools On Endpoint
id: a51bfe1a-94f0-48cc-b4e4-16a110145893
-version: 8
+version: 9
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
diff --git a/detections/endpoint/detect_regsvr32_application_control_bypass.yml b/detections/endpoint/detect_regsvr32_application_control_bypass.yml
index a3df354b36..a12339df48 100644
--- a/detections/endpoint/detect_regsvr32_application_control_bypass.yml
+++ b/detections/endpoint/detect_regsvr32_application_control_bypass.yml
@@ -1,6 +1,6 @@
name: Detect Regsvr32 Application Control Bypass
id: 070e9b80-6252-11eb-ae93-0242ac130002
-version: 9
+version: 10
date: '2025-02-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/powershell_webrequest_using_memory_stream.yml b/detections/endpoint/powershell_webrequest_using_memory_stream.yml
index 2c0fa1ba0d..8a72593916 100644
--- a/detections/endpoint/powershell_webrequest_using_memory_stream.yml
+++ b/detections/endpoint/powershell_webrequest_using_memory_stream.yml
@@ -1,6 +1,6 @@
name: PowerShell WebRequest Using Memory Stream
id: 103affa6-924a-4b53-aff4-1d5075342aab
-version: 4
+version: 5
date: '2024-11-13'
author: Steven Dick
status: production
diff --git a/detections/endpoint/system_user_discovery_with_whoami.yml b/detections/endpoint/system_user_discovery_with_whoami.yml
index 594b175c8d..380d3d6ac0 100644
--- a/detections/endpoint/system_user_discovery_with_whoami.yml
+++ b/detections/endpoint/system_user_discovery_with_whoami.yml
@@ -1,6 +1,6 @@
name: System User Discovery With Whoami
id: 894fc43e-6f50-47d5-a68b-ee9ee23e18f4
-version: 4
+version: 5
date: '2024-11-13'
author: Mauricio Velazco, Splunk
status: production
diff --git a/detections/endpoint/w3wp_spawning_shell.yml b/detections/endpoint/w3wp_spawning_shell.yml
index 21d2e3fb4f..dcc6145ea5 100644
--- a/detections/endpoint/w3wp_spawning_shell.yml
+++ b/detections/endpoint/w3wp_spawning_shell.yml
@@ -1,6 +1,6 @@
name: W3WP Spawning Shell
id: 0f03423c-7c6a-11eb-bc47-acde48001122
-version: 6
+version: 7
date: '2025-02-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_process_writing_file_to_world_writable_path.yml b/detections/endpoint/windows_process_writing_file_to_world_writable_path.yml
index 454d390356..5d244c589a 100644
--- a/detections/endpoint/windows_process_writing_file_to_world_writable_path.yml
+++ b/detections/endpoint/windows_process_writing_file_to_world_writable_path.yml
@@ -1,6 +1,6 @@
name: Windows Process Writing File to World Writable Path
id: c051b68c-60f7-4022-b3ad-773bec7a225b
-version: 4
+version: 5
date: '2024-11-13'
author: Michael Haag, Splunk
data_source: []
From 81a16341a3396153082b6e072f1593ab7b92b3e3 Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Mon, 17 Mar 2025 14:28:53 -0700
Subject: [PATCH 41/67] Revert "version updates"
This reverts commit 58d7d6052c9bc8788b658e3344932424b10b6205.
---
detections/endpoint/any_powershell_downloadstring.yml | 2 +-
detections/endpoint/attacker_tools_on_endpoint.yml | 2 +-
.../endpoint/detect_regsvr32_application_control_bypass.yml | 2 +-
.../endpoint/powershell_webrequest_using_memory_stream.yml | 2 +-
detections/endpoint/system_user_discovery_with_whoami.yml | 2 +-
detections/endpoint/w3wp_spawning_shell.yml | 2 +-
.../windows_process_writing_file_to_world_writable_path.yml | 2 +-
7 files changed, 7 insertions(+), 7 deletions(-)
diff --git a/detections/endpoint/any_powershell_downloadstring.yml b/detections/endpoint/any_powershell_downloadstring.yml
index 3974f041fa..7f516361ff 100644
--- a/detections/endpoint/any_powershell_downloadstring.yml
+++ b/detections/endpoint/any_powershell_downloadstring.yml
@@ -1,6 +1,6 @@
name: Any Powershell DownloadString
id: 4d015ef2-7adf-11eb-95da-acde48001122
-version: 10
+version: 9
date: '2025-02-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml
index 9838d2984e..a983aeb31d 100644
--- a/detections/endpoint/attacker_tools_on_endpoint.yml
+++ b/detections/endpoint/attacker_tools_on_endpoint.yml
@@ -1,6 +1,6 @@
name: Attacker Tools On Endpoint
id: a51bfe1a-94f0-48cc-b4e4-16a110145893
-version: 9
+version: 8
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
diff --git a/detections/endpoint/detect_regsvr32_application_control_bypass.yml b/detections/endpoint/detect_regsvr32_application_control_bypass.yml
index a12339df48..a3df354b36 100644
--- a/detections/endpoint/detect_regsvr32_application_control_bypass.yml
+++ b/detections/endpoint/detect_regsvr32_application_control_bypass.yml
@@ -1,6 +1,6 @@
name: Detect Regsvr32 Application Control Bypass
id: 070e9b80-6252-11eb-ae93-0242ac130002
-version: 10
+version: 9
date: '2025-02-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/powershell_webrequest_using_memory_stream.yml b/detections/endpoint/powershell_webrequest_using_memory_stream.yml
index 8a72593916..2c0fa1ba0d 100644
--- a/detections/endpoint/powershell_webrequest_using_memory_stream.yml
+++ b/detections/endpoint/powershell_webrequest_using_memory_stream.yml
@@ -1,6 +1,6 @@
name: PowerShell WebRequest Using Memory Stream
id: 103affa6-924a-4b53-aff4-1d5075342aab
-version: 5
+version: 4
date: '2024-11-13'
author: Steven Dick
status: production
diff --git a/detections/endpoint/system_user_discovery_with_whoami.yml b/detections/endpoint/system_user_discovery_with_whoami.yml
index 380d3d6ac0..594b175c8d 100644
--- a/detections/endpoint/system_user_discovery_with_whoami.yml
+++ b/detections/endpoint/system_user_discovery_with_whoami.yml
@@ -1,6 +1,6 @@
name: System User Discovery With Whoami
id: 894fc43e-6f50-47d5-a68b-ee9ee23e18f4
-version: 5
+version: 4
date: '2024-11-13'
author: Mauricio Velazco, Splunk
status: production
diff --git a/detections/endpoint/w3wp_spawning_shell.yml b/detections/endpoint/w3wp_spawning_shell.yml
index dcc6145ea5..21d2e3fb4f 100644
--- a/detections/endpoint/w3wp_spawning_shell.yml
+++ b/detections/endpoint/w3wp_spawning_shell.yml
@@ -1,6 +1,6 @@
name: W3WP Spawning Shell
id: 0f03423c-7c6a-11eb-bc47-acde48001122
-version: 7
+version: 6
date: '2025-02-10'
author: Michael Haag, Splunk
status: production
diff --git a/detections/endpoint/windows_process_writing_file_to_world_writable_path.yml b/detections/endpoint/windows_process_writing_file_to_world_writable_path.yml
index 5d244c589a..454d390356 100644
--- a/detections/endpoint/windows_process_writing_file_to_world_writable_path.yml
+++ b/detections/endpoint/windows_process_writing_file_to_world_writable_path.yml
@@ -1,6 +1,6 @@
name: Windows Process Writing File to World Writable Path
id: c051b68c-60f7-4022-b3ad-773bec7a225b
-version: 5
+version: 4
date: '2024-11-13'
author: Michael Haag, Splunk
data_source: []
From 89cc1aca90edcba24ec74f1d03ead86b4830f602 Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Mon, 17 Mar 2025 15:12:39 -0700
Subject: [PATCH 42/67] replacement stories
---
deprecated/deprecated_detection_mapping.yml | 27 ++++++++++++++-------
1 file changed, 18 insertions(+), 9 deletions(-)
diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml
index c5d72406cb..d6a0025376 100644
--- a/deprecated/deprecated_detection_mapping.yml
+++ b/deprecated/deprecated_detection_mapping.yml
@@ -1254,12 +1254,14 @@ stories:
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
+ replacement_content:
+ - Cloud Cryptomining
- deprecated_content: AWS Suspicious Provisioning Activities
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
+ replacement_content:
+ - Suspicious Cloud Provisioning Activities
- deprecated_content: Common Phishing Frameworks
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
@@ -1269,7 +1271,8 @@ stories:
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
+ replacement_content:
+ - Kubernetes Security
- deprecated_content: Host Redirection
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
@@ -1279,12 +1282,14 @@ stories:
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
+ replacement_content:
+ - Kubernetes Security
- deprecated_content: Lateral Movement
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
+ replacement_content:
+ - Compromised User Account
- deprecated_content: Monitor Backup Solution
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
@@ -1299,7 +1304,8 @@ stories:
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
+ replacement_content:
+ - Office 365 Account Takeover
- deprecated_content: Spectre And Meltdown Vulnerabilities
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
@@ -1309,12 +1315,14 @@ stories:
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
+ replacement_content:
+ - Suspicious Cloud Instance Activities
- deprecated_content: Unusual AWS EC2 Modifications
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
+ replacement_content:
+ - Suspicious Cloud Instance Activities
- deprecated_content: Web Fraud Detection
deprecated_in_version: 5.2.0
deprecated_date: 2025-03-12
@@ -1324,4 +1332,5 @@ stories:
deprecated_in_version: 5.4.0
deprecated_date: 2025-03-12
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
\ No newline at end of file
+ replacement_content:
+ - China-Nexus Threat Activity
\ No newline at end of file
From a24a2f0a1b6ba2dcb4de24317593c7980d68cf29 Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Mon, 17 Mar 2025 15:30:39 -0700
Subject: [PATCH 43/67] updating next batch to 5.4.0
---
deprecated/deprecated_detection_mapping.yml | 24 ++++++++++-----------
1 file changed, 12 insertions(+), 12 deletions(-)
diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml
index d6a0025376..618796b43d 100644
--- a/deprecated/deprecated_detection_mapping.yml
+++ b/deprecated/deprecated_detection_mapping.yml
@@ -898,62 +898,62 @@ detections:
replacement_content:
- Okta Multiple Failed MFA Requests For User
- deprecated_content: Excel Spawning Windows Script Host
- deprecated_in_version: 5.3.0
+ deprecated_in_version: 5.4.0
deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: GitHub Actions Disable Security Workflow
- deprecated_in_version: 5.3.0
+ deprecated_in_version: 5.4.0
deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Github Commit Changes In Master
- deprecated_in_version: 5.3.0
+ deprecated_in_version: 5.4.0
deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Github Commit In Develop
- deprecated_in_version: 5.3.0
+ deprecated_in_version: 5.4.0
deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: GitHub Dependabot Alert
- deprecated_in_version: 5.3.0
+ deprecated_in_version: 5.4.0
deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: GitHub Pull Request from Unknown User
- deprecated_in_version: 5.3.0
+ deprecated_in_version: 5.4.0
deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Known Services Killed by Ransomware
- deprecated_in_version: 5.3.0
+ deprecated_in_version: 5.4.0
deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Remote Desktop Network Bruteforce
- deprecated_in_version: 5.3.0
+ deprecated_in_version: 5.4.0
deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Suspicious Driver Loaded Path
- deprecated_in_version: 5.3.0
+ deprecated_in_version: 5.4.0
deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Suspicious Event Log Service Behavior
- deprecated_in_version: 5.3.0
+ deprecated_in_version: 5.4.0
deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Suspicious Process File Path
- deprecated_in_version: 5.3.0
+ deprecated_in_version: 5.4.0
deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
- deprecated_content: Windows Service Stop Via Net and SC Application
- deprecated_in_version: 5.3.0
+ deprecated_in_version: 5.4.0
deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content: []
From 5dcad4a631aaf9f67af8e1b694a10f2bc5df0edb Mon Sep 17 00:00:00 2001
From: pyth0n1c
Date: Mon, 17 Mar 2025 15:35:21 -0700
Subject: [PATCH 44/67] remove deprecated_date and replacement_content if there
is no content defined
---
deprecated/deprecated_detection_mapping.yml | 411 +-------------------
1 file changed, 21 insertions(+), 390 deletions(-)
diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml
index 618796b43d..c104358a54 100644
--- a/deprecated/deprecated_detection_mapping.yml
+++ b/deprecated/deprecated_detection_mapping.yml
@@ -1,69 +1,50 @@
detections:
- deprecated_content: ASL AWS Excessive Security Scanning
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: AWS Cloud Provisioning From Previously Unseen Region
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Provisioning Activity From Previously Unseen Region
- deprecated_content: First time seen command line argument
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Windows connhost exe started forcefully
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Detect Mimikatz Using Loaded Images
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Kubernetes Azure detect sensitive role access
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Web Fraud - Anomalous User Clickspeed
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: EC2 Instance Started With Previously Unseen Instance Type
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Compute Instance Created With Previously Unseen Instance Type
- deprecated_content: EC2 Instance Started With Previously Unseen AMI
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Compute Instance Created With Previously Unseen Image
- deprecated_content: Domain Group Discovery With Net
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Group Discovery Via Net
- deprecated_content: Kubernetes AWS detect sensitive role access
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Winword Spawning Windows Script Host
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: "The following analytics was deprecated in favour of a more generic approach.
Where instead of creating specific analytic for every potentially suspicious child
of an office product. We group them by threat level.\nThis would ease management
@@ -72,13 +53,11 @@ detections:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Winword Spawning PowerShell
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Attempted Credential Dump From Registry via Reg exe
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: This analytic had some overlap with another one, hence the deprecation.
It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry
Hive Dump Via CommandLine
@@ -86,122 +65,92 @@ detections:
- Windows Sensitive Registry Hive Dump Via CommandLine
- deprecated_content: Detect processes used for System Network Configuration Discovery
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Potential System Network Configuration Discovery Activity
- deprecated_content: Execution of File With Spaces Before Extension
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Updated to a new detection name
replacement_content:
- Execution of File with Multiple Extensions
- deprecated_content: EC2 Instance Started In Previously Unseen Region
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Compute Instance Created In Previously Unused Region
- deprecated_content: Office Document Spawned Child Process To Download
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Spawned Child Process For Download
- deprecated_content: Detect new API calls from user roles
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud API Calls From Previously Unseen User Roles
- deprecated_content: Cmdline Tool Not Executed In CMD Shell
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Cmdline Tool Execution From Non-Shell Process
- deprecated_content: Linux Auditd Find Private Keys
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Linux Auditd Private Keys and Certificate Enumeration
- deprecated_content: Detect AWS API Activities From Unapproved Accounts
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Monitor DNS For Brand Abuse
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Kubernetes GCP detect sensitive object access
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Kubernetes Azure scan fingerprint
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: ASL AWS Password Policy Changes
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: O365 Suspicious Admin Email Forwarding
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- O365 Mailbox Email Forwarding Enabled
- deprecated_content: AWS Cloud Provisioning From Previously Unseen City
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Provisioning Activity From Previously Unseen City
- deprecated_content: Kubernetes AWS detect service accounts forbidden failure access
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Osquery pack - ColdRoot detection
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Windows Modify Registry Reg Restore
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Registry Entries Restored Via Reg
- deprecated_content: Kubernetes GCP detect most active service accounts by pod
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Scheduled tasks used in BadRabbit ransomware
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Updated to a new detection name
replacement_content:
- Scheduled Task Deleted Or Created via CMD
- deprecated_content: Suspicious Rundll32 Rename
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Remote System Discovery with Net
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: "This analytic was focusing on 2 separate and unrelated type of threats
or actions. It was split into other analytics, namely:\r\n\r\nWindows Network
Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277\r\nWindows Sensitive
@@ -210,118 +159,91 @@ detections:
- Windows Network Share Interaction With Net
- deprecated_content: Remote System Discovery with Net
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Sensitive Group Discovery With Net
- deprecated_content: DNS Query Requests Resolved by Unauthorized DNS Servers
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Suspicious Changes to File Associations
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: GCP Detect high risk permissions by resource and account
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Office Product Writing cab or inf
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Dropped Cab or Inf File
- deprecated_content: Identify New User Accounts
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Office Product Spawn CMD Process
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Windows DLL Search Order Hijacking Hunt
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Windows DLL Search Order Hijacking Hunt with Sysmon
- deprecated_content: ASL AWS CreateAccessKey
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- ASL AWS Create Access Key
- deprecated_content: Okta ThreatInsight Login Failure with High Unknown users
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Detect Spike in Security Group Activity
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Abnormally High Number Of Cloud Security Group API Calls
- deprecated_content: Office Product Spawning BITSAdmin
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Create local admin accounts using net exe
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Create Local Administrator Account Via Net
- deprecated_content: Abnormally High AWS Instances Terminated by User - MLTK
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Windows Office Product Spawning MSDT
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Spawned MSDT
- deprecated_content: Detect Spike in AWS API Activity
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Office Product Spawning Windows Script Host
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Prohibited Software On Endpoint
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Attacker Tools On Endpoint
- deprecated_content: AWS Cloud Provisioning From Previously Unseen Country
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Provisioning Activity From Previously Unseen Country
- deprecated_content: Detect Critical Alerts from Security Tools
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: As discussed internally, this analytic was too generic for an analyst to
do anything with it. It was deprecated in favor of the more specific approach
provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender
@@ -331,141 +253,109 @@ detections:
- Microsoft Defender ATP Alerts
- deprecated_content: Detect Critical Alerts from Security Tools
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Microsoft Defender Incident Alerts
- deprecated_content: Excel Spawning PowerShell
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Office Application Spawn rundll32 process
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Excessive Usage Of Net App
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Excessive Usage Of Net App
- deprecated_content: Elevated Group Discovery With Net
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Sensitive Group Discovery With Net
- deprecated_content: Local Account Discovery with Net
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows User Discovery Via Net
- deprecated_content: Windows Command Shell Fetch Env Variables
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows List ENV Variables Via SET Command From Uncommon Parent
- deprecated_content: Suspicious Email - UBA Anomaly
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Detect web traffic to dynamic domain providers
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Updated to use a different log source
replacement_content:
- Detect hosts connecting to dynamic domain providers
- deprecated_content: Okta Failed SSO Attempts
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Unauthorized Access to Application
- deprecated_content: Kubernetes AWS detect RBAC authorization by account
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Kubernetes Azure detect service accounts forbidden failure access
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Remote Registry Key modifications
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: O365 Suspicious User Email Forwarding
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- O365 Mailbox Email Forwarding Enabled
- deprecated_content: Office Product Spawning MSHTA
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Kubernetes AWS detect most active service accounts by pod
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Correlation by Repository and Risk
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the datamodel
replacement_content:
- Risk Rule for Dev Sec Ops by Repository
- deprecated_content: Kubernetes Azure detect RBAC authorization by account
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Clients Connecting to Multiple DNS Servers
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Excessive Service Stop Attempt
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Excessive Service Stop Attempt
- deprecated_content: Multiple Okta Users With Invalid Credentials From The Same IP
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Multiple Users Failing To Authenticate From Ip
- deprecated_content: Suspicious writes to System Volume Information
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Detect new user AWS Console Login
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Detect AWS Console Login by New User
- deprecated_content: Domain Account Discovery With Net App
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: "This analytic was a TTP that looked only for commands that tries to query
info about the users via net user /do. This had a couple of issues, such as triggering
on creation of users via the /add flag etc..\nIt was deprecated in favor of a
@@ -474,191 +364,145 @@ detections:
- Windows User Discovery Via Net
- deprecated_content: Detection of DNS Tunnels
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Detect DNS requests to Phishing Sites leveraging EvilGinx2
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Office Document Creating Schedule Task
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Loading Taskschd DLL
- deprecated_content: Okta Account Locked Out
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Multiple Accounts Locked Out
- deprecated_content: Unsuccessful Netbackup backups
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Detect Mimikatz Via PowerShell And EventCode 4703
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Updated to a new detection name
replacement_content:
- Detect Mimikatz With PowerShell Script Block Logging
- deprecated_content: Winword Spawning Cmd
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: GCP Kubernetes cluster scan detection
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Kubernetes Scanning by Unauthenticated IP Address
- deprecated_content: Kubernetes GCP detect suspicious kubectl calls
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: gcp detect oauth token abuse
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Correlation by User and Risk
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the datamodel
replacement_content:
- Risk Rule for Dev Sec Ops by Repository
- deprecated_content: Processes created by netsh
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Updated to a new detection name
replacement_content:
- Processes launching netsh
- deprecated_content: Office Product Spawning Wmic
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Extraction of Registry Hives
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Sensitive Registry Hive Dump Via CommandLine
- deprecated_content: Attempt To Stop Security Service
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Attempt To Stop Security Service
- deprecated_content: Windows MSIExec With Network Connections
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows HTTP Network Communication From MSIExec
- deprecated_content: Windows Query Registry Reg Save
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Registry Entries Exported Via Reg
- deprecated_content: Cloud Network Access Control List Deleted
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- AWS Network Access Control List Deleted
- deprecated_content: O365 Suspicious Rights Delegation
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- O365 Elevated Mailbox Permission Assigned
- deprecated_content: Abnormally High AWS Instances Launched by User - MLTK
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Reg exe used to hide files directories via registry keys
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Detect Long DNS TXT Record Response
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Password Policy Discovery with Net
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Password Policy Discovery with Net
- deprecated_content: AWS Cloud Provisioning From Previously Unseen IP Address
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Provisioning Activity From Previously Unseen IP Address
- deprecated_content: Network Connection Discovery With Net
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Network Connection Discovery Via Net
- deprecated_content: Kubernetes Azure detect suspicious kubectl calls
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Kubernetes GCP detect sensitive role access
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Detect Webshell Exploit Behavior
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Suspicious Child Process Spawned From WebServer
- deprecated_content: DNS record changed
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Unsigned Image Loaded by LSASS
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Detect USB device insertion
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Windows Network Share Interaction With Net
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Network Share Interaction Via Net
- deprecated_content: Account Discovery With Net App
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: This analytic was a TTP that focused on unrelated things and called account
discovery. Since there were other detection that overlapped with it. I choose
to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122
@@ -667,670 +511,457 @@ detections:
- Windows Excessive Usage Of Net App
- deprecated_content: Change Default File Association
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows New Default File Association Value Set
- deprecated_content: Windows Lateral Tool Transfer RemCom
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Updated to a new detection name
replacement_content:
- Windows Service Execution RemCom
- deprecated_content: Office Document Executing Macro Code
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Loading VBE7 DLL
- deprecated_content: Okta Account Lockout Events
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Multiple Accounts Locked Out
- deprecated_content: Abnormally High AWS Instances Launched by User
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Abnormally High Number Of Cloud Instances Launched
- deprecated_content: EC2 Instance Modified With Previously Unseen User
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud API Calls From Previously Unseen User Roles
- deprecated_content: Windows Valid Account With Never Expires Password
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Set Account Password Policy To Unlimited Via Net
- deprecated_content: Windows hosts file modification
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: MSHTML Module Load in Office Product
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Loaded MSHTML Module
- deprecated_content: Abnormally High AWS Instances Terminated by User
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Abnormally High Number Of Cloud Instances Destroyed
- deprecated_content: Web Fraud - Account Harvesting
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Office Spawning Control
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Spawned Control
- deprecated_content: Detect Activity Related to Pass the Hash Attacks
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Deleting Of Net Users
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows User Deletion Via Net
- deprecated_content: Suspicious File Write
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: AWS EKS Kubernetes cluster sensitive object access
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Kubernetes Abuse of Secret by Unusual Location
- deprecated_content: Spectre and Meltdown Vulnerable Systems
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: EC2 Instance Started With Previously Unseen User
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Compute Instance Created By Previously Unseen User
- deprecated_content: Office Product Spawning CertUtil
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Kubernetes GCP detect RBAC authorizations by account
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Office Application Drop Executable
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Dropped Uncommon File
- deprecated_content: Kubernetes Azure active service accounts by pod namespace
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Kubernetes Azure pod scan fingerprint
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Detect Spike in Network ACL Activity
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Abnormally High Number Of Cloud Infrastructure API Calls
- deprecated_content: Suspicious Powershell Command-Line Arguments
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Malicious PowerShell Process - Encoded Command
- deprecated_content: Office Application Spawn Regsvr32 process
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- deprecated_content: Detect API activity from users without MFA
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- AWS Successful Single-Factor Authentication
- deprecated_content: Kubernetes Azure detect sensitive object access
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Web Fraud - Password Sharing Across Accounts
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Disabling Net User Account
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows User Disabled Via Net
- deprecated_content: GCP Detect accounts with high risk roles by project
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Kubernetes GCP detect service accounts forbidden failure access
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Extended Period Without Successful Netbackup Backups
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Office Product Spawning Rundll32 with no DLL
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Spawned Rundll32 With No DLL
- deprecated_content: Okta ThreatInsight Suspected PasswordSpray Attack
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta ThreatInsight Threat Detected
- deprecated_content: Net Localgroup Discovery
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44
/ Windows Group Discovery Via Net
replacement_content:
- Windows Group Discovery Via Net
- deprecated_content: Uncommon Processes On Endpoint
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Attacker Tools On Endpoint
- deprecated_content: Dump LSASS via procdump Rename
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Updated to a new detection name
replacement_content:
- Dump LSASS via procdump
- deprecated_content: Okta Two or More Rejected Okta Pushes
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Multiple Failed MFA Requests For User
- deprecated_content: Excel Spawning Windows Script Host
deprecated_in_version: 5.4.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: GitHub Actions Disable Security Workflow
deprecated_in_version: 5.4.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Github Commit Changes In Master
deprecated_in_version: 5.4.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Github Commit In Develop
deprecated_in_version: 5.4.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: GitHub Dependabot Alert
deprecated_in_version: 5.4.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: GitHub Pull Request from Unknown User
deprecated_in_version: 5.4.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Known Services Killed by Ransomware
deprecated_in_version: 5.4.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Remote Desktop Network Bruteforce
deprecated_in_version: 5.4.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Suspicious Driver Loaded Path
deprecated_in_version: 5.4.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Suspicious Event Log Service Behavior
deprecated_in_version: 5.4.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Suspicious Process File Path
deprecated_in_version: 5.4.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- deprecated_content: Windows Service Stop Via Net and SC Application
deprecated_in_version: 5.4.0
- deprecated_date: 2025-03-12
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
baselines:
- deprecated_content: Add Prohibited Processes to Enterprise Security
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- deprecated_content: Baseline of API Calls per User ARN
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- deprecated_content: Baseline of Excessive AWS Instances Launched by User - MLTK
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- deprecated_content: Baseline of Excessive AWS Instances Terminated by User - MLTK
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- deprecated_content: Previously seen API call per user roles in CloudTrail
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- deprecated_content: Previously Seen AWS Provisioning Activity Sources
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- deprecated_content: Previously Seen EC2 AMIs
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- deprecated_content: Previously Seen EC2 Instance Types
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- deprecated_content: Previously Seen EC2 Launches By User
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- deprecated_content: Previously seen users in CloudTrail
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
- deprecated_content: Update previously seen users in CloudTrail
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- replacement_content: []
investigations:
- deprecated_content: All backup logs for host
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Amazon EKS Kubernetes activity by src ip
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: AWS Investigate Security Hub alerts by dest
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: AWS Investigate User Activities By AccessKeyId
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: AWS Investigate User Activities By ARN
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: AWS Network ACL Details from ID
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: AWS Network Interface details via resourceId
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: AWS S3 Bucket details via bucketName
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: GCP Kubernetes activity by src ip
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get All AWS Activity From City
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get All AWS Activity From Country
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get All AWS Activity From IP Address
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get All AWS Activity From Region
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get Backup Logs For Endpoint
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get Certificate logs for a domain
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get DNS Server History for a host
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get DNS traffic ratio
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get EC2 Instance Details by instanceId
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get EC2 Launch Details
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get Email Info
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get Emails From Specific Sender
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get First Occurrence and Last Occurrence of a MAC Address
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get History Of Email Sources
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get Logon Rights Modifications For Endpoint
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get Logon Rights Modifications For User
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get Notable History
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get Outbound Emails to Hidden Cobra Threat Actors
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get Parent Process Info
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get Process File Activity
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get Process Info
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get Process Information For Port Activity
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get Process Responsible For The DNS Traffic
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get Sysmon WMI Activity for Host
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Get Web Session Information via session id
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Investigate AWS activities via region name
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Investigate AWS User Activities by user field
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Investigate Failed Logins for Multiple Destinations
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Investigate Network Traffic From src ip
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Investigate Okta Activity by app
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Investigate Okta Activity by IP Address
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Investigate Pass the Hash Attempts
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Investigate Pass the Ticket Attempts
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Investigate Previous Unseen User
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Investigate Successful Remote Desktop Authentications
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Investigate Suspicious Strings in HTTP Header
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Investigate User Activities In Okta
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
- deprecated_content: Investigate Web POSTs From src
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- replacement_content: []
stories:
- deprecated_content: AWS Cryptomining
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Cloud Cryptomining
- deprecated_content: AWS Suspicious Provisioning Activities
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Suspicious Cloud Provisioning Activities
- deprecated_content: Common Phishing Frameworks
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- - deprecated_content: Container Implantation Monitoring and Investigation
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: Container Implantation Monitoring and Investigation
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Kubernetes Security
- deprecated_content: Host Redirection
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- - deprecated_content: Kubernetes Sensitive Role Activity
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: Kubernetes Sensitive Role Activity
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Kubernetes Security
- deprecated_content: Lateral Movement
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Compromised User Account
- deprecated_content: Monitor Backup Solution
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- - deprecated_content: Monitor for Unauthorized Software
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: Monitor for Unauthorized Software
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- - deprecated_content: Office 365 Detections
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: Office 365 Detections
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Office 365 Account Takeover
- deprecated_content: Spectre And Meltdown Vulnerabilities
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- - deprecated_content: Suspicious AWS EC2 Activities
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: Suspicious AWS EC2 Activities
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Suspicious Cloud Instance Activities
- deprecated_content: Unusual AWS EC2 Modifications
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Suspicious Cloud Instance Activities
- deprecated_content: Web Fraud Detection
deprecated_in_version: 5.2.0
- deprecated_date: 2025-03-12
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content: []
- - deprecated_content: Nexus APT Threat Activity
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: Nexus APT Threat Activity
deprecated_in_version: 5.4.0
- deprecated_date: 2025-03-12
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- China-Nexus Threat Activity
\ No newline at end of file
From 990b5442719043d2172cfddb00414afeb21b10f8 Mon Sep 17 00:00:00 2001
From: pyth0n1c
Date: Mon, 17 Mar 2025 16:41:52 -0700
Subject: [PATCH 45/67] Fixed spacing in improperly formatted YML file
---
deprecated/deprecated_detection_mapping.yml | 126 ++++++++++----------
1 file changed, 63 insertions(+), 63 deletions(-)
diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml
index c104358a54..eb9b6abec0 100644
--- a/deprecated/deprecated_detection_mapping.yml
+++ b/deprecated/deprecated_detection_mapping.yml
@@ -902,66 +902,66 @@ investigations:
deprecated_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
stories:
- - deprecated_content: AWS Cryptomining
- deprecated_in_version: 5.2.0
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content:
- - Cloud Cryptomining
- - deprecated_content: AWS Suspicious Provisioning Activities
- deprecated_in_version: 5.2.0
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content:
- - Suspicious Cloud Provisioning Activities
- - deprecated_content: Common Phishing Frameworks
- deprecated_in_version: 5.2.0
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Container Implantation Monitoring and Investigation
- deprecated_in_version: 5.2.0
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content:
- - Kubernetes Security
- - deprecated_content: Host Redirection
- deprecated_in_version: 5.2.0
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Kubernetes Sensitive Role Activity
- deprecated_in_version: 5.2.0
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content:
- - Kubernetes Security
- - deprecated_content: Lateral Movement
- deprecated_in_version: 5.2.0
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content:
- - Compromised User Account
- - deprecated_content: Monitor Backup Solution
- deprecated_in_version: 5.2.0
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Monitor for Unauthorized Software
- deprecated_in_version: 5.2.0
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Office 365 Detections
- deprecated_in_version: 5.2.0
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content:
- - Office 365 Account Takeover
- - deprecated_content: Spectre And Meltdown Vulnerabilities
- deprecated_in_version: 5.2.0
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Suspicious AWS EC2 Activities
- deprecated_in_version: 5.2.0
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content:
- - Suspicious Cloud Instance Activities
- - deprecated_content: Unusual AWS EC2 Modifications
- deprecated_in_version: 5.2.0
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content:
- - Suspicious Cloud Instance Activities
- - deprecated_content: Web Fraud Detection
- deprecated_in_version: 5.2.0
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Nexus APT Threat Activity
- deprecated_in_version: 5.4.0
- reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- replacement_content:
- - China-Nexus Threat Activity
\ No newline at end of file
+ - deprecated_content: AWS Cryptomining
+ deprecated_in_version: 5.2.0
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content:
+ - Cloud Cryptomining
+ - deprecated_content: AWS Suspicious Provisioning Activities
+ deprecated_in_version: 5.2.0
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content:
+ - Suspicious Cloud Provisioning Activities
+ - deprecated_content: Common Phishing Frameworks
+ deprecated_in_version: 5.2.0
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: Container Implantation Monitoring and Investigation
+ deprecated_in_version: 5.2.0
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content:
+ - Kubernetes Security
+ - deprecated_content: Host Redirection
+ deprecated_in_version: 5.2.0
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: Kubernetes Sensitive Role Activity
+ deprecated_in_version: 5.2.0
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content:
+ - Kubernetes Security
+ - deprecated_content: Lateral Movement
+ deprecated_in_version: 5.2.0
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content:
+ - Compromised User Account
+ - deprecated_content: Monitor Backup Solution
+ deprecated_in_version: 5.2.0
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: Monitor for Unauthorized Software
+ deprecated_in_version: 5.2.0
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: Office 365 Detections
+ deprecated_in_version: 5.2.0
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content:
+ - Office 365 Account Takeover
+ - deprecated_content: Spectre And Meltdown Vulnerabilities
+ deprecated_in_version: 5.2.0
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: Suspicious AWS EC2 Activities
+ deprecated_in_version: 5.2.0
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content:
+ - Suspicious Cloud Instance Activities
+ - deprecated_content: Unusual AWS EC2 Modifications
+ deprecated_in_version: 5.2.0
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content:
+ - Suspicious Cloud Instance Activities
+ - deprecated_content: Web Fraud Detection
+ deprecated_in_version: 5.2.0
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: Nexus APT Threat Activity
+ deprecated_in_version: 5.4.0
+ reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+ replacement_content:
+ - China-Nexus Threat Activity
\ No newline at end of file
From 77dfe52b895e69d2cd0392e3e1eaa39b53cabf36 Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Mon, 17 Mar 2025 16:44:09 -0700
Subject: [PATCH 46/67] Update macro
---
macros/o365_suspect_search_terms_regex.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/macros/o365_suspect_search_terms_regex.yml b/macros/o365_suspect_search_terms_regex.yml
index e5190a3cb3..e78548955f 100644
--- a/macros/o365_suspect_search_terms_regex.yml
+++ b/macros/o365_suspect_search_terms_regex.yml
@@ -1,3 +1,3 @@
-definition: "(?i)password|credential|login|passwd|shadow|active directory|account|username|network|computer|access|MFA|bank|deposit|payroll|EFT|Electonic Funds|routing"
+definition: "\"(?i)password|credential|login|passwd|shadow|active directory|account|username|network|computer|access|MFA|bank|deposit|payroll|EFT|Electonic Funds|routing\""
description: A regex used with match statements preloaded with generic suspicious terms or phrases. Is used to detect malicious actor or insider threat searches, replace/modify these terms to suit your organization.
name: o365_suspect_search_terms_regex
From 53b19285121cf0c2be72e98d5ce39f22276ed73a Mon Sep 17 00:00:00 2001
From: delgado-jacob <29643013+delgado-jacob@users.noreply.github.com>
Date: Mon, 17 Mar 2025 17:07:03 -0700
Subject: [PATCH 47/67] normalize quotes
---
data_sources/azure_active_directory_add_member_to_role.yml | 2 +-
.../azure_active_directory_add_owner_to_application.yml | 2 +-
data_sources/azure_active_directory_add_service_principal.yml | 2 +-
data_sources/azure_active_directory_add_unverified_domain.yml | 2 +-
data_sources/azure_active_directory_consent_to_application.yml | 2 +-
.../azure_active_directory_disable_strong_authentication.yml | 2 +-
data_sources/azure_active_directory_enable_account.yml | 2 +-
data_sources/azure_active_directory_invite_external_user.yml | 2 +-
.../azure_active_directory_reset_password_(by_admin).yml | 2 +-
.../azure_active_directory_set_domain_authentication.yml | 2 +-
data_sources/azure_active_directory_sign_in_activity.yml | 2 +-
data_sources/azure_active_directory_update_application.yml | 2 +-
.../azure_active_directory_update_authorization_policy.yml | 2 +-
data_sources/azure_active_directory_update_user.yml | 2 +-
.../azure_active_directory_user_registered_security_info.yml | 2 +-
...azure_audit_create_or_update_an_azure_automation_account.yml | 2 +-
...azure_audit_create_or_update_an_azure_automation_runbook.yml | 2 +-
...azure_audit_create_or_update_an_azure_automation_webhook.yml | 2 +-
data_sources/azure_monitor_activity.yml | 2 +-
data_sources/g_suite_drive.yml | 2 +-
data_sources/g_suite_gmail.yml | 2 +-
data_sources/google_workspace.yml | 2 +-
data_sources/google_workspace_login_failure.yml | 2 +-
data_sources/google_workspace_login_success.yml | 2 +-
data_sources/o365.yml | 2 +-
data_sources/o365_add_app_role_assignment_grant_to_user_.yml | 2 +-
.../o365_add_app_role_assignment_to_service_principal_.yml | 2 +-
data_sources/o365_add_mailboxpermission.yml | 2 +-
data_sources/o365_add_member_to_role_.yml | 2 +-
data_sources/o365_add_owner_to_application_.yml | 2 +-
data_sources/o365_add_service_principal_.yml | 2 +-
data_sources/o365_change_user_license_.yml | 2 +-
32 files changed, 32 insertions(+), 32 deletions(-)
diff --git a/data_sources/azure_active_directory_add_member_to_role.yml b/data_sources/azure_active_directory_add_member_to_role.yml
index 737edf7f94..361ec5afe2 100644
--- a/data_sources/azure_active_directory_add_member_to_role.yml
+++ b/data_sources/azure_active_directory_add_member_to_role.yml
@@ -1,7 +1,7 @@
name: Azure Active Directory Add member to role
id: 1660d196-127f-4678-81b2-472d51711b07
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs the addition of a member to a directory role in Azure Active Directory,
including details about the role, the member added, and the user or process performing
diff --git a/data_sources/azure_active_directory_add_owner_to_application.yml b/data_sources/azure_active_directory_add_owner_to_application.yml
index 36786bbea3..1e80420bc9 100644
--- a/data_sources/azure_active_directory_add_owner_to_application.yml
+++ b/data_sources/azure_active_directory_add_owner_to_application.yml
@@ -1,7 +1,7 @@
name: Azure Active Directory Add owner to application
id: e895ed56-7be4-4b3a-b782-ecd0f594ec4c
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs the addition of an owner to an application in Azure Active Directory,
including details about the application, the owner added, and the user or process
diff --git a/data_sources/azure_active_directory_add_service_principal.yml b/data_sources/azure_active_directory_add_service_principal.yml
index 7ec49367e7..4900077c25 100644
--- a/data_sources/azure_active_directory_add_service_principal.yml
+++ b/data_sources/azure_active_directory_add_service_principal.yml
@@ -1,7 +1,7 @@
name: Azure Active Directory Add service principal
id: fd89d337-e4c0-4162-ad13-bca36f096fe6
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs the creation of a new service principal in Azure Active Directory,
including details about the service principal, associated application, and the user
diff --git a/data_sources/azure_active_directory_add_unverified_domain.yml b/data_sources/azure_active_directory_add_unverified_domain.yml
index 961e232a61..9c65ffb874 100644
--- a/data_sources/azure_active_directory_add_unverified_domain.yml
+++ b/data_sources/azure_active_directory_add_unverified_domain.yml
@@ -1,7 +1,7 @@
name: Azure Active Directory Add unverified domain
id: d4c01fb1-3b88-46d3-bd12-9b9e256450f7
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs the addition of an unverified domain to Azure Active Directory,
including details about the domain name and the user or process performing the action.
diff --git a/data_sources/azure_active_directory_consent_to_application.yml b/data_sources/azure_active_directory_consent_to_application.yml
index e009f3279a..a3fabfa139 100644
--- a/data_sources/azure_active_directory_consent_to_application.yml
+++ b/data_sources/azure_active_directory_consent_to_application.yml
@@ -1,7 +1,7 @@
name: Azure Active Directory Consent to application
id: 4c5d6c49-53e3-4980-a4de-c63e26291ed0
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs user or admin consent to an application's permissions in Azure Active
Directory, including details about the application, granted permissions, and the
diff --git a/data_sources/azure_active_directory_disable_strong_authentication.yml b/data_sources/azure_active_directory_disable_strong_authentication.yml
index 776d4966f2..dc3b8dbf05 100644
--- a/data_sources/azure_active_directory_disable_strong_authentication.yml
+++ b/data_sources/azure_active_directory_disable_strong_authentication.yml
@@ -1,7 +1,7 @@
name: Azure Active Directory Disable Strong Authentication
id: 8f31966d-c496-496d-8837-f7fd11f31255
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when strong authentication methods are disabled in Azure
Active Directory.
diff --git a/data_sources/azure_active_directory_enable_account.yml b/data_sources/azure_active_directory_enable_account.yml
index 6490ed964a..be0208edb9 100644
--- a/data_sources/azure_active_directory_enable_account.yml
+++ b/data_sources/azure_active_directory_enable_account.yml
@@ -1,7 +1,7 @@
name: Azure Active Directory Enable account
id: cb49f3cd-04ad-415c-a5ed-9b27b2829fa7
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when an Azure Active Directory account is enabled.
mitre_components:
diff --git a/data_sources/azure_active_directory_invite_external_user.yml b/data_sources/azure_active_directory_invite_external_user.yml
index 2ed2d7c705..fca5f7cf97 100644
--- a/data_sources/azure_active_directory_invite_external_user.yml
+++ b/data_sources/azure_active_directory_invite_external_user.yml
@@ -1,7 +1,7 @@
name: Azure Active Directory Invite external user
id: d3818bd5-f283-4518-8b67-df19240c3e40
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when an external user is invited to join an Azure Active
Directory tenant.
diff --git a/data_sources/azure_active_directory_reset_password_(by_admin).yml b/data_sources/azure_active_directory_reset_password_(by_admin).yml
index c35dabeb34..aff8092dee 100644
--- a/data_sources/azure_active_directory_reset_password_(by_admin).yml
+++ b/data_sources/azure_active_directory_reset_password_(by_admin).yml
@@ -1,7 +1,7 @@
name: Azure Active Directory Reset password (by admin)
id: dcd0e4dc-68f8-4b77-a66f-89c57b3afa6b
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when an admin resets a user's password in Azure Active
Directory.
diff --git a/data_sources/azure_active_directory_set_domain_authentication.yml b/data_sources/azure_active_directory_set_domain_authentication.yml
index 0b31d97f53..70c7e43888 100644
--- a/data_sources/azure_active_directory_set_domain_authentication.yml
+++ b/data_sources/azure_active_directory_set_domain_authentication.yml
@@ -1,7 +1,7 @@
name: Azure Active Directory Set domain authentication
id: e7bcdab9-908c-40ab-ba38-5db54fa87750
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when the authentication method for a domain in Azure Active
Directory is set or modified.
diff --git a/data_sources/azure_active_directory_sign_in_activity.yml b/data_sources/azure_active_directory_sign_in_activity.yml
index 3834f3e0b6..31a32e5a30 100644
--- a/data_sources/azure_active_directory_sign_in_activity.yml
+++ b/data_sources/azure_active_directory_sign_in_activity.yml
@@ -1,7 +1,7 @@
name: Azure Active Directory Sign-in activity
id: f9ed0a3a-9e20-4198-a035-d0a29593fbe0
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when a user attempts to sign into Azure Active Directory,
capturing authentication details and outcomes.
diff --git a/data_sources/azure_active_directory_update_application.yml b/data_sources/azure_active_directory_update_application.yml
index e180c237a0..23dcecde69 100644
--- a/data_sources/azure_active_directory_update_application.yml
+++ b/data_sources/azure_active_directory_update_application.yml
@@ -1,7 +1,7 @@
name: Azure Active Directory Update application
id: 2c08188a-ba25-496e-87c7-803cf28b6c90
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when an application in Azure Active Directory is updated,
such as changes to its settings or permissions.
diff --git a/data_sources/azure_active_directory_update_authorization_policy.yml b/data_sources/azure_active_directory_update_authorization_policy.yml
index 5a9cb19eb3..058f400e1a 100644
--- a/data_sources/azure_active_directory_update_authorization_policy.yml
+++ b/data_sources/azure_active_directory_update_authorization_policy.yml
@@ -1,7 +1,7 @@
name: Azure Active Directory Update authorization policy
id: c5b7ffcd-73d8-4fe5-afd8-b1218d715c0c
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when an authorization policy is updated in Azure Active
Directory.
diff --git a/data_sources/azure_active_directory_update_user.yml b/data_sources/azure_active_directory_update_user.yml
index a9e43502b0..9f99e199d8 100644
--- a/data_sources/azure_active_directory_update_user.yml
+++ b/data_sources/azure_active_directory_update_user.yml
@@ -1,7 +1,7 @@
name: Azure Active Directory Update user
id: 5495c90a-047c-4b8e-b2fe-1db6282d3872
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when a user account is updated in Azure Active Directory.
mitre_components:
diff --git a/data_sources/azure_active_directory_user_registered_security_info.yml b/data_sources/azure_active_directory_user_registered_security_info.yml
index 1f3474bc88..1379b9e4f8 100644
--- a/data_sources/azure_active_directory_user_registered_security_info.yml
+++ b/data_sources/azure_active_directory_user_registered_security_info.yml
@@ -1,7 +1,7 @@
name: Azure Active Directory User registered security info
id: b63240de-8a01-4ba8-8987-89d18d4b375d
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when a user registers or updates their security information
in Azure Active Directory.
diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml
index f6527d3d3b..d20eb1b740 100644
--- a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml
+++ b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml
@@ -1,7 +1,7 @@
name: Azure Audit Create or Update an Azure Automation account
id: 2ab182e7-feda-4249-9418-32710b55a885
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when an Azure Automation account is created or updated.
mitre_components:
diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml
index a8f5116f79..f2dbafa993 100644
--- a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml
+++ b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml
@@ -1,7 +1,7 @@
name: Azure Audit Create or Update an Azure Automation Runbook
id: 2bd83221-7a8b-436f-9b2b-efa1d44d009e
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when a new Azure Automation Runbook is created or an existing
one is updated.
diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml
index e3e30003a4..a8c611852b 100644
--- a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml
+++ b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml
@@ -1,7 +1,7 @@
name: Azure Audit Create or Update an Azure Automation webhook
id: 575faeb2-09d0-4849-b1f6-eae241f26ff2
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs an event when a webhook is created or updated in Azure Automation.
mitre_components:
diff --git a/data_sources/azure_monitor_activity.yml b/data_sources/azure_monitor_activity.yml
index c47465f05f..99c76ed47f 100644
--- a/data_sources/azure_monitor_activity.yml
+++ b/data_sources/azure_monitor_activity.yml
@@ -1,7 +1,7 @@
name: Azure Monitor Activity
id: 1997a515-a61a-4f78-ada9-54af34c764f2
version: 1
-date: "2025-01-13"
+date: '2025-01-13'
author: Bhavin Patel, Splunk
description:
Data source object for Azure Monitor Activity. The Splunk Add-on for
diff --git a/data_sources/g_suite_drive.yml b/data_sources/g_suite_drive.yml
index 050427ab42..0064416dbb 100644
--- a/data_sources/g_suite_drive.yml
+++ b/data_sources/g_suite_drive.yml
@@ -1,7 +1,7 @@
name: G Suite Drive
id: 5f79120f-a235-4468-bd0d-55203758ac22
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs activities related to Google Drive in G Suite, including file creation,
modification, sharing, and access details.
diff --git a/data_sources/g_suite_gmail.yml b/data_sources/g_suite_gmail.yml
index 9471a54484..2366e69b41 100644
--- a/data_sources/g_suite_gmail.yml
+++ b/data_sources/g_suite_gmail.yml
@@ -1,7 +1,7 @@
name: G Suite Gmail
id: 706c3978-41de-406b-b6e0-75bd01e12a5d
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs Gmail activities in G Suite, including email sending, receiving,
and access details, as well as potential security-related events.
diff --git a/data_sources/google_workspace.yml b/data_sources/google_workspace.yml
index 1e651b883e..cdc72f6062 100644
--- a/data_sources/google_workspace.yml
+++ b/data_sources/google_workspace.yml
@@ -1,7 +1,7 @@
name: Google Workspace
id: f1a044e3-113a-4e4d-84f2-b153ade83087
version: 1
-date: "2025-02-21"
+date: '2025-02-21'
author: Bhavin Patel, Splunk
description: Data source object for Google Workspace
source: google_workspace
diff --git a/data_sources/google_workspace_login_failure.yml b/data_sources/google_workspace_login_failure.yml
index 4a57f70c36..37b5e7dfd3 100644
--- a/data_sources/google_workspace_login_failure.yml
+++ b/data_sources/google_workspace_login_failure.yml
@@ -1,7 +1,7 @@
name: Google Workspace login_failure
id: cabec7cf-4008-4899-b47e-39c34a9a1255
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs failed login attempts to Google Workspace accounts, including details
about the user, IP address, and reason for failure.
diff --git a/data_sources/google_workspace_login_success.yml b/data_sources/google_workspace_login_success.yml
index 16beb865b8..ac11eece48 100644
--- a/data_sources/google_workspace_login_success.yml
+++ b/data_sources/google_workspace_login_success.yml
@@ -1,7 +1,7 @@
name: Google Workspace login_success
id: bffe8013-9cdf-4fe6-9c1b-6784391a4951
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs successful login attempts to Google Workspace accounts, including
details about the user, IP address, and session metadata.
diff --git a/data_sources/o365.yml b/data_sources/o365.yml
index c87c6d01cd..e3a8fe4084 100644
--- a/data_sources/o365.yml
+++ b/data_sources/o365.yml
@@ -1,7 +1,7 @@
name: O365
id: b32de97d-0074-4cca-853c-db22c392b6c0
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs management activities in Microsoft 365, including administrative
actions, user activities, and configuration changes across various services.
diff --git a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml
index 87d209241a..b423cfb188 100644
--- a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml
+++ b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml
@@ -1,7 +1,7 @@
name: O365 Add app role assignment grant to user.
id: ce1d7849-a1d2-47fd-b6eb-d7ef854a860c
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs the assignment of an application role grant to a user in Microsoft
365, including details about the role, user, and application involved.
diff --git a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml
index 8c76c22053..f701f5d05a 100644
--- a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml
+++ b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml
@@ -1,7 +1,7 @@
name: O365 Add app role assignment to service principal.
id: 785ba57a-ba7b-474e-97c8-9474e6e00b3a
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs the assignment of an application role to a service principal in
Microsoft 365, including details about the role, service principal, and application
diff --git a/data_sources/o365_add_mailboxpermission.yml b/data_sources/o365_add_mailboxpermission.yml
index eaaf573a62..73d8a6a770 100644
--- a/data_sources/o365_add_mailboxpermission.yml
+++ b/data_sources/o365_add_mailboxpermission.yml
@@ -1,7 +1,7 @@
name: O365 Add-MailboxPermission
id: 9c0babdb-bb15-449e-abba-0a9cdb3fc061
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs the addition of mailbox permissions in Microsoft 365, including
details about the mailbox, granted permissions, and the user or administrator performing
diff --git a/data_sources/o365_add_member_to_role_.yml b/data_sources/o365_add_member_to_role_.yml
index 6a582f6557..4bbd0ee8ac 100644
--- a/data_sources/o365_add_member_to_role_.yml
+++ b/data_sources/o365_add_member_to_role_.yml
@@ -1,7 +1,7 @@
name: O365 Add member to role.
id: 8b949f7c-4b5d-404f-9694-d7403c4ec096
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs the addition of a member to a role in Microsoft 365, including details
about the role, the added member, and the user or administrator performing the action.
diff --git a/data_sources/o365_add_owner_to_application_.yml b/data_sources/o365_add_owner_to_application_.yml
index f0b2874382..b1da0c1792 100644
--- a/data_sources/o365_add_owner_to_application_.yml
+++ b/data_sources/o365_add_owner_to_application_.yml
@@ -1,7 +1,7 @@
name: O365 Add owner to application.
id: da012cbf-af6e-40ee-a1ba-32a5f8da8f8a
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs the addition of an owner to an application in Microsoft 365, including
details about the application, the new owner, and the user or administrator performing
diff --git a/data_sources/o365_add_service_principal_.yml b/data_sources/o365_add_service_principal_.yml
index 145c7ea81c..b348c73689 100644
--- a/data_sources/o365_add_service_principal_.yml
+++ b/data_sources/o365_add_service_principal_.yml
@@ -1,7 +1,7 @@
name: O365 Add service principal.
id: 9c1ef9f5-bc30-4a47-a1bd-cb34484ee778
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs the addition of a new service principal in Microsoft 365, including
details about the associated application and the action initiator.
diff --git a/data_sources/o365_change_user_license_.yml b/data_sources/o365_change_user_license_.yml
index 5faab95680..9204dca910 100644
--- a/data_sources/o365_change_user_license_.yml
+++ b/data_sources/o365_change_user_license_.yml
@@ -1,7 +1,7 @@
name: O365 Change user license.
id: 1029a20d-3d0d-4fb9-b5e2-22ac5380b20a
version: 2
-date: "2025-01-23"
+date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs changes to user licenses in Microsoft 365, including additions,
removals, or updates to service plans associated with a user account.
From f672cb55c0fe2d9490227caf918115860e2d5813 Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Mon, 17 Mar 2025 17:48:11 -0700
Subject: [PATCH 48/67] updating missing detections
---
deprecated/deprecated_detection_mapping.yml | 23 ++++++++++++++++++++-
1 file changed, 22 insertions(+), 1 deletion(-)
diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml
index eb9b6abec0..f2a4a244dd 100644
--- a/deprecated/deprecated_detection_mapping.yml
+++ b/deprecated/deprecated_detection_mapping.yml
@@ -690,7 +690,7 @@ detections:
replacement_content:
- Okta Multiple Failed MFA Requests For User
- deprecated_content: Excel Spawning Windows Script Host
- deprecated_in_version: 5.4.0
+ deprecated_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- deprecated_content: GitHub Actions Disable Security Workflow
deprecated_in_version: 5.4.0
@@ -725,6 +725,27 @@ detections:
- deprecated_content: Windows Service Stop Via Net and SC Application
deprecated_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: AWS Cross Account Activity From Previously Unseen Account
+ deprecated_in_version: 5.4.0
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: aws detect attach to role policy
+ deprecated_in_version: 5.4.0
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: aws detect permanent key creation
+ deprecated_in_version: 5.4.0
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: aws detect role creation
+ deprecated_in_version: 5.4.0
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: aws detect sts assume role abuse
+ deprecated_in_version: 5.4.0
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: aws detect sts get session token abuse
+ deprecated_in_version: 5.4.0
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: AWS SAML Access by Provider User and Principal
+ deprecated_in_version: 5.4.0
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
baselines:
- deprecated_content: Add Prohibited Processes to Enterprise Security
deprecated_in_version: 5.2.0
From c345f920ed571afb19e38b153e3a70dd8371df19 Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Mon, 17 Mar 2025 18:04:26 -0700
Subject: [PATCH 49/67] adding gitkeep for empty folders
---
baselines/deprecated/.gitkeep | 0
deprecated/deprecated_detection_mapping.yml | 6 +++---
detections/deprecated/.gitkeep | 0
stories/deprecated/.gitkeep | 0
4 files changed, 3 insertions(+), 3 deletions(-)
create mode 100644 baselines/deprecated/.gitkeep
create mode 100644 detections/deprecated/.gitkeep
create mode 100644 stories/deprecated/.gitkeep
diff --git a/baselines/deprecated/.gitkeep b/baselines/deprecated/.gitkeep
new file mode 100644
index 0000000000..e69de29bb2
diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml
index f2a4a244dd..b4014fd419 100644
--- a/deprecated/deprecated_detection_mapping.yml
+++ b/deprecated/deprecated_detection_mapping.yml
@@ -689,6 +689,9 @@ detections:
TA update
replacement_content:
- Okta Multiple Failed MFA Requests For User
+ - deprecated_content: Windows Service Stop Via Net and SC Application
+ deprecated_in_version: 5.2.0
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- deprecated_content: Excel Spawning Windows Script Host
deprecated_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
@@ -722,9 +725,6 @@ detections:
- deprecated_content: Suspicious Process File Path
deprecated_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Windows Service Stop Via Net and SC Application
- deprecated_in_version: 5.4.0
- reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- deprecated_content: AWS Cross Account Activity From Previously Unseen Account
deprecated_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
diff --git a/detections/deprecated/.gitkeep b/detections/deprecated/.gitkeep
new file mode 100644
index 0000000000..e69de29bb2
diff --git a/stories/deprecated/.gitkeep b/stories/deprecated/.gitkeep
new file mode 100644
index 0000000000..e69de29bb2
From 99a4b6fa4b62174ae556c6b501812d9d1f51a857 Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Mon, 17 Mar 2025 18:09:42 -0700
Subject: [PATCH 50/67] adding missing baselines
---
deprecated/deprecated_detection_mapping.yml | 15 +++++++++++++++
1 file changed, 15 insertions(+)
diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml
index b4014fd419..57c872e1bb 100644
--- a/deprecated/deprecated_detection_mapping.yml
+++ b/deprecated/deprecated_detection_mapping.yml
@@ -780,6 +780,21 @@ baselines:
- deprecated_content: Update previously seen users in CloudTrail
deprecated_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ - deprecated_content: Monitor Successful Backups
+ deprecated_in_version: 5.2.0
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ - deprecated_content: Monitor Unsuccessful Backups
+ deprecated_in_version: 5.2.0
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ - deprecated_content: Previously Seen AWS Regions
+ deprecated_in_version: 5.2.0
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ - deprecated_content: Previously Seen EC2 Modifications By User
+ deprecated_in_version: 5.2.0
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ - deprecated_content: Systems Ready for Spectre-Meltdown Windows Patch
+ deprecated_in_version: 5.2.0
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
investigations:
- deprecated_content: All backup logs for host
deprecated_in_version: 5.2.0
From 4d4a1c664928464ca663d916d7225be763e695a1 Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Mon, 17 Mar 2025 18:19:56 -0700
Subject: [PATCH 51/67] adding cross account stuff
---
.../previously_seen_aws_cross_account_activity___initial.yml | 2 +-
.../previously_seen_aws_cross_account_activity___update.yml | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
rename baselines/{ => deprecated}/previously_seen_aws_cross_account_activity___initial.yml (98%)
rename baselines/{ => deprecated}/previously_seen_aws_cross_account_activity___update.yml (98%)
diff --git a/baselines/previously_seen_aws_cross_account_activity___initial.yml b/baselines/deprecated/previously_seen_aws_cross_account_activity___initial.yml
similarity index 98%
rename from baselines/previously_seen_aws_cross_account_activity___initial.yml
rename to baselines/deprecated/previously_seen_aws_cross_account_activity___initial.yml
index 6fad8d0f18..3cc411008a 100644
--- a/baselines/previously_seen_aws_cross_account_activity___initial.yml
+++ b/baselines/deprecated/previously_seen_aws_cross_account_activity___initial.yml
@@ -4,7 +4,7 @@ version: 1
date: '2020-08-15'
author: Rico Valdez, Splunk
type: Baseline
-status: production
+status: deprecated
description: This search looks for **AssumeRole** events where the requesting account
differs from the requested account, then writes these relationships to a lookup
file.
diff --git a/baselines/previously_seen_aws_cross_account_activity___update.yml b/baselines/deprecated/previously_seen_aws_cross_account_activity___update.yml
similarity index 98%
rename from baselines/previously_seen_aws_cross_account_activity___update.yml
rename to baselines/deprecated/previously_seen_aws_cross_account_activity___update.yml
index 9cb9c956b9..bc8eee0872 100644
--- a/baselines/previously_seen_aws_cross_account_activity___update.yml
+++ b/baselines/deprecated/previously_seen_aws_cross_account_activity___update.yml
@@ -4,7 +4,7 @@ version: 1
date: '2020-08-15'
author: Rico Valdez, Splunk
type: Baseline
-status: production
+status: deprecated
description: This search looks for **AssumeRole** events where the requesting account
differs from the requested account, then writes these relationships to a lookup
file.
From ca86201823f5d23dc29cd00921833aeb2c8926ae Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Mon, 17 Mar 2025 18:28:42 -0700
Subject: [PATCH 52/67] adding 2 deprecated baselines
---
deprecated/deprecated_detection_mapping.yml | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml
index 57c872e1bb..94813fd1da 100644
--- a/deprecated/deprecated_detection_mapping.yml
+++ b/deprecated/deprecated_detection_mapping.yml
@@ -795,6 +795,12 @@ baselines:
- deprecated_content: Systems Ready for Spectre-Meltdown Windows Patch
deprecated_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ - deprecated_content: Previously Seen AWS Cross Account Activity - Initial
+ deprecated_in_version: 5.4.0
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
+ - deprecated_content: Previously Seen AWS Cross Account Activity - Update
+ deprecated_in_version: 5.4.0
+ reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
investigations:
- deprecated_content: All backup logs for host
deprecated_in_version: 5.2.0
From 3819c6864d71c9c5592077775bc9c3fcf80fe0b3 Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Mon, 17 Mar 2025 19:14:58 -0700
Subject: [PATCH 53/67] updating detections
---
detections/cloud/aws_credential_access_getpassworddata.yml | 3 +--
detections/cloud/aws_ec2_snapshot_shared_externally.yml | 2 +-
.../cloud/aws_network_access_control_list_deleted.yml | 7 +++----
detections/cloud/aws_saml_update_identity_provider.yml | 6 +++---
detections/cloud/aws_updateloginprofile.yml | 2 +-
detections/endpoint/registry_keys_used_for_persistence.yml | 1 -
6 files changed, 9 insertions(+), 12 deletions(-)
diff --git a/detections/cloud/aws_credential_access_getpassworddata.yml b/detections/cloud/aws_credential_access_getpassworddata.yml
index 366d056882..f10dcbf896 100644
--- a/detections/cloud/aws_credential_access_getpassworddata.yml
+++ b/detections/cloud/aws_credential_access_getpassworddata.yml
@@ -46,8 +46,7 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
- message: User $user$ is seen to make mulitple `GetPasswordData` API calls to
- instance ids $instance_ids$ from IP $src$
+ message: User $user$ is seen to make mulitple `GetPasswordData` API calls to multiple instances from IP $src$
risk_objects:
- field: user
type: user
diff --git a/detections/cloud/aws_ec2_snapshot_shared_externally.yml b/detections/cloud/aws_ec2_snapshot_shared_externally.yml
index b5b351c84d..16499e4a92 100644
--- a/detections/cloud/aws_ec2_snapshot_shared_externally.yml
+++ b/detections/cloud/aws_ec2_snapshot_shared_externally.yml
@@ -22,7 +22,7 @@ search: '`cloudtrail` eventName=ModifySnapshotAttribute
| where match = "No Match"
| rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
| eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product requested_account_id
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `aws_ec2_snapshot_shared_externally_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
diff --git a/detections/cloud/aws_network_access_control_list_deleted.yml b/detections/cloud/aws_network_access_control_list_deleted.yml
index 1f7c98e312..8d91777aae 100644
--- a/detections/cloud/aws_network_access_control_list_deleted.yml
+++ b/detections/cloud/aws_network_access_control_list_deleted.yml
@@ -16,9 +16,9 @@ data_source:
- AWS CloudTrail DeleteNetworkAclEntry
search: '`cloudtrail` eventName=DeleteNetworkAclEntry requestParameters.egress=false
| fillnull
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
+ | rename eventName as signature, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
| eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product signature
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_network_access_control_list_deleted_filter`'
how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later)
and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail
@@ -41,8 +41,7 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
- message: User $user$ from $src$ has sucessfully deleted network ACLs entry (eventName=
- $eventName$), such that the instance is accessible from anywhere
+ message: User $user$ from $src$ has sucessfully deleted network ACLs entry, such that the instance is accessible from anywhere
risk_objects:
- field: user
type: user
diff --git a/detections/cloud/aws_saml_update_identity_provider.yml b/detections/cloud/aws_saml_update_identity_provider.yml
index 51e9b3ea04..666cf8c96e 100644
--- a/detections/cloud/aws_saml_update_identity_provider.yml
+++ b/detections/cloud/aws_saml_update_identity_provider.yml
@@ -16,9 +16,9 @@ description: The following analytic detects updates to the SAML provider in AWS.
data_source:
- AWS CloudTrail UpdateSAMLProvider
search: '`cloudtrail` eventName=UpdateSAMLProvider
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
+ | rename requestParameters.sAMLProviderArn as request_parameters , eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
| eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | stats count min(_time) as firstTime max(_time) as lastTime values(request_parameters) as request_parameters by action dest user user_agent src vendor_account vendor_region vendor_product signature
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|`aws_saml_update_identity_provider_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
@@ -46,7 +46,7 @@ drilldown_searches:
latest_offset: $info_max_time$
rba:
message: User $user$ from IP address $src$ has trigged
- an event $eventName$ to update the SAML provider to $requestParameters.sAMLProviderArn$
+ an event $signature$ to update the SAML provider to $request_parameters$
risk_objects:
- field: user
type: user
diff --git a/detections/cloud/aws_updateloginprofile.yml b/detections/cloud/aws_updateloginprofile.yml
index 0534a0819d..da468246ac 100644
--- a/detections/cloud/aws_updateloginprofile.yml
+++ b/detections/cloud/aws_updateloginprofile.yml
@@ -45,7 +45,7 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
- message: From IP address $src$, user agent $userAgent$ has trigged an event UpdateLoginProfile
+ message: From IP address $src$, user agent $user_agent$ has trigged an event UpdateLoginProfile
for updating the existing login profile, potentially giving user $user$ more
access privilleges
risk_objects:
diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml
index d7408e9944..e217da8fed 100644
--- a/detections/endpoint/registry_keys_used_for_persistence.yml
+++ b/detections/endpoint/registry_keys_used_for_persistence.yml
@@ -78,7 +78,6 @@ tags:
analytic_story:
- Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns
- MoonPeak
- - Amadey
- RedLine Stealer
- Emotet Malware DHS Report TA18-201A
- Chaos Ransomware
From f04362d709acaeeda5972687b4f98a1a6c286c28 Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Mon, 17 Mar 2025 19:41:07 -0700
Subject: [PATCH 54/67] sort
---
.../registry_keys_used_for_persistence.yml | 56 +++++++++----------
1 file changed, 28 insertions(+), 28 deletions(-)
diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml
index e217da8fed..65ff7b2113 100644
--- a/detections/endpoint/registry_keys_used_for_persistence.yml
+++ b/detections/endpoint/registry_keys_used_for_persistence.yml
@@ -76,38 +76,38 @@ rba:
threat_objects: []
tags:
analytic_story:
- - Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns
- - MoonPeak
- - RedLine Stealer
- - Emotet Malware DHS Report TA18-201A
- - Chaos Ransomware
- - WinDealer RAT
- - Warzone RAT
- - China-Nexus Threat Activity
- - Earth Estries
- - SnappyBee
- - Windows Persistence Techniques
- - Snake Keylogger
- - Ransomware
- - CISA AA23-347A
- - DHS Report TA18-074A
- - Windows Registry Abuse
- - Sneaky Active Directory Persistence Tricks
- - BlackSuit Ransomware
- - Qakbot
- - DarkGate Malware
- - IcedID
- - Braodo Stealer
- - Suspicious MSHTA Activity
- - NjRAT
+ - Amadey
- AsyncRAT
- Azorult
- - Amadey
- - SystemBC
- - Suspicious Windows Registry Activities
- - Derusbi
- BlackByte Ransomware
+ - BlackSuit Ransomware
+ - Braodo Stealer
+ - Chaos Ransomware
+ - China-Nexus Threat Activity
+ - CISA AA23-347A
+ - DarkGate Malware
+ - Derusbi
+ - DHS Report TA18-074A
+ - Earth Estries
+ - Emotet Malware DHS Report TA18-201A
+ - IcedID
+ - MoonPeak
+ - NjRAT
+ - Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns
+ - Qakbot
+ - Ransomware
+ - RedLine Stealer
- Remcos
+ - Snake Keylogger
+ - SnappyBee
+ - Sneaky Active Directory Persistence Tricks
+ - Suspicious MSHTA Activity
+ - Suspicious Windows Registry Activities
+ - SystemBC
+ - Warzone RAT
+ - WinDealer RAT
+ - Windows Persistence Techniques
+ - Windows Registry Abuse
asset_type: Endpoint
mitre_attack_id:
- T1547.001
From 3122cbbc8bf880e2f7543a1362e42a0bb6df7e5b Mon Sep 17 00:00:00 2001
From: Patrick Bareiss
Date: Tue, 18 Mar 2025 12:56:30 +0100
Subject: [PATCH 55/67] output improvements
---
data_sources/asl_aws_cloudtrail.yml | 1 -
data_sources/aws_cloudtrail_assumerolewithsaml.yml | 1 -
data_sources/aws_cloudtrail_consolelogin.yml | 1 -
data_sources/aws_cloudtrail_copyobject.yml | 1 -
data_sources/aws_cloudtrail_createaccesskey.yml | 1 -
data_sources/aws_cloudtrail_createkey.yml | 1 -
data_sources/aws_cloudtrail_createloginprofile.yml | 1 -
data_sources/aws_cloudtrail_createnetworkaclentry.yml | 1 -
data_sources/aws_cloudtrail_createpolicyversion.yml | 1 -
data_sources/aws_cloudtrail_createsnapshot.yml | 1 -
data_sources/aws_cloudtrail_createtask.yml | 1 -
data_sources/aws_cloudtrail_createvirtualmfadevice.yml | 1 -
data_sources/aws_cloudtrail_deactivatemfadevice.yml | 1 -
.../aws_cloudtrail_deleteaccountpasswordpolicy.yml | 1 -
data_sources/aws_cloudtrail_deletealarms.yml | 1 -
data_sources/aws_cloudtrail_deletedetector.yml | 1 -
data_sources/aws_cloudtrail_deletegroup.yml | 1 -
data_sources/aws_cloudtrail_deleteipset.yml | 1 -
data_sources/aws_cloudtrail_deleteloggroup.yml | 1 -
data_sources/aws_cloudtrail_deletelogstream.yml | 1 -
data_sources/aws_cloudtrail_deletenetworkaclentry.yml | 1 -
data_sources/aws_cloudtrail_deletepolicy.yml | 1 -
data_sources/aws_cloudtrail_deleterule.yml | 1 -
data_sources/aws_cloudtrail_deletesnapshot.yml | 1 -
data_sources/aws_cloudtrail_deletetrail.yml | 1 -
data_sources/aws_cloudtrail_deletevirtualmfadevice.yml | 1 -
data_sources/aws_cloudtrail_deletewebacl.yml | 1 -
data_sources/aws_cloudtrail_describeeventaggregates.yml | 1 -
.../aws_cloudtrail_describeimagescanfindings.yml | 1 -
data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml | 1 -
data_sources/aws_cloudtrail_getobject.yml | 1 -
data_sources/aws_cloudtrail_getpassworddata.yml | 1 -
data_sources/aws_cloudtrail_jobcreated.yml | 1 -
data_sources/aws_cloudtrail_modifydbinstance.yml | 1 -
data_sources/aws_cloudtrail_modifyimageattribute.yml | 1 -
data_sources/aws_cloudtrail_modifysnapshotattribute.yml | 1 -
data_sources/aws_cloudtrail_putbucketacl.yml | 1 -
data_sources/aws_cloudtrail_putbucketlifecycle.yml | 1 -
data_sources/aws_cloudtrail_putbucketreplication.yml | 1 -
data_sources/aws_cloudtrail_putbucketversioning.yml | 1 -
data_sources/aws_cloudtrail_putimage.yml | 2 --
data_sources/aws_cloudtrail_putkeypolicy.yml | 1 -
data_sources/aws_cloudtrail_replacenetworkaclentry.yml | 1 -
data_sources/aws_cloudtrail_setdefaultpolicyversion.yml | 1 -
data_sources/aws_cloudtrail_stoplogging.yml | 1 -
.../aws_cloudtrail_updateaccountpasswordpolicy.yml | 1 -
data_sources/aws_cloudtrail_updateloginprofile.yml | 1 -
data_sources/aws_cloudtrail_updatesamlprovider.yml | 1 -
data_sources/aws_cloudtrail_updatetrail.yml | 1 -
.../aws_ami_attribute_modification_for_exfiltration.yml | 5 ++---
.../cloud/aws_concurrent_sessions_from_different_ips.yml | 5 ++---
.../aws_console_login_failed_during_mfa_challenge.yml | 5 ++---
.../aws_create_policy_version_to_allow_all_resources.yml | 5 ++---
detections/cloud/aws_createaccesskey.yml | 5 ++---
detections/cloud/aws_createloginprofile.yml | 9 ++++-----
detections/cloud/aws_credential_access_failed_login.yml | 5 ++---
.../cloud/aws_credential_access_getpassworddata.yml | 5 ++---
.../cloud/aws_credential_access_rds_password_reset.yml | 5 ++---
.../cloud/aws_defense_evasion_delete_cloudtrail.yml | 5 ++---
.../aws_defense_evasion_delete_cloudwatch_log_group.yml | 5 ++---
.../aws_defense_evasion_impair_security_services.yml | 5 ++---
.../cloud/aws_defense_evasion_putbucketlifecycle.yml | 5 ++---
.../aws_defense_evasion_stop_logging_cloudtrail.yml | 5 ++---
.../cloud/aws_defense_evasion_update_cloudtrail.yml | 5 ++---
...ers_creating_keys_with_encrypt_policy_without_mfa.yml | 5 ++---
...tect_users_with_kms_keys_performing_encryption_s3.yml | 5 ++---
detections/cloud/aws_disable_bucket_versioning.yml | 5 ++---
detections/cloud/aws_ec2_snapshot_shared_externally.yml | 5 ++---
.../cloud/aws_ecr_container_scanning_findings_high.yml | 5 ++---
...ainer_scanning_findings_low_informational_unknown.yml | 5 ++---
.../cloud/aws_ecr_container_scanning_findings_medium.yml | 5 ++---
.../aws_ecr_container_upload_outside_business_hours.yml | 5 ++---
.../cloud/aws_ecr_container_upload_unknown_user.yml | 5 ++---
detections/cloud/aws_excessive_security_scanning.yml | 7 +++----
...exfiltration_via_anomalous_getobject_api_activity.yml | 5 ++---
detections/cloud/aws_exfiltration_via_batch_service.yml | 5 ++---
.../cloud/aws_exfiltration_via_bucket_replication.yml | 5 ++---
detections/cloud/aws_exfiltration_via_datasync_task.yml | 5 ++---
detections/cloud/aws_exfiltration_via_ec2_snapshot.yml | 5 ++---
...ws_high_number_of_failed_authentications_for_user.yml | 5 ++---
...aws_high_number_of_failed_authentications_from_ip.yml | 5 ++---
.../cloud/aws_iam_accessdenied_discovery_events.yml | 5 ++---
.../cloud/aws_iam_assume_role_policy_brute_force.yml | 5 ++---
detections/cloud/aws_iam_delete_policy.yml | 5 ++---
detections/cloud/aws_iam_failure_group_deletion.yml | 5 ++---
detections/cloud/aws_iam_successful_group_deletion.yml | 5 ++---
detections/cloud/aws_lambda_updatefunctioncode.yml | 5 ++---
.../cloud/aws_multi_factor_authentication_disabled.yml | 5 ++---
.../cloud/aws_multiple_failed_mfa_requests_for_user.yml | 5 ++---
...ws_multiple_users_failing_to_authenticate_from_ip.yml | 5 ++---
...k_access_control_list_created_with_all_open_ports.yml | 4 ++--
.../cloud/aws_network_access_control_list_deleted.yml | 5 ++---
.../cloud/aws_new_mfa_method_registered_for_user.yml | 7 +++----
detections/cloud/aws_password_policy_changes.yml | 5 ++---
detections/cloud/aws_saml_update_identity_provider.yml | 5 ++---
detections/cloud/aws_setdefaultpolicyversion.yml | 7 +++----
...ccessful_console_authentication_from_multiple_ips.yml | 5 ++---
.../aws_successful_single_factor_authentication.yml | 5 ++---
detections/cloud/aws_updateloginprofile.yml | 5 ++---
99 files changed, 105 insertions(+), 204 deletions(-)
diff --git a/data_sources/asl_aws_cloudtrail.yml b/data_sources/asl_aws_cloudtrail.yml
index 32818e97f8..4661cd7890 100644
--- a/data_sources/asl_aws_cloudtrail.yml
+++ b/data_sources/asl_aws_cloudtrail.yml
@@ -12,7 +12,6 @@ supported_TA:
url: https://splunkbase.splunk.com/app/1876
version: 7.9.1
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_assumerolewithsaml.yml b/data_sources/aws_cloudtrail_assumerolewithsaml.yml
index 909af5d7de..034bcab85f 100644
--- a/data_sources/aws_cloudtrail_assumerolewithsaml.yml
+++ b/data_sources/aws_cloudtrail_assumerolewithsaml.yml
@@ -125,7 +125,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "SAMLUser", "pri
"eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management",
"recipientAccountId": "111111111111"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_consolelogin.yml b/data_sources/aws_cloudtrail_consolelogin.yml
index 7078b7a26c..ce74a1ecd8 100644
--- a/data_sources/aws_cloudtrail_consolelogin.yml
+++ b/data_sources/aws_cloudtrail_consolelogin.yml
@@ -101,7 +101,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "acco
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "signin.aws.amazon.com"}}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_copyobject.yml b/data_sources/aws_cloudtrail_copyobject.yml
index 8e585a5e09..407633d8d1 100644
--- a/data_sources/aws_cloudtrail_copyobject.yml
+++ b/data_sources/aws_cloudtrail_copyobject.yml
@@ -118,7 +118,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"eventType": "AwsApiCall", "managementEvent": false, "recipientAccountId": "111111111111",
"eventCategory": "Data"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_createaccesskey.yml b/data_sources/aws_cloudtrail_createaccesskey.yml
index 8295e3b181..d6706c6c77 100644
--- a/data_sources/aws_cloudtrail_createaccesskey.yml
+++ b/data_sources/aws_cloudtrail_createaccesskey.yml
@@ -102,7 +102,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
"121521347698"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_createkey.yml b/data_sources/aws_cloudtrail_createkey.yml
index ca084d10a3..aa119d01f6 100644
--- a/data_sources/aws_cloudtrail_createkey.yml
+++ b/data_sources/aws_cloudtrail_createkey.yml
@@ -149,7 +149,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management",
"recipientAccountId": "111111111111"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_createloginprofile.yml b/data_sources/aws_cloudtrail_createloginprofile.yml
index c6a66e3f32..fb211300af 100644
--- a/data_sources/aws_cloudtrail_createloginprofile.yml
+++ b/data_sources/aws_cloudtrail_createloginprofile.yml
@@ -101,7 +101,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
"111111111111"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_createnetworkaclentry.yml b/data_sources/aws_cloudtrail_createnetworkaclentry.yml
index 832dcc56b7..e0aadefe51 100644
--- a/data_sources/aws_cloudtrail_createnetworkaclentry.yml
+++ b/data_sources/aws_cloudtrail_createnetworkaclentry.yml
@@ -120,7 +120,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"6d1ce00e-4099-463c-8a4d-2af2fb2178ba", "readOnly": false, "eventType": "AwsApiCall",
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_createpolicyversion.yml b/data_sources/aws_cloudtrail_createpolicyversion.yml
index aecc7809b4..8e1f4a6263 100644
--- a/data_sources/aws_cloudtrail_createpolicyversion.yml
+++ b/data_sources/aws_cloudtrail_createpolicyversion.yml
@@ -105,7 +105,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
"111111111111"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_createsnapshot.yml b/data_sources/aws_cloudtrail_createsnapshot.yml
index b9a3c9f135..a398e50065 100644
--- a/data_sources/aws_cloudtrail_createsnapshot.yml
+++ b/data_sources/aws_cloudtrail_createsnapshot.yml
@@ -117,7 +117,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_createtask.yml b/data_sources/aws_cloudtrail_createtask.yml
index e7fee0117d..d484587ba3 100644
--- a/data_sources/aws_cloudtrail_createtask.yml
+++ b/data_sources/aws_cloudtrail_createtask.yml
@@ -120,7 +120,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "datasync.us-west-2.amazonaws.com"},
"sessionCredentialFromConsole": "true"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml
index aac3d7e54e..a7a3d43c07 100644
--- a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml
+++ b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml
@@ -99,7 +99,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"140429656527", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_deactivatemfadevice.yml b/data_sources/aws_cloudtrail_deactivatemfadevice.yml
index f75ae55128..cda2dd961e 100644
--- a/data_sources/aws_cloudtrail_deactivatemfadevice.yml
+++ b/data_sources/aws_cloudtrail_deactivatemfadevice.yml
@@ -99,7 +99,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml
index adac6bc3c5..d2c730a4fb 100644
--- a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml
+++ b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml
@@ -99,7 +99,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_deletealarms.yml b/data_sources/aws_cloudtrail_deletealarms.yml
index d3f4838723..a1802e6af6 100644
--- a/data_sources/aws_cloudtrail_deletealarms.yml
+++ b/data_sources/aws_cloudtrail_deletealarms.yml
@@ -140,7 +140,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
"Management"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_deletedetector.yml b/data_sources/aws_cloudtrail_deletedetector.yml
index e9f71c39dd..6f7ce48ede 100644
--- a/data_sources/aws_cloudtrail_deletedetector.yml
+++ b/data_sources/aws_cloudtrail_deletedetector.yml
@@ -97,7 +97,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_deletegroup.yml b/data_sources/aws_cloudtrail_deletegroup.yml
index fb6fcd293c..e7356d4fc9 100644
--- a/data_sources/aws_cloudtrail_deletegroup.yml
+++ b/data_sources/aws_cloudtrail_deletegroup.yml
@@ -101,7 +101,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
"Management", "recipientAccountId": "121522247101"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_deleteipset.yml b/data_sources/aws_cloudtrail_deleteipset.yml
index 5dfa194a17..79384c92fc 100644
--- a/data_sources/aws_cloudtrail_deleteipset.yml
+++ b/data_sources/aws_cloudtrail_deleteipset.yml
@@ -98,7 +98,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_deleteloggroup.yml b/data_sources/aws_cloudtrail_deleteloggroup.yml
index b26cfaec87..2bbb117a51 100644
--- a/data_sources/aws_cloudtrail_deleteloggroup.yml
+++ b/data_sources/aws_cloudtrail_deleteloggroup.yml
@@ -99,7 +99,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite":
"ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "logs.us-west-2.amazonaws.com"}}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_deletelogstream.yml b/data_sources/aws_cloudtrail_deletelogstream.yml
index 7fc4b58fb7..701e581646 100644
--- a/data_sources/aws_cloudtrail_deletelogstream.yml
+++ b/data_sources/aws_cloudtrail_deletelogstream.yml
@@ -100,7 +100,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "logs.us-west-2.amazonaws.com"}}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml
index d126f8eec4..0eb7e6d70f 100644
--- a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml
+++ b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml
@@ -109,7 +109,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"b9e05770-e9b0-4ba1-91e8-6537097e06e7", "readOnly": false, "eventType": "AwsApiCall",
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_deletepolicy.yml b/data_sources/aws_cloudtrail_deletepolicy.yml
index c98ed8eef4..3c95c91f01 100644
--- a/data_sources/aws_cloudtrail_deletepolicy.yml
+++ b/data_sources/aws_cloudtrail_deletepolicy.yml
@@ -101,7 +101,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"abd071bf-0a38-4fab-af4a-5eee55f0935e", "readOnly": false, "eventType": "AwsApiCall",
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "151521547504"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_deleterule.yml b/data_sources/aws_cloudtrail_deleterule.yml
index 3fd4966201..60dac0131f 100644
--- a/data_sources/aws_cloudtrail_deleterule.yml
+++ b/data_sources/aws_cloudtrail_deleterule.yml
@@ -101,7 +101,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "waf.amazonaws.com"}}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_deletesnapshot.yml b/data_sources/aws_cloudtrail_deletesnapshot.yml
index ccba4f7ad5..02730fc756 100644
--- a/data_sources/aws_cloudtrail_deletesnapshot.yml
+++ b/data_sources/aws_cloudtrail_deletesnapshot.yml
@@ -144,7 +144,6 @@ example_log: '{"eventVersion": "1.09", "userIdentity": {"type": "AssumedRole", "
"managementEvent": true, "recipientAccountId": "11111111111111", "eventCategory":
"Management", "sessionCredentialFromConsole": "true"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_deletetrail.yml b/data_sources/aws_cloudtrail_deletetrail.yml
index 50b9c6c832..0944d15ccb 100644
--- a/data_sources/aws_cloudtrail_deletetrail.yml
+++ b/data_sources/aws_cloudtrail_deletetrail.yml
@@ -97,7 +97,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml
index 35d80d2cf2..b66f8dc30d 100644
--- a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml
+++ b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml
@@ -99,7 +99,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
"managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
"Management", "sessionCredentialFromConsole": "true"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_deletewebacl.yml b/data_sources/aws_cloudtrail_deletewebacl.yml
index ab9fadfa4f..81501ea4b4 100644
--- a/data_sources/aws_cloudtrail_deletewebacl.yml
+++ b/data_sources/aws_cloudtrail_deletewebacl.yml
@@ -101,7 +101,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "waf.amazonaws.com"}}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_describeeventaggregates.yml b/data_sources/aws_cloudtrail_describeeventaggregates.yml
index bb05e04cf1..50af28b6b6 100644
--- a/data_sources/aws_cloudtrail_describeeventaggregates.yml
+++ b/data_sources/aws_cloudtrail_describeeventaggregates.yml
@@ -96,7 +96,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
"AwsApiCall", "managementEvent": true, "recipientAccountId": "1111111111111111", "eventCategory":
"Management", "sessionCredentialFromConsole": "true"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_describeimagescanfindings.yml b/data_sources/aws_cloudtrail_describeimagescanfindings.yml
index 25383e9108..6146de4e17 100644
--- a/data_sources/aws_cloudtrail_describeimagescanfindings.yml
+++ b/data_sources/aws_cloudtrail_describeimagescanfindings.yml
@@ -894,7 +894,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml
index 8433aa0149..1b8f8e9eb9 100644
--- a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml
+++ b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml
@@ -98,7 +98,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "iam.amazonaws.com"}}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_getobject.yml b/data_sources/aws_cloudtrail_getobject.yml
index b6c55f6757..7d55728c59 100644
--- a/data_sources/aws_cloudtrail_getobject.yml
+++ b/data_sources/aws_cloudtrail_getobject.yml
@@ -112,7 +112,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"eventCategory": "Data", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite":
"ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "security-content.s3.us-west-2.amazonaws.com"}}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_getpassworddata.yml b/data_sources/aws_cloudtrail_getpassworddata.yml
index f7f9adc714..a83d3264e4 100644
--- a/data_sources/aws_cloudtrail_getpassworddata.yml
+++ b/data_sources/aws_cloudtrail_getpassworddata.yml
@@ -114,7 +114,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_jobcreated.yml b/data_sources/aws_cloudtrail_jobcreated.yml
index ca1acee232..c766323cf3 100644
--- a/data_sources/aws_cloudtrail_jobcreated.yml
+++ b/data_sources/aws_cloudtrail_jobcreated.yml
@@ -83,7 +83,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"accountId": "1111111111
"status": "New", "jobEventId": "4e70d2f1053c07a79d9be9a14e486020", "failureCodes":
[], "statusChangeReason": []}, "eventCategory": "Management"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_modifydbinstance.yml b/data_sources/aws_cloudtrail_modifydbinstance.yml
index c9d2597bf2..4afe6f330f 100644
--- a/data_sources/aws_cloudtrail_modifydbinstance.yml
+++ b/data_sources/aws_cloudtrail_modifydbinstance.yml
@@ -192,7 +192,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
"Management", "sessionCredentialFromConsole": "true"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_modifyimageattribute.yml b/data_sources/aws_cloudtrail_modifyimageattribute.yml
index 4b550d9c9a..22f0c62a72 100644
--- a/data_sources/aws_cloudtrail_modifyimageattribute.yml
+++ b/data_sources/aws_cloudtrail_modifyimageattribute.yml
@@ -107,7 +107,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
"Management", "sessionCredentialFromConsole": "true"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml
index 2a1711a395..cca1162048 100644
--- a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml
+++ b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml
@@ -100,7 +100,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_putbucketacl.yml b/data_sources/aws_cloudtrail_putbucketacl.yml
index 8607f79db3..37bc258120 100644
--- a/data_sources/aws_cloudtrail_putbucketacl.yml
+++ b/data_sources/aws_cloudtrail_putbucketacl.yml
@@ -115,7 +115,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"ARN": "arn:aws:s3:::patricktestbucket19"}], "eventType": "AwsApiCall", "managementEvent":
true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_putbucketlifecycle.yml b/data_sources/aws_cloudtrail_putbucketlifecycle.yml
index 8fb1f0ea5d..55cc0a7d94 100644
--- a/data_sources/aws_cloudtrail_putbucketlifecycle.yml
+++ b/data_sources/aws_cloudtrail_putbucketlifecycle.yml
@@ -119,7 +119,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "my-cloudtrail-bucket-alfsujjpnbpguqrh.s3.us-west-2.amazonaws.com"}}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_putbucketreplication.yml b/data_sources/aws_cloudtrail_putbucketreplication.yml
index d089c50bc7..49c397946a 100644
--- a/data_sources/aws_cloudtrail_putbucketreplication.yml
+++ b/data_sources/aws_cloudtrail_putbucketreplication.yml
@@ -140,7 +140,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "s3.us-west-2.amazonaws.com"}}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_putbucketversioning.yml b/data_sources/aws_cloudtrail_putbucketversioning.yml
index f7d9ea6c70..fed5c60bdf 100644
--- a/data_sources/aws_cloudtrail_putbucketversioning.yml
+++ b/data_sources/aws_cloudtrail_putbucketversioning.yml
@@ -128,7 +128,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "s3.us-west-2.amazonaws.com"}}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_putimage.yml b/data_sources/aws_cloudtrail_putimage.yml
index 00942041d0..4979d0984b 100644
--- a/data_sources/aws_cloudtrail_putimage.yml
+++ b/data_sources/aws_cloudtrail_putimage.yml
@@ -150,8 +150,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111",
"eventCategory": "Management"}'
output_fields:
-- action
-- dest
- user
- user_agent
- src
diff --git a/data_sources/aws_cloudtrail_putkeypolicy.yml b/data_sources/aws_cloudtrail_putkeypolicy.yml
index d2e74b6a55..6bd9926e53 100644
--- a/data_sources/aws_cloudtrail_putkeypolicy.yml
+++ b/data_sources/aws_cloudtrail_putkeypolicy.yml
@@ -131,7 +131,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management",
"recipientAccountId": "111111111111"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml
index df21b230e8..4668186ec5 100644
--- a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml
+++ b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml
@@ -117,7 +117,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"46fe04b8-d007-4933-8bb8-c8b65c1121fa", "readOnly": false, "eventType": "AwsApiCall",
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml
index 0e1b6c9c57..1d14b86f17 100644
--- a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml
+++ b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml
@@ -98,7 +98,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
"111111111111"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_stoplogging.yml b/data_sources/aws_cloudtrail_stoplogging.yml
index db0ffc8259..b41b64b887 100644
--- a/data_sources/aws_cloudtrail_stoplogging.yml
+++ b/data_sources/aws_cloudtrail_stoplogging.yml
@@ -94,7 +94,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml
index 15abc1be57..6dba8a4a21 100644
--- a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml
+++ b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml
@@ -106,7 +106,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_updateloginprofile.yml b/data_sources/aws_cloudtrail_updateloginprofile.yml
index eda86cdbd3..2c6f1d8f3a 100644
--- a/data_sources/aws_cloudtrail_updateloginprofile.yml
+++ b/data_sources/aws_cloudtrail_updateloginprofile.yml
@@ -96,7 +96,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
"Management", "recipientAccountId": "111111111111"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_updatesamlprovider.yml b/data_sources/aws_cloudtrail_updatesamlprovider.yml
index d2b4294c10..d43549d693 100644
--- a/data_sources/aws_cloudtrail_updatesamlprovider.yml
+++ b/data_sources/aws_cloudtrail_updatesamlprovider.yml
@@ -186,7 +186,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
"Management", "recipientAccountId": "111111111111"}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/data_sources/aws_cloudtrail_updatetrail.yml b/data_sources/aws_cloudtrail_updatetrail.yml
index 564b226acd..0aa753b227 100644
--- a/data_sources/aws_cloudtrail_updatetrail.yml
+++ b/data_sources/aws_cloudtrail_updatetrail.yml
@@ -106,7 +106,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}'
output_fields:
-- action
- dest
- user
- user_agent
diff --git a/detections/cloud/aws_ami_attribute_modification_for_exfiltration.yml b/detections/cloud/aws_ami_attribute_modification_for_exfiltration.yml
index 1f1fd7d422..040277bda5 100644
--- a/detections/cloud/aws_ami_attribute_modification_for_exfiltration.yml
+++ b/detections/cloud/aws_ami_attribute_modification_for_exfiltration.yml
@@ -19,9 +19,8 @@ search: '`cloudtrail` eventName=ModifyImageAttribute (requestParameters.launchPe
| rename requestParameters.launchPermission.add.items{}.group as group_added
| rename requestParameters.launchPermission.add.items{}.userId as accounts_added
| eval ami_status=if(match(group_added,"all") ,"Public AMI", "Not Public")
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime values(group_added) as group_added values(accounts_added) as accounts_added values(ami_status) as ami_status by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime values(group_added) as group_added values(accounts_added) as accounts_added values(ami_status) as ami_status by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `aws_ami_attribute_modification_for_exfiltration_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
diff --git a/detections/cloud/aws_concurrent_sessions_from_different_ips.yml b/detections/cloud/aws_concurrent_sessions_from_different_ips.yml
index 9787083dff..694f2a2989 100644
--- a/detections/cloud/aws_concurrent_sessions_from_different_ips.yml
+++ b/detections/cloud/aws_concurrent_sessions_from_different_ips.yml
@@ -17,9 +17,8 @@ data_source:
- AWS CloudTrail DescribeEventAggregates
search: '`cloudtrail` eventName = DescribeEventAggregates src_ip!="AWS Internal"
| bin span=5m _time
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats min(_time) as firstTime max(_time) as lastTime values(user_agent) as user_agent values(action) as action values(src) as src values(dest) as dest dc(src) as distinct_ip_count by _time user vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats min(_time) as firstTime max(_time) as lastTime values(user_agent) as user_agent values(signature) as signature values(src) as src values(dest) as dest dc(src) as distinct_ip_count by _time user vendor_account vendor_region vendor_product
| where distinct_ip_count > 1
| `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)`
| `aws_concurrent_sessions_from_different_ips_filter`'
diff --git a/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml b/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml
index 6796bcc648..0f5a179514 100644
--- a/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml
+++ b/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml
@@ -16,9 +16,8 @@ description: The following analytic identifies failed authentication attempts to
data_source:
- AWS CloudTrail ConsoleLogin
search: '`cloudtrail` eventName= ConsoleLogin errorMessage="Failed authentication" additionalEventData.MFAUsed = "Yes"
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product additionalEventData.MFAUsed errorMessage
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product additionalEventData.MFAUsed errorMessage
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `aws_console_login_failed_during_mfa_challenge_filter`'
diff --git a/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml b/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml
index 9742f0ee35..68f5e47739 100644
--- a/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml
+++ b/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml
@@ -19,9 +19,8 @@ search: '`cloudtrail` eventName=CreatePolicyVersion eventSource = iam.amazonaws.
| mvexpand key_policy_statements
| spath input=key_policy_statements output=key_policy_action_1 path=Action
| where key_policy_action_1 = "*"
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime values(key_policy_statements) as policy_added by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime values(key_policy_statements) as policy_added by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`aws_create_policy_version_to_allow_all_resources_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
diff --git a/detections/cloud/aws_createaccesskey.yml b/detections/cloud/aws_createaccesskey.yml
index d8fb41afe5..f549bef8e2 100644
--- a/detections/cloud/aws_createaccesskey.yml
+++ b/detections/cloud/aws_createaccesskey.yml
@@ -17,9 +17,8 @@ data_source:
search: '`cloudtrail` eventName = CreateAccessKey userAgent !=console.amazonaws.com errorCode = success
| eval match=if(match(userIdentity.userName,requestParameters.userName),1,0)
| search match=0
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`aws_createaccesskey_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
diff --git a/detections/cloud/aws_createloginprofile.yml b/detections/cloud/aws_createloginprofile.yml
index 2acc9beb62..48c0aaa588 100644
--- a/detections/cloud/aws_createloginprofile.yml
+++ b/detections/cloud/aws_createloginprofile.yml
@@ -20,10 +20,9 @@ search: '`cloudtrail` eventName = CreateLoginProfile
| join new_login_profile src_ip
[| search `cloudtrail` eventName = ConsoleLogin
| rename userIdentity.userName as new_login_profile
- | stats count values(eventName) min(_time) as firstTime max(_time) as lastTime by eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn new_login_profile src_ip
+ | stats count values(eventName) min(_time) as firstTime max(_time) as lastTime by eventSource aws_account_id errorCode user_agent eventID awsRegion userIdentity.principalId user_arn new_login_profile src_ip dest vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`]
- | rename eventName as action, eventSource as dest, user_arn as user, userAgent as user_agent, src_ip as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
+ | rename user_arn as user
| `aws_createloginprofile_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
@@ -48,13 +47,13 @@ drilldown_searches:
latest_offset: $info_max_time$
rba:
message: User $user$ is attempting to create a login profile for $new_login_profile$
- and did a console login from this IP $src$
+ and did a console login from this IP $src_ip$
risk_objects:
- field: user
type: user
score: 72
threat_objects:
- - field: src
+ - field: src_ip
type: ip_address
tags:
analytic_story:
diff --git a/detections/cloud/aws_credential_access_failed_login.yml b/detections/cloud/aws_credential_access_failed_login.yml
index ccf26bb80e..8ca873ae73 100644
--- a/detections/cloud/aws_credential_access_failed_login.yml
+++ b/detections/cloud/aws_credential_access_failed_login.yml
@@ -16,9 +16,8 @@ description: The following analytic identifies unsuccessful login attempts to th
data_source:
- AWS CloudTrail ConsoleLogin
search: '`cloudtrail` eventName = ConsoleLogin errorMessage="Failed authentication"
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_credential_access_failed_login_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
diff --git a/detections/cloud/aws_credential_access_getpassworddata.yml b/detections/cloud/aws_credential_access_getpassworddata.yml
index f10dcbf896..280f2fd046 100644
--- a/detections/cloud/aws_credential_access_getpassworddata.yml
+++ b/detections/cloud/aws_credential_access_getpassworddata.yml
@@ -17,9 +17,8 @@ data_source:
- AWS CloudTrail GetPasswordData
search: '`cloudtrail` eventName=GetPasswordData eventSource = ec2.amazonaws.com
| bin _time span=5m
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime dc(requestParameters.instanceId) as distinct_instance_ids by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime dc(requestParameters.instanceId) as distinct_instance_ids by signature dest user user_agent src vendor_account vendor_region vendor_product
| where distinct_instance_ids > 10
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `aws_credential_access_getpassworddata_filter`'
diff --git a/detections/cloud/aws_credential_access_rds_password_reset.yml b/detections/cloud/aws_credential_access_rds_password_reset.yml
index 1a6310fc2f..ce23361a3d 100644
--- a/detections/cloud/aws_credential_access_rds_password_reset.yml
+++ b/detections/cloud/aws_credential_access_rds_password_reset.yml
@@ -16,9 +16,8 @@ description: The following analytic detects the resetting of the master user pas
data_source:
- AWS CloudTrail ModifyDBInstance
search: '`cloudtrail` eventSource="rds.amazonaws.com" eventName=ModifyDBInstance "requestParameters.masterUserPassword"=*
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.dBInstanceIdentifier) as database_id by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.dBInstanceIdentifier) as database_id by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `aws_credential_access_rds_password_reset_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
diff --git a/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml b/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml
index c2c6adda25..a5d6a1069a 100644
--- a/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml
+++ b/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml
@@ -16,9 +16,8 @@ description: The following analytic detects the deletion of AWS CloudTrail logs
data_source:
- AWS CloudTrail DeleteTrail
search: '`cloudtrail` eventName = DeleteTrail eventSource = cloudtrail.amazonaws.com userAgent !=console.amazonaws.com errorCode = success
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `aws_defense_evasion_delete_cloudtrail_filter`'
how_to_implement: You must install Splunk AWS Add on and enable CloudTrail logs in
your AWS Environment.
diff --git a/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml b/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml
index 3308368693..289229b26d 100644
--- a/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml
+++ b/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml
@@ -16,9 +16,8 @@ description: The following analytic detects the deletion of CloudWatch log group
data_source:
- AWS CloudTrail DeleteLogGroup
search: '`cloudtrail` eventName = DeleteLogGroup eventSource = logs.amazonaws.com userAgent !=console.amazonaws.com errorCode = success
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `aws_defense_evasion_delete_cloudwatch_log_group_filter`'
how_to_implement: You must install Splunk AWS Add on and enable CloudTrail logs in
your AWS Environment.
diff --git a/detections/cloud/aws_defense_evasion_impair_security_services.yml b/detections/cloud/aws_defense_evasion_impair_security_services.yml
index 7dbfa9ad82..ba0d646ecb 100644
--- a/detections/cloud/aws_defense_evasion_impair_security_services.yml
+++ b/detections/cloud/aws_defense_evasion_impair_security_services.yml
@@ -23,9 +23,8 @@ data_source:
- AWS CloudTrail DeleteLoggingConfiguration
- AWS CloudTrail DeleteAlarms
search: '`cloudtrail` eventName IN ("DeleteLogStream","DeleteDetector","DeleteIPSet","DeleteWebACL","DeleteRule","DeleteRuleGroup","DeleteLoggingConfiguration","DeleteAlarms")
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `aws_defense_evasion_impair_security_services_filter`'
how_to_implement: You must install Splunk AWS Add on and enable CloudTrail logs in
your AWS Environment.
diff --git a/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml b/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml
index 243134cb17..89a5e96ddd 100644
--- a/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml
+++ b/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml
@@ -17,9 +17,8 @@ data_source:
search: '`cloudtrail` eventName=PutBucketLifecycle user_type=IAMUser errorCode=success
| spath path=requestParameters{}.LifecycleConfiguration{}.Rule{}.Expiration{}.Days output=expiration_days
| spath path=requestParameters{}.bucketName output=bucket_name
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product bucket_name expiration_days
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product bucket_name expiration_days
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_defense_evasion_putbucketlifecycle_filter`'
how_to_implement: You must install Splunk AWS Add on and enable CloudTrail logs in
your AWS Environment. We recommend our users to set the expiration days value according
diff --git a/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml b/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml
index 1373c8781b..cdc2bf356b 100644
--- a/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml
+++ b/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml
@@ -16,9 +16,8 @@ description: The following analytic detects `StopLogging` events in AWS CloudTra
data_source:
- AWS CloudTrail StopLogging
search: '`cloudtrail` eventName = StopLogging eventSource = cloudtrail.amazonaws.com userAgent!=console.amazonaws.com errorCode = success
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_defense_evasion_stop_logging_cloudtrail_filter`'
how_to_implement: You must install Splunk AWS Add on and enable Cloudtrail logs in
your AWS Environment.
diff --git a/detections/cloud/aws_defense_evasion_update_cloudtrail.yml b/detections/cloud/aws_defense_evasion_update_cloudtrail.yml
index 71a3be13fb..8959939a27 100644
--- a/detections/cloud/aws_defense_evasion_update_cloudtrail.yml
+++ b/detections/cloud/aws_defense_evasion_update_cloudtrail.yml
@@ -16,9 +16,8 @@ description: The following analytic detects `UpdateTrail` events in AWS CloudTra
data_source:
- AWS CloudTrail UpdateTrail
search: '`cloudtrail` eventName = UpdateTrail eventSource = cloudtrail.amazonaws.com userAgent !=console.amazonaws.com errorCode = success
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `aws_defense_evasion_update_cloudtrail_filter`'
how_to_implement: You must install Splunk AWS Add on and enable CloudTrail logs in
your AWS Environment.
diff --git a/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml b/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml
index 52c5bb40a6..64417b6060 100644
--- a/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml
+++ b/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml
@@ -24,9 +24,8 @@ search: '`cloudtrail` eventName=CreateKey OR eventName=PutKeyPolicy
| eval key_policy_action=mvappend(key_policy_action_1,key_policy_action_2)
| spath input=key_policy_statements output=key_policy_principal path=Principal.AWS
| search key_policy_action="kms:Encrypt" AND key_policy_principal="*"
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product key_policy_action key_policy_principal
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product key_policy_action key_policy_principal
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` |`aws_detect_users_creating_keys_with_encrypt_policy_without_mfa_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs
diff --git a/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml b/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml
index 9296c2c437..519597fbdc 100644
--- a/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml
+++ b/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml
@@ -16,9 +16,8 @@ data_source:
- AWS CloudTrail
search: '`cloudtrail` eventName=CopyObject requestParameters.x-amz-server-side-encryption="aws:kms"
| rename requestParameters.bucketName AS bucketName, requestParameters.x-amz-copy-source AS src_file, requestParameters.key AS dest_file
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product bucketName src_file dest_file
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product bucketName src_file dest_file
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `aws_detect_users_with_kms_keys_performing_encryption_s3_filter`'
how_to_implement: You must install Splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs
diff --git a/detections/cloud/aws_disable_bucket_versioning.yml b/detections/cloud/aws_disable_bucket_versioning.yml
index 633072c453..9cf1b782c4 100644
--- a/detections/cloud/aws_disable_bucket_versioning.yml
+++ b/detections/cloud/aws_disable_bucket_versioning.yml
@@ -15,9 +15,8 @@ description: The following analytic detects when AWS S3 bucket versioning is sus
lead to data loss and hinder recovery efforts, severely impacting data integrity
and availability.
search: '`cloudtrail` eventName= PutBucketVersioning "requestParameters.VersioningConfiguration.Status"=Suspended
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region, requestParameters.bucketName as bucket_name
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product bucket_name
+ | rename user_name as user, requestParameters.bucketName as bucket_name
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product bucket_name
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_disable_bucket_versioning_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
diff --git a/detections/cloud/aws_ec2_snapshot_shared_externally.yml b/detections/cloud/aws_ec2_snapshot_shared_externally.yml
index 16499e4a92..359d152a38 100644
--- a/detections/cloud/aws_ec2_snapshot_shared_externally.yml
+++ b/detections/cloud/aws_ec2_snapshot_shared_externally.yml
@@ -20,9 +20,8 @@ search: '`cloudtrail` eventName=ModifySnapshotAttribute
| search requested_account_id != NULL
| eval match=if(requested_account_id==aws_account_id,"Match","No Match")
| where match = "No Match"
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product requested_account_id
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product requested_account_id
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `aws_ec2_snapshot_shared_externally_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
diff --git a/detections/cloud/aws_ecr_container_scanning_findings_high.yml b/detections/cloud/aws_ecr_container_scanning_findings_high.yml
index 3714ddbd98..fd84cd5a47 100644
--- a/detections/cloud/aws_ecr_container_scanning_findings_high.yml
+++ b/detections/cloud/aws_ecr_container_scanning_findings_high.yml
@@ -22,9 +22,8 @@ search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanF
| spath input=findings
| search severity=HIGH
| rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest as imageDigest, requestParameters.repositoryName as repository
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product finding_name finding_description imageDigest repository
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product finding_name finding_description imageDigest repository
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_scanning_findings_high_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
diff --git a/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml b/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml
index 106f0ae2ed..c2a4626cf0 100644
--- a/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml
+++ b/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml
@@ -21,9 +21,8 @@ search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanF
| spath input=findings
| search severity IN ("LOW", "INFORMATIONAL", "UNKNOWN")
| rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest as imageDigest, requestParameters.repositoryName as repository
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product finding_name finding_description imageDigest repository
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product finding_name finding_description imageDigest repository
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `aws_ecr_container_scanning_findings_low_informational_unknown_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
diff --git a/detections/cloud/aws_ecr_container_scanning_findings_medium.yml b/detections/cloud/aws_ecr_container_scanning_findings_medium.yml
index 4f7b7f2c14..4bc30f42d7 100644
--- a/detections/cloud/aws_ecr_container_scanning_findings_medium.yml
+++ b/detections/cloud/aws_ecr_container_scanning_findings_medium.yml
@@ -21,9 +21,8 @@ search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanF
| spath input=findings
| search severity=MEDIUM
| rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest as imageDigest, requestParameters.repositoryName as repository
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product finding_name finding_description imageDigest repository
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product finding_name finding_description imageDigest repository
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_scanning_findings_medium_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
diff --git a/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml b/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml
index ec7d22be55..06ffc02b79 100644
--- a/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml
+++ b/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml
@@ -19,9 +19,8 @@ search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=PutImage date_hour
OR date_hour<8 OR date_wday=saturday OR date_wday=sunday
| rename requestParameters.* as *
| rename repositoryName AS repository
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product repository
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature user user_agent src vendor_account vendor_region vendor_product repository
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_upload_outside_business_hours_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
diff --git a/detections/cloud/aws_ecr_container_upload_unknown_user.yml b/detections/cloud/aws_ecr_container_upload_unknown_user.yml
index ecf00814e5..6efff0d27f 100644
--- a/detections/cloud/aws_ecr_container_upload_unknown_user.yml
+++ b/detections/cloud/aws_ecr_container_upload_unknown_user.yml
@@ -17,9 +17,8 @@ data_source:
search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=PutImage NOT `aws_ecr_users`
| rename requestParameters.* as *
| rename repositoryName AS image
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product image
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature user user_agent src vendor_account vendor_region vendor_product image
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `aws_ecr_container_upload_unknown_user_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
diff --git a/detections/cloud/aws_excessive_security_scanning.yml b/detections/cloud/aws_excessive_security_scanning.yml
index 5451636bfb..437210a221 100644
--- a/detections/cloud/aws_excessive_security_scanning.yml
+++ b/detections/cloud/aws_excessive_security_scanning.yml
@@ -16,9 +16,8 @@ data_source:
- AWS CloudTrail
search: '`cloudtrail` eventName=Describe* OR eventName=List* OR eventName=Get*
| fillnull
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats dc(action) as dc_events min(_time) as firstTime max(_time) as lastTime values(action) as action values(dest) as dest values(user_agent) as user_agent values(src) as src values(vendor_account) as vendor_account values(vendor_region) as vendor_region by user
+ | rename user_name as user
+ | stats dc(signature) as dc_events min(_time) as firstTime max(_time) as lastTime values(signature) as signature values(dest) as dest values(user_agent) as user_agent values(src) as src values(vendor_account) as vendor_account values(vendor_region) as vendor_region by user
| where dc_events > 50
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|`aws_excessive_security_scanning_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
@@ -42,7 +41,7 @@ drilldown_searches:
latest_offset: $info_max_time$
rba:
message: User $user$ has excessive number of api calls $dc_events$ from these IP
- addresses $src$, violating the threshold of 50, using the following actions $action$.
+ addresses $src$, violating the threshold of 50, using the following actions $signature$.
risk_objects:
- field: user
type: user
diff --git a/detections/cloud/aws_exfiltration_via_anomalous_getobject_api_activity.yml b/detections/cloud/aws_exfiltration_via_anomalous_getobject_api_activity.yml
index ac279b1848..7a7a3777b1 100644
--- a/detections/cloud/aws_exfiltration_via_anomalous_getobject_api_activity.yml
+++ b/detections/cloud/aws_exfiltration_via_anomalous_getobject_api_activity.yml
@@ -16,9 +16,8 @@ description: The following analytic identifies anomalous GetObject API activity
exfiltrate sensitive data, leading to data breaches and compliance violations.
search: '`cloudtrail` eventName=GetObject
| bin _time span=10m
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count values(requestParameters.bucketName) as bucketName by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count values(requestParameters.bucketName) as bucketName by signature dest user user_agent src vendor_account vendor_region vendor_product
| anomalydetection "count" "user" action=annotate
| search probable_cause=*
|`aws_exfiltration_via_anomalous_getobject_api_activity_filter`'
diff --git a/detections/cloud/aws_exfiltration_via_batch_service.yml b/detections/cloud/aws_exfiltration_via_batch_service.yml
index 4b76762dcb..b8d5a7fbd1 100644
--- a/detections/cloud/aws_exfiltration_via_batch_service.yml
+++ b/detections/cloud/aws_exfiltration_via_batch_service.yml
@@ -16,9 +16,8 @@ description: The following analytic identifies the creation of AWS Batch jobs th
and loss of sensitive information.
search: '`cloudtrail` eventName = JobCreated
| fillnull
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_exfiltration_via_batch_service_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
diff --git a/detections/cloud/aws_exfiltration_via_bucket_replication.yml b/detections/cloud/aws_exfiltration_via_bucket_replication.yml
index 93c4a38b18..4b51afcc02 100644
--- a/detections/cloud/aws_exfiltration_via_bucket_replication.yml
+++ b/detections/cloud/aws_exfiltration_via_bucket_replication.yml
@@ -15,9 +15,8 @@ description: The following analytic detects API calls to enable S3 bucket replic
could replicate sensitive data to external accounts, leading to data breaches and
compliance violations.
search: '`cloudtrail` eventName = PutBucketReplication eventSource = s3.amazonaws.com
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region, requestParameters.bucketName as bucket_name
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product bucket_name
+ | rename user_name as user, requestParameters.ReplicationConfiguration.Rule.Destination.Bucket as bucket_name
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product bucket_name
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_exfiltration_via_bucket_replication_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
diff --git a/detections/cloud/aws_exfiltration_via_datasync_task.yml b/detections/cloud/aws_exfiltration_via_datasync_task.yml
index b0e454b109..7d959dccfb 100644
--- a/detections/cloud/aws_exfiltration_via_datasync_task.yml
+++ b/detections/cloud/aws_exfiltration_via_datasync_task.yml
@@ -16,9 +16,8 @@ description: The following analytic detects the creation of an AWS DataSync task
data breaches and compliance violations.
search: '`cloudtrail` eventName = CreateTask eventSource="datasync.amazonaws.com"
| rename requestParameters.* as *
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product destinationLocationArn sourceLocationArn
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product destinationLocationArn sourceLocationArn
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_exfiltration_via_datasync_task_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
diff --git a/detections/cloud/aws_exfiltration_via_ec2_snapshot.yml b/detections/cloud/aws_exfiltration_via_ec2_snapshot.yml
index 29dcbe0b67..5b182eaf4b 100644
--- a/detections/cloud/aws_exfiltration_via_ec2_snapshot.yml
+++ b/detections/cloud/aws_exfiltration_via_ec2_snapshot.yml
@@ -20,9 +20,8 @@ description: The following analytic detects a series of AWS API calls related to
violations.
search: '`cloudtrail` eventName IN ("CreateSnapshot", "DescribeSnapshotAttribute", "ModifySnapshotAttribute", "DeleteSnapshot") src_ip !="guardduty.amazonaws.com"
| bin _time span=5m
- | eval vendor_product = "AWS"
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | stats count dc(action) as distinct_api_calls values(action) as action values(dest) as dest values(requestParameters.attributeType) as attributeType values(requestParameters.createVolumePermission.add.items{}.userId) as aws_account_id_added values(user_agent) as user_agent by _time user src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count dc(signature) as distinct_api_calls values(signature) as signature values(dest) as dest values(requestParameters.attributeType) as attributeType values(requestParameters.createVolumePermission.add.items{}.userId) as aws_account_id_added values(user_agent) as user_agent by _time user src vendor_account vendor_region vendor_product
| where distinct_api_calls >= 2
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `aws_exfiltration_via_ec2_snapshot_filter`'
diff --git a/detections/cloud/aws_high_number_of_failed_authentications_for_user.yml b/detections/cloud/aws_high_number_of_failed_authentications_for_user.yml
index d9afb8b908..a522509486 100644
--- a/detections/cloud/aws_high_number_of_failed_authentications_for_user.yml
+++ b/detections/cloud/aws_high_number_of_failed_authentications_for_user.yml
@@ -16,9 +16,8 @@ data_source:
- AWS CloudTrail ConsoleLogin
search: '`cloudtrail` eventName=ConsoleLogin action=failure
| bucket span=10m _time
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats dc(_raw) AS failed_attempts values(src) as src values(user_agent) as user_agent by _time, user, action, dest, vendor_account vendor_region, vendor_product
+ | rename user_name as user
+ | stats dc(_raw) AS failed_attempts values(src) as src values(user_agent) as user_agent by _time, user, signature, dest, vendor_account vendor_region, vendor_product
| where failed_attempts > 20
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `aws_high_number_of_failed_authentications_for_user_filter`'
diff --git a/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml b/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml
index 80213c5005..ead873137d 100644
--- a/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml
+++ b/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml
@@ -16,9 +16,8 @@ data_source:
- AWS CloudTrail ConsoleLogin
search: '`cloudtrail` eventName=ConsoleLogin action=failure
| bucket span=10m _time
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats dc(_raw) AS failed_attempts values(user) as user values(user_agent) as user_agent by _time, src, action, dest, vendor_account vendor_region, vendor_product
+ | rename user_name as user
+ | stats dc(_raw) AS failed_attempts values(user) as user values(user_agent) as user_agent by _time, src, signature, dest, vendor_account vendor_region, vendor_product
| where failed_attempts > 20
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `aws_high_number_of_failed_authentications_from_ip_filter`'
diff --git a/detections/cloud/aws_iam_accessdenied_discovery_events.yml b/detections/cloud/aws_iam_accessdenied_discovery_events.yml
index f3f2d7600f..32ebb2a3f9 100644
--- a/detections/cloud/aws_iam_accessdenied_discovery_events.yml
+++ b/detections/cloud/aws_iam_accessdenied_discovery_events.yml
@@ -16,9 +16,8 @@ data_source:
- AWS CloudTrail
search: '`cloudtrail` (errorCode = "AccessDenied") user_type=IAMUser (userAgent!=*.amazonaws.com)
| bucket _time span=1h
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count as failures min(_time) as firstTime max(_time) as lastTime, dc(action) as methods, dc(dest) as sources values(action) as action values(dest) as dest by src, user, vendor_account vendor_region, vendor_product
+ | rename user_name as user
+ | stats count as failures min(_time) as firstTime max(_time) as lastTime, dc(signature) as methods, dc(dest) as sources values(signature) as signature values(dest) as dest by src, user, vendor_account vendor_region, vendor_product
| where failures >= 5 and methods >= 1 and sources >= 1
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `aws_iam_accessdenied_discovery_events_filter`'
diff --git a/detections/cloud/aws_iam_assume_role_policy_brute_force.yml b/detections/cloud/aws_iam_assume_role_policy_brute_force.yml
index 5950c7d510..59362ff946 100644
--- a/detections/cloud/aws_iam_assume_role_policy_brute_force.yml
+++ b/detections/cloud/aws_iam_assume_role_policy_brute_force.yml
@@ -16,9 +16,8 @@ description: The following analytic detects multiple failed attempts to assume a
data_source:
- AWS CloudTrail
search: '`cloudtrail` (errorCode=MalformedPolicyDocumentException) status=failure (userAgent!=*.amazonaws.com)
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.policyName) as policy_name by src, user, vendor_account vendor_region, vendor_product, action, dest, errorCode
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.policyName) as policy_name by src, user, vendor_account vendor_region, vendor_product, signature, dest, errorCode
| where count >= 2
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_iam_assume_role_policy_brute_force_filter`'
how_to_implement: The Splunk AWS Add-on and Splunk App for AWS is required to utilize
diff --git a/detections/cloud/aws_iam_delete_policy.yml b/detections/cloud/aws_iam_delete_policy.yml
index 9a1ff45d95..1144a49768 100644
--- a/detections/cloud/aws_iam_delete_policy.yml
+++ b/detections/cloud/aws_iam_delete_policy.yml
@@ -16,9 +16,8 @@ description: The following analytic detects the deletion of an IAM policy in AWS
data_source:
- AWS CloudTrail DeletePolicy
search: '`cloudtrail` eventName=DeletePolicy (userAgent!=*.amazonaws.com)
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_iam_delete_policy_filter`'
how_to_implement: The Splunk AWS Add-on and Splunk App for AWS is required to utilize
this data. The search requires AWS CloudTrail logs.
diff --git a/detections/cloud/aws_iam_failure_group_deletion.yml b/detections/cloud/aws_iam_failure_group_deletion.yml
index c2d7f3f6be..72960b4c4d 100644
--- a/detections/cloud/aws_iam_failure_group_deletion.yml
+++ b/detections/cloud/aws_iam_failure_group_deletion.yml
@@ -16,9 +16,8 @@ description: The following analytic identifies failed attempts to delete AWS IAM
data_source:
- AWS CloudTrail DeleteGroup
search: '`cloudtrail` eventSource=iam.amazonaws.com eventName=DeleteGroup errorCode IN (NoSuchEntityException,DeleteConflictException, AccessDenied) (userAgent!=*.amazonaws.com)
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_iam_failure_group_deletion_filter`'
how_to_implement: The Splunk AWS Add-on and Splunk App for AWS is required to utilize
this data. The search requires AWS CloudTrail logs.
diff --git a/detections/cloud/aws_iam_successful_group_deletion.yml b/detections/cloud/aws_iam_successful_group_deletion.yml
index 95b05b3e42..665e28a8f0 100644
--- a/detections/cloud/aws_iam_successful_group_deletion.yml
+++ b/detections/cloud/aws_iam_successful_group_deletion.yml
@@ -16,9 +16,8 @@ description: The following analytic identifies the successful deletion of an IAM
data_source:
- AWS CloudTrail DeleteGroup
search: '`cloudtrail` eventSource=iam.amazonaws.com eventName=DeleteGroup errorCode=success (userAgent!=*.amazonaws.com)
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_iam_successful_group_deletion_filter`'
how_to_implement: The Splunk AWS Add-on and Splunk App for AWS is required to utilize
this data. The search requires AWS CloudTrail logs.
diff --git a/detections/cloud/aws_lambda_updatefunctioncode.yml b/detections/cloud/aws_lambda_updatefunctioncode.yml
index cead07f377..41391682b0 100644
--- a/detections/cloud/aws_lambda_updatefunctioncode.yml
+++ b/detections/cloud/aws_lambda_updatefunctioncode.yml
@@ -15,9 +15,8 @@ description: The following analytic identifies IAM users attempting to update or
data_source:
- AWS CloudTrail
search: '`cloudtrail` eventSource=lambda.amazonaws.com eventName=UpdateFunctionCode* errorCode = success user_type=IAMUser
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`aws_lambda_updatefunctioncode_filter`'
how_to_implement: You must install Splunk AWS Add on and enable Cloudtrail logs in
your AWS Environment.
diff --git a/detections/cloud/aws_multi_factor_authentication_disabled.yml b/detections/cloud/aws_multi_factor_authentication_disabled.yml
index 89e34fd41d..20be3ffafa 100644
--- a/detections/cloud/aws_multi_factor_authentication_disabled.yml
+++ b/detections/cloud/aws_multi_factor_authentication_disabled.yml
@@ -16,9 +16,8 @@ data_source:
- AWS CloudTrail DeleteVirtualMFADevice
- AWS CloudTrail DeactivateMFADevice
search: '`cloudtrail` (eventName= DeleteVirtualMFADevice OR eventName=DeactivateMFADevice)
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_multi_factor_authentication_disabled_filter`'
how_to_implement: The Splunk AWS Add-on is required to utilize this data. The search
requires AWS CloudTrail logs.
diff --git a/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml b/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml
index 5364cabcce..258579585e 100644
--- a/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml
+++ b/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml
@@ -16,9 +16,8 @@ data_source:
- AWS CloudTrail ConsoleLogin
search: '`cloudtrail` eventName= ConsoleLogin "additionalEventData.MFAUsed"=Yes errorMessage="Failed authentication"
| bucket span=5m _time
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats dc(_raw) as mfa_prompts min(_time) as firstTime max(_time) as lastTime values(user_agent) as user_agent values(src) as src by _time user dest action vendor_account vendor_region vendor_product errorMessage
+ | rename user_name as user
+ | stats dc(_raw) as mfa_prompts min(_time) as firstTime max(_time) as lastTime values(user_agent) as user_agent values(src) as src values(dest) as dest by _time user signature vendor_account vendor_region vendor_product errorMessage
| where mfa_prompts > 10
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_multiple_failed_mfa_requests_for_user_filter`'
how_to_implement: The Splunk AWS Add-on is required to utilize this data. The search
diff --git a/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml b/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml
index 8430271670..4ab70632ac 100644
--- a/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml
+++ b/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml
@@ -17,9 +17,8 @@ data_source:
- AWS CloudTrail ConsoleLogin
search: '`cloudtrail` eventName=ConsoleLogin action=failure
| bucket span=10m _time
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats dc(user) AS unique_accounts values(user) as user values(user_agent) as user_agent by _time, src, action, dest, vendor_account, vendor_region, vendor_product
+ | rename user_name as user
+ | stats dc(user) AS unique_accounts values(user) as user values(user_agent) as user_agent by _time, src, signature, dest, vendor_account, vendor_region, vendor_product
| where unique_accounts>30
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_multiple_users_failing_to_authenticate_from_ip_filter`'
how_to_implement: You must install Splunk Add-on for AWS in order to ingest Cloudtrail.
diff --git a/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml b/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml
index 53a0b53635..65b3e082ec 100644
--- a/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml
+++ b/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml
@@ -22,8 +22,8 @@ search: "`cloudtrail` eventName=CreateNetworkAclEntry OR eventName=ReplaceNetwor
| eval port_range='requestParameters.portRange.to' - 'requestParameters.portRange.from'
| where port_range>1024]
| fillnull
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product requestParameters.ruleAction requestParameters.egress requestParameters.aclProtocol requestParameters.portRange.to requestParameters.portRange.from requestParameters.cidrBlock
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product requestParameters.ruleAction requestParameters.egress requestParameters.aclProtocol requestParameters.portRange.to requestParameters.portRange.from requestParameters.cidrBlock
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `aws_network_access_control_list_created_with_all_open_ports_filter`"
how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later)
and Splunk Add-on for AWS, version 4.4.0 or later, and configure your AWS CloudTrail
diff --git a/detections/cloud/aws_network_access_control_list_deleted.yml b/detections/cloud/aws_network_access_control_list_deleted.yml
index 8d91777aae..0fa6db478b 100644
--- a/detections/cloud/aws_network_access_control_list_deleted.yml
+++ b/detections/cloud/aws_network_access_control_list_deleted.yml
@@ -16,9 +16,8 @@ data_source:
- AWS CloudTrail DeleteNetworkAclEntry
search: '`cloudtrail` eventName=DeleteNetworkAclEntry requestParameters.egress=false
| fillnull
- | rename eventName as signature, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product signature
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_network_access_control_list_deleted_filter`'
how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later)
and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail
diff --git a/detections/cloud/aws_new_mfa_method_registered_for_user.yml b/detections/cloud/aws_new_mfa_method_registered_for_user.yml
index 9023487963..b7c524e1b0 100644
--- a/detections/cloud/aws_new_mfa_method_registered_for_user.yml
+++ b/detections/cloud/aws_new_mfa_method_registered_for_user.yml
@@ -15,9 +15,8 @@ description: The following analytic detects the registration of a new Multi-Fact
data_source:
- AWS CloudTrail CreateVirtualMFADevice
search: '`cloudtrail` eventName=CreateVirtualMFADevice
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region, requestParameters.virtualMFADeviceName as virtualMFADeviceName
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product virtualMFADeviceName
+ | rename userName as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `aws_new_mfa_method_registered_for_user_filter`'
how_to_implement: You must install Splunk AWS add on and Splunk App for AWS. This
@@ -44,7 +43,7 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
- message: A new virtual device $virtualMFADeviceName$ is added to user $user$
+ message: A new virtual device is added to user $user$
risk_objects:
- field: user
type: user
diff --git a/detections/cloud/aws_password_policy_changes.yml b/detections/cloud/aws_password_policy_changes.yml
index 441a3eeec2..4795411501 100644
--- a/detections/cloud/aws_password_policy_changes.yml
+++ b/detections/cloud/aws_password_policy_changes.yml
@@ -18,9 +18,8 @@ data_source:
- AWS CloudTrail GetAccountPasswordPolicy
- AWS CloudTrail DeleteAccountPasswordPolicy
search: '`cloudtrail` eventName IN ("UpdateAccountPasswordPolicy","GetAccountPasswordPolicy","DeleteAccountPasswordPolicy") errorCode=success
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_password_policy_changes_filter`'
how_to_implement: You must install Splunk AWS Add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
diff --git a/detections/cloud/aws_saml_update_identity_provider.yml b/detections/cloud/aws_saml_update_identity_provider.yml
index 666cf8c96e..1cbc4848f6 100644
--- a/detections/cloud/aws_saml_update_identity_provider.yml
+++ b/detections/cloud/aws_saml_update_identity_provider.yml
@@ -16,9 +16,8 @@ description: The following analytic detects updates to the SAML provider in AWS.
data_source:
- AWS CloudTrail UpdateSAMLProvider
search: '`cloudtrail` eventName=UpdateSAMLProvider
- | rename requestParameters.sAMLProviderArn as request_parameters , eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime values(request_parameters) as request_parameters by action dest user user_agent src vendor_account vendor_region vendor_product signature
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime values(request_parameters) as request_parameters by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|`aws_saml_update_identity_provider_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
diff --git a/detections/cloud/aws_setdefaultpolicyversion.yml b/detections/cloud/aws_setdefaultpolicyversion.yml
index 5d775a0401..6d5fb033e9 100644
--- a/detections/cloud/aws_setdefaultpolicyversion.yml
+++ b/detections/cloud/aws_setdefaultpolicyversion.yml
@@ -15,9 +15,8 @@ description: The following analytic detects when a user sets a default policy ve
data_source:
- AWS CloudTrail SetDefaultPolicyVersion
search: '`cloudtrail` eventName=SetDefaultPolicyVersion eventSource = iam.amazonaws.com
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_setdefaultpolicyversion_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
@@ -43,7 +42,7 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
- message: From IP address $src$, user $user$ has trigged an action $action$
+ message: From IP address $src$, user $user$ has trigged an action $signature$
for updating the the default policy version
risk_objects:
- field: user
diff --git a/detections/cloud/aws_successful_console_authentication_from_multiple_ips.yml b/detections/cloud/aws_successful_console_authentication_from_multiple_ips.yml
index c159754c61..d7ec66df03 100644
--- a/detections/cloud/aws_successful_console_authentication_from_multiple_ips.yml
+++ b/detections/cloud/aws_successful_console_authentication_from_multiple_ips.yml
@@ -16,9 +16,8 @@ data_source:
- AWS CloudTrail ConsoleLogin
search: '`cloudtrail` eventName = ConsoleLogin
| bin span=5m _time
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats dc(src) as distinct_ip_count values(src) as src values(user_agent) as user_agent by _time, user, action, dest, vendor_account, vendor_region, vendor_product
+ | rename user_name as user
+ | stats dc(src) as distinct_ip_count values(src) as src values(user_agent) as user_agent values(dest) as dest by _time, user, signature, vendor_account, vendor_region, vendor_product
| where distinct_ip_count>1
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_successful_console_authentication_from_multiple_ips_filter`'
how_to_implement: You must install Splunk AWS add on and Splunk App for AWS. This
diff --git a/detections/cloud/aws_successful_single_factor_authentication.yml b/detections/cloud/aws_successful_single_factor_authentication.yml
index 9f326936db..798789c6c7 100644
--- a/detections/cloud/aws_successful_single_factor_authentication.yml
+++ b/detections/cloud/aws_successful_single_factor_authentication.yml
@@ -15,9 +15,8 @@ description: The following analytic identifies a successful Console Login authen
data_source:
- AWS CloudTrail ConsoleLogin
search: '`cloudtrail` eventName= ConsoleLogin errorCode=success "additionalEventData.MFAUsed"=No
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `aws_successful_single_factor_authentication_filter`'
how_to_implement: The Splunk AWS Add-on is required to utilize this data. The search
diff --git a/detections/cloud/aws_updateloginprofile.yml b/detections/cloud/aws_updateloginprofile.yml
index da468246ac..50948031d0 100644
--- a/detections/cloud/aws_updateloginprofile.yml
+++ b/detections/cloud/aws_updateloginprofile.yml
@@ -18,9 +18,8 @@ data_source:
search: '`cloudtrail` eventName = UpdateLoginProfile userAgent !=console.amazonaws.com
errorCode = success | eval match=if(match(userIdentity.userName,requestParameters.userName),
1,0) | search match=0
- | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
- | eval vendor_product = "AWS"
- | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product
+ | rename user_name as user
+ | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `aws_updateloginprofile_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
From 81e080182943d959536bb6fd2efe30e1149f865d Mon Sep 17 00:00:00 2001
From: Patrick Bareiss
Date: Tue, 18 Mar 2025 13:55:20 +0100
Subject: [PATCH 56/67] rerun CI
---
detections/cloud/aws_createloginprofile.yml | 2 ++
1 file changed, 2 insertions(+)
diff --git a/detections/cloud/aws_createloginprofile.yml b/detections/cloud/aws_createloginprofile.yml
index 48c0aaa588..aa3455544e 100644
--- a/detections/cloud/aws_createloginprofile.yml
+++ b/detections/cloud/aws_createloginprofile.yml
@@ -73,3 +73,5 @@ tests:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createloginprofile/aws_cloudtrail_events.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
+
+
\ No newline at end of file
From 6a53b8c61bf724a6f2b51d96da83d0fefeb417eb Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Tue, 18 Mar 2025 10:52:47 -0700
Subject: [PATCH 57/67] adding 2 splunk detections
---
deprecated/deprecated_detection_mapping.yml | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml
index 94813fd1da..e681484193 100644
--- a/deprecated/deprecated_detection_mapping.yml
+++ b/deprecated/deprecated_detection_mapping.yml
@@ -1,4 +1,10 @@
detections:
+ - deprecated_content: Open Redirect in Splunk Web
+ deprecated_in_version: 5.2.0
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
+ - deprecated_content: Splunk Enterprise Information Disclosure
+ deprecated_in_version: 5.2.0
+ reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- deprecated_content: ASL AWS Excessive Security Scanning
deprecated_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
From 86e7863669d628e53c181dde14c6de34b5cd1b6a Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Tue, 18 Mar 2025 11:16:32 -0700
Subject: [PATCH 58/67] updating file name
---
.../{deprecated_detection_mapping.yml => deprecation_mapping.YML} | 0
1 file changed, 0 insertions(+), 0 deletions(-)
rename deprecated/{deprecated_detection_mapping.yml => deprecation_mapping.YML} (100%)
diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecation_mapping.YML
similarity index 100%
rename from deprecated/deprecated_detection_mapping.yml
rename to deprecated/deprecation_mapping.YML
From da5c9b9bbd7a6ec7ac65ccafc25e6a751ebe0e82 Mon Sep 17 00:00:00 2001
From: delgado-jacob <29643013+delgado-jacob@users.noreply.github.com>
Date: Tue, 18 Mar 2025 11:37:35 -0700
Subject: [PATCH 59/67] fix separator_value field
---
data_sources/aws_cloudtrail_copyobject.yml | 2 +-
data_sources/aws_cloudtrail_createtask.yml | 2 +-
data_sources/powershell_script_block_logging_4104.yml | 2 +-
data_sources/sysmon_eventid_1.yml | 2 +-
data_sources/sysmon_eventid_10.yml | 2 +-
data_sources/sysmon_eventid_11.yml | 2 +-
data_sources/sysmon_eventid_12.yml | 2 +-
data_sources/sysmon_eventid_13.yml | 2 +-
data_sources/sysmon_eventid_15.yml | 2 +-
data_sources/sysmon_eventid_17.yml | 2 +-
data_sources/sysmon_eventid_18.yml | 2 +-
data_sources/sysmon_eventid_21.yml | 2 +-
data_sources/sysmon_eventid_22.yml | 2 +-
data_sources/sysmon_eventid_23.yml | 2 +-
data_sources/sysmon_eventid_3.yml | 2 +-
data_sources/sysmon_eventid_5.yml | 2 +-
data_sources/sysmon_eventid_6.yml | 2 +-
data_sources/sysmon_eventid_7.yml | 2 +-
data_sources/sysmon_eventid_8.yml | 2 +-
data_sources/sysmon_eventid_9.yml | 2 +-
data_sources/sysmon_for_linux_eventid_1.yml | 2 +-
data_sources/windows_event_log_application_3000.yml | 2 +-
data_sources/windows_event_log_capi2_70.yml | 2 +-
data_sources/windows_event_log_capi2_81.yml | 2 +-
.../windows_event_log_certificateservicesclient_1007.yml | 2 +-
data_sources/windows_event_log_defender_1121.yml | 2 +-
data_sources/windows_event_log_defender_1122.yml | 2 +-
data_sources/windows_event_log_defender_1129.yml | 2 +-
data_sources/windows_event_log_printservice_316.yml | 2 +-
data_sources/windows_event_log_printservice_808.yml | 2 +-
data_sources/windows_event_log_remoteconnectionmanager_1149.yml | 2 +-
data_sources/windows_event_log_security_1100.yml | 2 +-
data_sources/windows_event_log_security_1102.yml | 2 +-
data_sources/windows_event_log_security_4624.yml | 2 +-
data_sources/windows_event_log_security_4625.yml | 2 +-
data_sources/windows_event_log_security_4627.yml | 2 +-
data_sources/windows_event_log_security_4648.yml | 2 +-
data_sources/windows_event_log_security_4662.yml | 2 +-
data_sources/windows_event_log_security_4663.yml | 2 +-
data_sources/windows_event_log_security_4672.yml | 2 +-
data_sources/windows_event_log_security_4688.yml | 2 +-
data_sources/windows_event_log_security_4698.yml | 2 +-
data_sources/windows_event_log_security_4699.yml | 2 +-
data_sources/windows_event_log_security_4703.yml | 2 +-
data_sources/windows_event_log_security_4719.yml | 2 +-
data_sources/windows_event_log_security_4720.yml | 2 +-
data_sources/windows_event_log_security_4724.yml | 2 +-
data_sources/windows_event_log_security_4725.yml | 2 +-
data_sources/windows_event_log_security_4726.yml | 2 +-
data_sources/windows_event_log_security_4732.yml | 2 +-
data_sources/windows_event_log_security_4738.yml | 2 +-
data_sources/windows_event_log_security_4739.yml | 2 +-
data_sources/windows_event_log_security_4741.yml | 2 +-
data_sources/windows_event_log_security_4768.yml | 2 +-
data_sources/windows_event_log_security_4769.yml | 2 +-
data_sources/windows_event_log_security_4771.yml | 2 +-
data_sources/windows_event_log_security_4776.yml | 2 +-
data_sources/windows_event_log_security_4781.yml | 2 +-
data_sources/windows_event_log_security_4876.yml | 2 +-
data_sources/windows_event_log_security_4886.yml | 2 +-
data_sources/windows_event_log_security_4887.yml | 2 +-
data_sources/windows_event_log_security_5136.yml | 2 +-
data_sources/windows_event_log_security_5137.yml | 2 +-
data_sources/windows_event_log_security_5140.yml | 2 +-
data_sources/windows_event_log_security_5141.yml | 2 +-
data_sources/windows_event_log_security_5145.yml | 2 +-
data_sources/windows_event_log_system_4720.yml | 2 +-
data_sources/windows_event_log_system_4726.yml | 2 +-
data_sources/windows_event_log_system_4728.yml | 2 +-
data_sources/windows_event_log_system_7036.yml | 2 +-
data_sources/windows_event_log_system_7040.yml | 2 +-
data_sources/windows_event_log_system_7045.yml | 2 +-
data_sources/windows_event_log_taskscheduler_200.yml | 2 +-
data_sources/windows_iis_29.yml | 2 +-
74 files changed, 74 insertions(+), 74 deletions(-)
diff --git a/data_sources/aws_cloudtrail_copyobject.yml b/data_sources/aws_cloudtrail_copyobject.yml
index 1a505ff56f..9e10225b8d 100644
--- a/data_sources/aws_cloudtrail_copyobject.yml
+++ b/data_sources/aws_cloudtrail_copyobject.yml
@@ -13,7 +13,7 @@ mitre_components:
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
-separator_values: CopyObject
+separator_value: CopyObject
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/aws_cloudtrail_createtask.yml b/data_sources/aws_cloudtrail_createtask.yml
index f474925295..2cfea8e296 100644
--- a/data_sources/aws_cloudtrail_createtask.yml
+++ b/data_sources/aws_cloudtrail_createtask.yml
@@ -13,7 +13,7 @@ mitre_components:
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
-separator_name: CreateTask
+separator_value: CreateTask
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
diff --git a/data_sources/powershell_script_block_logging_4104.yml b/data_sources/powershell_script_block_logging_4104.yml
index 99f3ace10f..a92378edf7 100644
--- a/data_sources/powershell_script_block_logging_4104.yml
+++ b/data_sources/powershell_script_block_logging_4104.yml
@@ -14,7 +14,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
sourcetype: xmlwineventlog
separator: EventID
-separator_value: 4104
+separator_value: '4104'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/sysmon_eventid_1.yml b/data_sources/sysmon_eventid_1.yml
index ca295fd89b..82abab53f8 100644
--- a/data_sources/sysmon_eventid_1.yml
+++ b/data_sources/sysmon_eventid_1.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
-separator_value: 1
+separator_value: '1'
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_10.yml b/data_sources/sysmon_eventid_10.yml
index 844e023f1a..8afd1accf9 100644
--- a/data_sources/sysmon_eventid_10.yml
+++ b/data_sources/sysmon_eventid_10.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
-separator_value: 10
+separator_value: '10'
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_11.yml b/data_sources/sysmon_eventid_11.yml
index f0e6dee766..dc1c00aa6c 100644
--- a/data_sources/sysmon_eventid_11.yml
+++ b/data_sources/sysmon_eventid_11.yml
@@ -14,7 +14,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
-separator_value: 11
+separator_value: '11'
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_12.yml b/data_sources/sysmon_eventid_12.yml
index 5a2c89c0ec..d7253a27ee 100644
--- a/data_sources/sysmon_eventid_12.yml
+++ b/data_sources/sysmon_eventid_12.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
-separator_value: 12
+separator_value: '12'
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_13.yml b/data_sources/sysmon_eventid_13.yml
index 9af2d0673d..fa07a786fd 100644
--- a/data_sources/sysmon_eventid_13.yml
+++ b/data_sources/sysmon_eventid_13.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
-separator_value: 13
+separator_value: '13'
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_15.yml b/data_sources/sysmon_eventid_15.yml
index e679fb1ad9..c819cb661e 100644
--- a/data_sources/sysmon_eventid_15.yml
+++ b/data_sources/sysmon_eventid_15.yml
@@ -14,7 +14,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
-separator_value: 15
+separator_value: '15'
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_17.yml b/data_sources/sysmon_eventid_17.yml
index b871828540..efb671d8c5 100644
--- a/data_sources/sysmon_eventid_17.yml
+++ b/data_sources/sysmon_eventid_17.yml
@@ -9,7 +9,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
-separator_value: 17
+separator_value: '17'
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_18.yml b/data_sources/sysmon_eventid_18.yml
index f3b7854c2f..8447f15541 100644
--- a/data_sources/sysmon_eventid_18.yml
+++ b/data_sources/sysmon_eventid_18.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
-separator_value: 18
+separator_value: '18'
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_21.yml b/data_sources/sysmon_eventid_21.yml
index 8caa81e1bc..7cc11830ee 100644
--- a/data_sources/sysmon_eventid_21.yml
+++ b/data_sources/sysmon_eventid_21.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
-separator_value: 21
+separator_value: '21'
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_22.yml b/data_sources/sysmon_eventid_22.yml
index bcd9721dd8..fffc3f518a 100644
--- a/data_sources/sysmon_eventid_22.yml
+++ b/data_sources/sysmon_eventid_22.yml
@@ -14,7 +14,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
-separator_value: 22
+separator_value: '22'
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_23.yml b/data_sources/sysmon_eventid_23.yml
index 7dc515f54a..7e148df04e 100644
--- a/data_sources/sysmon_eventid_23.yml
+++ b/data_sources/sysmon_eventid_23.yml
@@ -14,7 +14,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
-separator_value: 23
+separator_value: '23'
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_3.yml b/data_sources/sysmon_eventid_3.yml
index b548310e17..04af350bfd 100644
--- a/data_sources/sysmon_eventid_3.yml
+++ b/data_sources/sysmon_eventid_3.yml
@@ -14,7 +14,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
-separator_value: 3
+separator_value: '3'
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_5.yml b/data_sources/sysmon_eventid_5.yml
index 946a3c0551..7b8abba8e9 100644
--- a/data_sources/sysmon_eventid_5.yml
+++ b/data_sources/sysmon_eventid_5.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
-separator_value: 5
+separator_value: '5'
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_6.yml b/data_sources/sysmon_eventid_6.yml
index c9d0d5d247..053de2de1d 100644
--- a/data_sources/sysmon_eventid_6.yml
+++ b/data_sources/sysmon_eventid_6.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
-separator_value: 6
+separator_value: '6'
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_7.yml b/data_sources/sysmon_eventid_7.yml
index 8c5dcd335e..8a67c2fab7 100644
--- a/data_sources/sysmon_eventid_7.yml
+++ b/data_sources/sysmon_eventid_7.yml
@@ -14,7 +14,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
-separator_value: 7
+separator_value: '7'
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_8.yml b/data_sources/sysmon_eventid_8.yml
index bb8b3a983b..1ee7641643 100644
--- a/data_sources/sysmon_eventid_8.yml
+++ b/data_sources/sysmon_eventid_8.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
-separator_value: 8
+separator_value: '8'
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_eventid_9.yml b/data_sources/sysmon_eventid_9.yml
index ba5499ae5b..f73b040876 100644
--- a/data_sources/sysmon_eventid_9.yml
+++ b/data_sources/sysmon_eventid_9.yml
@@ -14,7 +14,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
separator: EventID
-separator_value: 9
+separator_value: '9'
configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
diff --git a/data_sources/sysmon_for_linux_eventid_1.yml b/data_sources/sysmon_for_linux_eventid_1.yml
index 2027f90431..d8a01f3d5d 100644
--- a/data_sources/sysmon_for_linux_eventid_1.yml
+++ b/data_sources/sysmon_for_linux_eventid_1.yml
@@ -14,7 +14,7 @@ mitre_components:
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon:linux
separator: EventID
-separator_value: 1
+separator_value: '1'
supported_TA:
- name: Splunk Add-on for Sysmon for Linux
url: https://splunkbase.splunk.com/app/6652
diff --git a/data_sources/windows_event_log_application_3000.yml b/data_sources/windows_event_log_application_3000.yml
index a3dcec0bda..8f24d2587e 100644
--- a/data_sources/windows_event_log_application_3000.yml
+++ b/data_sources/windows_event_log_application_3000.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Application
sourcetype: XmlWinEventLog
separator: EventCode
-separator_value: 3000
+separator_value: '3000'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_capi2_70.yml b/data_sources/windows_event_log_capi2_70.yml
index cc9a329fac..eb570c28a9 100644
--- a/data_sources/windows_event_log_capi2_70.yml
+++ b/data_sources/windows_event_log_capi2_70.yml
@@ -14,7 +14,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-CAPI2/Operational
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 70
+separator_value: '70'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_capi2_81.yml b/data_sources/windows_event_log_capi2_81.yml
index e6641f83f8..12ef5132b5 100644
--- a/data_sources/windows_event_log_capi2_81.yml
+++ b/data_sources/windows_event_log_capi2_81.yml
@@ -14,7 +14,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-CAPI2/Operational
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 81
+separator_value: '81'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_certificateservicesclient_1007.yml b/data_sources/windows_event_log_certificateservicesclient_1007.yml
index edc911da2a..f3ba7e5eaa 100644
--- a/data_sources/windows_event_log_certificateservicesclient_1007.yml
+++ b/data_sources/windows_event_log_certificateservicesclient_1007.yml
@@ -14,7 +14,7 @@ mitre_components:
source: XmlWinEventLog:Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational
sourcetype: XmlWinEventLog
separator: EventCode
-separator_value: 1007
+separator_value: '1007'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_defender_1121.yml b/data_sources/windows_event_log_defender_1121.yml
index c1185da5d8..d24a5e359e 100644
--- a/data_sources/windows_event_log_defender_1121.yml
+++ b/data_sources/windows_event_log_defender_1121.yml
@@ -12,7 +12,7 @@ mitre_components:
source: WinEventLog:Microsoft-Windows-Windows Defender/Operational
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 1121
+separator_value: '1121'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_defender_1122.yml b/data_sources/windows_event_log_defender_1122.yml
index 708c4a09aa..8c16ab4757 100644
--- a/data_sources/windows_event_log_defender_1122.yml
+++ b/data_sources/windows_event_log_defender_1122.yml
@@ -12,7 +12,7 @@ mitre_components:
source: WinEventLog:Microsoft-Windows-Windows Defender/Operational
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 1122
+separator_value: '1122'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_defender_1129.yml b/data_sources/windows_event_log_defender_1129.yml
index 1e4fd843ff..41c76a99c0 100644
--- a/data_sources/windows_event_log_defender_1129.yml
+++ b/data_sources/windows_event_log_defender_1129.yml
@@ -12,7 +12,7 @@ mitre_components:
source: WinEventLog:Microsoft-Windows-Windows Defender/Operational
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 1129
+separator_value: '1129'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_printservice_316.yml b/data_sources/windows_event_log_printservice_316.yml
index a13491e365..46e5fea881 100644
--- a/data_sources/windows_event_log_printservice_316.yml
+++ b/data_sources/windows_event_log_printservice_316.yml
@@ -10,7 +10,7 @@ mitre_components:
source: WinEventLog:Microsoft-Windows-PrintService/Admin
sourcetype: WinEventLog
separator: EventCode
-separator_value: 316
+separator_value: '316'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_printservice_808.yml b/data_sources/windows_event_log_printservice_808.yml
index 2f1c1363e4..c989e88ce2 100644
--- a/data_sources/windows_event_log_printservice_808.yml
+++ b/data_sources/windows_event_log_printservice_808.yml
@@ -12,7 +12,7 @@ mitre_components:
source: WinEventLog:Microsoft-Windows-PrintService/Admin
sourcetype: WinEventLog
separator: EventCode
-separator_value: 808
+separator_value: '808'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml
index 17e1e81b90..c3352c16bd 100644
--- a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml
+++ b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml
@@ -11,7 +11,7 @@ mitre_components:
source: WinEventLog:Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational
sourcetype: wineventlog
separator: EventCode
-separator_value: 1149
+separator_value: '1149'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_1100.yml b/data_sources/windows_event_log_security_1100.yml
index f926bde8c2..1034fc5e50 100644
--- a/data_sources/windows_event_log_security_1100.yml
+++ b/data_sources/windows_event_log_security_1100.yml
@@ -10,7 +10,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 1100
+separator_value: '1100'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_1102.yml b/data_sources/windows_event_log_security_1102.yml
index d66920335f..b6209e3136 100644
--- a/data_sources/windows_event_log_security_1102.yml
+++ b/data_sources/windows_event_log_security_1102.yml
@@ -11,7 +11,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 1102
+separator_value: '1102'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4624.yml b/data_sources/windows_event_log_security_4624.yml
index 823b6f2dee..c27cbde9e8 100644
--- a/data_sources/windows_event_log_security_4624.yml
+++ b/data_sources/windows_event_log_security_4624.yml
@@ -11,7 +11,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4624
+separator_value: '4624'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4625.yml b/data_sources/windows_event_log_security_4625.yml
index 5fdd9b3c21..e37413ca43 100644
--- a/data_sources/windows_event_log_security_4625.yml
+++ b/data_sources/windows_event_log_security_4625.yml
@@ -10,7 +10,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4625
+separator_value: '4625'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4627.yml b/data_sources/windows_event_log_security_4627.yml
index 85b2053016..428fea6638 100644
--- a/data_sources/windows_event_log_security_4627.yml
+++ b/data_sources/windows_event_log_security_4627.yml
@@ -12,7 +12,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4627
+separator_value: '4627'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4648.yml b/data_sources/windows_event_log_security_4648.yml
index 41b1ea111d..204ee0a6ea 100644
--- a/data_sources/windows_event_log_security_4648.yml
+++ b/data_sources/windows_event_log_security_4648.yml
@@ -11,7 +11,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4648
+separator_value: '4648'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4662.yml b/data_sources/windows_event_log_security_4662.yml
index e7ab4e16cb..72241152a5 100644
--- a/data_sources/windows_event_log_security_4662.yml
+++ b/data_sources/windows_event_log_security_4662.yml
@@ -11,7 +11,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4662
+separator_value: '4662'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4663.yml b/data_sources/windows_event_log_security_4663.yml
index 0a9d7bc423..8464167492 100644
--- a/data_sources/windows_event_log_security_4663.yml
+++ b/data_sources/windows_event_log_security_4663.yml
@@ -11,7 +11,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4663
+separator_value: '4663'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4672.yml b/data_sources/windows_event_log_security_4672.yml
index b56a07aae1..c4ae46c0f1 100644
--- a/data_sources/windows_event_log_security_4672.yml
+++ b/data_sources/windows_event_log_security_4672.yml
@@ -11,7 +11,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4672
+separator_value: '4672'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4688.yml b/data_sources/windows_event_log_security_4688.yml
index 11371fe6ff..16b11249c1 100644
--- a/data_sources/windows_event_log_security_4688.yml
+++ b/data_sources/windows_event_log_security_4688.yml
@@ -10,7 +10,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4688
+separator_value: '4688'
configuration: Enabling Windows event log process command line logging via group policy
object https://lantern.splunk.com/Security/Product_Tips/Enterprise_Security/Enabling_Windows_event_log_process_command_line_logging_via_group_policy_object
supported_TA:
diff --git a/data_sources/windows_event_log_security_4698.yml b/data_sources/windows_event_log_security_4698.yml
index 27406cada2..b8c7911455 100644
--- a/data_sources/windows_event_log_security_4698.yml
+++ b/data_sources/windows_event_log_security_4698.yml
@@ -10,7 +10,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4698
+separator_value: '4698'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4699.yml b/data_sources/windows_event_log_security_4699.yml
index dc83e20aa6..7f05064a8f 100644
--- a/data_sources/windows_event_log_security_4699.yml
+++ b/data_sources/windows_event_log_security_4699.yml
@@ -10,7 +10,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4699
+separator_value: '4699'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4703.yml b/data_sources/windows_event_log_security_4703.yml
index 972a05a8d9..16ea3afc90 100644
--- a/data_sources/windows_event_log_security_4703.yml
+++ b/data_sources/windows_event_log_security_4703.yml
@@ -10,7 +10,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4703
+separator_value: '4703'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4719.yml b/data_sources/windows_event_log_security_4719.yml
index 37a72cc312..6edde73b99 100644
--- a/data_sources/windows_event_log_security_4719.yml
+++ b/data_sources/windows_event_log_security_4719.yml
@@ -10,7 +10,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4719
+separator_value: '4719'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4720.yml b/data_sources/windows_event_log_security_4720.yml
index ddd763d21b..e6bca434f1 100644
--- a/data_sources/windows_event_log_security_4720.yml
+++ b/data_sources/windows_event_log_security_4720.yml
@@ -9,7 +9,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4720
+separator_value: '4720'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4724.yml b/data_sources/windows_event_log_security_4724.yml
index 133f957f91..ed2d278c99 100644
--- a/data_sources/windows_event_log_security_4724.yml
+++ b/data_sources/windows_event_log_security_4724.yml
@@ -10,7 +10,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4724
+separator_value: '4724'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4725.yml b/data_sources/windows_event_log_security_4725.yml
index 129eafcb4f..5b91ceeb40 100644
--- a/data_sources/windows_event_log_security_4725.yml
+++ b/data_sources/windows_event_log_security_4725.yml
@@ -9,7 +9,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4725
+separator_value: '4725'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4726.yml b/data_sources/windows_event_log_security_4726.yml
index 201285eee9..8ee6b298fd 100644
--- a/data_sources/windows_event_log_security_4726.yml
+++ b/data_sources/windows_event_log_security_4726.yml
@@ -9,7 +9,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4726
+separator_value: '4726'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4732.yml b/data_sources/windows_event_log_security_4732.yml
index 5cab030eb0..5f312c3965 100644
--- a/data_sources/windows_event_log_security_4732.yml
+++ b/data_sources/windows_event_log_security_4732.yml
@@ -10,7 +10,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4732
+separator_value: '4732'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4738.yml b/data_sources/windows_event_log_security_4738.yml
index 45a903eb05..b42d8f7fa2 100644
--- a/data_sources/windows_event_log_security_4738.yml
+++ b/data_sources/windows_event_log_security_4738.yml
@@ -10,7 +10,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4738
+separator_value: '4738'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4739.yml b/data_sources/windows_event_log_security_4739.yml
index 30b07c99ee..7fb6bdc459 100644
--- a/data_sources/windows_event_log_security_4739.yml
+++ b/data_sources/windows_event_log_security_4739.yml
@@ -11,7 +11,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4739
+separator_value: '4739'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4741.yml b/data_sources/windows_event_log_security_4741.yml
index 8729366be5..2caa69385e 100644
--- a/data_sources/windows_event_log_security_4741.yml
+++ b/data_sources/windows_event_log_security_4741.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4741
+separator_value: '4741'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4768.yml b/data_sources/windows_event_log_security_4768.yml
index c391a51cfe..599f027991 100644
--- a/data_sources/windows_event_log_security_4768.yml
+++ b/data_sources/windows_event_log_security_4768.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4768
+separator_value: '4768'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4769.yml b/data_sources/windows_event_log_security_4769.yml
index d8c0cf195b..518f49f8da 100644
--- a/data_sources/windows_event_log_security_4769.yml
+++ b/data_sources/windows_event_log_security_4769.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4769
+separator_value: '4769'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4771.yml b/data_sources/windows_event_log_security_4771.yml
index 7b6e030b23..0e18ca2298 100644
--- a/data_sources/windows_event_log_security_4771.yml
+++ b/data_sources/windows_event_log_security_4771.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4771
+separator_value: '4771'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4776.yml b/data_sources/windows_event_log_security_4776.yml
index 59ae2a4748..d6581e3afc 100644
--- a/data_sources/windows_event_log_security_4776.yml
+++ b/data_sources/windows_event_log_security_4776.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4776
+separator_value: '4776'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4781.yml b/data_sources/windows_event_log_security_4781.yml
index 2e6adff3c4..9daa1781ae 100644
--- a/data_sources/windows_event_log_security_4781.yml
+++ b/data_sources/windows_event_log_security_4781.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4781
+separator_value: '4781'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4876.yml b/data_sources/windows_event_log_security_4876.yml
index 2340e3fb35..8d16e695d2 100644
--- a/data_sources/windows_event_log_security_4876.yml
+++ b/data_sources/windows_event_log_security_4876.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4876
+separator_value: '4876'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4886.yml b/data_sources/windows_event_log_security_4886.yml
index bf7533d343..a38f31f8cc 100644
--- a/data_sources/windows_event_log_security_4886.yml
+++ b/data_sources/windows_event_log_security_4886.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4886
+separator_value: '4886'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_4887.yml b/data_sources/windows_event_log_security_4887.yml
index 0bac032d6b..4b8188cb5d 100644
--- a/data_sources/windows_event_log_security_4887.yml
+++ b/data_sources/windows_event_log_security_4887.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4887
+separator_value: '4887'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_5136.yml b/data_sources/windows_event_log_security_5136.yml
index 1cc73e726e..048eaf46f7 100644
--- a/data_sources/windows_event_log_security_5136.yml
+++ b/data_sources/windows_event_log_security_5136.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 5136
+separator_value: '5136'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_5137.yml b/data_sources/windows_event_log_security_5137.yml
index b7da687fc2..1aa19af1d7 100644
--- a/data_sources/windows_event_log_security_5137.yml
+++ b/data_sources/windows_event_log_security_5137.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 5137
+separator_value: '5137'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_5140.yml b/data_sources/windows_event_log_security_5140.yml
index 537ad5db65..d8c6bd2297 100644
--- a/data_sources/windows_event_log_security_5140.yml
+++ b/data_sources/windows_event_log_security_5140.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 5140
+separator_value: '5140'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_5141.yml b/data_sources/windows_event_log_security_5141.yml
index cc5825f11b..d507ac5298 100644
--- a/data_sources/windows_event_log_security_5141.yml
+++ b/data_sources/windows_event_log_security_5141.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 5141
+separator_value: '5141'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_security_5145.yml b/data_sources/windows_event_log_security_5145.yml
index aadb0c15ea..5346b703d7 100644
--- a/data_sources/windows_event_log_security_5145.yml
+++ b/data_sources/windows_event_log_security_5145.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 5145
+separator_value: '5145'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_system_4720.yml b/data_sources/windows_event_log_system_4720.yml
index de3cea6a37..e5a0d75f83 100644
--- a/data_sources/windows_event_log_system_4720.yml
+++ b/data_sources/windows_event_log_system_4720.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:System
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4720
+separator_value: '4720'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_system_4726.yml b/data_sources/windows_event_log_system_4726.yml
index 2a4c9d93e3..b76450a928 100644
--- a/data_sources/windows_event_log_system_4726.yml
+++ b/data_sources/windows_event_log_system_4726.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:System
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4726
+separator_value: '4726'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_system_4728.yml b/data_sources/windows_event_log_system_4728.yml
index bf93ff45f0..b7d5ada0c2 100644
--- a/data_sources/windows_event_log_system_4728.yml
+++ b/data_sources/windows_event_log_system_4728.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:System
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 4728
+separator_value: '4728'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_system_7036.yml b/data_sources/windows_event_log_system_7036.yml
index 2d84bd44d8..c5eade1a31 100644
--- a/data_sources/windows_event_log_system_7036.yml
+++ b/data_sources/windows_event_log_system_7036.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:System
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 7036
+separator_value: '7036'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_system_7040.yml b/data_sources/windows_event_log_system_7040.yml
index 0f26b121a0..8c17c4cec7 100644
--- a/data_sources/windows_event_log_system_7040.yml
+++ b/data_sources/windows_event_log_system_7040.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:System
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 7040
+separator_value: '7040'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_system_7045.yml b/data_sources/windows_event_log_system_7045.yml
index 87c78b1a51..e019802f0c 100644
--- a/data_sources/windows_event_log_system_7045.yml
+++ b/data_sources/windows_event_log_system_7045.yml
@@ -13,7 +13,7 @@ mitre_components:
source: XmlWinEventLog:System
sourcetype: xmlwineventlog
separator: EventCode
-separator_value: 7045
+separator_value: '7045'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_event_log_taskscheduler_200.yml b/data_sources/windows_event_log_taskscheduler_200.yml
index 2348f6b3f8..16cec6a1f0 100644
--- a/data_sources/windows_event_log_taskscheduler_200.yml
+++ b/data_sources/windows_event_log_taskscheduler_200.yml
@@ -13,7 +13,7 @@ mitre_components:
source: WinEventLog:Microsoft-Windows-TaskScheduler/Operational
sourcetype: wineventlog
separator: EventCode
-separator_value: 200
+separator_value: '200'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
diff --git a/data_sources/windows_iis_29.yml b/data_sources/windows_iis_29.yml
index 9ab6d3794a..7eeb8eeb79 100644
--- a/data_sources/windows_iis_29.yml
+++ b/data_sources/windows_iis_29.yml
@@ -13,7 +13,7 @@ mitre_components:
source: IIS:Configuration:Operational
sourcetype: IIS:Configuration:Operational
separator: EventID
-separator_value: 29
+separator_value: '29'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
From 5e0d59e186c213c393e13a6b610deb328b1fae7a Mon Sep 17 00:00:00 2001
From: Eric
Date: Tue, 18 Mar 2025 12:07:47 -0700
Subject: [PATCH 60/67] bump version in prep for release and so that
deprecation stuff works properly.
---
contentctl.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/contentctl.yml b/contentctl.yml
index 0fcd575b4a..0fec06f9bf 100644
--- a/contentctl.yml
+++ b/contentctl.yml
@@ -3,7 +3,7 @@ app:
uid: 3449
title: ES Content Updates
appid: DA-ESS-ContentUpdate
- version: 5.1.1
+ version: 5.2.0
description: Explore the Analytic Stories included with ES Content Updates.
prefix: ESCU
label: ESCU
From ad55d26fe4ce165475fe3f8f368c8930223970ce Mon Sep 17 00:00:00 2001
From: Eric
Date: Tue, 18 Mar 2025 12:33:06 -0700
Subject: [PATCH 61/67] add 'status: removed' instead of 'status: deprecated'
to removed detections
---
.../add_prohibited_processes_to_enterprise_security.yml | 2 +-
deprecated/baselines/baseline_of_api_calls_per_user_arn.yml | 2 +-
...eline_of_excessive_aws_instances_launched_by_user___mltk.yml | 2 +-
...ine_of_excessive_aws_instances_terminated_by_user___mltk.yml | 2 +-
deprecated/baselines/monitor_successful_backups.yml | 2 +-
deprecated/baselines/monitor_unsuccessful_backups.yml | 2 +-
.../previously_seen_api_call_per_user_roles_in_cloudtrail.yml | 2 +-
.../previously_seen_aws_provisioning_activity_sources.yml | 2 +-
deprecated/baselines/previously_seen_aws_regions.yml | 2 +-
deprecated/baselines/previously_seen_ec2_amis.yml | 2 +-
deprecated/baselines/previously_seen_ec2_instance_types.yml | 2 +-
deprecated/baselines/previously_seen_ec2_launches_by_user.yml | 2 +-
.../baselines/previously_seen_ec2_modifications_by_user.yml | 2 +-
deprecated/baselines/previously_seen_users_in_cloudtrail.yml | 2 +-
.../systems_ready_for_spectre_meltdown_windows_patch.yml | 2 +-
.../baselines/update_previously_seen_users_in_cloudtrail.yml | 2 +-
.../abnormally_high_aws_instances_launched_by_user.yml | 2 +-
.../abnormally_high_aws_instances_launched_by_user___mltk.yml | 2 +-
.../abnormally_high_aws_instances_terminated_by_user.yml | 2 +-
.../abnormally_high_aws_instances_terminated_by_user___mltk.yml | 2 +-
deprecated/detections/account_discovery_with_net_app.yml | 2 +-
deprecated/detections/asl_aws_createaccesskey.yml | 2 +-
deprecated/detections/asl_aws_excessive_security_scanning.yml | 2 +-
deprecated/detections/asl_aws_password_policy_changes.yml | 2 +-
deprecated/detections/attempt_to_stop_security_service.yml | 2 +-
.../attempted_credential_dump_from_registry_via_reg_exe.yml | 2 +-
.../aws_cloud_provisioning_from_previously_unseen_city.yml | 2 +-
.../aws_cloud_provisioning_from_previously_unseen_country.yml | 2 +-
...aws_cloud_provisioning_from_previously_unseen_ip_address.yml | 2 +-
.../aws_cloud_provisioning_from_previously_unseen_region.yml | 2 +-
.../aws_eks_kubernetes_cluster_sensitive_object_access.yml | 2 +-
deprecated/detections/change_default_file_association.yml | 2 +-
.../detections/clients_connecting_to_multiple_dns_servers.yml | 2 +-
.../detections/cloud_network_access_control_list_deleted.yml | 2 +-
.../detections/cmdline_tool_not_executed_in_cmd_shell.yml | 2 +-
deprecated/detections/correlation_by_repository_and_risk.yml | 2 +-
deprecated/detections/correlation_by_user_and_risk.yml | 2 +-
.../detections/create_local_admin_accounts_using_net_exe.yml | 2 +-
deprecated/detections/deleting_of_net_users.yml | 2 +-
.../detect_activity_related_to_pass_the_hash_attacks.yml | 2 +-
.../detections/detect_api_activity_from_users_without_mfa.yml | 2 +-
.../detect_aws_api_activities_from_unapproved_accounts.yml | 2 +-
.../detections/detect_critical_alerts_from_security_tools.yml | 2 +-
...tect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml | 2 +-
deprecated/detections/detect_long_dns_txt_record_response.yml | 2 +-
deprecated/detections/detect_mimikatz_using_loaded_images.yml | 2 +-
.../detect_mimikatz_via_powershell_and_eventcode_4703.yml | 2 +-
deprecated/detections/detect_new_api_calls_from_user_roles.yml | 2 +-
deprecated/detections/detect_new_user_aws_console_login.yml | 2 +-
...rocesses_used_for_system_network_configuration_discovery.yml | 2 +-
deprecated/detections/detect_spike_in_aws_api_activity.yml | 2 +-
deprecated/detections/detect_spike_in_network_acl_activity.yml | 2 +-
.../detections/detect_spike_in_security_group_activity.yml | 2 +-
deprecated/detections/detect_usb_device_insertion.yml | 2 +-
.../detect_web_traffic_to_dynamic_domain_providers.yml | 2 +-
deprecated/detections/detect_webshell_exploit_behavior.yml | 2 +-
deprecated/detections/detection_of_dns_tunnels.yml | 2 +-
deprecated/detections/disabling_net_user_account.yml | 2 +-
.../dns_query_requests_resolved_by_unauthorized_dns_servers.yml | 2 +-
deprecated/detections/dns_record_changed.yml | 2 +-
deprecated/detections/domain_account_discovery_with_net_app.yml | 2 +-
deprecated/detections/domain_group_discovery_with_net.yml | 2 +-
deprecated/detections/dump_lsass_via_procdump_rename.yml | 2 +-
.../ec2_instance_modified_with_previously_unseen_user.yml | 2 +-
.../ec2_instance_started_in_previously_unseen_region.yml | 2 +-
.../ec2_instance_started_with_previously_unseen_ami.yml | 2 +-
...c2_instance_started_with_previously_unseen_instance_type.yml | 2 +-
.../ec2_instance_started_with_previously_unseen_user.yml | 2 +-
deprecated/detections/elevated_group_discovery_with_net.yml | 2 +-
deprecated/detections/excel_spawning_powershell.yml | 2 +-
deprecated/detections/excel_spawning_windows_script_host.yml | 2 +-
deprecated/detections/excessive_service_stop_attempt.yml | 2 +-
deprecated/detections/excessive_usage_of_net_app.yml | 2 +-
.../execution_of_file_with_spaces_before_extension.yml | 2 +-
.../extended_period_without_successful_netbackup_backups.yml | 2 +-
deprecated/detections/extraction_of_registry_hives.yml | 2 +-
deprecated/detections/first_time_seen_command_line_argument.yml | 2 +-
.../gcp_detect_accounts_with_high_risk_roles_by_project.yml | 2 +-
...gcp_detect_high_risk_permissions_by_resource_and_account.yml | 2 +-
deprecated/detections/gcp_detect_oauth_token_abuse.yml | 2 +-
deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml | 2 +-
deprecated/detections/identify_new_user_accounts.yml | 2 +-
...ubernetes_aws_detect_most_active_service_accounts_by_pod.yml | 2 +-
.../kubernetes_aws_detect_rbac_authorization_by_account.yml | 2 +-
.../detections/kubernetes_aws_detect_sensitive_role_access.yml | 2 +-
...tes_aws_detect_service_accounts_forbidden_failure_access.yml | 2 +-
...ubernetes_azure_active_service_accounts_by_pod_namespace.yml | 2 +-
.../kubernetes_azure_detect_rbac_authorization_by_account.yml | 2 +-
.../kubernetes_azure_detect_sensitive_object_access.yml | 2 +-
.../kubernetes_azure_detect_sensitive_role_access.yml | 2 +-
...s_azure_detect_service_accounts_forbidden_failure_access.yml | 2 +-
.../kubernetes_azure_detect_suspicious_kubectl_calls.yml | 2 +-
deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml | 2 +-
deprecated/detections/kubernetes_azure_scan_fingerprint.yml | 2 +-
...ubernetes_gcp_detect_most_active_service_accounts_by_pod.yml | 2 +-
.../kubernetes_gcp_detect_rbac_authorizations_by_account.yml | 2 +-
.../kubernetes_gcp_detect_sensitive_object_access.yml | 2 +-
.../detections/kubernetes_gcp_detect_sensitive_role_access.yml | 2 +-
...tes_gcp_detect_service_accounts_forbidden_failure_access.yml | 2 +-
.../kubernetes_gcp_detect_suspicious_kubectl_calls.yml | 2 +-
deprecated/detections/linux_auditd_find_private_keys.yml | 2 +-
deprecated/detections/local_account_discovery_with_net.yml | 2 +-
deprecated/detections/monitor_dns_for_brand_abuse.yml | 2 +-
deprecated/detections/mshtml_module_load_in_office_product.yml | 2 +-
...ple_okta_users_with_invalid_credentials_from_the_same_ip.yml | 2 +-
deprecated/detections/net_localgroup_discovery.yml | 2 +-
deprecated/detections/network_connection_discovery_with_net.yml | 2 +-
.../detections/o365_suspicious_admin_email_forwarding.yml | 2 +-
deprecated/detections/o365_suspicious_rights_delegation.yml | 2 +-
deprecated/detections/o365_suspicious_user_email_forwarding.yml | 2 +-
deprecated/detections/office_application_drop_executable.yml | 2 +-
.../detections/office_application_spawn_regsvr32_process.yml | 2 +-
.../detections/office_application_spawn_rundll32_process.yml | 2 +-
.../detections/office_document_creating_schedule_task.yml | 2 +-
deprecated/detections/office_document_executing_macro_code.yml | 2 +-
.../office_document_spawned_child_process_to_download.yml | 2 +-
deprecated/detections/office_product_spawn_cmd_process.yml | 2 +-
deprecated/detections/office_product_spawning_bitsadmin.yml | 2 +-
deprecated/detections/office_product_spawning_certutil.yml | 2 +-
deprecated/detections/office_product_spawning_mshta.yml | 2 +-
.../detections/office_product_spawning_rundll32_with_no_dll.yml | 2 +-
.../detections/office_product_spawning_windows_script_host.yml | 2 +-
deprecated/detections/office_product_spawning_wmic.yml | 2 +-
deprecated/detections/office_product_writing_cab_or_inf.yml | 2 +-
deprecated/detections/office_spawning_control.yml | 2 +-
deprecated/detections/okta_account_locked_out.yml | 2 +-
deprecated/detections/okta_account_lockout_events.yml | 2 +-
deprecated/detections/okta_failed_sso_attempts.yml | 2 +-
...okta_threatinsight_login_failure_with_high_unknown_users.yml | 2 +-
.../okta_threatinsight_suspected_passwordspray_attack.yml | 2 +-
deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml | 2 +-
deprecated/detections/osquery_pack___coldroot_detection.yml | 2 +-
deprecated/detections/password_policy_discovery_with_net.yml | 2 +-
deprecated/detections/processes_created_by_netsh.yml | 2 +-
deprecated/detections/prohibited_software_on_endpoint.yml | 2 +-
...reg_exe_used_to_hide_files_directories_via_registry_keys.yml | 2 +-
deprecated/detections/remote_registry_key_modifications.yml | 2 +-
deprecated/detections/remote_system_discovery_with_net.yml | 2 +-
.../detections/scheduled_tasks_used_in_badrabbit_ransomware.yml | 2 +-
.../detections/spectre_and_meltdown_vulnerable_systems.yml | 2 +-
.../detections/suspicious_changes_to_file_associations.yml | 2 +-
deprecated/detections/suspicious_email___uba_anomaly.yml | 2 +-
deprecated/detections/suspicious_file_write.yml | 2 +-
.../detections/suspicious_powershell_command_line_arguments.yml | 2 +-
deprecated/detections/suspicious_rundll32_rename.yml | 2 +-
.../suspicious_writes_to_system_volume_information.yml | 2 +-
deprecated/detections/uncommon_processes_on_endpoint.yml | 2 +-
deprecated/detections/unsigned_image_loaded_by_lsass.yml | 2 +-
deprecated/detections/unsuccessful_netbackup_backups.yml | 2 +-
deprecated/detections/web_fraud___account_harvesting.yml | 2 +-
deprecated/detections/web_fraud___anomalous_user_clickspeed.yml | 2 +-
.../detections/web_fraud___password_sharing_across_accounts.yml | 2 +-
.../detections/windows_command_shell_fetch_env_variables.yml | 2 +-
.../detections/windows_connhost_exe_started_forcefully.yml | 2 +-
.../detections/windows_dll_search_order_hijacking_hunt.yml | 2 +-
deprecated/detections/windows_hosts_file_modification.yml | 2 +-
deprecated/detections/windows_lateral_tool_transfer_remcom.yml | 2 +-
deprecated/detections/windows_modify_registry_reg_restore.yml | 2 +-
.../detections/windows_msiexec_with_network_connections.yml | 2 +-
.../detections/windows_network_share_interaction_with_net.yml | 2 +-
deprecated/detections/windows_office_product_spawning_msdt.yml | 2 +-
deprecated/detections/windows_query_registry_reg_save.yml | 2 +-
.../windows_service_stop_via_net__and_sc_application.yml | 2 +-
.../windows_valid_account_with_never_expires_password.yml | 2 +-
deprecated/detections/winword_spawning_cmd.yml | 2 +-
deprecated/detections/winword_spawning_powershell.yml | 2 +-
deprecated/detections/winword_spawning_windows_script_host.yml | 2 +-
deprecated/investigations/all_backup_logs_for_host.yml | 2 +-
.../investigations/amazon_eks_kubernetes_activity_by_src_ip.yml | 2 +-
.../aws_investigate_security_hub_alerts_by_dest.yml | 2 +-
.../aws_investigate_user_activities_by_accesskeyid.yml | 2 +-
.../investigations/aws_investigate_user_activities_by_arn.yml | 2 +-
deprecated/investigations/aws_network_acl_details_from_id.yml | 2 +-
.../aws_network_interface_details_via_resourceid.yml | 2 +-
.../investigations/aws_s3_bucket_details_via_bucketname.yml | 2 +-
deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml | 2 +-
deprecated/investigations/get_all_aws_activity_from_city.yml | 2 +-
deprecated/investigations/get_all_aws_activity_from_country.yml | 2 +-
.../investigations/get_all_aws_activity_from_ip_address.yml | 2 +-
deprecated/investigations/get_all_aws_activity_from_region.yml | 2 +-
deprecated/investigations/get_backup_logs_for_endpoint.yml | 2 +-
deprecated/investigations/get_certificate_logs_for_a_domain.yml | 2 +-
deprecated/investigations/get_dns_server_history_for_a_host.yml | 2 +-
deprecated/investigations/get_dns_traffic_ratio.yml | 2 +-
.../investigations/get_ec2_instance_details_by_instanceid.yml | 2 +-
deprecated/investigations/get_ec2_launch_details.yml | 2 +-
deprecated/investigations/get_email_info.yml | 2 +-
deprecated/investigations/get_emails_from_specific_sender.yml | 2 +-
...et_first_occurrence_and_last_occurrence_of_a_mac_address.yml | 2 +-
deprecated/investigations/get_history_of_email_sources.yml | 2 +-
.../get_logon_rights_modifications_for_endpoint.yml | 2 +-
.../investigations/get_logon_rights_modifications_for_user.yml | 2 +-
deprecated/investigations/get_notable_history.yml | 2 +-
.../get_outbound_emails_to_hidden_cobra_threat_actors.yml | 2 +-
deprecated/investigations/get_parent_process_info.yml | 2 +-
deprecated/investigations/get_process_file_activity.yml | 2 +-
deprecated/investigations/get_process_info.yml | 2 +-
.../get_process_information_for_port_activity.yml | 2 +-
.../get_process_responsible_for_the_dns_traffic.yml | 2 +-
deprecated/investigations/get_sysmon_wmi_activity_for_host.yml | 2 +-
.../get_web_session_information_via_session_id.yml | 2 +-
.../investigate_aws_activities_via_region_name.yml | 2 +-
.../investigate_aws_user_activities_by_user_field.yml | 2 +-
.../investigate_failed_logins_for_multiple_destinations.yml | 2 +-
.../investigations/investigate_network_traffic_from_src_ip.yml | 2 +-
deprecated/investigations/investigate_okta_activity_by_app.yml | 2 +-
.../investigations/investigate_okta_activity_by_ip_address.yml | 2 +-
.../investigations/investigate_pass_the_hash_attempts.yml | 2 +-
.../investigations/investigate_pass_the_ticket_attempts.yml | 2 +-
deprecated/investigations/investigate_previous_unseen_user.yml | 2 +-
.../investigate_successful_remote_desktop_authentications.yml | 2 +-
.../investigate_suspicious_strings_in_http_header.yml | 2 +-
.../investigations/investigate_user_activities_in_okta.yml | 2 +-
deprecated/investigations/investigate_web_posts_from_src.yml | 2 +-
deprecated/stories/aws_cryptomining.yml | 2 +-
deprecated/stories/aws_suspicious_provisioning_activities.yml | 2 +-
deprecated/stories/common_phishing_frameworks.yml | 2 +-
.../container_implantation_monitoring_and_investigation.yml | 2 +-
deprecated/stories/host_redirection.yml | 2 +-
deprecated/stories/kubernetes_sensitive_role_activity.yml | 2 +-
deprecated/stories/lateral_movement.yml | 2 +-
deprecated/stories/monitor_backup_solution.yml | 2 +-
deprecated/stories/monitor_for_unauthorized_software.yml | 2 +-
deprecated/stories/office_365_detections.yml | 2 +-
deprecated/stories/spectre_and_meltdown_vulnerabilities.yml | 2 +-
deprecated/stories/suspicious_aws_ec2_activities.yml | 2 +-
deprecated/stories/unusual_aws_ec2_modifications.yml | 2 +-
deprecated/stories/web_fraud_detection.yml | 2 +-
228 files changed, 228 insertions(+), 228 deletions(-)
diff --git a/deprecated/baselines/add_prohibited_processes_to_enterprise_security.yml b/deprecated/baselines/add_prohibited_processes_to_enterprise_security.yml
index 607a5f9829..571031fc48 100644
--- a/deprecated/baselines/add_prohibited_processes_to_enterprise_security.yml
+++ b/deprecated/baselines/add_prohibited_processes_to_enterprise_security.yml
@@ -4,7 +4,7 @@ version: 1
date: '2017-09-15'
author: David Dorsey, Splunk
type: Baseline
-status: deprecated
+status: removed
description: This search takes the existing interesting process table from ES, filters
out any existing additions added by ESCU and then updates the table with processes
identified by ESCU that should be prohibited on your endpoints.
diff --git a/deprecated/baselines/baseline_of_api_calls_per_user_arn.yml b/deprecated/baselines/baseline_of_api_calls_per_user_arn.yml
index 461b657a67..2673563607 100644
--- a/deprecated/baselines/baseline_of_api_calls_per_user_arn.yml
+++ b/deprecated/baselines/baseline_of_api_calls_per_user_arn.yml
@@ -4,7 +4,7 @@ version: 1
date: '2018-04-09'
author: David Dorsey, Splunk
type: Baseline
-status: deprecated
+status: removed
description: This search establishes, on a per-hour basis, the average and the standard
deviation of the number of API calls made by each user. Also recorded is the number
of data points for each user. This table is then outputted to a lookup file to allow
diff --git a/deprecated/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml b/deprecated/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml
index ade1932593..f239369ff1 100644
--- a/deprecated/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml
+++ b/deprecated/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml
@@ -4,7 +4,7 @@ version: 1
date: '2019-11-14'
author: Jason Brewer, Splunk
type: Baseline
-status: deprecated
+status: removed
description: This search is used to build a Machine Learning Toolkit (MLTK) model
for how many RunInstances users do in the environment. By default, the search uses
the last 90 days of data to build the model. The model created by this search is
diff --git a/deprecated/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml b/deprecated/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml
index a6d890da08..66859b3998 100644
--- a/deprecated/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml
+++ b/deprecated/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml
@@ -4,7 +4,7 @@ version: 1
date: '2019-11-14'
author: Jason Brewer, Splunk
type: Baseline
-status: deprecated
+status: removed
description: This search is used to build a Machine Learning Toolkit (MLTK) model
for how many TerminateInstances users do in the environment. By default, the search
uses the last 90 days of data to build the model. The model created by this search
diff --git a/deprecated/baselines/monitor_successful_backups.yml b/deprecated/baselines/monitor_successful_backups.yml
index f178992d32..ab88e7b269 100644
--- a/deprecated/baselines/monitor_successful_backups.yml
+++ b/deprecated/baselines/monitor_successful_backups.yml
@@ -4,7 +4,7 @@ version: 2
date: '2025-02-27'
author: David Dorsey, Splunk
type: Baseline
-status: deprecated
+status: removed
description: This search is intended to give you a feel for how often successful backups
are conducted in your environment. Fluctuations in these numbers will allow you
to determine when you should investigate.
diff --git a/deprecated/baselines/monitor_unsuccessful_backups.yml b/deprecated/baselines/monitor_unsuccessful_backups.yml
index bd694ee2b0..19c0d4ca73 100644
--- a/deprecated/baselines/monitor_unsuccessful_backups.yml
+++ b/deprecated/baselines/monitor_unsuccessful_backups.yml
@@ -4,7 +4,7 @@ version: 2
date: '2025-02-27'
author: David Dorsey, Splunk
type: Baseline
-status: deprecated
+status: removed
description: This search is intended to give you a feel for how often backup failures
happen in your environments. Fluctuations in these numbers will allow you to determine
when you should investigate.
diff --git a/deprecated/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml b/deprecated/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml
index 71a860c70b..8725c77478 100644
--- a/deprecated/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml
+++ b/deprecated/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml
@@ -4,7 +4,7 @@ version: 1
date: '2018-04-16'
author: Bhavin Patel, Splunk
type: Baseline
-status: deprecated
+status: removed
description: This search looks for successful API calls made by different user roles,
then creates a baseline of the earliest and latest times we have encountered this
user role. It also returns the name of the API call in our dataset--grouped by user
diff --git a/deprecated/baselines/previously_seen_aws_provisioning_activity_sources.yml b/deprecated/baselines/previously_seen_aws_provisioning_activity_sources.yml
index b0c5e90290..96f8dccd31 100644
--- a/deprecated/baselines/previously_seen_aws_provisioning_activity_sources.yml
+++ b/deprecated/baselines/previously_seen_aws_provisioning_activity_sources.yml
@@ -4,7 +4,7 @@ version: 1
date: '2018-03-16'
author: David Dorsey, Splunk
type: Baseline
-status: deprecated
+status: removed
description: This search builds a table of the first and last times seen for every
IP address (along with its physical location) previously associated with cloud-provisioning
activity. This is broadly defined as any event that runs or creates something.
diff --git a/deprecated/baselines/previously_seen_aws_regions.yml b/deprecated/baselines/previously_seen_aws_regions.yml
index 24fd59423f..c64933b437 100644
--- a/deprecated/baselines/previously_seen_aws_regions.yml
+++ b/deprecated/baselines/previously_seen_aws_regions.yml
@@ -4,7 +4,7 @@ version: 2
date: '2025-02-27'
author: Bhavin Patel, Splunk
type: Baseline
-status: deprecated
+status: removed
description: This search looks for CloudTrail events where an AWS instance is started
and creates a baseline of most recent time (latest) and the first time (earliest)
we've seen this region in our dataset grouped by the value awsRegion for the last
diff --git a/deprecated/baselines/previously_seen_ec2_amis.yml b/deprecated/baselines/previously_seen_ec2_amis.yml
index 1550cdf588..bc7c7ec00e 100644
--- a/deprecated/baselines/previously_seen_ec2_amis.yml
+++ b/deprecated/baselines/previously_seen_ec2_amis.yml
@@ -4,7 +4,7 @@ version: 2
date: '2025-01-16'
author: David Dorsey, Splunk
type: Baseline
-status: deprecated
+status: removed
description: This search builds a table of previously seen AMIs used to launch EC2
instances
search: '`cloudtrail` eventName=RunInstances errorCode=success | rename requestParameters.instancesSet.items{}.imageId
diff --git a/deprecated/baselines/previously_seen_ec2_instance_types.yml b/deprecated/baselines/previously_seen_ec2_instance_types.yml
index cfff4e6d58..4c1f2fa439 100644
--- a/deprecated/baselines/previously_seen_ec2_instance_types.yml
+++ b/deprecated/baselines/previously_seen_ec2_instance_types.yml
@@ -4,7 +4,7 @@ version: 2
date: '2025-01-16'
author: David Dorsey, Splunk
type: Baseline
-status: deprecated
+status: removed
description: This search builds a table of previously seen EC2 instance types
search: '`cloudtrail` eventName=RunInstances errorCode=success | rename requestParameters.instanceType
as instanceType | fillnull value="m1.small" instanceType | stats earliest(_time)
diff --git a/deprecated/baselines/previously_seen_ec2_launches_by_user.yml b/deprecated/baselines/previously_seen_ec2_launches_by_user.yml
index d1aa8e8045..d90c9b44cc 100644
--- a/deprecated/baselines/previously_seen_ec2_launches_by_user.yml
+++ b/deprecated/baselines/previously_seen_ec2_launches_by_user.yml
@@ -4,7 +4,7 @@ version: 2
date: '2025-01-16'
author: David Dorsey, Splunk
type: Baseline
-status: deprecated
+status: removed
description: This search builds a table of previously seen ARNs that have launched
a EC2 instance.
search: '`cloudtrail` eventName=RunInstances errorCode=success | rename userIdentity.arn
diff --git a/deprecated/baselines/previously_seen_ec2_modifications_by_user.yml b/deprecated/baselines/previously_seen_ec2_modifications_by_user.yml
index 426a1181ad..09a26dca86 100644
--- a/deprecated/baselines/previously_seen_ec2_modifications_by_user.yml
+++ b/deprecated/baselines/previously_seen_ec2_modifications_by_user.yml
@@ -4,7 +4,7 @@ version: 2
date: '2025-02-27'
author: David Dorsey, Splunk
type: Baseline
-status: deprecated
+status: removed
description: This search builds a table of previously seen ARNs that have launched
a EC2 instance.
search: '`cloudtrail` `ec2_modification_api_calls` errorCode=success | spath output=arn
diff --git a/deprecated/baselines/previously_seen_users_in_cloudtrail.yml b/deprecated/baselines/previously_seen_users_in_cloudtrail.yml
index f8e40480d7..2e3a762c8d 100644
--- a/deprecated/baselines/previously_seen_users_in_cloudtrail.yml
+++ b/deprecated/baselines/previously_seen_users_in_cloudtrail.yml
@@ -4,7 +4,7 @@ version: 1
date: '2018-04-30'
author: Jason Brewer, Splunk
type: Baseline
-status: deprecated
+status: removed
description: This search looks for CloudTrail events where a user logs into the console,
then creates a baseline of the latest and earliest times, City, Region, and Country
we have encountered this user in our dataset, grouped by ARN, within the last 30
diff --git a/deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml b/deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml
index 763652d0e0..54085fb1b2 100644
--- a/deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml
+++ b/deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml
@@ -4,7 +4,7 @@ version: 2
date: '2025-02-27'
author: David Dorsey, Splunk
type: Baseline
-status: deprecated
+status: removed
description: Some AV applications can cause the Spectre/Meltdown patch for Windows
not to install successfully. This registry key is supposed to be created by the
AV engine when it has been patched to be able to handle the Windows patch. If this
diff --git a/deprecated/baselines/update_previously_seen_users_in_cloudtrail.yml b/deprecated/baselines/update_previously_seen_users_in_cloudtrail.yml
index 063ad93dcc..b12c1c002f 100644
--- a/deprecated/baselines/update_previously_seen_users_in_cloudtrail.yml
+++ b/deprecated/baselines/update_previously_seen_users_in_cloudtrail.yml
@@ -4,7 +4,7 @@ version: 2
date: '2025-01-16'
author: Jason Brewer, Splunk
type: Baseline
-status: deprecated
+status: removed
description: This search looks for CloudTrail events where a user logs into the console,
then updates the baseline of the latest and earliest times, City, Region, and Country
we have encountered this user in our dataset, grouped by ARN, within the last hour.
diff --git a/deprecated/detections/abnormally_high_aws_instances_launched_by_user.yml b/deprecated/detections/abnormally_high_aws_instances_launched_by_user.yml
index e46dec6369..595bc299da 100644
--- a/deprecated/detections/abnormally_high_aws_instances_launched_by_user.yml
+++ b/deprecated/detections/abnormally_high_aws_instances_launched_by_user.yml
@@ -3,7 +3,7 @@ id: 2a9b80d3-6340-4345-b5ad-290bf5d0dac4
version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This search looks for AWS CloudTrail events where a user successfully
launches an abnormally high number of instances. This search is deprecated and have
diff --git a/deprecated/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml b/deprecated/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml
index 9acc4411b2..d70e23808e 100644
--- a/deprecated/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml
+++ b/deprecated/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml
@@ -3,7 +3,7 @@ id: dec41ad5-d579-42cb-b4c6-f5dbb778bbe5
version: 5
date: '2024-11-14'
author: Jason Brewer, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This search looks for AWS CloudTrail events where a user successfully
launches an abnormally high number of instances. This search is deprecated and have
diff --git a/deprecated/detections/abnormally_high_aws_instances_terminated_by_user.yml b/deprecated/detections/abnormally_high_aws_instances_terminated_by_user.yml
index ae3c15024b..7ce46aff25 100644
--- a/deprecated/detections/abnormally_high_aws_instances_terminated_by_user.yml
+++ b/deprecated/detections/abnormally_high_aws_instances_terminated_by_user.yml
@@ -3,7 +3,7 @@ id: 8d301246-fccf-45e2-a8e7-3655fd14379c
version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This search looks for AWS CloudTrail events where an abnormally high
number of instances were successfully terminated by a user in a 10-minute window.
diff --git a/deprecated/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml b/deprecated/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml
index 04f88a704a..4581feda8f 100644
--- a/deprecated/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml
+++ b/deprecated/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml
@@ -3,7 +3,7 @@ id: 1c02b86a-cd85-473e-a50b-014a9ac8fe3e
version: 5
date: '2024-11-14'
author: Jason Brewer, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This search looks for AWS CloudTrail events where a user successfully
terminates an abnormally high number of instances. This search is deprecated and
diff --git a/deprecated/detections/account_discovery_with_net_app.yml b/deprecated/detections/account_discovery_with_net_app.yml
index 074b4fba7a..ddb1846f2e 100644
--- a/deprecated/detections/account_discovery_with_net_app.yml
+++ b/deprecated/detections/account_discovery_with_net_app.yml
@@ -3,7 +3,7 @@ id: 339805ce-ac30-11eb-b87d-acde48001122
version: 9
date: '2025-02-10'
author: Teoderick Contreras, Splunk, TheLawsOfChaos, Github Community
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated in favour of the more generic
"45e52536-ae42-11eb-b5c6-acde48001122". The following analytic detects potential
diff --git a/deprecated/detections/asl_aws_createaccesskey.yml b/deprecated/detections/asl_aws_createaccesskey.yml
index e7588388f6..a4fe172ca3 100644
--- a/deprecated/detections/asl_aws_createaccesskey.yml
+++ b/deprecated/detections/asl_aws_createaccesskey.yml
@@ -3,7 +3,7 @@ id: ccb3e4af-23d6-407f-9842-a26212816c9e
version: 3
date: '2024-11-14'
author: Patrick Bareiss, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This detection rule monitors for the creation of AWS Identity and Access
Management (IAM) access keys. An IAM access key consists of an access key ID and
diff --git a/deprecated/detections/asl_aws_excessive_security_scanning.yml b/deprecated/detections/asl_aws_excessive_security_scanning.yml
index 0ee3a463e3..6f8c8c2cf2 100644
--- a/deprecated/detections/asl_aws_excessive_security_scanning.yml
+++ b/deprecated/detections/asl_aws_excessive_security_scanning.yml
@@ -3,7 +3,7 @@ id: ff2bfdbc-65b7-4434-8f08-d55761d1d446
version: 4
date: '2024-11-14'
author: Patrick Bareiss, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This search looks for AWS CloudTrail events and analyse the amount of
eventNames which starts with Describe by a single user. This indicates that this
diff --git a/deprecated/detections/asl_aws_password_policy_changes.yml b/deprecated/detections/asl_aws_password_policy_changes.yml
index d791f17208..faa1c0ef93 100644
--- a/deprecated/detections/asl_aws_password_policy_changes.yml
+++ b/deprecated/detections/asl_aws_password_policy_changes.yml
@@ -3,7 +3,7 @@ id: 5ade5937-11a2-4363-ba6b-39a3ee8d5b1a
version: 3
date: '2024-11-14'
author: Patrick Bareiss, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search looks for AWS CloudTrail events from Amazon Security Lake
where a user is making successful API calls to view/update/delete the existing password
diff --git a/deprecated/detections/attempt_to_stop_security_service.yml b/deprecated/detections/attempt_to_stop_security_service.yml
index 1964d9b110..0fca86d98e 100644
--- a/deprecated/detections/attempt_to_stop_security_service.yml
+++ b/deprecated/detections/attempt_to_stop_security_service.yml
@@ -3,7 +3,7 @@ id: c8e349c6-b97c-486e-8949-bd7bcd1f3910
version: 11
date: '2025-02-10'
author: Rico Valdez, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated. The following analytic detects
attempts to stop security-related services on an endpoint, which may indicate malicious
diff --git a/deprecated/detections/attempted_credential_dump_from_registry_via_reg_exe.yml b/deprecated/detections/attempted_credential_dump_from_registry_via_reg_exe.yml
index 65c188a991..5dfdbf1e49 100644
--- a/deprecated/detections/attempted_credential_dump_from_registry_via_reg_exe.yml
+++ b/deprecated/detections/attempted_credential_dump_from_registry_via_reg_exe.yml
@@ -3,7 +3,7 @@ id: e9fb4a59-c5fb-440a-9f24-191fbc6b2911
version: 14
date: '2025-02-10'
author: Patrick Bareiss, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated in favour of "8bbb7d58-b360-11eb-ba21-acde48001122".
The following analytic detects the execution of reg.exe with parameters that export
diff --git a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_city.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_city.yml
index 91a576d2f0..93e513cc2c 100644
--- a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_city.yml
+++ b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_city.yml
@@ -3,7 +3,7 @@ id: 344a1778-0b25-490c-adb1-de8beddf59cd
version: 5
date: '2024-11-14'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This search looks for AWS provisioning activities from previously unseen
cities. Provisioning activities are defined broadly as any event that begins with
diff --git a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_country.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_country.yml
index 986a31d1f0..5c7257858e 100644
--- a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_country.yml
+++ b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_country.yml
@@ -3,7 +3,7 @@ id: ceb8d3d8-06cb-49eb-beaf-829526e33ff0
version: 5
date: '2024-11-14'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This search looks for AWS provisioning activities from previously unseen
countries. Provisioning activities are defined broadly as any event that begins
diff --git a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml
index 5568175da0..13a7f90294 100644
--- a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml
+++ b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml
@@ -3,7 +3,7 @@ id: 42e15012-ac14-4801-94f4-f1acbe64880b
version: 5
date: '2024-11-14'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This search looks for AWS provisioning activities from previously unseen
IP addresses. Provisioning activities are defined broadly as any event that begins
diff --git a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_region.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_region.yml
index 5efa68a449..039f1cd76c 100644
--- a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_region.yml
+++ b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_region.yml
@@ -3,7 +3,7 @@ id: 7971d3df-da82-4648-a6e5-b5637bea5253
version: 4
date: '2024-11-14'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This search looks for AWS provisioning activities from previously unseen
regions. Region in this context is similar to a state in the United States. Provisioning
diff --git a/deprecated/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml b/deprecated/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml
index 866bca7809..c337fae5d0 100644
--- a/deprecated/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml
+++ b/deprecated/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml
@@ -3,7 +3,7 @@ id: 7f227943-2196-4d4d-8d6a-ac8cb308e61c
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides information on Kubernetes accounts accessing sensitve
objects such as configmaps or secrets
diff --git a/deprecated/detections/change_default_file_association.yml b/deprecated/detections/change_default_file_association.yml
index e5e583848a..3025b5adeb 100644
--- a/deprecated/detections/change_default_file_association.yml
+++ b/deprecated/detections/change_default_file_association.yml
@@ -3,7 +3,7 @@ id: 462d17d8-1f71-11ec-ad07-acde48001122
version: 6
date: '2025-02-10'
author: Teoderick Contreras, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated. The following analytic detects
suspicious registry modifications that change the default file association to execute
diff --git a/deprecated/detections/clients_connecting_to_multiple_dns_servers.yml b/deprecated/detections/clients_connecting_to_multiple_dns_servers.yml
index eb01c32ea2..d5371b4c99 100644
--- a/deprecated/detections/clients_connecting_to_multiple_dns_servers.yml
+++ b/deprecated/detections/clients_connecting_to_multiple_dns_servers.yml
@@ -3,7 +3,7 @@ id: 74ec6f18-604b-4202-a567-86b2066be3ce
version: 6
date: '2024-11-14'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
type: TTP
description: This search allows you to identify the endpoints that have connected
to more than five DNS servers and made DNS Queries over the time frame of the search.
diff --git a/deprecated/detections/cloud_network_access_control_list_deleted.yml b/deprecated/detections/cloud_network_access_control_list_deleted.yml
index 8a9036b76a..bb84da3f50 100644
--- a/deprecated/detections/cloud_network_access_control_list_deleted.yml
+++ b/deprecated/detections/cloud_network_access_control_list_deleted.yml
@@ -3,7 +3,7 @@ id: 021abc51-1862-41dd-ad43-43c739c0a983
version: 4
date: '2024-11-14'
author: Peter Gael, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: Enforcing network-access controls is one of the defensive mechanisms
used by cloud administrators to restrict access to a cloud instance. After the attacker
diff --git a/deprecated/detections/cmdline_tool_not_executed_in_cmd_shell.yml b/deprecated/detections/cmdline_tool_not_executed_in_cmd_shell.yml
index 74087020ed..772d5444d8 100644
--- a/deprecated/detections/cmdline_tool_not_executed_in_cmd_shell.yml
+++ b/deprecated/detections/cmdline_tool_not_executed_in_cmd_shell.yml
@@ -3,7 +3,7 @@ id: 6c3f7dd8-153c-11ec-ac2d-acde48001122
version: 9
date: '2025-02-10'
author: Teoderick Contreras, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic identifies instances where `ipconfig.exe`, `systeminfo.exe`,
or similar tools are executed by a non-standard parent process, excluding CMD, PowerShell,
diff --git a/deprecated/detections/correlation_by_repository_and_risk.yml b/deprecated/detections/correlation_by_repository_and_risk.yml
index 681f046bf4..a3e5fea3e7 100644
--- a/deprecated/detections/correlation_by_repository_and_risk.yml
+++ b/deprecated/detections/correlation_by_repository_and_risk.yml
@@ -3,7 +3,7 @@ id: 8da9fdd9-6a1b-4ae0-8a34-8c25e6be9687
version: 4
date: '2025-02-10'
author: Patrick Bareiss, Splunk
-status: deprecated
+status: removed
type: Correlation
description: |-
This search has been deprecated and updated with Risk Rule for Dev Sec Ops by Repository detection. The following analytic detects by correlating repository and risk score to identify patterns and trends in the data based on the level of risk associated. The analytic adds any null values and calculates the sum of the risk scores for each detection. Then, the analytic captures the source and user information for each detection and sorts the results in ascending order based on the risk score. Finally, the analytic filters the detections with a risk score below 80 and focuses only on high-risk detections.This detection is important because it provides valuable insights into the distribution of high-risk activities across different repositories. It also identifies the most vulnerable repositories that are frequently targeted by potential threats. Additionally, it proactively detects and responds to potential threats, thereby minimizing the impact of attacks and safeguarding critical assets. Finally, it provides a comprehensive view of the risk landscape and helps to make informed decisions to protect the organization's data and infrastructure. False positives might occur so it is important to identify the impact of the attack and prioritize response and mitigation efforts.
diff --git a/deprecated/detections/correlation_by_user_and_risk.yml b/deprecated/detections/correlation_by_user_and_risk.yml
index d121453be9..95a4e50e10 100644
--- a/deprecated/detections/correlation_by_user_and_risk.yml
+++ b/deprecated/detections/correlation_by_user_and_risk.yml
@@ -3,7 +3,7 @@ id: 610e12dc-b6fa-4541-825e-4a0b3b6f6773
version: 4
date: '2025-02-10'
author: Patrick Bareiss, Splunk
-status: deprecated
+status: removed
type: Correlation
description: |-
The following analytic detects the correlation between the user and risk score and identifies users with a high risk score that pose a significant security risk such as unauthorized access attempts, suspicious behavior, or potential insider threats. Next, the analytic calculates the sum of the risk scores and groups the results by user, the corresponding signals, and the repository. The results are sorted in descending order based on the risk score and filtered to include records with a risk score greater than 80. Finally, the results are passed through a correlation filter specific to the user and risk. This detection is important because it identifies users who have a high risk score and helps to prioritize investigations and allocate resources. False positives might occur but the impact of such an attack can vary depending on the specific scenario such as data exfiltration, system compromise, or the disruption of critical services. Please investigate this notable event.
diff --git a/deprecated/detections/create_local_admin_accounts_using_net_exe.yml b/deprecated/detections/create_local_admin_accounts_using_net_exe.yml
index 05bd612ba3..5534cdc2d0 100644
--- a/deprecated/detections/create_local_admin_accounts_using_net_exe.yml
+++ b/deprecated/detections/create_local_admin_accounts_using_net_exe.yml
@@ -3,7 +3,7 @@ id: b89919ed-fe5f-492c-b139-151bb162040e
version: 17
date: '2025-02-10'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated. The following analytic detects
the creation of local administrator accounts using the net.exe command. It leverages
diff --git a/deprecated/detections/deleting_of_net_users.yml b/deprecated/detections/deleting_of_net_users.yml
index 379264584f..48c661fd73 100644
--- a/deprecated/detections/deleting_of_net_users.yml
+++ b/deprecated/detections/deleting_of_net_users.yml
@@ -3,7 +3,7 @@ id: 1c8c6f66-acce-11eb-aafb-acde48001122
version: 8
date: '2025-01-24'
author: Teoderick Contreras, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated.
The following analytic detects the use of net.exe or net1.exe command-line
diff --git a/deprecated/detections/detect_activity_related_to_pass_the_hash_attacks.yml b/deprecated/detections/detect_activity_related_to_pass_the_hash_attacks.yml
index 9b6c9aec2c..c57b95da42 100644
--- a/deprecated/detections/detect_activity_related_to_pass_the_hash_attacks.yml
+++ b/deprecated/detections/detect_activity_related_to_pass_the_hash_attacks.yml
@@ -3,7 +3,7 @@ id: f5939373-8054-40ad-8c64-cec478a22a4b
version: 10
date: '2025-02-10'
author: Bhavin Patel, Patrick Bareiss, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search looks for specific authentication events from the Windows
Security Event logs to detect potential attempts at using the Pass-the-Hash technique.
diff --git a/deprecated/detections/detect_api_activity_from_users_without_mfa.yml b/deprecated/detections/detect_api_activity_from_users_without_mfa.yml
index e0ad2efcfc..f7da7f035d 100644
--- a/deprecated/detections/detect_api_activity_from_users_without_mfa.yml
+++ b/deprecated/detections/detect_api_activity_from_users_without_mfa.yml
@@ -3,7 +3,7 @@ id: 4d46e8bd-4072-48e4-92db-0325889ef894
version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search looks for AWS CloudTrail events where a user logged into
the AWS account, is making API calls and has not enabled Multi Factor authentication.
diff --git a/deprecated/detections/detect_aws_api_activities_from_unapproved_accounts.yml b/deprecated/detections/detect_aws_api_activities_from_unapproved_accounts.yml
index 23e833aac1..98b40ed434 100644
--- a/deprecated/detections/detect_aws_api_activities_from_unapproved_accounts.yml
+++ b/deprecated/detections/detect_aws_api_activities_from_unapproved_accounts.yml
@@ -3,7 +3,7 @@ id: ada0f478-84a8-4641-a3f1-d82362d4bd55
version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search looks for successful AWS CloudTrail activity by user accounts
that are not listed in the identity table or `aws_service_accounts.csv`. It returns
diff --git a/deprecated/detections/detect_critical_alerts_from_security_tools.yml b/deprecated/detections/detect_critical_alerts_from_security_tools.yml
index 79ba56809d..a1bdeec87e 100644
--- a/deprecated/detections/detect_critical_alerts_from_security_tools.yml
+++ b/deprecated/detections/detect_critical_alerts_from_security_tools.yml
@@ -3,7 +3,7 @@ id: 483e8a68-f2f7-45be-8fc9-bf725f0e22fd
version: 2
date: '2025-01-13'
author: Gowthamaraj Rajendran, Patrick Bareiss, Bhavin Patel, Bryan Pluta, Splunk
-status: deprecated
+status: removed
type: TTP
data_source:
- Windows Defender Alerts
diff --git a/deprecated/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml b/deprecated/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml
index 2d4975f3ec..05a6f77ef4 100644
--- a/deprecated/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml
+++ b/deprecated/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml
@@ -3,7 +3,7 @@ id: 24dd17b1-e2fb-4c31-878c-d4f226595bfa
version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: TTP
description: This search looks for DNS requests for phishing domains that are leveraging
EvilGinx tools to mimic websites.
diff --git a/deprecated/detections/detect_long_dns_txt_record_response.yml b/deprecated/detections/detect_long_dns_txt_record_response.yml
index 57a2fb80be..1329c3bf26 100644
--- a/deprecated/detections/detect_long_dns_txt_record_response.yml
+++ b/deprecated/detections/detect_long_dns_txt_record_response.yml
@@ -3,7 +3,7 @@ id: 05437c07-62f5-452e-afdc-04dd44815bb9
version: 5
date: '2024-11-14'
author: Rico Valdez, Splunk
-status: deprecated
+status: removed
type: TTP
description: This search is used to detect attempts to use DNS tunneling, by calculating
the length of responses to DNS TXT queries. Endpoints using DNS as a method of transmission
diff --git a/deprecated/detections/detect_mimikatz_using_loaded_images.yml b/deprecated/detections/detect_mimikatz_using_loaded_images.yml
index 75e66c0061..6fbe7ff5e7 100644
--- a/deprecated/detections/detect_mimikatz_using_loaded_images.yml
+++ b/deprecated/detections/detect_mimikatz_using_loaded_images.yml
@@ -3,7 +3,7 @@ id: 29e307ba-40af-4ab2-91b2-3c6b392bbba0
version: 4
date: '2025-02-10'
author: Patrick Bareiss, Splunk
-status: deprecated
+status: removed
type: TTP
description: This search looks for reading loaded Images unique to credential dumping
with Mimikatz. Deprecated because mimikatz libraries changed and very noisy sysmon
diff --git a/deprecated/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml b/deprecated/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml
index aa9cabe8d3..a97cc408bb 100644
--- a/deprecated/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml
+++ b/deprecated/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml
@@ -3,7 +3,7 @@ id: 98917be2-bfc8-475a-8618-a9bb06575188
version: 5
date: '2024-11-14'
author: Rico Valdez, Splunk
-status: deprecated
+status: removed
type: TTP
description: This search looks for PowerShell requesting privileges consistent with
credential dumping. Deprecated, looks like things changed from a logging perspective.
diff --git a/deprecated/detections/detect_new_api_calls_from_user_roles.yml b/deprecated/detections/detect_new_api_calls_from_user_roles.yml
index 5ed0943c52..6875898fc1 100644
--- a/deprecated/detections/detect_new_api_calls_from_user_roles.yml
+++ b/deprecated/detections/detect_new_api_calls_from_user_roles.yml
@@ -3,7 +3,7 @@ id: 22773e84-bac0-4595-b086-20d3f335b4f1
version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This search detects new API calls that have either never been seen before
or that have not been seen in the previous hour, where the identity type is `AssumedRole`.
diff --git a/deprecated/detections/detect_new_user_aws_console_login.yml b/deprecated/detections/detect_new_user_aws_console_login.yml
index 1713d3b52d..75f7756e52 100644
--- a/deprecated/detections/detect_new_user_aws_console_login.yml
+++ b/deprecated/detections/detect_new_user_aws_console_login.yml
@@ -3,7 +3,7 @@ id: ada0f478-84a8-4641-a3f3-d82362dffd75
version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search looks for AWS CloudTrail events wherein a console login event
by a user was recorded within the last hour, then compares the event to a lookup
diff --git a/deprecated/detections/detect_processes_used_for_system_network_configuration_discovery.yml b/deprecated/detections/detect_processes_used_for_system_network_configuration_discovery.yml
index d0851935d2..e46c595fe9 100644
--- a/deprecated/detections/detect_processes_used_for_system_network_configuration_discovery.yml
+++ b/deprecated/detections/detect_processes_used_for_system_network_configuration_discovery.yml
@@ -3,7 +3,7 @@ id: a51bfe1a-94f0-48cc-b1e4-16ae10145893
version: 8
date: '2025-01-24'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated.
The following analytic identifies the rapid execution of processes used
diff --git a/deprecated/detections/detect_spike_in_aws_api_activity.yml b/deprecated/detections/detect_spike_in_aws_api_activity.yml
index 5a7efe7007..97feb48d8b 100644
--- a/deprecated/detections/detect_spike_in_aws_api_activity.yml
+++ b/deprecated/detections/detect_spike_in_aws_api_activity.yml
@@ -3,7 +3,7 @@ id: ada0f478-84a8-4641-a3f1-d32362d4bd55
version: 5
date: '2024-11-14'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This search will detect users creating spikes of API activity in your
AWS environment. It will also update the cache file that factors in the latest
diff --git a/deprecated/detections/detect_spike_in_network_acl_activity.yml b/deprecated/detections/detect_spike_in_network_acl_activity.yml
index a7e693bf9e..fa43ca2e7d 100644
--- a/deprecated/detections/detect_spike_in_network_acl_activity.yml
+++ b/deprecated/detections/detect_spike_in_network_acl_activity.yml
@@ -3,7 +3,7 @@ id: ada0f478-84a8-4641-a1f1-e32372d4bd53
version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This search will detect users creating spikes in API activity related
to network access-control lists (ACLs)in your AWS environment. This search is deprecated
diff --git a/deprecated/detections/detect_spike_in_security_group_activity.yml b/deprecated/detections/detect_spike_in_security_group_activity.yml
index de1cad3b6d..a6c75ede25 100644
--- a/deprecated/detections/detect_spike_in_security_group_activity.yml
+++ b/deprecated/detections/detect_spike_in_security_group_activity.yml
@@ -3,7 +3,7 @@ id: ada0f478-84a8-4641-a3f1-e32372d4bd53
version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This search will detect users creating spikes in API activity related
to security groups in your AWS environment. It will also update the cache file
diff --git a/deprecated/detections/detect_usb_device_insertion.yml b/deprecated/detections/detect_usb_device_insertion.yml
index 2d6dd088f5..98ea80b3e0 100644
--- a/deprecated/detections/detect_usb_device_insertion.yml
+++ b/deprecated/detections/detect_usb_device_insertion.yml
@@ -3,7 +3,7 @@ id: 104658f4-afdc-499f-9719-17a43f9826f5
version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: TTP
description: The search is used to detect hosts that generate Windows Event ID 4663
for successful attempts to write to or read from a removable storage and Event ID
diff --git a/deprecated/detections/detect_web_traffic_to_dynamic_domain_providers.yml b/deprecated/detections/detect_web_traffic_to_dynamic_domain_providers.yml
index deadd5d14b..7b61741b56 100644
--- a/deprecated/detections/detect_web_traffic_to_dynamic_domain_providers.yml
+++ b/deprecated/detections/detect_web_traffic_to_dynamic_domain_providers.yml
@@ -3,7 +3,7 @@ id: 134da869-e264-4a8f-8d7e-fcd01c18f301
version: 6
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: TTP
description: This search looks for web connections to dynamic DNS providers.
data_source: []
diff --git a/deprecated/detections/detect_webshell_exploit_behavior.yml b/deprecated/detections/detect_webshell_exploit_behavior.yml
index a460946a1a..679f7cfd64 100644
--- a/deprecated/detections/detect_webshell_exploit_behavior.yml
+++ b/deprecated/detections/detect_webshell_exploit_behavior.yml
@@ -3,7 +3,7 @@ id: 22597426-6dbd-49bd-bcdc-4ec19857192f
version: 8
date: '2025-02-10'
author: Steven Dick
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated. The following analytic identifies
the execution of suspicious processes typically associated with webshell activity
diff --git a/deprecated/detections/detection_of_dns_tunnels.yml b/deprecated/detections/detection_of_dns_tunnels.yml
index e903bf4d9a..cabfa19b64 100644
--- a/deprecated/detections/detection_of_dns_tunnels.yml
+++ b/deprecated/detections/detection_of_dns_tunnels.yml
@@ -3,7 +3,7 @@ id: 104658f4-afdc-499f-9719-17a43f9826f4
version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: TTP
description: "This search is used to detect DNS tunneling, by calculating the sum
of the length of DNS queries and DNS answers. The search also filters out potential
diff --git a/deprecated/detections/disabling_net_user_account.yml b/deprecated/detections/disabling_net_user_account.yml
index 409e89854a..56936042e3 100644
--- a/deprecated/detections/disabling_net_user_account.yml
+++ b/deprecated/detections/disabling_net_user_account.yml
@@ -3,7 +3,7 @@ id: c0325326-acd6-11eb-98c2-acde48001122
version: 8
date: '2025-01-24'
author: Teoderick Contreras, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated.
The following analytic detects the use of the `net.exe` utility to disable
diff --git a/deprecated/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml b/deprecated/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml
index b52f87457a..680f232852 100644
--- a/deprecated/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml
+++ b/deprecated/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml
@@ -3,7 +3,7 @@ id: 1a67f15a-f4ff-4170-84e9-08cf6f75d6f6
version: 6
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: TTP
description: This search will detect DNS requests resolved by unauthorized DNS servers.
Legitimate DNS servers should be identified in the Enterprise Security Assets and
diff --git a/deprecated/detections/dns_record_changed.yml b/deprecated/detections/dns_record_changed.yml
index 1da12999ba..d620468bcf 100644
--- a/deprecated/detections/dns_record_changed.yml
+++ b/deprecated/detections/dns_record_changed.yml
@@ -3,7 +3,7 @@ id: 44d3a43e-dcd5-49f7-8356-5209bb369065
version: 6
date: '2024-11-14'
author: Jose Hernandez, Splunk
-status: deprecated
+status: removed
type: TTP
description: The search takes the DNS records and their answers results of the discovered_dns_records
lookup and finds if any records have changed by searching DNS response from the
diff --git a/deprecated/detections/domain_account_discovery_with_net_app.yml b/deprecated/detections/domain_account_discovery_with_net_app.yml
index a1518a4c1f..98dfe89c93 100644
--- a/deprecated/detections/domain_account_discovery_with_net_app.yml
+++ b/deprecated/detections/domain_account_discovery_with_net_app.yml
@@ -3,7 +3,7 @@ id: 98f6a534-04c2-11ec-96b2-acde48001122
version: 6
date: '2025-02-10'
author: Teoderick Contreras, Mauricio Velazco, Splunk
-status: deprecated
+status: removed
type: TTP
description: This following analytic has been deprecated in favour of the generic
version "5d0d4830-0133-11ec-bae3-acde48001122". The following analytic detects the
diff --git a/deprecated/detections/domain_group_discovery_with_net.yml b/deprecated/detections/domain_group_discovery_with_net.yml
index 928dec10e8..cdb1b85e11 100644
--- a/deprecated/detections/domain_group_discovery_with_net.yml
+++ b/deprecated/detections/domain_group_discovery_with_net.yml
@@ -3,7 +3,7 @@ id: f2f14ac7-fa81-471a-80d5-7eb65c3c7349
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search has been deprecated in favour of the more generic analytic
"c5c8e0f3-147a-43da-bf04-4cfaec27dc44". The following analytic identifies the execution
diff --git a/deprecated/detections/dump_lsass_via_procdump_rename.yml b/deprecated/detections/dump_lsass_via_procdump_rename.yml
index db67928fa4..646606d2fa 100644
--- a/deprecated/detections/dump_lsass_via_procdump_rename.yml
+++ b/deprecated/detections/dump_lsass_via_procdump_rename.yml
@@ -3,7 +3,7 @@ id: 21276daa-663d-11eb-ae93-0242ac130002
version: 4
date: '2024-11-14'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: Hunting
description: "Detect a renamed instance of procdump.exe dumping the lsass process.
This query looks for both -mm and -ma usage. -mm will produce a mini dump file and
diff --git a/deprecated/detections/ec2_instance_modified_with_previously_unseen_user.yml b/deprecated/detections/ec2_instance_modified_with_previously_unseen_user.yml
index c0dddee3ca..c41e9ef0f2 100644
--- a/deprecated/detections/ec2_instance_modified_with_previously_unseen_user.yml
+++ b/deprecated/detections/ec2_instance_modified_with_previously_unseen_user.yml
@@ -3,7 +3,7 @@ id: 56f91724-cf3f-4666-84e1-e3712fb41e76
version: 6
date: '2024-11-14'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This search looks for EC2 instances being modified by users who have
not previously modified them. This search is deprecated and have been translated
diff --git a/deprecated/detections/ec2_instance_started_in_previously_unseen_region.yml b/deprecated/detections/ec2_instance_started_in_previously_unseen_region.yml
index 0d7e62b234..0ddc56e39b 100644
--- a/deprecated/detections/ec2_instance_started_in_previously_unseen_region.yml
+++ b/deprecated/detections/ec2_instance_started_in_previously_unseen_region.yml
@@ -3,7 +3,7 @@ id: ada0f478-84a8-4641-a3f3-d82362d6fd75
version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search looks for AWS CloudTrail events where an instance is started
in a particular region in the last one hour and then compares it to a lookup file
diff --git a/deprecated/detections/ec2_instance_started_with_previously_unseen_ami.yml b/deprecated/detections/ec2_instance_started_with_previously_unseen_ami.yml
index 80a929eefb..a801015f2d 100644
--- a/deprecated/detections/ec2_instance_started_with_previously_unseen_ami.yml
+++ b/deprecated/detections/ec2_instance_started_with_previously_unseen_ami.yml
@@ -3,7 +3,7 @@ id: 347ec301-601b-48b9-81aa-9ddf9c829dd3
version: 5
date: '2025-01-16'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This search looks for EC2 instances being created with previously unseen
AMIs. This search is deprecated and have been translated to use the latest Change
diff --git a/deprecated/detections/ec2_instance_started_with_previously_unseen_instance_type.yml b/deprecated/detections/ec2_instance_started_with_previously_unseen_instance_type.yml
index e1a95404a0..1f549688bd 100644
--- a/deprecated/detections/ec2_instance_started_with_previously_unseen_instance_type.yml
+++ b/deprecated/detections/ec2_instance_started_with_previously_unseen_instance_type.yml
@@ -3,7 +3,7 @@ id: 65541c80-03c7-4e05-83c8-1dcd57a2e1ad
version: 6
date: '2025-01-16'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This search looks for EC2 instances being created with previously unseen
instance types. This search is deprecated and have been translated to use the latest
diff --git a/deprecated/detections/ec2_instance_started_with_previously_unseen_user.yml b/deprecated/detections/ec2_instance_started_with_previously_unseen_user.yml
index d43786da55..e2b75f6b5d 100644
--- a/deprecated/detections/ec2_instance_started_with_previously_unseen_user.yml
+++ b/deprecated/detections/ec2_instance_started_with_previously_unseen_user.yml
@@ -3,7 +3,7 @@ id: 22773e84-bac0-4595-b086-20d3f735b4f1
version: 6
date: '2025-01-16'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This search looks for EC2 instances being created by users who have not
created them before. This search is deprecated and have been translated to use the
diff --git a/deprecated/detections/elevated_group_discovery_with_net.yml b/deprecated/detections/elevated_group_discovery_with_net.yml
index a941649159..d2239f33b0 100644
--- a/deprecated/detections/elevated_group_discovery_with_net.yml
+++ b/deprecated/detections/elevated_group_discovery_with_net.yml
@@ -3,7 +3,7 @@ id: a23a0e20-0b1b-4a07-82e5-ec5f70811e7a
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated. The following analytic detects
the execution of `net.exe` or `net1.exe` with command-line arguments used to query
diff --git a/deprecated/detections/excel_spawning_powershell.yml b/deprecated/detections/excel_spawning_powershell.yml
index 764de86234..10332d5d80 100644
--- a/deprecated/detections/excel_spawning_powershell.yml
+++ b/deprecated/detections/excel_spawning_powershell.yml
@@ -3,7 +3,7 @@ id: 42d40a22-9be3-11eb-8f08-acde48001122
version: 9
date: '2025-02-10'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/deprecated/detections/excel_spawning_windows_script_host.yml b/deprecated/detections/excel_spawning_windows_script_host.yml
index 40deb89c49..404e72e788 100644
--- a/deprecated/detections/excel_spawning_windows_script_host.yml
+++ b/deprecated/detections/excel_spawning_windows_script_host.yml
@@ -3,7 +3,7 @@ id: 57fe880a-9be3-11eb-9bf3-acde48001122
version: 10
date: '2025-02-10'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach. The following analytic identifies instances where Microsoft Excel spawns
diff --git a/deprecated/detections/excessive_service_stop_attempt.yml b/deprecated/detections/excessive_service_stop_attempt.yml
index 3e27dc456b..c1d3ad9f3c 100644
--- a/deprecated/detections/excessive_service_stop_attempt.yml
+++ b/deprecated/detections/excessive_service_stop_attempt.yml
@@ -3,7 +3,7 @@ id: ae8d3f4a-acd7-11eb-8846-acde48001122
version: 7
date: '2025-01-24'
author: Teoderick Contreras, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: The following analytic has been deprecated.
The following analytic detects multiple attempts to stop or delete services
diff --git a/deprecated/detections/excessive_usage_of_net_app.yml b/deprecated/detections/excessive_usage_of_net_app.yml
index 1b3556f57b..c993f62522 100644
--- a/deprecated/detections/excessive_usage_of_net_app.yml
+++ b/deprecated/detections/excessive_usage_of_net_app.yml
@@ -3,7 +3,7 @@ id: 45e52536-ae42-11eb-b5c6-acde48001122
version: 7
date: '2025-01-24'
author: Teoderick Contreras, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: The following analytic has been deprecated.
The following analytic detects excessive usage of `net.exe` or `net1.exe`
diff --git a/deprecated/detections/execution_of_file_with_spaces_before_extension.yml b/deprecated/detections/execution_of_file_with_spaces_before_extension.yml
index 6e453a7f03..ef42aea3b4 100644
--- a/deprecated/detections/execution_of_file_with_spaces_before_extension.yml
+++ b/deprecated/detections/execution_of_file_with_spaces_before_extension.yml
@@ -3,7 +3,7 @@ id: ab0353e6-a956-420b-b724-a8b4846d5d5a
version: 6
date: '2024-11-14'
author: Rico Valdez, Splunk
-status: deprecated
+status: removed
type: TTP
description: This search looks for processes launched from files with at least five
spaces in the name before the extension. This is typically done to obfuscate the
diff --git a/deprecated/detections/extended_period_without_successful_netbackup_backups.yml b/deprecated/detections/extended_period_without_successful_netbackup_backups.yml
index c72e3977a2..fa3e78bc00 100644
--- a/deprecated/detections/extended_period_without_successful_netbackup_backups.yml
+++ b/deprecated/detections/extended_period_without_successful_netbackup_backups.yml
@@ -3,7 +3,7 @@ id: a34aae96-ccf8-4aef-952c-3ea214444440
version: 4
date: '2024-11-14'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search returns a list of hosts that have not successfully completed
a backup in over a week. Deprecated because it's a infrastructure monitoring.
diff --git a/deprecated/detections/extraction_of_registry_hives.yml b/deprecated/detections/extraction_of_registry_hives.yml
index ceb5264fa6..ed19f50850 100644
--- a/deprecated/detections/extraction_of_registry_hives.yml
+++ b/deprecated/detections/extraction_of_registry_hives.yml
@@ -3,7 +3,7 @@ id: 8bbb7d58-b360-11eb-ba21-acde48001122
version: 8
date: '2025-02-10'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated. The following analytic detects
the use of `reg.exe` to export Windows Registry hives, which may contain sensitive
diff --git a/deprecated/detections/first_time_seen_command_line_argument.yml b/deprecated/detections/first_time_seen_command_line_argument.yml
index 5df827cada..b11889326f 100644
--- a/deprecated/detections/first_time_seen_command_line_argument.yml
+++ b/deprecated/detections/first_time_seen_command_line_argument.yml
@@ -3,7 +3,7 @@ id: a1b6e73f-98d5-470f-99ac-77aacd578473
version: 8
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search looks for command-line arguments that use a `/c` parameter
to execute a command that has not previously been seen.
diff --git a/deprecated/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml b/deprecated/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml
index 10a412fbc9..e1ff155ab4 100644
--- a/deprecated/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml
+++ b/deprecated/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml
@@ -3,7 +3,7 @@ id: 27af8c15-38b0-4408-b339-920170724adb
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides detection of accounts with high risk roles by projects.
Compromised accounts with high risk roles can move laterally or even scalate privileges
diff --git a/deprecated/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml b/deprecated/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml
index 1291444493..4082bc1b56 100644
--- a/deprecated/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml
+++ b/deprecated/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml
@@ -3,7 +3,7 @@ id: 2e70ef35-2187-431f-aedc-4503dc9b06ba
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides detection of high risk permissions by resource and
accounts. These are permissions that can allow attackers with compromised accounts
diff --git a/deprecated/detections/gcp_detect_oauth_token_abuse.yml b/deprecated/detections/gcp_detect_oauth_token_abuse.yml
index 25144dd436..16b1471ac1 100644
--- a/deprecated/detections/gcp_detect_oauth_token_abuse.yml
+++ b/deprecated/detections/gcp_detect_oauth_token_abuse.yml
@@ -3,7 +3,7 @@ id: a7e9f7bb-8901-4ad0-8d88-0a4ab07b1972
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides detection of possible GCP Oauth token abuse. GCP
Oauth token without time limit can be exfiltrated and reused for keeping access
diff --git a/deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml b/deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml
index f8fabad5ff..414be67679 100644
--- a/deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml
+++ b/deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml
@@ -3,7 +3,7 @@ id: db5957ec-0144-4c56-b512-9dccbe7a2d26
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: TTP
description: This search provides information of unauthenticated requests via user
agent, and authentication data against Kubernetes cluster
diff --git a/deprecated/detections/identify_new_user_accounts.yml b/deprecated/detections/identify_new_user_accounts.yml
index 55b528d72a..89e8250b82 100644
--- a/deprecated/detections/identify_new_user_accounts.yml
+++ b/deprecated/detections/identify_new_user_accounts.yml
@@ -3,7 +3,7 @@ id: 475b9e27-17e4-46e2-b7e2-648221be3b89
version: 4
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This detection search will help profile user accounts in your environment
by identifying newly created accounts that have been added to your network in the
diff --git a/deprecated/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml b/deprecated/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml
index 8aed9288a5..20458780df 100644
--- a/deprecated/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml
+++ b/deprecated/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml
@@ -3,7 +3,7 @@ id: 5b30b25d-7d32-42d8-95ca-64dfcd9076e6
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides information on Kubernetes service accounts,accessing
pods by IP address, verb and decision
diff --git a/deprecated/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml b/deprecated/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml
index 6d04bf8d94..5f424be025 100644
--- a/deprecated/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml
+++ b/deprecated/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml
@@ -3,7 +3,7 @@ id: de7264ed-3ed9-4fef-bb01-6eefc87cefe8
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides information on Kubernetes RBAC authorizations by
accounts, this search can be modified by adding top to see both extremes of RBAC
diff --git a/deprecated/detections/kubernetes_aws_detect_sensitive_role_access.yml b/deprecated/detections/kubernetes_aws_detect_sensitive_role_access.yml
index bb7b707a96..ed19c6d3f0 100644
--- a/deprecated/detections/kubernetes_aws_detect_sensitive_role_access.yml
+++ b/deprecated/detections/kubernetes_aws_detect_sensitive_role_access.yml
@@ -3,7 +3,7 @@ id: b6013a7b-85e0-4a45-b051-10b252d69569
version: 5
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides information on Kubernetes accounts accessing sensitve
objects such as configmpas or secrets
diff --git a/deprecated/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml b/deprecated/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml
index 17722e0587..9dd04f706e 100644
--- a/deprecated/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml
+++ b/deprecated/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml
@@ -3,7 +3,7 @@ id: a6959c57-fa8f-4277-bb86-7c32fba579d5
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides information on Kubernetes service accounts with
failure or forbidden access status, this search can be extended by using top or
diff --git a/deprecated/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml b/deprecated/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml
index ef9d02ecbe..900b6fd517 100644
--- a/deprecated/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml
+++ b/deprecated/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml
@@ -3,7 +3,7 @@ id: 55a2264a-b7f0-45e5-addd-1e5ab3415c72
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides information on Kubernetes service accounts,accessing
pods and namespaces by IP address and verb
diff --git a/deprecated/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml b/deprecated/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml
index 0adc47769d..a40aa3b80e 100644
--- a/deprecated/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml
+++ b/deprecated/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml
@@ -3,7 +3,7 @@ id: 47af7d20-0607-4079-97d7-7a29af58b54e
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides information on Kubernetes RBAC authorizations by
accounts, this search can be modified by adding rare or top to see both extremes
diff --git a/deprecated/detections/kubernetes_azure_detect_sensitive_object_access.yml b/deprecated/detections/kubernetes_azure_detect_sensitive_object_access.yml
index 8ae1ee647e..d06b658319 100644
--- a/deprecated/detections/kubernetes_azure_detect_sensitive_object_access.yml
+++ b/deprecated/detections/kubernetes_azure_detect_sensitive_object_access.yml
@@ -3,7 +3,7 @@ id: 1bba382b-07fd-4ffa-b390-8002739b76e8
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides information on Kubernetes accounts accessing sensitve
objects such as configmpas or secrets
diff --git a/deprecated/detections/kubernetes_azure_detect_sensitive_role_access.yml b/deprecated/detections/kubernetes_azure_detect_sensitive_role_access.yml
index 9993a0a115..a42d6e5acd 100644
--- a/deprecated/detections/kubernetes_azure_detect_sensitive_role_access.yml
+++ b/deprecated/detections/kubernetes_azure_detect_sensitive_role_access.yml
@@ -3,7 +3,7 @@ id: f27349e5-1641-4f6a-9e68-30402be0ad4c
version: 5
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides information on Kubernetes accounts accessing sensitve
objects such as configmpas or secrets
diff --git a/deprecated/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml b/deprecated/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml
index ccbf5daf0c..502f1644b6 100644
--- a/deprecated/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml
+++ b/deprecated/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml
@@ -3,7 +3,7 @@ id: 019690d7-420f-4da0-b320-f27b09961514
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides information on Kubernetes service accounts with
failure or forbidden access status
diff --git a/deprecated/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml b/deprecated/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml
index ef3fed2b2d..f213575ef1 100644
--- a/deprecated/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml
+++ b/deprecated/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml
@@ -3,7 +3,7 @@ id: 4b6d1ba8-0000-4cec-87e6-6cbbd71651b5
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides information on rare Kubectl calls with IP, verb
namespace and object access context
diff --git a/deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml b/deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml
index 1b1378b2f7..715ad90996 100644
--- a/deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml
+++ b/deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml
@@ -3,7 +3,7 @@ id: 86aad3e0-732f-4f66-bbbc-70df448e461d
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides information of unauthenticated requests via source
IP user agent, request URI and response status data against Kubernetes cluster pod
diff --git a/deprecated/detections/kubernetes_azure_scan_fingerprint.yml b/deprecated/detections/kubernetes_azure_scan_fingerprint.yml
index 8a6b44473d..1604bee2ce 100644
--- a/deprecated/detections/kubernetes_azure_scan_fingerprint.yml
+++ b/deprecated/detections/kubernetes_azure_scan_fingerprint.yml
@@ -3,7 +3,7 @@ id: c5e5bd5c-1013-4841-8b23-e7b3253c840a
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides information of unauthenticated requests via source
IP user agent, request URI and response status data against Kubernetes cluster in
diff --git a/deprecated/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml b/deprecated/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml
index 0d3a4cdf11..32d73fe7a4 100644
--- a/deprecated/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml
+++ b/deprecated/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml
@@ -3,7 +3,7 @@ id: 7f5c2779-88a0-4824-9caa-0f606c8f260f
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides information on Kubernetes service accounts,accessing
pods by IP address, verb and decision
diff --git a/deprecated/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml b/deprecated/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml
index 09a26684ce..a73ac757ba 100644
--- a/deprecated/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml
+++ b/deprecated/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml
@@ -3,7 +3,7 @@ id: 99487de3-7192-4b41-939d-fbe9acfb1340
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides information on Kubernetes RBAC authorizations by
accounts, this search can be modified by adding top to see both extremes of RBAC
diff --git a/deprecated/detections/kubernetes_gcp_detect_sensitive_object_access.yml b/deprecated/detections/kubernetes_gcp_detect_sensitive_object_access.yml
index 557ab8a5c3..f6d58fb55d 100644
--- a/deprecated/detections/kubernetes_gcp_detect_sensitive_object_access.yml
+++ b/deprecated/detections/kubernetes_gcp_detect_sensitive_object_access.yml
@@ -3,7 +3,7 @@ id: bdb6d596-86a0-4aba-8369-418ae8b9963a
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides information on Kubernetes accounts accessing sensitve
objects such as configmaps or secrets
diff --git a/deprecated/detections/kubernetes_gcp_detect_sensitive_role_access.yml b/deprecated/detections/kubernetes_gcp_detect_sensitive_role_access.yml
index da1b2cf148..97f65baf4a 100644
--- a/deprecated/detections/kubernetes_gcp_detect_sensitive_role_access.yml
+++ b/deprecated/detections/kubernetes_gcp_detect_sensitive_role_access.yml
@@ -3,7 +3,7 @@ id: a46923f6-36b9-4806-a681-31f314907c30
version: 5
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides information on Kubernetes accounts accessing sensitve
objects such as configmpas or secrets
diff --git a/deprecated/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml b/deprecated/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml
index fff4730076..830d71836c 100644
--- a/deprecated/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml
+++ b/deprecated/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml
@@ -3,7 +3,7 @@ id: 7094808d-432a-48e7-bb3c-77e96c894f3b
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides information on Kubernetes service accounts with
failure or forbidden access status, this search can be extended by using top or
diff --git a/deprecated/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml b/deprecated/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml
index a78e967c70..d3893b3ba1 100644
--- a/deprecated/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml
+++ b/deprecated/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml
@@ -3,7 +3,7 @@ id: a5bed417-070a-41f2-a1e4-82b6aa281557
version: 4
date: '2024-11-14'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search provides information on anonymous Kubectl calls with IP,
verb namespace and object access context
diff --git a/deprecated/detections/linux_auditd_find_private_keys.yml b/deprecated/detections/linux_auditd_find_private_keys.yml
index d45b98a890..225211371a 100644
--- a/deprecated/detections/linux_auditd_find_private_keys.yml
+++ b/deprecated/detections/linux_auditd_find_private_keys.yml
@@ -3,7 +3,7 @@ id: 80bb9988-190b-4ee0-a3c3-509545a8f678
version: 6
date: '2025-02-10'
author: Teoderick Contreras, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated. The following analytic detects
suspicious attempts to find private keys, which may indicate an attacker's effort
diff --git a/deprecated/detections/local_account_discovery_with_net.yml b/deprecated/detections/local_account_discovery_with_net.yml
index 69f3af6598..2203098764 100644
--- a/deprecated/detections/local_account_discovery_with_net.yml
+++ b/deprecated/detections/local_account_discovery_with_net.yml
@@ -3,7 +3,7 @@ id: 5d0d4830-0133-11ec-bae3-acde48001122
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Splunk
-status: deprecated
+status: removed
type: Hunting
description: The following analytic has been deprecated. The following analytic detects
the execution of `net.exe` or `net1.exe` with command-line arguments `user` or `users`
diff --git a/deprecated/detections/monitor_dns_for_brand_abuse.yml b/deprecated/detections/monitor_dns_for_brand_abuse.yml
index 9ad520f284..23a96ac7d0 100644
--- a/deprecated/detections/monitor_dns_for_brand_abuse.yml
+++ b/deprecated/detections/monitor_dns_for_brand_abuse.yml
@@ -3,7 +3,7 @@ id: 24dd17b1-e2fb-4c31-878c-d4f746595bfa
version: 4
date: '2024-11-14'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
type: TTP
description: This search looks for DNS requests for faux domains similar to the domains
that you want to have monitored for abuse.
diff --git a/deprecated/detections/mshtml_module_load_in_office_product.yml b/deprecated/detections/mshtml_module_load_in_office_product.yml
index 833a24a872..03be60e1c7 100644
--- a/deprecated/detections/mshtml_module_load_in_office_product.yml
+++ b/deprecated/detections/mshtml_module_load_in_office_product.yml
@@ -3,7 +3,7 @@ id: 5f1c168e-118b-11ec-84ff-acde48001122
version: 8
date: '2025-02-10'
author: Michael Haag, Mauricio Velazco, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated. The following analytic detects
the loading of the mshtml.dll module into an Office product, which is indicative
diff --git a/deprecated/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml b/deprecated/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml
index 1ebadf8ebc..96b3b69893 100644
--- a/deprecated/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml
+++ b/deprecated/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml
@@ -3,7 +3,7 @@ id: 19cba45f-cad3-4032-8911-0c09e0444552
version: 6
date: '2025-02-10'
author: Michael Haag, Mauricio Velazco, Rico Valdez, Splunk
-status: deprecated
+status: removed
type: TTP
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `Okta Multiple Users Failing To Authenticate From Ip`. This analytic identifies
diff --git a/deprecated/detections/net_localgroup_discovery.yml b/deprecated/detections/net_localgroup_discovery.yml
index 31b775f015..261b7b7902 100644
--- a/deprecated/detections/net_localgroup_discovery.yml
+++ b/deprecated/detections/net_localgroup_discovery.yml
@@ -3,7 +3,7 @@ id: 54f5201e-155b-11ec-a6e2-acde48001122
version: 6
date: '2025-02-10'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search has been deprecated in favour of the more generic analytic
"c5c8e0f3-147a-43da-bf04-4cfaec27dc44". The following analytic detects the execution
diff --git a/deprecated/detections/network_connection_discovery_with_net.yml b/deprecated/detections/network_connection_discovery_with_net.yml
index 0002699f31..b90d9bdde6 100644
--- a/deprecated/detections/network_connection_discovery_with_net.yml
+++ b/deprecated/detections/network_connection_discovery_with_net.yml
@@ -3,7 +3,7 @@ id: 640337e5-6e41-4b7f-af06-9d9eab5e1e2d
version: 6
date: '2025-01-24'
author: Mauricio Velazco, Splunk
-status: deprecated
+status: removed
type: Hunting
description: The following analytic has been deprecated.
The following analytic identifies the execution of `net.exe` or `net1.exe`
diff --git a/deprecated/detections/o365_suspicious_admin_email_forwarding.yml b/deprecated/detections/o365_suspicious_admin_email_forwarding.yml
index b706b2d0a8..7d67c799b3 100644
--- a/deprecated/detections/o365_suspicious_admin_email_forwarding.yml
+++ b/deprecated/detections/o365_suspicious_admin_email_forwarding.yml
@@ -3,7 +3,7 @@ id: 7f398cfb-918d-41f4-8db8-2e2474e02c28
version: 4
date: '2025-02-10'
author: Patrick Bareiss, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `O365 Mailbox Email Forwarding Enabled`. This search detects when an admin
diff --git a/deprecated/detections/o365_suspicious_rights_delegation.yml b/deprecated/detections/o365_suspicious_rights_delegation.yml
index 716fd6289c..f2ed6c205b 100644
--- a/deprecated/detections/o365_suspicious_rights_delegation.yml
+++ b/deprecated/detections/o365_suspicious_rights_delegation.yml
@@ -3,7 +3,7 @@ id: b25d2973-303e-47c8-bacd-52b61604c6a7
version: 5
date: '2025-02-10'
author: Patrick Bareiss, Mauricio Velazco, Splunk
-status: deprecated
+status: removed
type: TTP
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `O365 Elevated Mailbox Permission Assigned`. This analytic identifies instances
diff --git a/deprecated/detections/o365_suspicious_user_email_forwarding.yml b/deprecated/detections/o365_suspicious_user_email_forwarding.yml
index 4ea5ecc88d..534b319903 100644
--- a/deprecated/detections/o365_suspicious_user_email_forwarding.yml
+++ b/deprecated/detections/o365_suspicious_user_email_forwarding.yml
@@ -3,7 +3,7 @@ id: f8dfe015-dbb3-4569-ba75-b13787e06aa4
version: 5
date: '2025-02-10'
author: Patrick Bareiss, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `O365 Mailbox Email Forwarding Enabled`. The following analytic detects when
diff --git a/deprecated/detections/office_application_drop_executable.yml b/deprecated/detections/office_application_drop_executable.yml
index c87210ccf6..6289572cc2 100644
--- a/deprecated/detections/office_application_drop_executable.yml
+++ b/deprecated/detections/office_application_drop_executable.yml
@@ -3,7 +3,7 @@ id: 73ce70c4-146d-11ec-9184-acde48001122
version: 10
date: '2025-02-10'
author: Teoderick Contreras, Michael Haag, Splunk, TheLawsOfChaos, Github
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated. The following analytic detects
Microsoft Office applications dropping or creating executables or scripts on a Windows
diff --git a/deprecated/detections/office_application_spawn_regsvr32_process.yml b/deprecated/detections/office_application_spawn_regsvr32_process.yml
index 8aa07a2de3..305da934ed 100644
--- a/deprecated/detections/office_application_spawn_regsvr32_process.yml
+++ b/deprecated/detections/office_application_spawn_regsvr32_process.yml
@@ -3,7 +3,7 @@ id: 2d9fc90c-f11f-11eb-9300-acde48001122
version: 9
date: '2025-02-10'
author: Teoderick Contreras, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/deprecated/detections/office_application_spawn_rundll32_process.yml b/deprecated/detections/office_application_spawn_rundll32_process.yml
index e648095cc9..6fb15cde36 100644
--- a/deprecated/detections/office_application_spawn_rundll32_process.yml
+++ b/deprecated/detections/office_application_spawn_rundll32_process.yml
@@ -3,7 +3,7 @@ id: 958751e4-9c5f-11eb-b103-acde48001122
version: 9
date: '2025-02-10'
author: Teoderick Contreras, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/deprecated/detections/office_document_creating_schedule_task.yml b/deprecated/detections/office_document_creating_schedule_task.yml
index ef59131ecc..75fbcf448d 100644
--- a/deprecated/detections/office_document_creating_schedule_task.yml
+++ b/deprecated/detections/office_document_creating_schedule_task.yml
@@ -3,7 +3,7 @@ id: cc8b7b74-9d0f-11eb-8342-acde48001122
version: 11
date: '2025-02-10'
author: Teoderick Contreras, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated. The following analytic detects
an Office document creating a scheduled task, either through a macro VBA API or
diff --git a/deprecated/detections/office_document_executing_macro_code.yml b/deprecated/detections/office_document_executing_macro_code.yml
index 8d74ea1aa2..503de3d2b6 100644
--- a/deprecated/detections/office_document_executing_macro_code.yml
+++ b/deprecated/detections/office_document_executing_macro_code.yml
@@ -3,7 +3,7 @@ id: b12c89bc-9d06-11eb-a592-acde48001122
version: 10
date: '2025-02-10'
author: Teoderick Contreras, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated. The following analytic identifies
office documents executing macro code. It leverages Sysmon EventCode 7 to detect
diff --git a/deprecated/detections/office_document_spawned_child_process_to_download.yml b/deprecated/detections/office_document_spawned_child_process_to_download.yml
index 2e78ed372c..9579d186f0 100644
--- a/deprecated/detections/office_document_spawned_child_process_to_download.yml
+++ b/deprecated/detections/office_document_spawned_child_process_to_download.yml
@@ -3,7 +3,7 @@ id: 6fed27d2-9ec7-11eb-8fe4-aa665a019aa3
version: 11
date: '2025-02-10'
author: Teoderick Contreras, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated. The following analytic identifies
Office applications spawning child processes to download content via HTTP/HTTPS.
diff --git a/deprecated/detections/office_product_spawn_cmd_process.yml b/deprecated/detections/office_product_spawn_cmd_process.yml
index 4893d60d9f..949962d43e 100644
--- a/deprecated/detections/office_product_spawn_cmd_process.yml
+++ b/deprecated/detections/office_product_spawn_cmd_process.yml
@@ -3,7 +3,7 @@ id: b8b19420-e892-11eb-9244-acde48001122
version: 10
date: '2025-02-10'
author: Teoderick Contreras, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/deprecated/detections/office_product_spawning_bitsadmin.yml b/deprecated/detections/office_product_spawning_bitsadmin.yml
index 28ee0cc811..e4a1cd88ff 100644
--- a/deprecated/detections/office_product_spawning_bitsadmin.yml
+++ b/deprecated/detections/office_product_spawning_bitsadmin.yml
@@ -3,7 +3,7 @@ id: e8c591f4-a6d7-11eb-8cf7-acde48001122
version: 10
date: '2025-02-10'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/deprecated/detections/office_product_spawning_certutil.yml b/deprecated/detections/office_product_spawning_certutil.yml
index 698343c8ae..d1819873df 100644
--- a/deprecated/detections/office_product_spawning_certutil.yml
+++ b/deprecated/detections/office_product_spawning_certutil.yml
@@ -3,7 +3,7 @@ id: 6925fe72-a6d5-11eb-9e17-acde48001122
version: 10
date: '2025-02-10'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/deprecated/detections/office_product_spawning_mshta.yml b/deprecated/detections/office_product_spawning_mshta.yml
index 9c8c8ae1ce..e21d9688c5 100644
--- a/deprecated/detections/office_product_spawning_mshta.yml
+++ b/deprecated/detections/office_product_spawning_mshta.yml
@@ -3,7 +3,7 @@ id: 6078fa20-a6d2-11eb-b662-acde48001122
version: 9
date: '2025-02-10'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/deprecated/detections/office_product_spawning_rundll32_with_no_dll.yml b/deprecated/detections/office_product_spawning_rundll32_with_no_dll.yml
index 41f3f9df66..2e4c38fdd5 100644
--- a/deprecated/detections/office_product_spawning_rundll32_with_no_dll.yml
+++ b/deprecated/detections/office_product_spawning_rundll32_with_no_dll.yml
@@ -3,7 +3,7 @@ id: c661f6be-a38c-11eb-be57-acde48001122
version: 11
date: '2025-02-10'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated. The following analytic detects
any Windows Office Product spawning `rundll32.exe` without a `.dll` file extension.
diff --git a/deprecated/detections/office_product_spawning_windows_script_host.yml b/deprecated/detections/office_product_spawning_windows_script_host.yml
index b4da3bfa8e..b33dc038c5 100644
--- a/deprecated/detections/office_product_spawning_windows_script_host.yml
+++ b/deprecated/detections/office_product_spawning_windows_script_host.yml
@@ -3,7 +3,7 @@ id: b3628a5b-8d02-42fa-a891-eebf2351cbe1
version: 12
date: '2025-02-10'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/deprecated/detections/office_product_spawning_wmic.yml b/deprecated/detections/office_product_spawning_wmic.yml
index 0e60c6e32f..f8f0be00c5 100644
--- a/deprecated/detections/office_product_spawning_wmic.yml
+++ b/deprecated/detections/office_product_spawning_wmic.yml
@@ -3,7 +3,7 @@ id: ffc236d6-a6c9-11eb-95f1-acde48001122
version: 11
date: '2025-02-10'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/deprecated/detections/office_product_writing_cab_or_inf.yml b/deprecated/detections/office_product_writing_cab_or_inf.yml
index 9d29d2a888..7b6f06bb42 100644
--- a/deprecated/detections/office_product_writing_cab_or_inf.yml
+++ b/deprecated/detections/office_product_writing_cab_or_inf.yml
@@ -3,7 +3,7 @@ id: f48cd1d4-125a-11ec-a447-acde48001122
version: 11
date: '2025-02-10'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated. The following analytic detects
Office products writing .cab or .inf files, indicative of CVE-2021-40444 exploitation.
diff --git a/deprecated/detections/office_spawning_control.yml b/deprecated/detections/office_spawning_control.yml
index f141b89519..37487e24a7 100644
--- a/deprecated/detections/office_spawning_control.yml
+++ b/deprecated/detections/office_spawning_control.yml
@@ -3,7 +3,7 @@ id: 053e027c-10c7-11ec-8437-acde48001122
version: 12
date: '2025-02-10'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated. The following analytic identifies
instances where `control.exe` is spawned by a Microsoft Office product. It leverages
diff --git a/deprecated/detections/okta_account_locked_out.yml b/deprecated/detections/okta_account_locked_out.yml
index 0ad8243973..827f3fd86a 100644
--- a/deprecated/detections/okta_account_locked_out.yml
+++ b/deprecated/detections/okta_account_locked_out.yml
@@ -3,7 +3,7 @@ id: d650c0ae-bdc5-400e-9f0f-f7aa0a010ef1
version: 3
date: '2024-11-14'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `Okta Multiple Accounts Locked Out`. The following analytic utilizes the user.acount.lock
diff --git a/deprecated/detections/okta_account_lockout_events.yml b/deprecated/detections/okta_account_lockout_events.yml
index b2ec1f14ef..cacf38cb37 100644
--- a/deprecated/detections/okta_account_lockout_events.yml
+++ b/deprecated/detections/okta_account_lockout_events.yml
@@ -3,7 +3,7 @@ id: 62b70968-a0a5-4724-8ac4-67871e6f544d
version: 5
date: '2025-02-10'
author: Michael Haag, Rico Valdez, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `Okta Multiple Accounts Locked Out`. The following anomaly will generate based
diff --git a/deprecated/detections/okta_failed_sso_attempts.yml b/deprecated/detections/okta_failed_sso_attempts.yml
index 3c1d92c759..7ab6ebad6c 100644
--- a/deprecated/detections/okta_failed_sso_attempts.yml
+++ b/deprecated/detections/okta_failed_sso_attempts.yml
@@ -3,7 +3,7 @@ id: 371a6545-2618-4032-ad84-93386b8698c5
version: 6
date: '2025-02-10'
author: Michael Haag, Rico Valdez, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with this detection `Okta Unauthorized Access to Application - DM`. The following
diff --git a/deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml b/deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml
index 00af9d0aa5..865053caa9 100644
--- a/deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml
+++ b/deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml
@@ -4,7 +4,7 @@ version: 5
date: '2025-02-10'
author: Okta, Inc, Michael Haag, Splunk
type: TTP
-status: deprecated
+status: removed
data_source: []
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `Okta ThreatInsight Threat Detected`. The following analytic utilizes Oktas
diff --git a/deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml b/deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml
index e68cf87729..4a6f29d878 100644
--- a/deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml
+++ b/deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml
@@ -4,7 +4,7 @@ version: 5
date: '2025-02-10'
author: Okta, Inc, Michael Haag, Splunk
type: TTP
-status: deprecated
+status: removed
data_source: []
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `Okta ThreatInsight Threat Detected`. The following analytic utilizes Oktas
diff --git a/deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml b/deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml
index 9817b5f845..cd09e9e972 100644
--- a/deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml
+++ b/deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml
@@ -3,7 +3,7 @@ id: d93f785e-4c2c-4262-b8c7-12b77a13fd39
version: 4
date: '2024-11-14'
author: Michael Haag, Marissa Bower, Splunk
-status: deprecated
+status: removed
type: TTP
description: '**DEPRECATION NOTE** - This search has been deprecated and replaced
with `Okta Multiple Failed MFA Requests For User`. The following analytic identifies
diff --git a/deprecated/detections/osquery_pack___coldroot_detection.yml b/deprecated/detections/osquery_pack___coldroot_detection.yml
index 369173b8fd..7b3a494261 100644
--- a/deprecated/detections/osquery_pack___coldroot_detection.yml
+++ b/deprecated/detections/osquery_pack___coldroot_detection.yml
@@ -3,7 +3,7 @@ id: a6fffe5e-05c3-4c04-badc-887607fbb8dc
version: 5
date: '2024-11-14'
author: Rico Valdez, Splunk
-status: deprecated
+status: removed
type: TTP
description: This search looks for ColdRoot events from the osx-attacks osquery pack.
data_source: []
diff --git a/deprecated/detections/password_policy_discovery_with_net.yml b/deprecated/detections/password_policy_discovery_with_net.yml
index 0656e661c8..527907ea6f 100644
--- a/deprecated/detections/password_policy_discovery_with_net.yml
+++ b/deprecated/detections/password_policy_discovery_with_net.yml
@@ -3,7 +3,7 @@ id: 09336538-065a-11ec-8665-acde48001122
version: 7
date: '2025-01-24'
author: Teoderick Contreras, Mauricio Velazco, Splunk
-status: deprecated
+status: removed
type: Hunting
description: The following analytic has been deprecated.
The following analytic identifies the execution of `net.exe` or `net1.exe`
diff --git a/deprecated/detections/processes_created_by_netsh.yml b/deprecated/detections/processes_created_by_netsh.yml
index cb947299d8..a7ff65c024 100644
--- a/deprecated/detections/processes_created_by_netsh.yml
+++ b/deprecated/detections/processes_created_by_netsh.yml
@@ -3,7 +3,7 @@ id: b89919ed-fe5f-492c-b139-95dbb162041e
version: 8
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: TTP
description: This search looks for processes launching netsh.exe to execute various
commands via the netsh command-line utility. Netsh.exe is a command-line scripting
diff --git a/deprecated/detections/prohibited_software_on_endpoint.yml b/deprecated/detections/prohibited_software_on_endpoint.yml
index 243c1c8374..0572b6f2bf 100644
--- a/deprecated/detections/prohibited_software_on_endpoint.yml
+++ b/deprecated/detections/prohibited_software_on_endpoint.yml
@@ -3,7 +3,7 @@ id: a51bfe1a-94f0-48cc-b4e4-b6ae50145893
version: 5
date: '2024-11-14'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search looks for applications on the endpoint that you have marked
as prohibited.
diff --git a/deprecated/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml b/deprecated/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml
index b003f3bd58..bc776d7e9a 100644
--- a/deprecated/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml
+++ b/deprecated/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml
@@ -3,7 +3,7 @@ id: 61a7d1e6-f5d4-41d9-a9be-39a1ffe69459
version: 5
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: TTP
description: The search looks for command-line arguments used to hide a file or directory
using the reg add command.
diff --git a/deprecated/detections/remote_registry_key_modifications.yml b/deprecated/detections/remote_registry_key_modifications.yml
index 71f902a8ad..ffd7eff675 100644
--- a/deprecated/detections/remote_registry_key_modifications.yml
+++ b/deprecated/detections/remote_registry_key_modifications.yml
@@ -3,7 +3,7 @@ id: c9f4b923-f8af-4155-b697-1354f5dcbc5e
version: 6
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: TTP
description: This search monitors for remote modifications to registry keys.
data_source:
diff --git a/deprecated/detections/remote_system_discovery_with_net.yml b/deprecated/detections/remote_system_discovery_with_net.yml
index 2377264b52..8961d33627 100644
--- a/deprecated/detections/remote_system_discovery_with_net.yml
+++ b/deprecated/detections/remote_system_discovery_with_net.yml
@@ -3,7 +3,7 @@ id: 9df16706-04a2-41e2-bbfe-9b38b34409d3
version: 5
date: '2025-01-13'
author: Mauricio Velazco, Splunk
-status: deprecated
+status: removed
type: Hunting
description: The following analytic has been deprecated in favour of two dedicated analytics "4dc3951f-b3f8-4f46-b412-76a483f72277" and "a23a0e20-0b1b-4a07-82e5-ec5f70811e7a" .The following analytic identifies the execution of `net.exe` or `net1.exe` with command-line arguments used to discover remote systems, such as `domain computers /domain`. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments. This activity is significant as it indicates potential reconnaissance efforts by adversaries or Red Teams to map out networked systems and Active Directory structures. If confirmed malicious, this behavior could lead to further network exploitation, privilege escalation, or lateral movement within the environment.
data_source:
diff --git a/deprecated/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml b/deprecated/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml
index 0197ba45a3..19aaa1b2c4 100644
--- a/deprecated/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml
+++ b/deprecated/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml
@@ -3,7 +3,7 @@ id: 1297fb80-f42a-4b4a-9c8b-78c066437cf6
version: 6
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: TTP
description: This search looks for flags passed to schtasks.exe on the command-line
that indicate that task names related to the execution of Bad Rabbit ransomware
diff --git a/deprecated/detections/spectre_and_meltdown_vulnerable_systems.yml b/deprecated/detections/spectre_and_meltdown_vulnerable_systems.yml
index 1f4a043402..1859af0f86 100644
--- a/deprecated/detections/spectre_and_meltdown_vulnerable_systems.yml
+++ b/deprecated/detections/spectre_and_meltdown_vulnerable_systems.yml
@@ -3,7 +3,7 @@ id: 354be8e0-32cd-4da0-8c47-796de13b60ea
version: 4
date: '2024-11-14'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
type: TTP
description: The search is used to detect systems that are still vulnerable to the
Spectre and Meltdown vulnerabilities.
diff --git a/deprecated/detections/suspicious_changes_to_file_associations.yml b/deprecated/detections/suspicious_changes_to_file_associations.yml
index e9438be5a1..9b9a6fa348 100644
--- a/deprecated/detections/suspicious_changes_to_file_associations.yml
+++ b/deprecated/detections/suspicious_changes_to_file_associations.yml
@@ -3,7 +3,7 @@ id: 1b989a0e-0129-4446-a695-f193a5b746fc
version: 7
date: '2024-11-14'
author: Rico Valdez, Splunk
-status: deprecated
+status: removed
type: TTP
description: This search looks for changes to registry values that control Windows
file associations, executed by a process that is not typical for legitimate, routine
diff --git a/deprecated/detections/suspicious_email___uba_anomaly.yml b/deprecated/detections/suspicious_email___uba_anomaly.yml
index 0e3a3f31d6..7399390137 100644
--- a/deprecated/detections/suspicious_email___uba_anomaly.yml
+++ b/deprecated/detections/suspicious_email___uba_anomaly.yml
@@ -3,7 +3,7 @@ id: 56e877a6-1455-4479-ad16-0550dc1e33f8
version: 6
date: '2024-11-14'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This detection looks for emails that are suspicious because of their
sender, domain rareness, or behavior differences. This is an anomaly generated by
diff --git a/deprecated/detections/suspicious_file_write.yml b/deprecated/detections/suspicious_file_write.yml
index 8630632e57..12e9533132 100644
--- a/deprecated/detections/suspicious_file_write.yml
+++ b/deprecated/detections/suspicious_file_write.yml
@@ -3,7 +3,7 @@ id: 57f76b8a-32f0-42ed-b358-d9fa3ca7bac8
version: 6
date: '2024-11-14'
author: Rico Valdez, Splunk
-status: deprecated
+status: removed
type: Hunting
description: The search looks for files created with names that have been linked to
malicious activity.
diff --git a/deprecated/detections/suspicious_powershell_command_line_arguments.yml b/deprecated/detections/suspicious_powershell_command_line_arguments.yml
index b2efc4ee51..c7a8ffa35b 100644
--- a/deprecated/detections/suspicious_powershell_command_line_arguments.yml
+++ b/deprecated/detections/suspicious_powershell_command_line_arguments.yml
@@ -3,7 +3,7 @@ id: 2cdb91d2-542c-497f-b252-be495e71f38c
version: 9
date: '2024-11-14'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
type: TTP
description: This search looks for PowerShell processes started with a base64 encoded
command-line passed to it, with parameters to modify the execution policy for the
diff --git a/deprecated/detections/suspicious_rundll32_rename.yml b/deprecated/detections/suspicious_rundll32_rename.yml
index eee4228129..81ead5651f 100644
--- a/deprecated/detections/suspicious_rundll32_rename.yml
+++ b/deprecated/detections/suspicious_rundll32_rename.yml
@@ -3,7 +3,7 @@ id: 7360137f-abad-473e-8189-acbdaa34d114
version: 8
date: '2025-02-10'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: Hunting
description: The following hunting analytic identifies renamed instances of rundll32.exe
executing. rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64.
diff --git a/deprecated/detections/suspicious_writes_to_system_volume_information.yml b/deprecated/detections/suspicious_writes_to_system_volume_information.yml
index 866160575b..e9c1f20721 100644
--- a/deprecated/detections/suspicious_writes_to_system_volume_information.yml
+++ b/deprecated/detections/suspicious_writes_to_system_volume_information.yml
@@ -3,7 +3,7 @@ id: cd6297cd-2bdd-4aa1-84aa-5d2f84228fac
version: 5
date: '2024-11-14'
author: Rico Valdez, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search detects writes to the 'System Volume Information' folder
by something other than the System process.
diff --git a/deprecated/detections/uncommon_processes_on_endpoint.yml b/deprecated/detections/uncommon_processes_on_endpoint.yml
index e0378b0e1f..fa6e1d6c2d 100644
--- a/deprecated/detections/uncommon_processes_on_endpoint.yml
+++ b/deprecated/detections/uncommon_processes_on_endpoint.yml
@@ -3,7 +3,7 @@ id: 29ccce64-a10c-4389-a45f-337cb29ba1f7
version: 7
date: '2024-11-14'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search looks for applications on the endpoint that you have marked
as uncommon.
diff --git a/deprecated/detections/unsigned_image_loaded_by_lsass.yml b/deprecated/detections/unsigned_image_loaded_by_lsass.yml
index db021a2bf3..bda913376f 100644
--- a/deprecated/detections/unsigned_image_loaded_by_lsass.yml
+++ b/deprecated/detections/unsigned_image_loaded_by_lsass.yml
@@ -3,7 +3,7 @@ id: 56ef054c-76ef-45f9-af4a-a634695dcd65
version: 4
date: '2024-11-14'
author: Patrick Bareiss, Splunk
-status: deprecated
+status: removed
type: TTP
description: This search detects loading of unsigned images by LSASS. Deprecated because
too noisy.
diff --git a/deprecated/detections/unsuccessful_netbackup_backups.yml b/deprecated/detections/unsuccessful_netbackup_backups.yml
index 3e8fc0b5af..afa6f95673 100644
--- a/deprecated/detections/unsuccessful_netbackup_backups.yml
+++ b/deprecated/detections/unsuccessful_netbackup_backups.yml
@@ -3,7 +3,7 @@ id: a34aae96-ccf8-4aaa-952c-3ea21444444f
version: 4
date: '2024-11-14'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
type: Hunting
description: This search gives you the hosts where a backup was attempted and then
failed.
diff --git a/deprecated/detections/web_fraud___account_harvesting.yml b/deprecated/detections/web_fraud___account_harvesting.yml
index 4fb3b3b784..ba78a3fa1a 100644
--- a/deprecated/detections/web_fraud___account_harvesting.yml
+++ b/deprecated/detections/web_fraud___account_harvesting.yml
@@ -3,7 +3,7 @@ id: bf1d7b5c-df2f-4249-a401-c09fdc221ddf
version: 4
date: '2024-11-14'
author: Jim Apger, Splunk
-status: deprecated
+status: removed
type: TTP
description: This search is used to identify the creation of multiple user accounts
using the same email domain name.
diff --git a/deprecated/detections/web_fraud___anomalous_user_clickspeed.yml b/deprecated/detections/web_fraud___anomalous_user_clickspeed.yml
index 518a5be28e..c084525674 100644
--- a/deprecated/detections/web_fraud___anomalous_user_clickspeed.yml
+++ b/deprecated/detections/web_fraud___anomalous_user_clickspeed.yml
@@ -3,7 +3,7 @@ id: 31337bbb-bc22-4752-b599-ef192df2dc7a
version: 4
date: '2024-11-14'
author: Jim Apger, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This search is used to examine web sessions to identify those where the
clicks are occurring too quickly for a human or are occurring with a near-perfect
diff --git a/deprecated/detections/web_fraud___password_sharing_across_accounts.yml b/deprecated/detections/web_fraud___password_sharing_across_accounts.yml
index 48c9b3908c..c1ac8d3080 100644
--- a/deprecated/detections/web_fraud___password_sharing_across_accounts.yml
+++ b/deprecated/detections/web_fraud___password_sharing_across_accounts.yml
@@ -3,7 +3,7 @@ id: 31337a1a-53b9-4e05-96e9-55c934cb71d3
version: 4
date: '2024-11-14'
author: Jim Apger, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: This search is used to identify user accounts that share a common password.
data_source: []
diff --git a/deprecated/detections/windows_command_shell_fetch_env_variables.yml b/deprecated/detections/windows_command_shell_fetch_env_variables.yml
index 90618ba3e5..f604adbab8 100644
--- a/deprecated/detections/windows_command_shell_fetch_env_variables.yml
+++ b/deprecated/detections/windows_command_shell_fetch_env_variables.yml
@@ -3,7 +3,7 @@ id: 048839e4-1eaa-43ff-8a22-86d17f6fcc13
version: 5
date: '2025-01-24'
author: Teoderick Contreras, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated.
The following analytic identifies a suspicious process command line fetching
diff --git a/deprecated/detections/windows_connhost_exe_started_forcefully.yml b/deprecated/detections/windows_connhost_exe_started_forcefully.yml
index 2718083864..5574cb0440 100644
--- a/deprecated/detections/windows_connhost_exe_started_forcefully.yml
+++ b/deprecated/detections/windows_connhost_exe_started_forcefully.yml
@@ -3,7 +3,7 @@ id: c114aaca-68ee-41c2-ad8c-32bf21db8769
version: 5
date: '2024-11-14'
author: Rod Soto, Jose Hernandez, Splunk
-status: deprecated
+status: removed
type: TTP
description: The search looks for the Console Window Host process (connhost.exe) executed
using the force flag -ForceV1. This is not regular behavior in the Windows OS and
diff --git a/deprecated/detections/windows_dll_search_order_hijacking_hunt.yml b/deprecated/detections/windows_dll_search_order_hijacking_hunt.yml
index 6149fc746d..a2b4d5bffc 100644
--- a/deprecated/detections/windows_dll_search_order_hijacking_hunt.yml
+++ b/deprecated/detections/windows_dll_search_order_hijacking_hunt.yml
@@ -3,7 +3,7 @@ id: 79c7d0fc-60c7-41be-a616-ccda752efe89
version: 6
date: '2025-02-10'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: Hunting
description: The following hunting analytic is an experimental query built against
a accidental feature using the latest Sysmon TA 3.0 (https://splunkbase.splunk.com/app/5709/)
diff --git a/deprecated/detections/windows_hosts_file_modification.yml b/deprecated/detections/windows_hosts_file_modification.yml
index 0c7453eab3..7f40e5ea32 100644
--- a/deprecated/detections/windows_hosts_file_modification.yml
+++ b/deprecated/detections/windows_hosts_file_modification.yml
@@ -3,7 +3,7 @@ id: 06a6fc63-a72d-41dc-8736-7e3dd9612116
version: 4
date: '2024-11-14'
author: Rico Valdez, Splunk
-status: deprecated
+status: removed
type: TTP
description: The search looks for modifications to the hosts file on all Windows endpoints
across your environment.
diff --git a/deprecated/detections/windows_lateral_tool_transfer_remcom.yml b/deprecated/detections/windows_lateral_tool_transfer_remcom.yml
index 47789c6b30..e1d64bf004 100644
--- a/deprecated/detections/windows_lateral_tool_transfer_remcom.yml
+++ b/deprecated/detections/windows_lateral_tool_transfer_remcom.yml
@@ -4,7 +4,7 @@ version: 6
date: '2024-12-10'
author: Michael Haag, Splunk
type: TTP
-status: deprecated
+status: removed
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
diff --git a/deprecated/detections/windows_modify_registry_reg_restore.yml b/deprecated/detections/windows_modify_registry_reg_restore.yml
index f63d1b0214..8045b06c1e 100644
--- a/deprecated/detections/windows_modify_registry_reg_restore.yml
+++ b/deprecated/detections/windows_modify_registry_reg_restore.yml
@@ -3,7 +3,7 @@ id: d0072bd2-6d73-4c1b-bc77-ded6d2da3a4e
version: 5
date: '2025-01-24'
author: Teoderick Contreras, Splunk
-status: deprecated
+status: removed
type: Hunting
description: The following analytic has been deprecated.
The following analytic detects the execution of reg.exe with the "restore"
diff --git a/deprecated/detections/windows_msiexec_with_network_connections.yml b/deprecated/detections/windows_msiexec_with_network_connections.yml
index 5c17518468..e8ace70d6d 100644
--- a/deprecated/detections/windows_msiexec_with_network_connections.yml
+++ b/deprecated/detections/windows_msiexec_with_network_connections.yml
@@ -3,7 +3,7 @@ id: 827409a1-5393-4d8d-8da4-bbb297c262a7
version: 7
date: '2025-01-24'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated.
The following analytic detects MSIExec making network connections over
diff --git a/deprecated/detections/windows_network_share_interaction_with_net.yml b/deprecated/detections/windows_network_share_interaction_with_net.yml
index fea71519c1..d07e5475c4 100644
--- a/deprecated/detections/windows_network_share_interaction_with_net.yml
+++ b/deprecated/detections/windows_network_share_interaction_with_net.yml
@@ -3,7 +3,7 @@ id: 4dc3951f-b3f8-4f46-b412-76a483f72277
version: 6
date: '2025-01-24'
author: Dean Luxton
-status: deprecated
+status: removed
type: TTP
data_source:
- Sysmon EventID 1
diff --git a/deprecated/detections/windows_office_product_spawning_msdt.yml b/deprecated/detections/windows_office_product_spawning_msdt.yml
index 9415352231..7938c379ea 100644
--- a/deprecated/detections/windows_office_product_spawning_msdt.yml
+++ b/deprecated/detections/windows_office_product_spawning_msdt.yml
@@ -3,7 +3,7 @@ id: 127eba64-c981-40bf-8589-1830638864a7
version: 11
date: '2025-02-10'
author: Michael Haag, Teoderick Contreras, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated. The following analytic detects
a Microsoft Office product spawning the Windows msdt.exe process. This detection
diff --git a/deprecated/detections/windows_query_registry_reg_save.yml b/deprecated/detections/windows_query_registry_reg_save.yml
index 291c0cf7a0..b72b968b31 100644
--- a/deprecated/detections/windows_query_registry_reg_save.yml
+++ b/deprecated/detections/windows_query_registry_reg_save.yml
@@ -3,7 +3,7 @@ id: cbee60c1-b776-456f-83c2-faa56bdbe6c6
version: 6
date: '2025-01-24'
author: Teoderick Contreras, Splunk
-status: deprecated
+status: removed
type: Hunting
description: The following analytic has been deprecated.
The following analytic detects the execution of the reg.exe process with
diff --git a/deprecated/detections/windows_service_stop_via_net__and_sc_application.yml b/deprecated/detections/windows_service_stop_via_net__and_sc_application.yml
index 00ff416650..2a90df0a04 100644
--- a/deprecated/detections/windows_service_stop_via_net__and_sc_application.yml
+++ b/deprecated/detections/windows_service_stop_via_net__and_sc_application.yml
@@ -3,7 +3,7 @@ id: 827af04b-0d08-479b-9b84-b7d4644e4b80
version: 5
date: '2025-01-24'
author: Teoderick Contreras, Splunk
-status: deprecated
+status: removed
type: Anomaly
description: The following analytic has been deprecated.
The following analytic identifies attempts to stop services on a system
diff --git a/deprecated/detections/windows_valid_account_with_never_expires_password.yml b/deprecated/detections/windows_valid_account_with_never_expires_password.yml
index 01b416d1d5..3e3a6be6b4 100644
--- a/deprecated/detections/windows_valid_account_with_never_expires_password.yml
+++ b/deprecated/detections/windows_valid_account_with_never_expires_password.yml
@@ -3,7 +3,7 @@ id: 73a931db-1830-48b3-8296-cd9cfa09c3c8
version: 6
date: '2025-01-24'
author: Teoderick Contreras, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated.
The following analytic detects the use of net.exe to update user account
diff --git a/deprecated/detections/winword_spawning_cmd.yml b/deprecated/detections/winword_spawning_cmd.yml
index 2d65e01f22..b9ec89bd35 100644
--- a/deprecated/detections/winword_spawning_cmd.yml
+++ b/deprecated/detections/winword_spawning_cmd.yml
@@ -3,7 +3,7 @@ id: 6fcbaedc-a37b-11eb-956b-acde48001122
version: 8
date: '2025-02-10'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/deprecated/detections/winword_spawning_powershell.yml b/deprecated/detections/winword_spawning_powershell.yml
index 4164d64cf7..d9dd1b7902 100644
--- a/deprecated/detections/winword_spawning_powershell.yml
+++ b/deprecated/detections/winword_spawning_powershell.yml
@@ -3,7 +3,7 @@ id: b2c950b8-9be2-11eb-8658-acde48001122
version: 8
date: '2025-02-10'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach in "Windows Office Product Spawned Uncommon Process". The following analytic
diff --git a/deprecated/detections/winword_spawning_windows_script_host.yml b/deprecated/detections/winword_spawning_windows_script_host.yml
index 47feee0635..736daa38b8 100644
--- a/deprecated/detections/winword_spawning_windows_script_host.yml
+++ b/deprecated/detections/winword_spawning_windows_script_host.yml
@@ -3,7 +3,7 @@ id: 637e1b5c-9be1-11eb-9c32-acde48001122
version: 7
date: '2025-02-10'
author: Michael Haag, Splunk
-status: deprecated
+status: removed
type: TTP
description: The following analytic has been deprecated in favour of a more generic
approach. The following analytic identifies instances where Microsoft Winword.exe
diff --git a/deprecated/investigations/all_backup_logs_for_host.yml b/deprecated/investigations/all_backup_logs_for_host.yml
index 526e0760f2..b6bfc3dfb0 100644
--- a/deprecated/investigations/all_backup_logs_for_host.yml
+++ b/deprecated/investigations/all_backup_logs_for_host.yml
@@ -4,7 +4,7 @@ version: 1
date: '2017-09-12'
author: Rico Valdez, Splunk
type: Investigation
-status: deprecated
+status: removed
description: Retrieve the backup logs for the last 2 weeks for a specific host in
order to investigate why backups are not completing successfully.
search: '| search `netbackup` dest=$dest$'
diff --git a/deprecated/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml b/deprecated/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml
index fdd85fd8e0..e1462cd64e 100644
--- a/deprecated/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml
+++ b/deprecated/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml
@@ -4,7 +4,7 @@ version: 1
date: '2020-04-13'
author: Rod Soto, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search provides investigation data about requests via user agent,
authentication request URI, verb and cluster name data against Kubernetes cluster
from a specific IP address
diff --git a/deprecated/investigations/aws_investigate_security_hub_alerts_by_dest.yml b/deprecated/investigations/aws_investigate_security_hub_alerts_by_dest.yml
index c68fadb66c..2159c1a135 100644
--- a/deprecated/investigations/aws_investigate_security_hub_alerts_by_dest.yml
+++ b/deprecated/investigations/aws_investigate_security_hub_alerts_by_dest.yml
@@ -4,7 +4,7 @@ version: 1
date: '2020-06-08'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search retrieves the all the alerts created by AWS Security Hub
for a specific dest(instance_id).
search: '`aws_securityhub_firehose` "findings{}.Resources{}.Type"=AWSEC2Instance |
diff --git a/deprecated/investigations/aws_investigate_user_activities_by_accesskeyid.yml b/deprecated/investigations/aws_investigate_user_activities_by_accesskeyid.yml
index c9523dd2fd..59a95196e1 100644
--- a/deprecated/investigations/aws_investigate_user_activities_by_accesskeyid.yml
+++ b/deprecated/investigations/aws_investigate_user_activities_by_accesskeyid.yml
@@ -4,7 +4,7 @@ version: 1
date: '2018-06-08'
author: David Dorsey, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search retrieves the times, ARN, source IPs, AWS regions, event
names, and the result of the event for specific credentials.
search: '`cloudtrail` | rename userIdentity.accessKeyId as accessKeyId| search accessKeyId=$accessKeyId$
diff --git a/deprecated/investigations/aws_investigate_user_activities_by_arn.yml b/deprecated/investigations/aws_investigate_user_activities_by_arn.yml
index d15290547a..4646dfe30a 100644
--- a/deprecated/investigations/aws_investigate_user_activities_by_arn.yml
+++ b/deprecated/investigations/aws_investigate_user_activities_by_arn.yml
@@ -4,7 +4,7 @@ version: 2
date: '2019-04-30'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search lists all the logged CloudTrail activities by a specific
user ARN and will create a table containing the source of the user, the region of
the activity, the name and type of the event, the action taken, and all the user's
diff --git a/deprecated/investigations/aws_network_acl_details_from_id.yml b/deprecated/investigations/aws_network_acl_details_from_id.yml
index 71ef17baf8..de00a587d7 100644
--- a/deprecated/investigations/aws_network_acl_details_from_id.yml
+++ b/deprecated/investigations/aws_network_acl_details_from_id.yml
@@ -4,7 +4,7 @@ version: 1
date: '2017-01-22'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search queries AWS description logs and returns all the information
about a specific network ACL via network ACL ID
search: '`aws_description` | rename id as networkAclId | search networkAclId=$networkAclId$
diff --git a/deprecated/investigations/aws_network_interface_details_via_resourceid.yml b/deprecated/investigations/aws_network_interface_details_via_resourceid.yml
index 081ba1bdc4..6ae2a743e0 100644
--- a/deprecated/investigations/aws_network_interface_details_via_resourceid.yml
+++ b/deprecated/investigations/aws_network_interface_details_via_resourceid.yml
@@ -4,7 +4,7 @@ version: 1
date: '2018-05-07'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search queries AWS configuration logs and returns the information
about a specific network interface via network interface ID. The information will
include the ARN of the network interface, its relationships with other AWS resources,
diff --git a/deprecated/investigations/aws_s3_bucket_details_via_bucketname.yml b/deprecated/investigations/aws_s3_bucket_details_via_bucketname.yml
index 86946b4438..30ba740556 100644
--- a/deprecated/investigations/aws_s3_bucket_details_via_bucketname.yml
+++ b/deprecated/investigations/aws_s3_bucket_details_via_bucketname.yml
@@ -4,7 +4,7 @@ version: 1
date: '2018-06-26'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search queries AWS configuration logs and returns the information
about a specific S3 bucket. The information returned includes the time the S3 bucket
was created, the resource ID, the region it belongs to, the value of action performed,
diff --git a/deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml b/deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml
index d4359faeb0..ea800a69ab 100644
--- a/deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml
+++ b/deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml
@@ -4,7 +4,7 @@ version: 1
date: '2020-04-13'
author: Rod Soto, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search provides investigation data about requests via user agent,
authentication request URI, resource path and cluster name data against Kubernetes
cluster from a specific IP address
diff --git a/deprecated/investigations/get_all_aws_activity_from_city.yml b/deprecated/investigations/get_all_aws_activity_from_city.yml
index 4e9d0f79a9..53a66d3aa7 100644
--- a/deprecated/investigations/get_all_aws_activity_from_city.yml
+++ b/deprecated/investigations/get_all_aws_activity_from_city.yml
@@ -4,7 +4,7 @@ version: 1
date: '2018-03-19'
author: David Dorsey, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search retrieves all the activity from a specific city and will
create a table containing the time, city, ARN, username, the type of user, the source
IP address, the AWS region the activity was in, the API called, and whether or not
diff --git a/deprecated/investigations/get_all_aws_activity_from_country.yml b/deprecated/investigations/get_all_aws_activity_from_country.yml
index aef67b8395..de55cb7b02 100644
--- a/deprecated/investigations/get_all_aws_activity_from_country.yml
+++ b/deprecated/investigations/get_all_aws_activity_from_country.yml
@@ -4,7 +4,7 @@ version: 1
date: '2018-03-19'
author: David Dorsey, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search retrieves all the activity from a specific country and will
create a table containing the time, country, ARN, username, the type of user, the
source IP address, the AWS region the activity was in, the API called, and whether
diff --git a/deprecated/investigations/get_all_aws_activity_from_ip_address.yml b/deprecated/investigations/get_all_aws_activity_from_ip_address.yml
index ad00e31621..52af123579 100644
--- a/deprecated/investigations/get_all_aws_activity_from_ip_address.yml
+++ b/deprecated/investigations/get_all_aws_activity_from_ip_address.yml
@@ -4,7 +4,7 @@ version: 1
date: '2018-03-19'
author: David Dorsey, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search retrieves all the activity from a specific IP address and
will create a table containing the time, ARN, username, the type of user, the IP
address, the AWS region the activity was in, the API called, and whether or not
diff --git a/deprecated/investigations/get_all_aws_activity_from_region.yml b/deprecated/investigations/get_all_aws_activity_from_region.yml
index a9be04ab63..383729b151 100644
--- a/deprecated/investigations/get_all_aws_activity_from_region.yml
+++ b/deprecated/investigations/get_all_aws_activity_from_region.yml
@@ -4,7 +4,7 @@ version: 1
date: '2018-03-19'
author: David Dorsey, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search retrieves all the activity from a specific geographic region
and will create a table containing the time, geographic region, ARN, username, the
type of user, the source IP address, the AWS region the activity was in, the API
diff --git a/deprecated/investigations/get_backup_logs_for_endpoint.yml b/deprecated/investigations/get_backup_logs_for_endpoint.yml
index 92c86ed03a..ba01f79f92 100644
--- a/deprecated/investigations/get_backup_logs_for_endpoint.yml
+++ b/deprecated/investigations/get_backup_logs_for_endpoint.yml
@@ -4,7 +4,7 @@ version: 1
date: '2017-09-14'
author: David Dorsey, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search will tell you the backup status from your netbackup_logs
of a specific endpoint for the last week.
search: '`netbackup` COMPUTERNAME=$dest$ | rename COMPUTERNAME as dest, MESSAGE as
diff --git a/deprecated/investigations/get_certificate_logs_for_a_domain.yml b/deprecated/investigations/get_certificate_logs_for_a_domain.yml
index f0b2aa4a3d..1dc65d87e5 100644
--- a/deprecated/investigations/get_certificate_logs_for_a_domain.yml
+++ b/deprecated/investigations/get_certificate_logs_for_a_domain.yml
@@ -4,7 +4,7 @@ version: 2
date: '2019-04-29'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search queries the Certificates datamodel and give you all the information
for a specific domain. Please note that the certificates issued by "Let's Encrypt"
are widely used by attackers.
diff --git a/deprecated/investigations/get_dns_server_history_for_a_host.yml b/deprecated/investigations/get_dns_server_history_for_a_host.yml
index 58ba43d1c1..f6b7e5c1c0 100644
--- a/deprecated/investigations/get_dns_server_history_for_a_host.yml
+++ b/deprecated/investigations/get_dns_server_history_for_a_host.yml
@@ -4,7 +4,7 @@ version: 1
date: '2017-11-09'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: While investigating any detections it is important to understand which
and how many DNS servers a host has connected to in the past. This search uses data
that is tagged as DNS and gives you a count and list of DNS servers that a particular
diff --git a/deprecated/investigations/get_dns_traffic_ratio.yml b/deprecated/investigations/get_dns_traffic_ratio.yml
index ede0480799..99247a4007 100644
--- a/deprecated/investigations/get_dns_traffic_ratio.yml
+++ b/deprecated/investigations/get_dns_traffic_ratio.yml
@@ -4,7 +4,7 @@ version: 2
date: '2024-09-24'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search calculates the ratio of DNS traffic originating and coming
from a host to a list of DNS servers over the last 24 hours. A high value of this
ratio could be very useful to quickly understand if a src_ip (host) is sending a
diff --git a/deprecated/investigations/get_ec2_instance_details_by_instanceid.yml b/deprecated/investigations/get_ec2_instance_details_by_instanceid.yml
index ed0ddf0c52..800e16d849 100644
--- a/deprecated/investigations/get_ec2_instance_details_by_instanceid.yml
+++ b/deprecated/investigations/get_ec2_instance_details_by_instanceid.yml
@@ -4,7 +4,7 @@ version: 1
date: '2018-02-12'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search queries AWS description logs and returns all the information
about a specific instance via the instanceId field
search: '`aws_description` | dedup id sortby -_time |rename id as instanceId| search
diff --git a/deprecated/investigations/get_ec2_launch_details.yml b/deprecated/investigations/get_ec2_launch_details.yml
index 46432d9945..e9b715feb1 100644
--- a/deprecated/investigations/get_ec2_launch_details.yml
+++ b/deprecated/investigations/get_ec2_launch_details.yml
@@ -4,7 +4,7 @@ version: 1
date: '2018-03-12'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search returns some of the launch details for a EC2 instance.
search: '`cloudtrail` dest=$dest$ |rename userIdentity.arn as arn, responseElements.instancesSet.items{}.instanceId
as dest, responseElements.instancesSet.items{}.privateIpAddress as privateIpAddress,
diff --git a/deprecated/investigations/get_email_info.yml b/deprecated/investigations/get_email_info.yml
index 247576a7cc..fc572aad29 100644
--- a/deprecated/investigations/get_email_info.yml
+++ b/deprecated/investigations/get_email_info.yml
@@ -4,7 +4,7 @@ version: 1
date: '2017-11-09'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search returns all the information Splunk might have collected a
specific email message over the last 2 hours.
search: '| from datamodel Email.All_Email | search message_id=$message_id$'
diff --git a/deprecated/investigations/get_emails_from_specific_sender.yml b/deprecated/investigations/get_emails_from_specific_sender.yml
index c4e5b0389a..b10b60a45a 100644
--- a/deprecated/investigations/get_emails_from_specific_sender.yml
+++ b/deprecated/investigations/get_emails_from_specific_sender.yml
@@ -4,7 +4,7 @@ version: 1
date: '2017-11-09'
author: David Dorsey, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search returns all the emails from a specific sender over the last
24 and next hours.
search: '| from datamodel Email.All_Email | search src_user=$src_user$'
diff --git a/deprecated/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml b/deprecated/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml
index 22da000f97..d1f48ff599 100644
--- a/deprecated/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml
+++ b/deprecated/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml
@@ -4,7 +4,7 @@ version: 1
date: '2017-09-13'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search allows you to gather more context around a notable which
has detected a new device connecting to your network. Use this search to determine
the first and last occurrences of the suspicious device attempting to connect with
diff --git a/deprecated/investigations/get_history_of_email_sources.yml b/deprecated/investigations/get_history_of_email_sources.yml
index 6b5b7d83af..8b03896433 100644
--- a/deprecated/investigations/get_history_of_email_sources.yml
+++ b/deprecated/investigations/get_history_of_email_sources.yml
@@ -4,7 +4,7 @@ version: 1
date: '2019-02-21'
author: Rico Valdez, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search returns a list of all email sources seen in the 48 hours
prior to the notable event to 24 hours after, and the number of emails from each
source.
diff --git a/deprecated/investigations/get_logon_rights_modifications_for_endpoint.yml b/deprecated/investigations/get_logon_rights_modifications_for_endpoint.yml
index 42405d395a..55a7a805d3 100644
--- a/deprecated/investigations/get_logon_rights_modifications_for_endpoint.yml
+++ b/deprecated/investigations/get_logon_rights_modifications_for_endpoint.yml
@@ -4,7 +4,7 @@ version: 2
date: '2017-09-12'
author: David Dorsey, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search allows you to retrieve any modifications to logon rights
associated with a specific host.
search: '`wineventlog_security` (signature_id=4718 OR signature_id=4717) dest=$dest$
diff --git a/deprecated/investigations/get_logon_rights_modifications_for_user.yml b/deprecated/investigations/get_logon_rights_modifications_for_user.yml
index 10d81579af..5ef3f59e75 100644
--- a/deprecated/investigations/get_logon_rights_modifications_for_user.yml
+++ b/deprecated/investigations/get_logon_rights_modifications_for_user.yml
@@ -4,7 +4,7 @@ version: 2
date: '2019-02-27'
author: David Dorsey, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search allows you to retrieve any modifications to logon rights
for a specific user account.
search: '`wineventlog_security` (signature_id=4718 OR signature_id=4717) user=$user$
diff --git a/deprecated/investigations/get_notable_history.yml b/deprecated/investigations/get_notable_history.yml
index 0263940a86..fdd158e5a3 100644
--- a/deprecated/investigations/get_notable_history.yml
+++ b/deprecated/investigations/get_notable_history.yml
@@ -4,7 +4,7 @@ version: 2
date: '2017-09-20'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search queries the notable index and returns all the Notable Events
for the particular destination host, giving the analyst an overview of the incidents
that may have occurred with the host under investigation.
diff --git a/deprecated/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml b/deprecated/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml
index eb30eaa867..3ba36659b0 100644
--- a/deprecated/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml
+++ b/deprecated/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml
@@ -4,7 +4,7 @@ version: 1
date: '2018-06-14'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: 'This search returns the information of the users that sent emails to
the accounts controlled by the Hidden Cobra Threat Actors: specifically to `misswang8107@gmail.com`,
and from `redhat@gmail.com`.'
diff --git a/deprecated/investigations/get_parent_process_info.yml b/deprecated/investigations/get_parent_process_info.yml
index 54a97aea2b..e42faa26af 100644
--- a/deprecated/investigations/get_parent_process_info.yml
+++ b/deprecated/investigations/get_parent_process_info.yml
@@ -4,7 +4,7 @@ version: 2
date: '2019-02-28'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search queries the Endpoint data model to give you details about
the parent process of a process running on a host which is under investigation.
Enter the values of the process name in question and the dest
diff --git a/deprecated/investigations/get_process_file_activity.yml b/deprecated/investigations/get_process_file_activity.yml
index 04450db005..88dc720dac 100644
--- a/deprecated/investigations/get_process_file_activity.yml
+++ b/deprecated/investigations/get_process_file_activity.yml
@@ -4,7 +4,7 @@ version: 2
date: '2019-11-06'
author: David Dorsey, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search returns the file activity for a specific process on a specific
endpoint
search: '| tstats `security_content_summariesonly` values(Filesystem.file_name) as
diff --git a/deprecated/investigations/get_process_info.yml b/deprecated/investigations/get_process_info.yml
index c5e6c10d84..8d03f447e0 100644
--- a/deprecated/investigations/get_process_info.yml
+++ b/deprecated/investigations/get_process_info.yml
@@ -4,7 +4,7 @@ version: 2
date: '2019-04-01'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search queries the Endpoint data model to give you details about
the process running on a host which is under investigation. To gather the process
info, enter the values for the process name in question and the destination IP address.
diff --git a/deprecated/investigations/get_process_information_for_port_activity.yml b/deprecated/investigations/get_process_information_for_port_activity.yml
index de14541ff3..4b0ae45559 100644
--- a/deprecated/investigations/get_process_information_for_port_activity.yml
+++ b/deprecated/investigations/get_process_information_for_port_activity.yml
@@ -4,7 +4,7 @@ version: 2
date: '2019-04-01'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search will return information about the process associated with
observed network traffic to a specific destination port from a specific host.
search: '| tstats `security_content_summariesonly` count min(_time) max(_time) as
diff --git a/deprecated/investigations/get_process_responsible_for_the_dns_traffic.yml b/deprecated/investigations/get_process_responsible_for_the_dns_traffic.yml
index 09b50690c7..86e2ad11be 100644
--- a/deprecated/investigations/get_process_responsible_for_the_dns_traffic.yml
+++ b/deprecated/investigations/get_process_responsible_for_the_dns_traffic.yml
@@ -4,7 +4,7 @@ version: 2
date: '2019-04-01'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: While investigating, an analyst will want to know what process and parent_process
is responsible for generating suspicious DNS traffic. Use the following search and
enter the value of `dest` in the search to get specific details on the process responsible
diff --git a/deprecated/investigations/get_sysmon_wmi_activity_for_host.yml b/deprecated/investigations/get_sysmon_wmi_activity_for_host.yml
index e066466664..166013dd2a 100644
--- a/deprecated/investigations/get_sysmon_wmi_activity_for_host.yml
+++ b/deprecated/investigations/get_sysmon_wmi_activity_for_host.yml
@@ -4,7 +4,7 @@ version: 1
date: '2018-10-23'
author: Rico Valdez, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search queries Sysmon WMI events for the host of interest.
search: '`sysmon` EventCode>18 EventCode<22 | rename host as dest | search dest=$dest$|
table _time, dest, user, Name, Operation, EventType, Type, Query, Consumer, Filter'
diff --git a/deprecated/investigations/get_web_session_information_via_session_id.yml b/deprecated/investigations/get_web_session_information_via_session_id.yml
index 955b678802..5952077391 100644
--- a/deprecated/investigations/get_web_session_information_via_session_id.yml
+++ b/deprecated/investigations/get_web_session_information_via_session_id.yml
@@ -4,7 +4,7 @@ version: 1
date: '2018-10-08'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search helps an analyst investigate a notable event to find out
more about a specific web session. The search looks for a specific web session ID
in the HTTP web traffic and outputs the URL and user agents, grouped by source IP
diff --git a/deprecated/investigations/investigate_aws_activities_via_region_name.yml b/deprecated/investigations/investigate_aws_activities_via_region_name.yml
index d1f8bd0bbb..335daad51e 100644
--- a/deprecated/investigations/investigate_aws_activities_via_region_name.yml
+++ b/deprecated/investigations/investigate_aws_activities_via_region_name.yml
@@ -4,7 +4,7 @@ version: 1
date: '2018-02-09'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search lists all the user activities logged by CloudTrail for a
specific region in question and will create a table of the values of parameters
requested, the type of the event and the response from the AWS API by each user
diff --git a/deprecated/investigations/investigate_aws_user_activities_by_user_field.yml b/deprecated/investigations/investigate_aws_user_activities_by_user_field.yml
index 84f4231bcd..d0932da712 100644
--- a/deprecated/investigations/investigate_aws_user_activities_by_user_field.yml
+++ b/deprecated/investigations/investigate_aws_user_activities_by_user_field.yml
@@ -4,7 +4,7 @@ version: 2
date: '2024-09-24'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search lists all the logged CloudTrail activities by a specific
user and will create a table containing the source of the user, the region of the
activity, the name and type of the event, the action taken, and the user's identity
diff --git a/deprecated/investigations/investigate_failed_logins_for_multiple_destinations.yml b/deprecated/investigations/investigate_failed_logins_for_multiple_destinations.yml
index 929d971fd4..fbd88dcfb6 100644
--- a/deprecated/investigations/investigate_failed_logins_for_multiple_destinations.yml
+++ b/deprecated/investigations/investigate_failed_logins_for_multiple_destinations.yml
@@ -4,7 +4,7 @@ version: 1
date: '2019-12-10'
author: Patrick Bareiss, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search returns failed logins to multiple destinations by user.
search: '| tstats count `security_content_summariesonly` earliest(_time) as first_login
latest(_time) as last_login dc(Authentication.dest) AS distinct_count_dest values(Authentication.dest)
diff --git a/deprecated/investigations/investigate_network_traffic_from_src_ip.yml b/deprecated/investigations/investigate_network_traffic_from_src_ip.yml
index ba7875b78f..3fc46d2dbe 100644
--- a/deprecated/investigations/investigate_network_traffic_from_src_ip.yml
+++ b/deprecated/investigations/investigate_network_traffic_from_src_ip.yml
@@ -4,7 +4,7 @@ version: 1
date: '2018-06-15'
author: David Dorsey, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search allows you to find all the network traffic from a specific
IP address.
search: '| from datamodel Network_Traffic.All_Traffic | search src_ip=$src_ip$'
diff --git a/deprecated/investigations/investigate_okta_activity_by_app.yml b/deprecated/investigations/investigate_okta_activity_by_app.yml
index 9c9111a9aa..40a8e95697 100644
--- a/deprecated/investigations/investigate_okta_activity_by_app.yml
+++ b/deprecated/investigations/investigate_okta_activity_by_app.yml
@@ -4,7 +4,7 @@ version: 1
date: '2020-04-02'
author: Rico Valdez, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search returns all okta events associated with a specific app
search: '`okta` app=$app$ | rename client.geographicalContext.country as country,
client.geographicalContext.state as state, client.geographicalContext.city as city
diff --git a/deprecated/investigations/investigate_okta_activity_by_ip_address.yml b/deprecated/investigations/investigate_okta_activity_by_ip_address.yml
index a3a945fed5..0f5fbab9f9 100644
--- a/deprecated/investigations/investigate_okta_activity_by_ip_address.yml
+++ b/deprecated/investigations/investigate_okta_activity_by_ip_address.yml
@@ -4,7 +4,7 @@ version: 1
date: '2020-04-02'
author: Rico Valdez, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search returns all okta events from a specific IP address.
search: '`okta` src_ip={src_ip} | rename client.geographicalContext.country as country,
client.geographicalContext.state as state, client.geographicalContext.city as city
diff --git a/deprecated/investigations/investigate_pass_the_hash_attempts.yml b/deprecated/investigations/investigate_pass_the_hash_attempts.yml
index e4a495f05f..5f62609ac9 100644
--- a/deprecated/investigations/investigate_pass_the_hash_attempts.yml
+++ b/deprecated/investigations/investigate_pass_the_hash_attempts.yml
@@ -4,7 +4,7 @@ version: 1
date: '2019-12-10'
author: Patrick Bareiss, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search hunts for dumped NTLM hashes used for pass the hash.
search: '`wineventlog_security` EventCode=4624 Logon_Type=9 AuthenticationPackageName=Negotiate
| stats count earliest(_time) as first_login latest(_time) as last_login by src_user
diff --git a/deprecated/investigations/investigate_pass_the_ticket_attempts.yml b/deprecated/investigations/investigate_pass_the_ticket_attempts.yml
index 3e971419a5..e341b89e92 100644
--- a/deprecated/investigations/investigate_pass_the_ticket_attempts.yml
+++ b/deprecated/investigations/investigate_pass_the_ticket_attempts.yml
@@ -4,7 +4,7 @@ version: 2
date: '2024-09-24'
author: Patrick Bareiss, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search hunts for dumped kerberos ticket from LSASS memory.
search: '`wineventlog_security` EventCode=4768 OR EventCode=4769 | rex field=user
"(?[^\@]+)" | stats count BY new_user, dest, EventCode | stats max(count)
diff --git a/deprecated/investigations/investigate_previous_unseen_user.yml b/deprecated/investigations/investigate_previous_unseen_user.yml
index 1e70b07b01..9b9e865fc4 100644
--- a/deprecated/investigations/investigate_previous_unseen_user.yml
+++ b/deprecated/investigations/investigate_previous_unseen_user.yml
@@ -4,7 +4,7 @@ version: 1
date: '2019-12-10'
author: Patrick Bareiss, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search returns previous unseen user, which didn't log in for 30
days.
search: '| tstats count `security_content_summariesonly` earliest(_time) as first_login
diff --git a/deprecated/investigations/investigate_successful_remote_desktop_authentications.yml b/deprecated/investigations/investigate_successful_remote_desktop_authentications.yml
index b5c02044c6..5f4109c67c 100644
--- a/deprecated/investigations/investigate_successful_remote_desktop_authentications.yml
+++ b/deprecated/investigations/investigate_successful_remote_desktop_authentications.yml
@@ -4,7 +4,7 @@ version: 2
date: '2024-09-24'
author: Jose Hernandez, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search returns the source, destination, and user for all successful
remote-desktop authentications. A successful authentication after a brute-force
attack on a destination machine is suspicious behavior.
diff --git a/deprecated/investigations/investigate_suspicious_strings_in_http_header.yml b/deprecated/investigations/investigate_suspicious_strings_in_http_header.yml
index d2d83857e1..6aa7a6cefd 100644
--- a/deprecated/investigations/investigate_suspicious_strings_in_http_header.yml
+++ b/deprecated/investigations/investigate_suspicious_strings_in_http_header.yml
@@ -4,7 +4,7 @@ version: 1
date: '2017-10-20'
author: Bhavin Patel, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search helps an analyst investigate a notable event related to a
potential Apache Struts exploitation. To investigate, we will want to isolate and
analyze the "payload" or the commands that were passed to the vulnerable hosts by
diff --git a/deprecated/investigations/investigate_user_activities_in_okta.yml b/deprecated/investigations/investigate_user_activities_in_okta.yml
index 522e019822..cb133eb7e5 100644
--- a/deprecated/investigations/investigate_user_activities_in_okta.yml
+++ b/deprecated/investigations/investigate_user_activities_in_okta.yml
@@ -4,7 +4,7 @@ version: 1
date: '2020-04-02'
author: Rico Valdez, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This search returns all okta events by a specific user
search: '`okta` user=$user$ | rename client.geographicalContext.country as country,
client.geographicalContext.state as state, client.geographicalContext.city as city
diff --git a/deprecated/investigations/investigate_web_posts_from_src.yml b/deprecated/investigations/investigate_web_posts_from_src.yml
index 89d2b23432..0ca5d92202 100644
--- a/deprecated/investigations/investigate_web_posts_from_src.yml
+++ b/deprecated/investigations/investigate_web_posts_from_src.yml
@@ -4,7 +4,7 @@ version: 2
date: '2024-09-24'
author: Jose Hernandez, Splunk
type: Investigation
-status: deprecated
+status: removed
description: This investigative search retrieves POST requests from a specified source
IP or hostname. Identifying the POST requests, as well as their associated destination
URLs and user agent(s), may help you scope and characterize the suspicious traffic.
diff --git a/deprecated/stories/aws_cryptomining.yml b/deprecated/stories/aws_cryptomining.yml
index abd30eff4d..67599b5632 100644
--- a/deprecated/stories/aws_cryptomining.yml
+++ b/deprecated/stories/aws_cryptomining.yml
@@ -3,7 +3,7 @@ id: ced74200-8465-4bc3-bd2c-9a782eec6750
version: 1
date: '2018-03-08'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
description: Monitor your AWS EC2 instances for activities related to cryptojacking/cryptomining.
New instances that originate from previously unseen regions, users who launch abnormally
high numbers of instances, or EC2 instances started by previously unseen users are
diff --git a/deprecated/stories/aws_suspicious_provisioning_activities.yml b/deprecated/stories/aws_suspicious_provisioning_activities.yml
index c5403b49fa..d6d7def438 100644
--- a/deprecated/stories/aws_suspicious_provisioning_activities.yml
+++ b/deprecated/stories/aws_suspicious_provisioning_activities.yml
@@ -3,7 +3,7 @@ id: 3338b567-3804-4261-9889-cf0ca4753c7f
version: 1
date: '2018-03-16'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
description: Monitor your AWS provisioning activities for behaviors originating from
unfamiliar or unusual locations. These behaviors may indicate that malicious activities
are occurring somewhere within your network.
diff --git a/deprecated/stories/common_phishing_frameworks.yml b/deprecated/stories/common_phishing_frameworks.yml
index 055ff6b43a..6c8f0279d1 100644
--- a/deprecated/stories/common_phishing_frameworks.yml
+++ b/deprecated/stories/common_phishing_frameworks.yml
@@ -3,7 +3,7 @@ id: 9a64ab44-9214-4639-8163-7eaa2621bd61
version: 2
date: '2024-09-24'
author: Splunk Research Team, Splunk
-status: deprecated
+status: removed
description: 'Detect DNS and web requests to fake websites generated by the EvilGinx2
toolkit. These websites are designed to fool unwitting users who have clicked on
a malicious link in a phishing email.'
diff --git a/deprecated/stories/container_implantation_monitoring_and_investigation.yml b/deprecated/stories/container_implantation_monitoring_and_investigation.yml
index 53ee1b98a8..8fc04b5754 100644
--- a/deprecated/stories/container_implantation_monitoring_and_investigation.yml
+++ b/deprecated/stories/container_implantation_monitoring_and_investigation.yml
@@ -3,7 +3,7 @@ id: aa0e28b1-0521-4b6f-9d2a-7b87e34af246
version: 1
date: '2020-02-20'
author: Rod Soto, Rico Valdez, Splunk
-status: deprecated
+status: removed
description: Use the searches in this story to monitor your Kubernetes registry repositories
for upload, and deployment of potentially vulnerable, backdoor, or implanted containers.
These searches provide information on source users, destination path, container
diff --git a/deprecated/stories/host_redirection.yml b/deprecated/stories/host_redirection.yml
index 90953fb738..8a3c52c671 100644
--- a/deprecated/stories/host_redirection.yml
+++ b/deprecated/stories/host_redirection.yml
@@ -3,7 +3,7 @@ id: 2e8948a5-5239-406b-b56b-6c50fe268af4
version: 1
date: '2017-09-14'
author: Rico Valdez, Splunk
-status: deprecated
+status: removed
description: Detect evidence of tactics used to redirect traffic from a host to a
destination other than the one intended--potentially one that is part of an adversary's
attack infrastructure. An example is redirecting communications regarding patches
diff --git a/deprecated/stories/kubernetes_sensitive_role_activity.yml b/deprecated/stories/kubernetes_sensitive_role_activity.yml
index 735eb620fa..3e4aea5653 100644
--- a/deprecated/stories/kubernetes_sensitive_role_activity.yml
+++ b/deprecated/stories/kubernetes_sensitive_role_activity.yml
@@ -3,7 +3,7 @@ id: 8b3984d2-17b6-47e9-ba43-a3376e70fdcc
version: 1
date: '2020-05-20'
author: Rod Soto, Splunk
-status: deprecated
+status: removed
description: This story addresses detection and response around Sensitive Role usage
within a Kubernetes clusters against cluster resources and namespaces.
narrative: Kubernetes is the most used container orchestration platform, this orchestration
diff --git a/deprecated/stories/lateral_movement.yml b/deprecated/stories/lateral_movement.yml
index 20c7ee6a69..6fbf027832 100644
--- a/deprecated/stories/lateral_movement.yml
+++ b/deprecated/stories/lateral_movement.yml
@@ -3,7 +3,7 @@ id: 399d65dc-1f08-499b-a259-abd9051f38ad
version: 3
date: '2024-09-24'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
description: "DEPRECATED IN FAVOR OF ACTIVE DIRECTORY LATERAL MOVEMENT. Detect and investigate tactics, techniques, and procedures around how attackers move laterally within the enterprise. Because lateral movement can expose the adversary to detection, it should be an important focus for security analysts."
narrative: "Once attackers gain a foothold within an enterprise, they will seek to expand their accesses and leverage techniques that facilitate lateral movement. Attackers will often spend quite a bit of time and effort moving laterally. Because lateral movement renders an attacker the most vulnerable to detection, it's an excellent focus for detection and investigation. Indications of lateral movement can include the abuse of system utilities (such as `psexec.exe`), unauthorized use of remote desktop services, `file/admin$` shares, WMI, PowerShell, pass-the-hash, or the abuse of scheduled tasks. Organizations must be extra vigilant in detecting lateral movement techniques and look for suspicious activity in and around high-value strategic network assets, such as Active Directory, which are often considered the primary target or \"crown jewels\" to a persistent threat actor. An adversary can use lateral movement for multiple purposes, including remote execution of tools, pivoting to additional systems, obtaining access to specific information or files, access to additional credentials, exfiltrating data, or delivering a secondary effect. Adversaries may use legitimate credentials alongside inherent network and operating-system functionality to remotely connect to other systems and remain under the radar of network defenders. If there is evidence of lateral movement, it is imperative for analysts to collect evidence of the associated offending hosts. For example, an attacker might leverage host A to gain access to host B. From there, the attacker may try to move laterally to host C. In this example, the analyst should gather as much information as possible from all three hosts. It is also important to collect authentication logs for each host, to ensure that the offending accounts are well-documented. Analysts should account for all processes to ensure that the attackers did not install unauthorized software."
references:
diff --git a/deprecated/stories/monitor_backup_solution.yml b/deprecated/stories/monitor_backup_solution.yml
index c3f2dc7a32..3b0074346d 100644
--- a/deprecated/stories/monitor_backup_solution.yml
+++ b/deprecated/stories/monitor_backup_solution.yml
@@ -3,7 +3,7 @@ id: abe807c7-1eb6-4304-ac32-6e7aacdb891d
version: 1
date: '2017-09-12'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
description: Address common concerns when monitoring your backup processes. These
searches can help you reduce risks from ransomware, device theft, or denial of physical
access to a host by backing up data on endpoints.
diff --git a/deprecated/stories/monitor_for_unauthorized_software.yml b/deprecated/stories/monitor_for_unauthorized_software.yml
index a9e7d9688d..62b812f61c 100644
--- a/deprecated/stories/monitor_for_unauthorized_software.yml
+++ b/deprecated/stories/monitor_for_unauthorized_software.yml
@@ -3,7 +3,7 @@ id: 8892a655-6205-43f7-abba-06460e38c8ae
version: 2
date: '2024-09-24'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
description: 'Identify and investigate prohibited/unauthorized software or processes
that may be concealing malicious behavior within your environment.'
narrative: 'It is critical to identify unauthorized software and processes running
diff --git a/deprecated/stories/office_365_detections.yml b/deprecated/stories/office_365_detections.yml
index d2fb3d09b7..00b0764a96 100644
--- a/deprecated/stories/office_365_detections.yml
+++ b/deprecated/stories/office_365_detections.yml
@@ -3,7 +3,7 @@ id: 1a51dd71-effc-48b2-abc4-3e9cdb61e5b9
version: 2
date: '2020-12-16'
author: Patrick Bareiss, Mauricio Velazco, Splunk
-status: deprecated
+status: removed
description: Monitor for activities and anomalies indicative of potential threats within Office 365 environments.
narrative: Office 365 (O365) is Microsoft's cloud-based suite of productivity tools, encompassing email, collaboration platforms, and office applications, all integrated with Azure Active Directory for identity and access management. Given the centralized storage of sensitive organizational data within O365 and its widespread adoption, it has become a focal point for cybersecurity efforts. The platform's complexity, combined with its ubiquity, makes it both a valuable asset and a prime target for potential threats. As O365's importance grows, it increasingly becomes a target for attackers seeking to exploit organizational data and systems. Security teams should prioritize monitoring O365 not just because of the sensitive data it often holds, but also due to the myriad ways the platform can be exploited. Understanding and monitoring O365's security landscape is crucial for organizations to detect, respond to, and mitigate potential threats in a timely manner.
references:
diff --git a/deprecated/stories/spectre_and_meltdown_vulnerabilities.yml b/deprecated/stories/spectre_and_meltdown_vulnerabilities.yml
index 3b0bbf9c8d..baa7d5b14c 100644
--- a/deprecated/stories/spectre_and_meltdown_vulnerabilities.yml
+++ b/deprecated/stories/spectre_and_meltdown_vulnerabilities.yml
@@ -3,7 +3,7 @@ id: 6d3306f6-bb2b-4219-8609-8efad64032f2
version: 1
date: '2018-01-08'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
description: Assess and mitigate your systems' vulnerability to Spectre and Meltdown
exploitation with the searches in this Analytic Story.
narrative: Meltdown and Spectre exploit critical vulnerabilities in modern CPUs that
diff --git a/deprecated/stories/suspicious_aws_ec2_activities.yml b/deprecated/stories/suspicious_aws_ec2_activities.yml
index 89b5348253..06649b6670 100644
--- a/deprecated/stories/suspicious_aws_ec2_activities.yml
+++ b/deprecated/stories/suspicious_aws_ec2_activities.yml
@@ -3,7 +3,7 @@ id: 2e8948a5-5239-406b-b56b-6c50f1268af3
version: 1
date: '2018-02-09'
author: Bhavin Patel, Splunk
-status: deprecated
+status: removed
description: Use the searches in this Analytic Story to monitor your AWS EC2 instances
for evidence of anomalous activity and suspicious behaviors, such as EC2 instances
that originate from unusual locations or those launched by previously unseen users
diff --git a/deprecated/stories/unusual_aws_ec2_modifications.yml b/deprecated/stories/unusual_aws_ec2_modifications.yml
index f0f1fc4b54..98eb84e135 100644
--- a/deprecated/stories/unusual_aws_ec2_modifications.yml
+++ b/deprecated/stories/unusual_aws_ec2_modifications.yml
@@ -3,7 +3,7 @@ id: 73de57ef-0dfc-411f-b1e7-fa24428aeae0
version: 1
date: '2018-04-09'
author: David Dorsey, Splunk
-status: deprecated
+status: removed
description: Identify unusual changes to your AWS EC2 instances that may indicate
malicious activity. Modifications to your EC2 instances by previously unseen users
is an example of an activity that may warrant further investigation.
diff --git a/deprecated/stories/web_fraud_detection.yml b/deprecated/stories/web_fraud_detection.yml
index 81d8ee3448..7e066b1e4c 100644
--- a/deprecated/stories/web_fraud_detection.yml
+++ b/deprecated/stories/web_fraud_detection.yml
@@ -3,7 +3,7 @@ id: 18bb45b9-7684-45c6-9e97-1fdd0d98c0a7
version: 1
date: '2018-10-08'
author: Jim Apger, Splunk
-status: deprecated
+status: removed
description: Monitor your environment for activity consistent with common attack techniques
bad actors use when attempting to compromise web servers or other web-related assets.
narrative: 'The Federal Bureau of Investigations (FBI) defines Internet fraud as the
From 0d2d727083b3b7377744a9ddac21b213ed2aa556 Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Tue, 18 Mar 2025 13:39:39 -0700
Subject: [PATCH 62/67] updating replace
---
deprecated/deprecation_mapping.YML | 9 +--------
1 file changed, 1 insertion(+), 8 deletions(-)
diff --git a/deprecated/deprecation_mapping.YML b/deprecated/deprecation_mapping.YML
index e681484193..e070b62001 100644
--- a/deprecated/deprecation_mapping.YML
+++ b/deprecated/deprecation_mapping.YML
@@ -158,14 +158,7 @@ detections:
- deprecated_content: Remote System Discovery with Net
deprecated_in_version: 5.2.0
reason: "This analytic was focusing on 2 separate and unrelated type of threats
- or actions. It was split into other analytics, namely:\r\n\r\nWindows Network
- Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277\r\nWindows Sensitive
- Group Discovery With Net / a23a0e20-0b1b-4a07-82e5-ec5f70811e7a"
- replacement_content:
- - Windows Network Share Interaction With Net
- - deprecated_content: Remote System Discovery with Net
- deprecated_in_version: 5.2.0
- reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
+ or actions. PLease use the replacement content"
replacement_content:
- Windows Sensitive Group Discovery With Net
- deprecated_content: DNS Query Requests Resolved by Unauthorized DNS Servers
From b1d1ae90d9b5620481dade9ce1b2e74cb124327a Mon Sep 17 00:00:00 2001
From: Eric
Date: Tue, 18 Mar 2025 14:14:37 -0700
Subject: [PATCH 63/67] rename deprecated directory to removed
---
.../baselines/add_prohibited_processes_to_enterprise_security.yml | 0
.../baselines/baseline_of_api_calls_per_user_arn.yml | 0
...aseline_of_excessive_aws_instances_launched_by_user___mltk.yml | 0
...eline_of_excessive_aws_instances_terminated_by_user___mltk.yml | 0
{deprecated => removed}/baselines/monitor_successful_backups.yml | 0
.../baselines/monitor_unsuccessful_backups.yml | 0
.../previously_seen_api_call_per_user_roles_in_cloudtrail.yml | 0
.../previously_seen_aws_provisioning_activity_sources.yml | 0
{deprecated => removed}/baselines/previously_seen_aws_regions.yml | 0
{deprecated => removed}/baselines/previously_seen_ec2_amis.yml | 0
.../baselines/previously_seen_ec2_instance_types.yml | 0
.../baselines/previously_seen_ec2_launches_by_user.yml | 0
.../baselines/previously_seen_ec2_modifications_by_user.yml | 0
.../baselines/previously_seen_users_in_cloudtrail.yml | 0
.../systems_ready_for_spectre_meltdown_windows_patch.yml | 0
.../baselines/update_previously_seen_users_in_cloudtrail.yml | 0
{deprecated => removed}/deprecation_mapping.YML | 0
.../detections/abnormally_high_aws_instances_launched_by_user.yml | 0
.../abnormally_high_aws_instances_launched_by_user___mltk.yml | 0
.../abnormally_high_aws_instances_terminated_by_user.yml | 0
.../abnormally_high_aws_instances_terminated_by_user___mltk.yml | 0
.../detections/account_discovery_with_net_app.yml | 0
{deprecated => removed}/detections/asl_aws_createaccesskey.yml | 0
.../detections/asl_aws_excessive_security_scanning.yml | 0
.../detections/asl_aws_password_policy_changes.yml | 0
.../detections/attempt_to_stop_security_service.yml | 0
.../attempted_credential_dump_from_registry_via_reg_exe.yml | 0
.../aws_cloud_provisioning_from_previously_unseen_city.yml | 0
.../aws_cloud_provisioning_from_previously_unseen_country.yml | 0
.../aws_cloud_provisioning_from_previously_unseen_ip_address.yml | 0
.../aws_cloud_provisioning_from_previously_unseen_region.yml | 0
.../aws_eks_kubernetes_cluster_sensitive_object_access.yml | 0
.../detections/change_default_file_association.yml | 0
.../detections/clients_connecting_to_multiple_dns_servers.yml | 0
.../detections/cloud_network_access_control_list_deleted.yml | 0
.../detections/cmdline_tool_not_executed_in_cmd_shell.yml | 0
.../detections/correlation_by_repository_and_risk.yml | 0
.../detections/correlation_by_user_and_risk.yml | 0
.../detections/create_local_admin_accounts_using_net_exe.yml | 0
{deprecated => removed}/detections/deleting_of_net_users.yml | 0
.../detect_activity_related_to_pass_the_hash_attacks.yml | 0
.../detections/detect_api_activity_from_users_without_mfa.yml | 0
.../detect_aws_api_activities_from_unapproved_accounts.yml | 0
.../detections/detect_critical_alerts_from_security_tools.yml | 0
...detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml | 0
.../detections/detect_long_dns_txt_record_response.yml | 0
.../detections/detect_mimikatz_using_loaded_images.yml | 0
.../detect_mimikatz_via_powershell_and_eventcode_4703.yml | 0
.../detections/detect_new_api_calls_from_user_roles.yml | 0
.../detections/detect_new_user_aws_console_login.yml | 0
..._processes_used_for_system_network_configuration_discovery.yml | 0
.../detections/detect_spike_in_aws_api_activity.yml | 0
.../detections/detect_spike_in_network_acl_activity.yml | 0
.../detections/detect_spike_in_security_group_activity.yml | 0
.../detections/detect_usb_device_insertion.yml | 0
.../detections/detect_web_traffic_to_dynamic_domain_providers.yml | 0
.../detections/detect_webshell_exploit_behavior.yml | 0
{deprecated => removed}/detections/detection_of_dns_tunnels.yml | 0
{deprecated => removed}/detections/disabling_net_user_account.yml | 0
.../dns_query_requests_resolved_by_unauthorized_dns_servers.yml | 0
{deprecated => removed}/detections/dns_record_changed.yml | 0
.../detections/domain_account_discovery_with_net_app.yml | 0
.../detections/domain_group_discovery_with_net.yml | 0
.../detections/dump_lsass_via_procdump_rename.yml | 0
.../ec2_instance_modified_with_previously_unseen_user.yml | 0
.../ec2_instance_started_in_previously_unseen_region.yml | 0
.../ec2_instance_started_with_previously_unseen_ami.yml | 0
.../ec2_instance_started_with_previously_unseen_instance_type.yml | 0
.../ec2_instance_started_with_previously_unseen_user.yml | 0
.../detections/elevated_group_discovery_with_net.yml | 0
{deprecated => removed}/detections/excel_spawning_powershell.yml | 0
.../detections/excel_spawning_windows_script_host.yml | 0
.../detections/excessive_service_stop_attempt.yml | 0
{deprecated => removed}/detections/excessive_usage_of_net_app.yml | 0
.../detections/execution_of_file_with_spaces_before_extension.yml | 0
.../extended_period_without_successful_netbackup_backups.yml | 0
.../detections/extraction_of_registry_hives.yml | 0
.../detections/first_time_seen_command_line_argument.yml | 0
.../gcp_detect_accounts_with_high_risk_roles_by_project.yml | 0
.../gcp_detect_high_risk_permissions_by_resource_and_account.yml | 0
.../detections/gcp_detect_oauth_token_abuse.yml | 0
.../detections/gcp_kubernetes_cluster_scan_detection.yml | 0
{deprecated => removed}/detections/identify_new_user_accounts.yml | 0
.../kubernetes_aws_detect_most_active_service_accounts_by_pod.yml | 0
.../kubernetes_aws_detect_rbac_authorization_by_account.yml | 0
.../detections/kubernetes_aws_detect_sensitive_role_access.yml | 0
...netes_aws_detect_service_accounts_forbidden_failure_access.yml | 0
.../kubernetes_azure_active_service_accounts_by_pod_namespace.yml | 0
.../kubernetes_azure_detect_rbac_authorization_by_account.yml | 0
.../kubernetes_azure_detect_sensitive_object_access.yml | 0
.../detections/kubernetes_azure_detect_sensitive_role_access.yml | 0
...tes_azure_detect_service_accounts_forbidden_failure_access.yml | 0
.../kubernetes_azure_detect_suspicious_kubectl_calls.yml | 0
.../detections/kubernetes_azure_pod_scan_fingerprint.yml | 0
.../detections/kubernetes_azure_scan_fingerprint.yml | 0
.../kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml | 0
.../kubernetes_gcp_detect_rbac_authorizations_by_account.yml | 0
.../detections/kubernetes_gcp_detect_sensitive_object_access.yml | 0
.../detections/kubernetes_gcp_detect_sensitive_role_access.yml | 0
...netes_gcp_detect_service_accounts_forbidden_failure_access.yml | 0
.../detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml | 0
.../detections/linux_auditd_find_private_keys.yml | 0
.../detections/local_account_discovery_with_net.yml | 0
.../detections/monitor_dns_for_brand_abuse.yml | 0
.../detections/mshtml_module_load_in_office_product.yml | 0
...tiple_okta_users_with_invalid_credentials_from_the_same_ip.yml | 0
{deprecated => removed}/detections/net_localgroup_discovery.yml | 0
.../detections/network_connection_discovery_with_net.yml | 0
.../detections/o365_suspicious_admin_email_forwarding.yml | 0
.../detections/o365_suspicious_rights_delegation.yml | 0
.../detections/o365_suspicious_user_email_forwarding.yml | 0
.../detections/office_application_drop_executable.yml | 0
.../detections/office_application_spawn_regsvr32_process.yml | 0
.../detections/office_application_spawn_rundll32_process.yml | 0
.../detections/office_document_creating_schedule_task.yml | 0
.../detections/office_document_executing_macro_code.yml | 0
.../office_document_spawned_child_process_to_download.yml | 0
.../detections/office_product_spawn_cmd_process.yml | 0
.../detections/office_product_spawning_bitsadmin.yml | 0
.../detections/office_product_spawning_certutil.yml | 0
.../detections/office_product_spawning_mshta.yml | 0
.../detections/office_product_spawning_rundll32_with_no_dll.yml | 0
.../detections/office_product_spawning_windows_script_host.yml | 0
.../detections/office_product_spawning_wmic.yml | 0
.../detections/office_product_writing_cab_or_inf.yml | 0
{deprecated => removed}/detections/office_spawning_control.yml | 0
{deprecated => removed}/detections/okta_account_locked_out.yml | 0
.../detections/okta_account_lockout_events.yml | 0
{deprecated => removed}/detections/okta_failed_sso_attempts.yml | 0
.../okta_threatinsight_login_failure_with_high_unknown_users.yml | 0
.../okta_threatinsight_suspected_passwordspray_attack.yml | 0
.../detections/okta_two_or_more_rejected_okta_pushes.yml | 0
.../detections/osquery_pack___coldroot_detection.yml | 0
.../detections/password_policy_discovery_with_net.yml | 0
{deprecated => removed}/detections/processes_created_by_netsh.yml | 0
.../detections/prohibited_software_on_endpoint.yml | 0
.../reg_exe_used_to_hide_files_directories_via_registry_keys.yml | 0
.../detections/remote_registry_key_modifications.yml | 0
.../detections/remote_system_discovery_with_net.yml | 0
.../detections/scheduled_tasks_used_in_badrabbit_ransomware.yml | 0
.../detections/spectre_and_meltdown_vulnerable_systems.yml | 0
.../detections/suspicious_changes_to_file_associations.yml | 0
.../detections/suspicious_email___uba_anomaly.yml | 0
{deprecated => removed}/detections/suspicious_file_write.yml | 0
.../detections/suspicious_powershell_command_line_arguments.yml | 0
{deprecated => removed}/detections/suspicious_rundll32_rename.yml | 0
.../detections/suspicious_writes_to_system_volume_information.yml | 0
.../detections/uncommon_processes_on_endpoint.yml | 0
.../detections/unsigned_image_loaded_by_lsass.yml | 0
.../detections/unsuccessful_netbackup_backups.yml | 0
.../detections/web_fraud___account_harvesting.yml | 0
.../detections/web_fraud___anomalous_user_clickspeed.yml | 0
.../detections/web_fraud___password_sharing_across_accounts.yml | 0
.../detections/windows_command_shell_fetch_env_variables.yml | 0
.../detections/windows_connhost_exe_started_forcefully.yml | 0
.../detections/windows_dll_search_order_hijacking_hunt.yml | 0
.../detections/windows_hosts_file_modification.yml | 0
.../detections/windows_lateral_tool_transfer_remcom.yml | 0
.../detections/windows_modify_registry_reg_restore.yml | 0
.../detections/windows_msiexec_with_network_connections.yml | 0
.../detections/windows_network_share_interaction_with_net.yml | 0
.../detections/windows_office_product_spawning_msdt.yml | 0
.../detections/windows_query_registry_reg_save.yml | 0
.../windows_service_stop_via_net__and_sc_application.yml | 0
.../windows_valid_account_with_never_expires_password.yml | 0
{deprecated => removed}/detections/winword_spawning_cmd.yml | 0
.../detections/winword_spawning_powershell.yml | 0
.../detections/winword_spawning_windows_script_host.yml | 0
.../investigations/all_backup_logs_for_host.yml | 0
.../investigations/amazon_eks_kubernetes_activity_by_src_ip.yml | 0
.../aws_investigate_security_hub_alerts_by_dest.yml | 0
.../aws_investigate_user_activities_by_accesskeyid.yml | 0
.../investigations/aws_investigate_user_activities_by_arn.yml | 0
.../investigations/aws_network_acl_details_from_id.yml | 0
.../aws_network_interface_details_via_resourceid.yml | 0
.../investigations/aws_s3_bucket_details_via_bucketname.yml | 0
.../investigations/gcp_kubernetes_activity_by_src_ip.yml | 0
.../investigations/get_all_aws_activity_from_city.yml | 0
.../investigations/get_all_aws_activity_from_country.yml | 0
.../investigations/get_all_aws_activity_from_ip_address.yml | 0
.../investigations/get_all_aws_activity_from_region.yml | 0
.../investigations/get_backup_logs_for_endpoint.yml | 0
.../investigations/get_certificate_logs_for_a_domain.yml | 0
.../investigations/get_dns_server_history_for_a_host.yml | 0
{deprecated => removed}/investigations/get_dns_traffic_ratio.yml | 0
.../investigations/get_ec2_instance_details_by_instanceid.yml | 0
{deprecated => removed}/investigations/get_ec2_launch_details.yml | 0
{deprecated => removed}/investigations/get_email_info.yml | 0
.../investigations/get_emails_from_specific_sender.yml | 0
.../get_first_occurrence_and_last_occurrence_of_a_mac_address.yml | 0
.../investigations/get_history_of_email_sources.yml | 0
.../get_logon_rights_modifications_for_endpoint.yml | 0
.../investigations/get_logon_rights_modifications_for_user.yml | 0
{deprecated => removed}/investigations/get_notable_history.yml | 0
.../get_outbound_emails_to_hidden_cobra_threat_actors.yml | 0
.../investigations/get_parent_process_info.yml | 0
.../investigations/get_process_file_activity.yml | 0
{deprecated => removed}/investigations/get_process_info.yml | 0
.../investigations/get_process_information_for_port_activity.yml | 0
.../get_process_responsible_for_the_dns_traffic.yml | 0
.../investigations/get_sysmon_wmi_activity_for_host.yml | 0
.../investigations/get_web_session_information_via_session_id.yml | 0
.../investigations/investigate_aws_activities_via_region_name.yml | 0
.../investigate_aws_user_activities_by_user_field.yml | 0
.../investigate_failed_logins_for_multiple_destinations.yml | 0
.../investigations/investigate_network_traffic_from_src_ip.yml | 0
.../investigations/investigate_okta_activity_by_app.yml | 0
.../investigations/investigate_okta_activity_by_ip_address.yml | 0
.../investigations/investigate_pass_the_hash_attempts.yml | 0
.../investigations/investigate_pass_the_ticket_attempts.yml | 0
.../investigations/investigate_previous_unseen_user.yml | 0
.../investigate_successful_remote_desktop_authentications.yml | 0
.../investigate_suspicious_strings_in_http_header.yml | 0
.../investigations/investigate_user_activities_in_okta.yml | 0
.../investigations/investigate_web_posts_from_src.yml | 0
{deprecated => removed}/stories/aws_cryptomining.yml | 0
.../stories/aws_suspicious_provisioning_activities.yml | 0
{deprecated => removed}/stories/common_phishing_frameworks.yml | 0
.../container_implantation_monitoring_and_investigation.yml | 0
{deprecated => removed}/stories/host_redirection.yml | 0
.../stories/kubernetes_sensitive_role_activity.yml | 0
{deprecated => removed}/stories/lateral_movement.yml | 0
{deprecated => removed}/stories/monitor_backup_solution.yml | 0
.../stories/monitor_for_unauthorized_software.yml | 0
{deprecated => removed}/stories/office_365_detections.yml | 0
.../stories/spectre_and_meltdown_vulnerabilities.yml | 0
{deprecated => removed}/stories/suspicious_aws_ec2_activities.yml | 0
{deprecated => removed}/stories/unusual_aws_ec2_modifications.yml | 0
{deprecated => removed}/stories/web_fraud_detection.yml | 0
229 files changed, 0 insertions(+), 0 deletions(-)
rename {deprecated => removed}/baselines/add_prohibited_processes_to_enterprise_security.yml (100%)
rename {deprecated => removed}/baselines/baseline_of_api_calls_per_user_arn.yml (100%)
rename {deprecated => removed}/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml (100%)
rename {deprecated => removed}/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml (100%)
rename {deprecated => removed}/baselines/monitor_successful_backups.yml (100%)
rename {deprecated => removed}/baselines/monitor_unsuccessful_backups.yml (100%)
rename {deprecated => removed}/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml (100%)
rename {deprecated => removed}/baselines/previously_seen_aws_provisioning_activity_sources.yml (100%)
rename {deprecated => removed}/baselines/previously_seen_aws_regions.yml (100%)
rename {deprecated => removed}/baselines/previously_seen_ec2_amis.yml (100%)
rename {deprecated => removed}/baselines/previously_seen_ec2_instance_types.yml (100%)
rename {deprecated => removed}/baselines/previously_seen_ec2_launches_by_user.yml (100%)
rename {deprecated => removed}/baselines/previously_seen_ec2_modifications_by_user.yml (100%)
rename {deprecated => removed}/baselines/previously_seen_users_in_cloudtrail.yml (100%)
rename {deprecated => removed}/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml (100%)
rename {deprecated => removed}/baselines/update_previously_seen_users_in_cloudtrail.yml (100%)
rename {deprecated => removed}/deprecation_mapping.YML (100%)
rename {deprecated => removed}/detections/abnormally_high_aws_instances_launched_by_user.yml (100%)
rename {deprecated => removed}/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml (100%)
rename {deprecated => removed}/detections/abnormally_high_aws_instances_terminated_by_user.yml (100%)
rename {deprecated => removed}/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml (100%)
rename {deprecated => removed}/detections/account_discovery_with_net_app.yml (100%)
rename {deprecated => removed}/detections/asl_aws_createaccesskey.yml (100%)
rename {deprecated => removed}/detections/asl_aws_excessive_security_scanning.yml (100%)
rename {deprecated => removed}/detections/asl_aws_password_policy_changes.yml (100%)
rename {deprecated => removed}/detections/attempt_to_stop_security_service.yml (100%)
rename {deprecated => removed}/detections/attempted_credential_dump_from_registry_via_reg_exe.yml (100%)
rename {deprecated => removed}/detections/aws_cloud_provisioning_from_previously_unseen_city.yml (100%)
rename {deprecated => removed}/detections/aws_cloud_provisioning_from_previously_unseen_country.yml (100%)
rename {deprecated => removed}/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml (100%)
rename {deprecated => removed}/detections/aws_cloud_provisioning_from_previously_unseen_region.yml (100%)
rename {deprecated => removed}/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml (100%)
rename {deprecated => removed}/detections/change_default_file_association.yml (100%)
rename {deprecated => removed}/detections/clients_connecting_to_multiple_dns_servers.yml (100%)
rename {deprecated => removed}/detections/cloud_network_access_control_list_deleted.yml (100%)
rename {deprecated => removed}/detections/cmdline_tool_not_executed_in_cmd_shell.yml (100%)
rename {deprecated => removed}/detections/correlation_by_repository_and_risk.yml (100%)
rename {deprecated => removed}/detections/correlation_by_user_and_risk.yml (100%)
rename {deprecated => removed}/detections/create_local_admin_accounts_using_net_exe.yml (100%)
rename {deprecated => removed}/detections/deleting_of_net_users.yml (100%)
rename {deprecated => removed}/detections/detect_activity_related_to_pass_the_hash_attacks.yml (100%)
rename {deprecated => removed}/detections/detect_api_activity_from_users_without_mfa.yml (100%)
rename {deprecated => removed}/detections/detect_aws_api_activities_from_unapproved_accounts.yml (100%)
rename {deprecated => removed}/detections/detect_critical_alerts_from_security_tools.yml (100%)
rename {deprecated => removed}/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml (100%)
rename {deprecated => removed}/detections/detect_long_dns_txt_record_response.yml (100%)
rename {deprecated => removed}/detections/detect_mimikatz_using_loaded_images.yml (100%)
rename {deprecated => removed}/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml (100%)
rename {deprecated => removed}/detections/detect_new_api_calls_from_user_roles.yml (100%)
rename {deprecated => removed}/detections/detect_new_user_aws_console_login.yml (100%)
rename {deprecated => removed}/detections/detect_processes_used_for_system_network_configuration_discovery.yml (100%)
rename {deprecated => removed}/detections/detect_spike_in_aws_api_activity.yml (100%)
rename {deprecated => removed}/detections/detect_spike_in_network_acl_activity.yml (100%)
rename {deprecated => removed}/detections/detect_spike_in_security_group_activity.yml (100%)
rename {deprecated => removed}/detections/detect_usb_device_insertion.yml (100%)
rename {deprecated => removed}/detections/detect_web_traffic_to_dynamic_domain_providers.yml (100%)
rename {deprecated => removed}/detections/detect_webshell_exploit_behavior.yml (100%)
rename {deprecated => removed}/detections/detection_of_dns_tunnels.yml (100%)
rename {deprecated => removed}/detections/disabling_net_user_account.yml (100%)
rename {deprecated => removed}/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml (100%)
rename {deprecated => removed}/detections/dns_record_changed.yml (100%)
rename {deprecated => removed}/detections/domain_account_discovery_with_net_app.yml (100%)
rename {deprecated => removed}/detections/domain_group_discovery_with_net.yml (100%)
rename {deprecated => removed}/detections/dump_lsass_via_procdump_rename.yml (100%)
rename {deprecated => removed}/detections/ec2_instance_modified_with_previously_unseen_user.yml (100%)
rename {deprecated => removed}/detections/ec2_instance_started_in_previously_unseen_region.yml (100%)
rename {deprecated => removed}/detections/ec2_instance_started_with_previously_unseen_ami.yml (100%)
rename {deprecated => removed}/detections/ec2_instance_started_with_previously_unseen_instance_type.yml (100%)
rename {deprecated => removed}/detections/ec2_instance_started_with_previously_unseen_user.yml (100%)
rename {deprecated => removed}/detections/elevated_group_discovery_with_net.yml (100%)
rename {deprecated => removed}/detections/excel_spawning_powershell.yml (100%)
rename {deprecated => removed}/detections/excel_spawning_windows_script_host.yml (100%)
rename {deprecated => removed}/detections/excessive_service_stop_attempt.yml (100%)
rename {deprecated => removed}/detections/excessive_usage_of_net_app.yml (100%)
rename {deprecated => removed}/detections/execution_of_file_with_spaces_before_extension.yml (100%)
rename {deprecated => removed}/detections/extended_period_without_successful_netbackup_backups.yml (100%)
rename {deprecated => removed}/detections/extraction_of_registry_hives.yml (100%)
rename {deprecated => removed}/detections/first_time_seen_command_line_argument.yml (100%)
rename {deprecated => removed}/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml (100%)
rename {deprecated => removed}/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml (100%)
rename {deprecated => removed}/detections/gcp_detect_oauth_token_abuse.yml (100%)
rename {deprecated => removed}/detections/gcp_kubernetes_cluster_scan_detection.yml (100%)
rename {deprecated => removed}/detections/identify_new_user_accounts.yml (100%)
rename {deprecated => removed}/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml (100%)
rename {deprecated => removed}/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml (100%)
rename {deprecated => removed}/detections/kubernetes_aws_detect_sensitive_role_access.yml (100%)
rename {deprecated => removed}/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml (100%)
rename {deprecated => removed}/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml (100%)
rename {deprecated => removed}/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml (100%)
rename {deprecated => removed}/detections/kubernetes_azure_detect_sensitive_object_access.yml (100%)
rename {deprecated => removed}/detections/kubernetes_azure_detect_sensitive_role_access.yml (100%)
rename {deprecated => removed}/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml (100%)
rename {deprecated => removed}/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml (100%)
rename {deprecated => removed}/detections/kubernetes_azure_pod_scan_fingerprint.yml (100%)
rename {deprecated => removed}/detections/kubernetes_azure_scan_fingerprint.yml (100%)
rename {deprecated => removed}/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml (100%)
rename {deprecated => removed}/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml (100%)
rename {deprecated => removed}/detections/kubernetes_gcp_detect_sensitive_object_access.yml (100%)
rename {deprecated => removed}/detections/kubernetes_gcp_detect_sensitive_role_access.yml (100%)
rename {deprecated => removed}/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml (100%)
rename {deprecated => removed}/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml (100%)
rename {deprecated => removed}/detections/linux_auditd_find_private_keys.yml (100%)
rename {deprecated => removed}/detections/local_account_discovery_with_net.yml (100%)
rename {deprecated => removed}/detections/monitor_dns_for_brand_abuse.yml (100%)
rename {deprecated => removed}/detections/mshtml_module_load_in_office_product.yml (100%)
rename {deprecated => removed}/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml (100%)
rename {deprecated => removed}/detections/net_localgroup_discovery.yml (100%)
rename {deprecated => removed}/detections/network_connection_discovery_with_net.yml (100%)
rename {deprecated => removed}/detections/o365_suspicious_admin_email_forwarding.yml (100%)
rename {deprecated => removed}/detections/o365_suspicious_rights_delegation.yml (100%)
rename {deprecated => removed}/detections/o365_suspicious_user_email_forwarding.yml (100%)
rename {deprecated => removed}/detections/office_application_drop_executable.yml (100%)
rename {deprecated => removed}/detections/office_application_spawn_regsvr32_process.yml (100%)
rename {deprecated => removed}/detections/office_application_spawn_rundll32_process.yml (100%)
rename {deprecated => removed}/detections/office_document_creating_schedule_task.yml (100%)
rename {deprecated => removed}/detections/office_document_executing_macro_code.yml (100%)
rename {deprecated => removed}/detections/office_document_spawned_child_process_to_download.yml (100%)
rename {deprecated => removed}/detections/office_product_spawn_cmd_process.yml (100%)
rename {deprecated => removed}/detections/office_product_spawning_bitsadmin.yml (100%)
rename {deprecated => removed}/detections/office_product_spawning_certutil.yml (100%)
rename {deprecated => removed}/detections/office_product_spawning_mshta.yml (100%)
rename {deprecated => removed}/detections/office_product_spawning_rundll32_with_no_dll.yml (100%)
rename {deprecated => removed}/detections/office_product_spawning_windows_script_host.yml (100%)
rename {deprecated => removed}/detections/office_product_spawning_wmic.yml (100%)
rename {deprecated => removed}/detections/office_product_writing_cab_or_inf.yml (100%)
rename {deprecated => removed}/detections/office_spawning_control.yml (100%)
rename {deprecated => removed}/detections/okta_account_locked_out.yml (100%)
rename {deprecated => removed}/detections/okta_account_lockout_events.yml (100%)
rename {deprecated => removed}/detections/okta_failed_sso_attempts.yml (100%)
rename {deprecated => removed}/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml (100%)
rename {deprecated => removed}/detections/okta_threatinsight_suspected_passwordspray_attack.yml (100%)
rename {deprecated => removed}/detections/okta_two_or_more_rejected_okta_pushes.yml (100%)
rename {deprecated => removed}/detections/osquery_pack___coldroot_detection.yml (100%)
rename {deprecated => removed}/detections/password_policy_discovery_with_net.yml (100%)
rename {deprecated => removed}/detections/processes_created_by_netsh.yml (100%)
rename {deprecated => removed}/detections/prohibited_software_on_endpoint.yml (100%)
rename {deprecated => removed}/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml (100%)
rename {deprecated => removed}/detections/remote_registry_key_modifications.yml (100%)
rename {deprecated => removed}/detections/remote_system_discovery_with_net.yml (100%)
rename {deprecated => removed}/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml (100%)
rename {deprecated => removed}/detections/spectre_and_meltdown_vulnerable_systems.yml (100%)
rename {deprecated => removed}/detections/suspicious_changes_to_file_associations.yml (100%)
rename {deprecated => removed}/detections/suspicious_email___uba_anomaly.yml (100%)
rename {deprecated => removed}/detections/suspicious_file_write.yml (100%)
rename {deprecated => removed}/detections/suspicious_powershell_command_line_arguments.yml (100%)
rename {deprecated => removed}/detections/suspicious_rundll32_rename.yml (100%)
rename {deprecated => removed}/detections/suspicious_writes_to_system_volume_information.yml (100%)
rename {deprecated => removed}/detections/uncommon_processes_on_endpoint.yml (100%)
rename {deprecated => removed}/detections/unsigned_image_loaded_by_lsass.yml (100%)
rename {deprecated => removed}/detections/unsuccessful_netbackup_backups.yml (100%)
rename {deprecated => removed}/detections/web_fraud___account_harvesting.yml (100%)
rename {deprecated => removed}/detections/web_fraud___anomalous_user_clickspeed.yml (100%)
rename {deprecated => removed}/detections/web_fraud___password_sharing_across_accounts.yml (100%)
rename {deprecated => removed}/detections/windows_command_shell_fetch_env_variables.yml (100%)
rename {deprecated => removed}/detections/windows_connhost_exe_started_forcefully.yml (100%)
rename {deprecated => removed}/detections/windows_dll_search_order_hijacking_hunt.yml (100%)
rename {deprecated => removed}/detections/windows_hosts_file_modification.yml (100%)
rename {deprecated => removed}/detections/windows_lateral_tool_transfer_remcom.yml (100%)
rename {deprecated => removed}/detections/windows_modify_registry_reg_restore.yml (100%)
rename {deprecated => removed}/detections/windows_msiexec_with_network_connections.yml (100%)
rename {deprecated => removed}/detections/windows_network_share_interaction_with_net.yml (100%)
rename {deprecated => removed}/detections/windows_office_product_spawning_msdt.yml (100%)
rename {deprecated => removed}/detections/windows_query_registry_reg_save.yml (100%)
rename {deprecated => removed}/detections/windows_service_stop_via_net__and_sc_application.yml (100%)
rename {deprecated => removed}/detections/windows_valid_account_with_never_expires_password.yml (100%)
rename {deprecated => removed}/detections/winword_spawning_cmd.yml (100%)
rename {deprecated => removed}/detections/winword_spawning_powershell.yml (100%)
rename {deprecated => removed}/detections/winword_spawning_windows_script_host.yml (100%)
rename {deprecated => removed}/investigations/all_backup_logs_for_host.yml (100%)
rename {deprecated => removed}/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml (100%)
rename {deprecated => removed}/investigations/aws_investigate_security_hub_alerts_by_dest.yml (100%)
rename {deprecated => removed}/investigations/aws_investigate_user_activities_by_accesskeyid.yml (100%)
rename {deprecated => removed}/investigations/aws_investigate_user_activities_by_arn.yml (100%)
rename {deprecated => removed}/investigations/aws_network_acl_details_from_id.yml (100%)
rename {deprecated => removed}/investigations/aws_network_interface_details_via_resourceid.yml (100%)
rename {deprecated => removed}/investigations/aws_s3_bucket_details_via_bucketname.yml (100%)
rename {deprecated => removed}/investigations/gcp_kubernetes_activity_by_src_ip.yml (100%)
rename {deprecated => removed}/investigations/get_all_aws_activity_from_city.yml (100%)
rename {deprecated => removed}/investigations/get_all_aws_activity_from_country.yml (100%)
rename {deprecated => removed}/investigations/get_all_aws_activity_from_ip_address.yml (100%)
rename {deprecated => removed}/investigations/get_all_aws_activity_from_region.yml (100%)
rename {deprecated => removed}/investigations/get_backup_logs_for_endpoint.yml (100%)
rename {deprecated => removed}/investigations/get_certificate_logs_for_a_domain.yml (100%)
rename {deprecated => removed}/investigations/get_dns_server_history_for_a_host.yml (100%)
rename {deprecated => removed}/investigations/get_dns_traffic_ratio.yml (100%)
rename {deprecated => removed}/investigations/get_ec2_instance_details_by_instanceid.yml (100%)
rename {deprecated => removed}/investigations/get_ec2_launch_details.yml (100%)
rename {deprecated => removed}/investigations/get_email_info.yml (100%)
rename {deprecated => removed}/investigations/get_emails_from_specific_sender.yml (100%)
rename {deprecated => removed}/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml (100%)
rename {deprecated => removed}/investigations/get_history_of_email_sources.yml (100%)
rename {deprecated => removed}/investigations/get_logon_rights_modifications_for_endpoint.yml (100%)
rename {deprecated => removed}/investigations/get_logon_rights_modifications_for_user.yml (100%)
rename {deprecated => removed}/investigations/get_notable_history.yml (100%)
rename {deprecated => removed}/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml (100%)
rename {deprecated => removed}/investigations/get_parent_process_info.yml (100%)
rename {deprecated => removed}/investigations/get_process_file_activity.yml (100%)
rename {deprecated => removed}/investigations/get_process_info.yml (100%)
rename {deprecated => removed}/investigations/get_process_information_for_port_activity.yml (100%)
rename {deprecated => removed}/investigations/get_process_responsible_for_the_dns_traffic.yml (100%)
rename {deprecated => removed}/investigations/get_sysmon_wmi_activity_for_host.yml (100%)
rename {deprecated => removed}/investigations/get_web_session_information_via_session_id.yml (100%)
rename {deprecated => removed}/investigations/investigate_aws_activities_via_region_name.yml (100%)
rename {deprecated => removed}/investigations/investigate_aws_user_activities_by_user_field.yml (100%)
rename {deprecated => removed}/investigations/investigate_failed_logins_for_multiple_destinations.yml (100%)
rename {deprecated => removed}/investigations/investigate_network_traffic_from_src_ip.yml (100%)
rename {deprecated => removed}/investigations/investigate_okta_activity_by_app.yml (100%)
rename {deprecated => removed}/investigations/investigate_okta_activity_by_ip_address.yml (100%)
rename {deprecated => removed}/investigations/investigate_pass_the_hash_attempts.yml (100%)
rename {deprecated => removed}/investigations/investigate_pass_the_ticket_attempts.yml (100%)
rename {deprecated => removed}/investigations/investigate_previous_unseen_user.yml (100%)
rename {deprecated => removed}/investigations/investigate_successful_remote_desktop_authentications.yml (100%)
rename {deprecated => removed}/investigations/investigate_suspicious_strings_in_http_header.yml (100%)
rename {deprecated => removed}/investigations/investigate_user_activities_in_okta.yml (100%)
rename {deprecated => removed}/investigations/investigate_web_posts_from_src.yml (100%)
rename {deprecated => removed}/stories/aws_cryptomining.yml (100%)
rename {deprecated => removed}/stories/aws_suspicious_provisioning_activities.yml (100%)
rename {deprecated => removed}/stories/common_phishing_frameworks.yml (100%)
rename {deprecated => removed}/stories/container_implantation_monitoring_and_investigation.yml (100%)
rename {deprecated => removed}/stories/host_redirection.yml (100%)
rename {deprecated => removed}/stories/kubernetes_sensitive_role_activity.yml (100%)
rename {deprecated => removed}/stories/lateral_movement.yml (100%)
rename {deprecated => removed}/stories/monitor_backup_solution.yml (100%)
rename {deprecated => removed}/stories/monitor_for_unauthorized_software.yml (100%)
rename {deprecated => removed}/stories/office_365_detections.yml (100%)
rename {deprecated => removed}/stories/spectre_and_meltdown_vulnerabilities.yml (100%)
rename {deprecated => removed}/stories/suspicious_aws_ec2_activities.yml (100%)
rename {deprecated => removed}/stories/unusual_aws_ec2_modifications.yml (100%)
rename {deprecated => removed}/stories/web_fraud_detection.yml (100%)
diff --git a/deprecated/baselines/add_prohibited_processes_to_enterprise_security.yml b/removed/baselines/add_prohibited_processes_to_enterprise_security.yml
similarity index 100%
rename from deprecated/baselines/add_prohibited_processes_to_enterprise_security.yml
rename to removed/baselines/add_prohibited_processes_to_enterprise_security.yml
diff --git a/deprecated/baselines/baseline_of_api_calls_per_user_arn.yml b/removed/baselines/baseline_of_api_calls_per_user_arn.yml
similarity index 100%
rename from deprecated/baselines/baseline_of_api_calls_per_user_arn.yml
rename to removed/baselines/baseline_of_api_calls_per_user_arn.yml
diff --git a/deprecated/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml b/removed/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml
similarity index 100%
rename from deprecated/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml
rename to removed/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml
diff --git a/deprecated/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml b/removed/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml
similarity index 100%
rename from deprecated/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml
rename to removed/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml
diff --git a/deprecated/baselines/monitor_successful_backups.yml b/removed/baselines/monitor_successful_backups.yml
similarity index 100%
rename from deprecated/baselines/monitor_successful_backups.yml
rename to removed/baselines/monitor_successful_backups.yml
diff --git a/deprecated/baselines/monitor_unsuccessful_backups.yml b/removed/baselines/monitor_unsuccessful_backups.yml
similarity index 100%
rename from deprecated/baselines/monitor_unsuccessful_backups.yml
rename to removed/baselines/monitor_unsuccessful_backups.yml
diff --git a/deprecated/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml b/removed/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml
similarity index 100%
rename from deprecated/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml
rename to removed/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml
diff --git a/deprecated/baselines/previously_seen_aws_provisioning_activity_sources.yml b/removed/baselines/previously_seen_aws_provisioning_activity_sources.yml
similarity index 100%
rename from deprecated/baselines/previously_seen_aws_provisioning_activity_sources.yml
rename to removed/baselines/previously_seen_aws_provisioning_activity_sources.yml
diff --git a/deprecated/baselines/previously_seen_aws_regions.yml b/removed/baselines/previously_seen_aws_regions.yml
similarity index 100%
rename from deprecated/baselines/previously_seen_aws_regions.yml
rename to removed/baselines/previously_seen_aws_regions.yml
diff --git a/deprecated/baselines/previously_seen_ec2_amis.yml b/removed/baselines/previously_seen_ec2_amis.yml
similarity index 100%
rename from deprecated/baselines/previously_seen_ec2_amis.yml
rename to removed/baselines/previously_seen_ec2_amis.yml
diff --git a/deprecated/baselines/previously_seen_ec2_instance_types.yml b/removed/baselines/previously_seen_ec2_instance_types.yml
similarity index 100%
rename from deprecated/baselines/previously_seen_ec2_instance_types.yml
rename to removed/baselines/previously_seen_ec2_instance_types.yml
diff --git a/deprecated/baselines/previously_seen_ec2_launches_by_user.yml b/removed/baselines/previously_seen_ec2_launches_by_user.yml
similarity index 100%
rename from deprecated/baselines/previously_seen_ec2_launches_by_user.yml
rename to removed/baselines/previously_seen_ec2_launches_by_user.yml
diff --git a/deprecated/baselines/previously_seen_ec2_modifications_by_user.yml b/removed/baselines/previously_seen_ec2_modifications_by_user.yml
similarity index 100%
rename from deprecated/baselines/previously_seen_ec2_modifications_by_user.yml
rename to removed/baselines/previously_seen_ec2_modifications_by_user.yml
diff --git a/deprecated/baselines/previously_seen_users_in_cloudtrail.yml b/removed/baselines/previously_seen_users_in_cloudtrail.yml
similarity index 100%
rename from deprecated/baselines/previously_seen_users_in_cloudtrail.yml
rename to removed/baselines/previously_seen_users_in_cloudtrail.yml
diff --git a/deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml b/removed/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml
similarity index 100%
rename from deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml
rename to removed/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml
diff --git a/deprecated/baselines/update_previously_seen_users_in_cloudtrail.yml b/removed/baselines/update_previously_seen_users_in_cloudtrail.yml
similarity index 100%
rename from deprecated/baselines/update_previously_seen_users_in_cloudtrail.yml
rename to removed/baselines/update_previously_seen_users_in_cloudtrail.yml
diff --git a/deprecated/deprecation_mapping.YML b/removed/deprecation_mapping.YML
similarity index 100%
rename from deprecated/deprecation_mapping.YML
rename to removed/deprecation_mapping.YML
diff --git a/deprecated/detections/abnormally_high_aws_instances_launched_by_user.yml b/removed/detections/abnormally_high_aws_instances_launched_by_user.yml
similarity index 100%
rename from deprecated/detections/abnormally_high_aws_instances_launched_by_user.yml
rename to removed/detections/abnormally_high_aws_instances_launched_by_user.yml
diff --git a/deprecated/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml b/removed/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml
similarity index 100%
rename from deprecated/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml
rename to removed/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml
diff --git a/deprecated/detections/abnormally_high_aws_instances_terminated_by_user.yml b/removed/detections/abnormally_high_aws_instances_terminated_by_user.yml
similarity index 100%
rename from deprecated/detections/abnormally_high_aws_instances_terminated_by_user.yml
rename to removed/detections/abnormally_high_aws_instances_terminated_by_user.yml
diff --git a/deprecated/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml b/removed/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml
similarity index 100%
rename from deprecated/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml
rename to removed/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml
diff --git a/deprecated/detections/account_discovery_with_net_app.yml b/removed/detections/account_discovery_with_net_app.yml
similarity index 100%
rename from deprecated/detections/account_discovery_with_net_app.yml
rename to removed/detections/account_discovery_with_net_app.yml
diff --git a/deprecated/detections/asl_aws_createaccesskey.yml b/removed/detections/asl_aws_createaccesskey.yml
similarity index 100%
rename from deprecated/detections/asl_aws_createaccesskey.yml
rename to removed/detections/asl_aws_createaccesskey.yml
diff --git a/deprecated/detections/asl_aws_excessive_security_scanning.yml b/removed/detections/asl_aws_excessive_security_scanning.yml
similarity index 100%
rename from deprecated/detections/asl_aws_excessive_security_scanning.yml
rename to removed/detections/asl_aws_excessive_security_scanning.yml
diff --git a/deprecated/detections/asl_aws_password_policy_changes.yml b/removed/detections/asl_aws_password_policy_changes.yml
similarity index 100%
rename from deprecated/detections/asl_aws_password_policy_changes.yml
rename to removed/detections/asl_aws_password_policy_changes.yml
diff --git a/deprecated/detections/attempt_to_stop_security_service.yml b/removed/detections/attempt_to_stop_security_service.yml
similarity index 100%
rename from deprecated/detections/attempt_to_stop_security_service.yml
rename to removed/detections/attempt_to_stop_security_service.yml
diff --git a/deprecated/detections/attempted_credential_dump_from_registry_via_reg_exe.yml b/removed/detections/attempted_credential_dump_from_registry_via_reg_exe.yml
similarity index 100%
rename from deprecated/detections/attempted_credential_dump_from_registry_via_reg_exe.yml
rename to removed/detections/attempted_credential_dump_from_registry_via_reg_exe.yml
diff --git a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_city.yml b/removed/detections/aws_cloud_provisioning_from_previously_unseen_city.yml
similarity index 100%
rename from deprecated/detections/aws_cloud_provisioning_from_previously_unseen_city.yml
rename to removed/detections/aws_cloud_provisioning_from_previously_unseen_city.yml
diff --git a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_country.yml b/removed/detections/aws_cloud_provisioning_from_previously_unseen_country.yml
similarity index 100%
rename from deprecated/detections/aws_cloud_provisioning_from_previously_unseen_country.yml
rename to removed/detections/aws_cloud_provisioning_from_previously_unseen_country.yml
diff --git a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml b/removed/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml
similarity index 100%
rename from deprecated/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml
rename to removed/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml
diff --git a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_region.yml b/removed/detections/aws_cloud_provisioning_from_previously_unseen_region.yml
similarity index 100%
rename from deprecated/detections/aws_cloud_provisioning_from_previously_unseen_region.yml
rename to removed/detections/aws_cloud_provisioning_from_previously_unseen_region.yml
diff --git a/deprecated/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml b/removed/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml
similarity index 100%
rename from deprecated/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml
rename to removed/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml
diff --git a/deprecated/detections/change_default_file_association.yml b/removed/detections/change_default_file_association.yml
similarity index 100%
rename from deprecated/detections/change_default_file_association.yml
rename to removed/detections/change_default_file_association.yml
diff --git a/deprecated/detections/clients_connecting_to_multiple_dns_servers.yml b/removed/detections/clients_connecting_to_multiple_dns_servers.yml
similarity index 100%
rename from deprecated/detections/clients_connecting_to_multiple_dns_servers.yml
rename to removed/detections/clients_connecting_to_multiple_dns_servers.yml
diff --git a/deprecated/detections/cloud_network_access_control_list_deleted.yml b/removed/detections/cloud_network_access_control_list_deleted.yml
similarity index 100%
rename from deprecated/detections/cloud_network_access_control_list_deleted.yml
rename to removed/detections/cloud_network_access_control_list_deleted.yml
diff --git a/deprecated/detections/cmdline_tool_not_executed_in_cmd_shell.yml b/removed/detections/cmdline_tool_not_executed_in_cmd_shell.yml
similarity index 100%
rename from deprecated/detections/cmdline_tool_not_executed_in_cmd_shell.yml
rename to removed/detections/cmdline_tool_not_executed_in_cmd_shell.yml
diff --git a/deprecated/detections/correlation_by_repository_and_risk.yml b/removed/detections/correlation_by_repository_and_risk.yml
similarity index 100%
rename from deprecated/detections/correlation_by_repository_and_risk.yml
rename to removed/detections/correlation_by_repository_and_risk.yml
diff --git a/deprecated/detections/correlation_by_user_and_risk.yml b/removed/detections/correlation_by_user_and_risk.yml
similarity index 100%
rename from deprecated/detections/correlation_by_user_and_risk.yml
rename to removed/detections/correlation_by_user_and_risk.yml
diff --git a/deprecated/detections/create_local_admin_accounts_using_net_exe.yml b/removed/detections/create_local_admin_accounts_using_net_exe.yml
similarity index 100%
rename from deprecated/detections/create_local_admin_accounts_using_net_exe.yml
rename to removed/detections/create_local_admin_accounts_using_net_exe.yml
diff --git a/deprecated/detections/deleting_of_net_users.yml b/removed/detections/deleting_of_net_users.yml
similarity index 100%
rename from deprecated/detections/deleting_of_net_users.yml
rename to removed/detections/deleting_of_net_users.yml
diff --git a/deprecated/detections/detect_activity_related_to_pass_the_hash_attacks.yml b/removed/detections/detect_activity_related_to_pass_the_hash_attacks.yml
similarity index 100%
rename from deprecated/detections/detect_activity_related_to_pass_the_hash_attacks.yml
rename to removed/detections/detect_activity_related_to_pass_the_hash_attacks.yml
diff --git a/deprecated/detections/detect_api_activity_from_users_without_mfa.yml b/removed/detections/detect_api_activity_from_users_without_mfa.yml
similarity index 100%
rename from deprecated/detections/detect_api_activity_from_users_without_mfa.yml
rename to removed/detections/detect_api_activity_from_users_without_mfa.yml
diff --git a/deprecated/detections/detect_aws_api_activities_from_unapproved_accounts.yml b/removed/detections/detect_aws_api_activities_from_unapproved_accounts.yml
similarity index 100%
rename from deprecated/detections/detect_aws_api_activities_from_unapproved_accounts.yml
rename to removed/detections/detect_aws_api_activities_from_unapproved_accounts.yml
diff --git a/deprecated/detections/detect_critical_alerts_from_security_tools.yml b/removed/detections/detect_critical_alerts_from_security_tools.yml
similarity index 100%
rename from deprecated/detections/detect_critical_alerts_from_security_tools.yml
rename to removed/detections/detect_critical_alerts_from_security_tools.yml
diff --git a/deprecated/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml b/removed/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml
similarity index 100%
rename from deprecated/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml
rename to removed/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml
diff --git a/deprecated/detections/detect_long_dns_txt_record_response.yml b/removed/detections/detect_long_dns_txt_record_response.yml
similarity index 100%
rename from deprecated/detections/detect_long_dns_txt_record_response.yml
rename to removed/detections/detect_long_dns_txt_record_response.yml
diff --git a/deprecated/detections/detect_mimikatz_using_loaded_images.yml b/removed/detections/detect_mimikatz_using_loaded_images.yml
similarity index 100%
rename from deprecated/detections/detect_mimikatz_using_loaded_images.yml
rename to removed/detections/detect_mimikatz_using_loaded_images.yml
diff --git a/deprecated/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml b/removed/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml
similarity index 100%
rename from deprecated/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml
rename to removed/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml
diff --git a/deprecated/detections/detect_new_api_calls_from_user_roles.yml b/removed/detections/detect_new_api_calls_from_user_roles.yml
similarity index 100%
rename from deprecated/detections/detect_new_api_calls_from_user_roles.yml
rename to removed/detections/detect_new_api_calls_from_user_roles.yml
diff --git a/deprecated/detections/detect_new_user_aws_console_login.yml b/removed/detections/detect_new_user_aws_console_login.yml
similarity index 100%
rename from deprecated/detections/detect_new_user_aws_console_login.yml
rename to removed/detections/detect_new_user_aws_console_login.yml
diff --git a/deprecated/detections/detect_processes_used_for_system_network_configuration_discovery.yml b/removed/detections/detect_processes_used_for_system_network_configuration_discovery.yml
similarity index 100%
rename from deprecated/detections/detect_processes_used_for_system_network_configuration_discovery.yml
rename to removed/detections/detect_processes_used_for_system_network_configuration_discovery.yml
diff --git a/deprecated/detections/detect_spike_in_aws_api_activity.yml b/removed/detections/detect_spike_in_aws_api_activity.yml
similarity index 100%
rename from deprecated/detections/detect_spike_in_aws_api_activity.yml
rename to removed/detections/detect_spike_in_aws_api_activity.yml
diff --git a/deprecated/detections/detect_spike_in_network_acl_activity.yml b/removed/detections/detect_spike_in_network_acl_activity.yml
similarity index 100%
rename from deprecated/detections/detect_spike_in_network_acl_activity.yml
rename to removed/detections/detect_spike_in_network_acl_activity.yml
diff --git a/deprecated/detections/detect_spike_in_security_group_activity.yml b/removed/detections/detect_spike_in_security_group_activity.yml
similarity index 100%
rename from deprecated/detections/detect_spike_in_security_group_activity.yml
rename to removed/detections/detect_spike_in_security_group_activity.yml
diff --git a/deprecated/detections/detect_usb_device_insertion.yml b/removed/detections/detect_usb_device_insertion.yml
similarity index 100%
rename from deprecated/detections/detect_usb_device_insertion.yml
rename to removed/detections/detect_usb_device_insertion.yml
diff --git a/deprecated/detections/detect_web_traffic_to_dynamic_domain_providers.yml b/removed/detections/detect_web_traffic_to_dynamic_domain_providers.yml
similarity index 100%
rename from deprecated/detections/detect_web_traffic_to_dynamic_domain_providers.yml
rename to removed/detections/detect_web_traffic_to_dynamic_domain_providers.yml
diff --git a/deprecated/detections/detect_webshell_exploit_behavior.yml b/removed/detections/detect_webshell_exploit_behavior.yml
similarity index 100%
rename from deprecated/detections/detect_webshell_exploit_behavior.yml
rename to removed/detections/detect_webshell_exploit_behavior.yml
diff --git a/deprecated/detections/detection_of_dns_tunnels.yml b/removed/detections/detection_of_dns_tunnels.yml
similarity index 100%
rename from deprecated/detections/detection_of_dns_tunnels.yml
rename to removed/detections/detection_of_dns_tunnels.yml
diff --git a/deprecated/detections/disabling_net_user_account.yml b/removed/detections/disabling_net_user_account.yml
similarity index 100%
rename from deprecated/detections/disabling_net_user_account.yml
rename to removed/detections/disabling_net_user_account.yml
diff --git a/deprecated/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml b/removed/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml
similarity index 100%
rename from deprecated/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml
rename to removed/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml
diff --git a/deprecated/detections/dns_record_changed.yml b/removed/detections/dns_record_changed.yml
similarity index 100%
rename from deprecated/detections/dns_record_changed.yml
rename to removed/detections/dns_record_changed.yml
diff --git a/deprecated/detections/domain_account_discovery_with_net_app.yml b/removed/detections/domain_account_discovery_with_net_app.yml
similarity index 100%
rename from deprecated/detections/domain_account_discovery_with_net_app.yml
rename to removed/detections/domain_account_discovery_with_net_app.yml
diff --git a/deprecated/detections/domain_group_discovery_with_net.yml b/removed/detections/domain_group_discovery_with_net.yml
similarity index 100%
rename from deprecated/detections/domain_group_discovery_with_net.yml
rename to removed/detections/domain_group_discovery_with_net.yml
diff --git a/deprecated/detections/dump_lsass_via_procdump_rename.yml b/removed/detections/dump_lsass_via_procdump_rename.yml
similarity index 100%
rename from deprecated/detections/dump_lsass_via_procdump_rename.yml
rename to removed/detections/dump_lsass_via_procdump_rename.yml
diff --git a/deprecated/detections/ec2_instance_modified_with_previously_unseen_user.yml b/removed/detections/ec2_instance_modified_with_previously_unseen_user.yml
similarity index 100%
rename from deprecated/detections/ec2_instance_modified_with_previously_unseen_user.yml
rename to removed/detections/ec2_instance_modified_with_previously_unseen_user.yml
diff --git a/deprecated/detections/ec2_instance_started_in_previously_unseen_region.yml b/removed/detections/ec2_instance_started_in_previously_unseen_region.yml
similarity index 100%
rename from deprecated/detections/ec2_instance_started_in_previously_unseen_region.yml
rename to removed/detections/ec2_instance_started_in_previously_unseen_region.yml
diff --git a/deprecated/detections/ec2_instance_started_with_previously_unseen_ami.yml b/removed/detections/ec2_instance_started_with_previously_unseen_ami.yml
similarity index 100%
rename from deprecated/detections/ec2_instance_started_with_previously_unseen_ami.yml
rename to removed/detections/ec2_instance_started_with_previously_unseen_ami.yml
diff --git a/deprecated/detections/ec2_instance_started_with_previously_unseen_instance_type.yml b/removed/detections/ec2_instance_started_with_previously_unseen_instance_type.yml
similarity index 100%
rename from deprecated/detections/ec2_instance_started_with_previously_unseen_instance_type.yml
rename to removed/detections/ec2_instance_started_with_previously_unseen_instance_type.yml
diff --git a/deprecated/detections/ec2_instance_started_with_previously_unseen_user.yml b/removed/detections/ec2_instance_started_with_previously_unseen_user.yml
similarity index 100%
rename from deprecated/detections/ec2_instance_started_with_previously_unseen_user.yml
rename to removed/detections/ec2_instance_started_with_previously_unseen_user.yml
diff --git a/deprecated/detections/elevated_group_discovery_with_net.yml b/removed/detections/elevated_group_discovery_with_net.yml
similarity index 100%
rename from deprecated/detections/elevated_group_discovery_with_net.yml
rename to removed/detections/elevated_group_discovery_with_net.yml
diff --git a/deprecated/detections/excel_spawning_powershell.yml b/removed/detections/excel_spawning_powershell.yml
similarity index 100%
rename from deprecated/detections/excel_spawning_powershell.yml
rename to removed/detections/excel_spawning_powershell.yml
diff --git a/deprecated/detections/excel_spawning_windows_script_host.yml b/removed/detections/excel_spawning_windows_script_host.yml
similarity index 100%
rename from deprecated/detections/excel_spawning_windows_script_host.yml
rename to removed/detections/excel_spawning_windows_script_host.yml
diff --git a/deprecated/detections/excessive_service_stop_attempt.yml b/removed/detections/excessive_service_stop_attempt.yml
similarity index 100%
rename from deprecated/detections/excessive_service_stop_attempt.yml
rename to removed/detections/excessive_service_stop_attempt.yml
diff --git a/deprecated/detections/excessive_usage_of_net_app.yml b/removed/detections/excessive_usage_of_net_app.yml
similarity index 100%
rename from deprecated/detections/excessive_usage_of_net_app.yml
rename to removed/detections/excessive_usage_of_net_app.yml
diff --git a/deprecated/detections/execution_of_file_with_spaces_before_extension.yml b/removed/detections/execution_of_file_with_spaces_before_extension.yml
similarity index 100%
rename from deprecated/detections/execution_of_file_with_spaces_before_extension.yml
rename to removed/detections/execution_of_file_with_spaces_before_extension.yml
diff --git a/deprecated/detections/extended_period_without_successful_netbackup_backups.yml b/removed/detections/extended_period_without_successful_netbackup_backups.yml
similarity index 100%
rename from deprecated/detections/extended_period_without_successful_netbackup_backups.yml
rename to removed/detections/extended_period_without_successful_netbackup_backups.yml
diff --git a/deprecated/detections/extraction_of_registry_hives.yml b/removed/detections/extraction_of_registry_hives.yml
similarity index 100%
rename from deprecated/detections/extraction_of_registry_hives.yml
rename to removed/detections/extraction_of_registry_hives.yml
diff --git a/deprecated/detections/first_time_seen_command_line_argument.yml b/removed/detections/first_time_seen_command_line_argument.yml
similarity index 100%
rename from deprecated/detections/first_time_seen_command_line_argument.yml
rename to removed/detections/first_time_seen_command_line_argument.yml
diff --git a/deprecated/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml b/removed/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml
similarity index 100%
rename from deprecated/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml
rename to removed/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml
diff --git a/deprecated/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml b/removed/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml
similarity index 100%
rename from deprecated/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml
rename to removed/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml
diff --git a/deprecated/detections/gcp_detect_oauth_token_abuse.yml b/removed/detections/gcp_detect_oauth_token_abuse.yml
similarity index 100%
rename from deprecated/detections/gcp_detect_oauth_token_abuse.yml
rename to removed/detections/gcp_detect_oauth_token_abuse.yml
diff --git a/deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml b/removed/detections/gcp_kubernetes_cluster_scan_detection.yml
similarity index 100%
rename from deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml
rename to removed/detections/gcp_kubernetes_cluster_scan_detection.yml
diff --git a/deprecated/detections/identify_new_user_accounts.yml b/removed/detections/identify_new_user_accounts.yml
similarity index 100%
rename from deprecated/detections/identify_new_user_accounts.yml
rename to removed/detections/identify_new_user_accounts.yml
diff --git a/deprecated/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml b/removed/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml
similarity index 100%
rename from deprecated/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml
rename to removed/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml
diff --git a/deprecated/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml b/removed/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml
similarity index 100%
rename from deprecated/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml
rename to removed/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml
diff --git a/deprecated/detections/kubernetes_aws_detect_sensitive_role_access.yml b/removed/detections/kubernetes_aws_detect_sensitive_role_access.yml
similarity index 100%
rename from deprecated/detections/kubernetes_aws_detect_sensitive_role_access.yml
rename to removed/detections/kubernetes_aws_detect_sensitive_role_access.yml
diff --git a/deprecated/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml b/removed/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml
similarity index 100%
rename from deprecated/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml
rename to removed/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml
diff --git a/deprecated/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml b/removed/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml
similarity index 100%
rename from deprecated/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml
rename to removed/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml
diff --git a/deprecated/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml b/removed/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml
similarity index 100%
rename from deprecated/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml
rename to removed/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml
diff --git a/deprecated/detections/kubernetes_azure_detect_sensitive_object_access.yml b/removed/detections/kubernetes_azure_detect_sensitive_object_access.yml
similarity index 100%
rename from deprecated/detections/kubernetes_azure_detect_sensitive_object_access.yml
rename to removed/detections/kubernetes_azure_detect_sensitive_object_access.yml
diff --git a/deprecated/detections/kubernetes_azure_detect_sensitive_role_access.yml b/removed/detections/kubernetes_azure_detect_sensitive_role_access.yml
similarity index 100%
rename from deprecated/detections/kubernetes_azure_detect_sensitive_role_access.yml
rename to removed/detections/kubernetes_azure_detect_sensitive_role_access.yml
diff --git a/deprecated/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml b/removed/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml
similarity index 100%
rename from deprecated/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml
rename to removed/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml
diff --git a/deprecated/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml b/removed/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml
similarity index 100%
rename from deprecated/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml
rename to removed/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml
diff --git a/deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml b/removed/detections/kubernetes_azure_pod_scan_fingerprint.yml
similarity index 100%
rename from deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml
rename to removed/detections/kubernetes_azure_pod_scan_fingerprint.yml
diff --git a/deprecated/detections/kubernetes_azure_scan_fingerprint.yml b/removed/detections/kubernetes_azure_scan_fingerprint.yml
similarity index 100%
rename from deprecated/detections/kubernetes_azure_scan_fingerprint.yml
rename to removed/detections/kubernetes_azure_scan_fingerprint.yml
diff --git a/deprecated/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml b/removed/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml
similarity index 100%
rename from deprecated/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml
rename to removed/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml
diff --git a/deprecated/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml b/removed/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml
similarity index 100%
rename from deprecated/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml
rename to removed/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml
diff --git a/deprecated/detections/kubernetes_gcp_detect_sensitive_object_access.yml b/removed/detections/kubernetes_gcp_detect_sensitive_object_access.yml
similarity index 100%
rename from deprecated/detections/kubernetes_gcp_detect_sensitive_object_access.yml
rename to removed/detections/kubernetes_gcp_detect_sensitive_object_access.yml
diff --git a/deprecated/detections/kubernetes_gcp_detect_sensitive_role_access.yml b/removed/detections/kubernetes_gcp_detect_sensitive_role_access.yml
similarity index 100%
rename from deprecated/detections/kubernetes_gcp_detect_sensitive_role_access.yml
rename to removed/detections/kubernetes_gcp_detect_sensitive_role_access.yml
diff --git a/deprecated/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml b/removed/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml
similarity index 100%
rename from deprecated/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml
rename to removed/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml
diff --git a/deprecated/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml b/removed/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml
similarity index 100%
rename from deprecated/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml
rename to removed/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml
diff --git a/deprecated/detections/linux_auditd_find_private_keys.yml b/removed/detections/linux_auditd_find_private_keys.yml
similarity index 100%
rename from deprecated/detections/linux_auditd_find_private_keys.yml
rename to removed/detections/linux_auditd_find_private_keys.yml
diff --git a/deprecated/detections/local_account_discovery_with_net.yml b/removed/detections/local_account_discovery_with_net.yml
similarity index 100%
rename from deprecated/detections/local_account_discovery_with_net.yml
rename to removed/detections/local_account_discovery_with_net.yml
diff --git a/deprecated/detections/monitor_dns_for_brand_abuse.yml b/removed/detections/monitor_dns_for_brand_abuse.yml
similarity index 100%
rename from deprecated/detections/monitor_dns_for_brand_abuse.yml
rename to removed/detections/monitor_dns_for_brand_abuse.yml
diff --git a/deprecated/detections/mshtml_module_load_in_office_product.yml b/removed/detections/mshtml_module_load_in_office_product.yml
similarity index 100%
rename from deprecated/detections/mshtml_module_load_in_office_product.yml
rename to removed/detections/mshtml_module_load_in_office_product.yml
diff --git a/deprecated/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml b/removed/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml
similarity index 100%
rename from deprecated/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml
rename to removed/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml
diff --git a/deprecated/detections/net_localgroup_discovery.yml b/removed/detections/net_localgroup_discovery.yml
similarity index 100%
rename from deprecated/detections/net_localgroup_discovery.yml
rename to removed/detections/net_localgroup_discovery.yml
diff --git a/deprecated/detections/network_connection_discovery_with_net.yml b/removed/detections/network_connection_discovery_with_net.yml
similarity index 100%
rename from deprecated/detections/network_connection_discovery_with_net.yml
rename to removed/detections/network_connection_discovery_with_net.yml
diff --git a/deprecated/detections/o365_suspicious_admin_email_forwarding.yml b/removed/detections/o365_suspicious_admin_email_forwarding.yml
similarity index 100%
rename from deprecated/detections/o365_suspicious_admin_email_forwarding.yml
rename to removed/detections/o365_suspicious_admin_email_forwarding.yml
diff --git a/deprecated/detections/o365_suspicious_rights_delegation.yml b/removed/detections/o365_suspicious_rights_delegation.yml
similarity index 100%
rename from deprecated/detections/o365_suspicious_rights_delegation.yml
rename to removed/detections/o365_suspicious_rights_delegation.yml
diff --git a/deprecated/detections/o365_suspicious_user_email_forwarding.yml b/removed/detections/o365_suspicious_user_email_forwarding.yml
similarity index 100%
rename from deprecated/detections/o365_suspicious_user_email_forwarding.yml
rename to removed/detections/o365_suspicious_user_email_forwarding.yml
diff --git a/deprecated/detections/office_application_drop_executable.yml b/removed/detections/office_application_drop_executable.yml
similarity index 100%
rename from deprecated/detections/office_application_drop_executable.yml
rename to removed/detections/office_application_drop_executable.yml
diff --git a/deprecated/detections/office_application_spawn_regsvr32_process.yml b/removed/detections/office_application_spawn_regsvr32_process.yml
similarity index 100%
rename from deprecated/detections/office_application_spawn_regsvr32_process.yml
rename to removed/detections/office_application_spawn_regsvr32_process.yml
diff --git a/deprecated/detections/office_application_spawn_rundll32_process.yml b/removed/detections/office_application_spawn_rundll32_process.yml
similarity index 100%
rename from deprecated/detections/office_application_spawn_rundll32_process.yml
rename to removed/detections/office_application_spawn_rundll32_process.yml
diff --git a/deprecated/detections/office_document_creating_schedule_task.yml b/removed/detections/office_document_creating_schedule_task.yml
similarity index 100%
rename from deprecated/detections/office_document_creating_schedule_task.yml
rename to removed/detections/office_document_creating_schedule_task.yml
diff --git a/deprecated/detections/office_document_executing_macro_code.yml b/removed/detections/office_document_executing_macro_code.yml
similarity index 100%
rename from deprecated/detections/office_document_executing_macro_code.yml
rename to removed/detections/office_document_executing_macro_code.yml
diff --git a/deprecated/detections/office_document_spawned_child_process_to_download.yml b/removed/detections/office_document_spawned_child_process_to_download.yml
similarity index 100%
rename from deprecated/detections/office_document_spawned_child_process_to_download.yml
rename to removed/detections/office_document_spawned_child_process_to_download.yml
diff --git a/deprecated/detections/office_product_spawn_cmd_process.yml b/removed/detections/office_product_spawn_cmd_process.yml
similarity index 100%
rename from deprecated/detections/office_product_spawn_cmd_process.yml
rename to removed/detections/office_product_spawn_cmd_process.yml
diff --git a/deprecated/detections/office_product_spawning_bitsadmin.yml b/removed/detections/office_product_spawning_bitsadmin.yml
similarity index 100%
rename from deprecated/detections/office_product_spawning_bitsadmin.yml
rename to removed/detections/office_product_spawning_bitsadmin.yml
diff --git a/deprecated/detections/office_product_spawning_certutil.yml b/removed/detections/office_product_spawning_certutil.yml
similarity index 100%
rename from deprecated/detections/office_product_spawning_certutil.yml
rename to removed/detections/office_product_spawning_certutil.yml
diff --git a/deprecated/detections/office_product_spawning_mshta.yml b/removed/detections/office_product_spawning_mshta.yml
similarity index 100%
rename from deprecated/detections/office_product_spawning_mshta.yml
rename to removed/detections/office_product_spawning_mshta.yml
diff --git a/deprecated/detections/office_product_spawning_rundll32_with_no_dll.yml b/removed/detections/office_product_spawning_rundll32_with_no_dll.yml
similarity index 100%
rename from deprecated/detections/office_product_spawning_rundll32_with_no_dll.yml
rename to removed/detections/office_product_spawning_rundll32_with_no_dll.yml
diff --git a/deprecated/detections/office_product_spawning_windows_script_host.yml b/removed/detections/office_product_spawning_windows_script_host.yml
similarity index 100%
rename from deprecated/detections/office_product_spawning_windows_script_host.yml
rename to removed/detections/office_product_spawning_windows_script_host.yml
diff --git a/deprecated/detections/office_product_spawning_wmic.yml b/removed/detections/office_product_spawning_wmic.yml
similarity index 100%
rename from deprecated/detections/office_product_spawning_wmic.yml
rename to removed/detections/office_product_spawning_wmic.yml
diff --git a/deprecated/detections/office_product_writing_cab_or_inf.yml b/removed/detections/office_product_writing_cab_or_inf.yml
similarity index 100%
rename from deprecated/detections/office_product_writing_cab_or_inf.yml
rename to removed/detections/office_product_writing_cab_or_inf.yml
diff --git a/deprecated/detections/office_spawning_control.yml b/removed/detections/office_spawning_control.yml
similarity index 100%
rename from deprecated/detections/office_spawning_control.yml
rename to removed/detections/office_spawning_control.yml
diff --git a/deprecated/detections/okta_account_locked_out.yml b/removed/detections/okta_account_locked_out.yml
similarity index 100%
rename from deprecated/detections/okta_account_locked_out.yml
rename to removed/detections/okta_account_locked_out.yml
diff --git a/deprecated/detections/okta_account_lockout_events.yml b/removed/detections/okta_account_lockout_events.yml
similarity index 100%
rename from deprecated/detections/okta_account_lockout_events.yml
rename to removed/detections/okta_account_lockout_events.yml
diff --git a/deprecated/detections/okta_failed_sso_attempts.yml b/removed/detections/okta_failed_sso_attempts.yml
similarity index 100%
rename from deprecated/detections/okta_failed_sso_attempts.yml
rename to removed/detections/okta_failed_sso_attempts.yml
diff --git a/deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml b/removed/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml
similarity index 100%
rename from deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml
rename to removed/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml
diff --git a/deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml b/removed/detections/okta_threatinsight_suspected_passwordspray_attack.yml
similarity index 100%
rename from deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml
rename to removed/detections/okta_threatinsight_suspected_passwordspray_attack.yml
diff --git a/deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml b/removed/detections/okta_two_or_more_rejected_okta_pushes.yml
similarity index 100%
rename from deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml
rename to removed/detections/okta_two_or_more_rejected_okta_pushes.yml
diff --git a/deprecated/detections/osquery_pack___coldroot_detection.yml b/removed/detections/osquery_pack___coldroot_detection.yml
similarity index 100%
rename from deprecated/detections/osquery_pack___coldroot_detection.yml
rename to removed/detections/osquery_pack___coldroot_detection.yml
diff --git a/deprecated/detections/password_policy_discovery_with_net.yml b/removed/detections/password_policy_discovery_with_net.yml
similarity index 100%
rename from deprecated/detections/password_policy_discovery_with_net.yml
rename to removed/detections/password_policy_discovery_with_net.yml
diff --git a/deprecated/detections/processes_created_by_netsh.yml b/removed/detections/processes_created_by_netsh.yml
similarity index 100%
rename from deprecated/detections/processes_created_by_netsh.yml
rename to removed/detections/processes_created_by_netsh.yml
diff --git a/deprecated/detections/prohibited_software_on_endpoint.yml b/removed/detections/prohibited_software_on_endpoint.yml
similarity index 100%
rename from deprecated/detections/prohibited_software_on_endpoint.yml
rename to removed/detections/prohibited_software_on_endpoint.yml
diff --git a/deprecated/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml b/removed/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml
similarity index 100%
rename from deprecated/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml
rename to removed/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml
diff --git a/deprecated/detections/remote_registry_key_modifications.yml b/removed/detections/remote_registry_key_modifications.yml
similarity index 100%
rename from deprecated/detections/remote_registry_key_modifications.yml
rename to removed/detections/remote_registry_key_modifications.yml
diff --git a/deprecated/detections/remote_system_discovery_with_net.yml b/removed/detections/remote_system_discovery_with_net.yml
similarity index 100%
rename from deprecated/detections/remote_system_discovery_with_net.yml
rename to removed/detections/remote_system_discovery_with_net.yml
diff --git a/deprecated/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml b/removed/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml
similarity index 100%
rename from deprecated/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml
rename to removed/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml
diff --git a/deprecated/detections/spectre_and_meltdown_vulnerable_systems.yml b/removed/detections/spectre_and_meltdown_vulnerable_systems.yml
similarity index 100%
rename from deprecated/detections/spectre_and_meltdown_vulnerable_systems.yml
rename to removed/detections/spectre_and_meltdown_vulnerable_systems.yml
diff --git a/deprecated/detections/suspicious_changes_to_file_associations.yml b/removed/detections/suspicious_changes_to_file_associations.yml
similarity index 100%
rename from deprecated/detections/suspicious_changes_to_file_associations.yml
rename to removed/detections/suspicious_changes_to_file_associations.yml
diff --git a/deprecated/detections/suspicious_email___uba_anomaly.yml b/removed/detections/suspicious_email___uba_anomaly.yml
similarity index 100%
rename from deprecated/detections/suspicious_email___uba_anomaly.yml
rename to removed/detections/suspicious_email___uba_anomaly.yml
diff --git a/deprecated/detections/suspicious_file_write.yml b/removed/detections/suspicious_file_write.yml
similarity index 100%
rename from deprecated/detections/suspicious_file_write.yml
rename to removed/detections/suspicious_file_write.yml
diff --git a/deprecated/detections/suspicious_powershell_command_line_arguments.yml b/removed/detections/suspicious_powershell_command_line_arguments.yml
similarity index 100%
rename from deprecated/detections/suspicious_powershell_command_line_arguments.yml
rename to removed/detections/suspicious_powershell_command_line_arguments.yml
diff --git a/deprecated/detections/suspicious_rundll32_rename.yml b/removed/detections/suspicious_rundll32_rename.yml
similarity index 100%
rename from deprecated/detections/suspicious_rundll32_rename.yml
rename to removed/detections/suspicious_rundll32_rename.yml
diff --git a/deprecated/detections/suspicious_writes_to_system_volume_information.yml b/removed/detections/suspicious_writes_to_system_volume_information.yml
similarity index 100%
rename from deprecated/detections/suspicious_writes_to_system_volume_information.yml
rename to removed/detections/suspicious_writes_to_system_volume_information.yml
diff --git a/deprecated/detections/uncommon_processes_on_endpoint.yml b/removed/detections/uncommon_processes_on_endpoint.yml
similarity index 100%
rename from deprecated/detections/uncommon_processes_on_endpoint.yml
rename to removed/detections/uncommon_processes_on_endpoint.yml
diff --git a/deprecated/detections/unsigned_image_loaded_by_lsass.yml b/removed/detections/unsigned_image_loaded_by_lsass.yml
similarity index 100%
rename from deprecated/detections/unsigned_image_loaded_by_lsass.yml
rename to removed/detections/unsigned_image_loaded_by_lsass.yml
diff --git a/deprecated/detections/unsuccessful_netbackup_backups.yml b/removed/detections/unsuccessful_netbackup_backups.yml
similarity index 100%
rename from deprecated/detections/unsuccessful_netbackup_backups.yml
rename to removed/detections/unsuccessful_netbackup_backups.yml
diff --git a/deprecated/detections/web_fraud___account_harvesting.yml b/removed/detections/web_fraud___account_harvesting.yml
similarity index 100%
rename from deprecated/detections/web_fraud___account_harvesting.yml
rename to removed/detections/web_fraud___account_harvesting.yml
diff --git a/deprecated/detections/web_fraud___anomalous_user_clickspeed.yml b/removed/detections/web_fraud___anomalous_user_clickspeed.yml
similarity index 100%
rename from deprecated/detections/web_fraud___anomalous_user_clickspeed.yml
rename to removed/detections/web_fraud___anomalous_user_clickspeed.yml
diff --git a/deprecated/detections/web_fraud___password_sharing_across_accounts.yml b/removed/detections/web_fraud___password_sharing_across_accounts.yml
similarity index 100%
rename from deprecated/detections/web_fraud___password_sharing_across_accounts.yml
rename to removed/detections/web_fraud___password_sharing_across_accounts.yml
diff --git a/deprecated/detections/windows_command_shell_fetch_env_variables.yml b/removed/detections/windows_command_shell_fetch_env_variables.yml
similarity index 100%
rename from deprecated/detections/windows_command_shell_fetch_env_variables.yml
rename to removed/detections/windows_command_shell_fetch_env_variables.yml
diff --git a/deprecated/detections/windows_connhost_exe_started_forcefully.yml b/removed/detections/windows_connhost_exe_started_forcefully.yml
similarity index 100%
rename from deprecated/detections/windows_connhost_exe_started_forcefully.yml
rename to removed/detections/windows_connhost_exe_started_forcefully.yml
diff --git a/deprecated/detections/windows_dll_search_order_hijacking_hunt.yml b/removed/detections/windows_dll_search_order_hijacking_hunt.yml
similarity index 100%
rename from deprecated/detections/windows_dll_search_order_hijacking_hunt.yml
rename to removed/detections/windows_dll_search_order_hijacking_hunt.yml
diff --git a/deprecated/detections/windows_hosts_file_modification.yml b/removed/detections/windows_hosts_file_modification.yml
similarity index 100%
rename from deprecated/detections/windows_hosts_file_modification.yml
rename to removed/detections/windows_hosts_file_modification.yml
diff --git a/deprecated/detections/windows_lateral_tool_transfer_remcom.yml b/removed/detections/windows_lateral_tool_transfer_remcom.yml
similarity index 100%
rename from deprecated/detections/windows_lateral_tool_transfer_remcom.yml
rename to removed/detections/windows_lateral_tool_transfer_remcom.yml
diff --git a/deprecated/detections/windows_modify_registry_reg_restore.yml b/removed/detections/windows_modify_registry_reg_restore.yml
similarity index 100%
rename from deprecated/detections/windows_modify_registry_reg_restore.yml
rename to removed/detections/windows_modify_registry_reg_restore.yml
diff --git a/deprecated/detections/windows_msiexec_with_network_connections.yml b/removed/detections/windows_msiexec_with_network_connections.yml
similarity index 100%
rename from deprecated/detections/windows_msiexec_with_network_connections.yml
rename to removed/detections/windows_msiexec_with_network_connections.yml
diff --git a/deprecated/detections/windows_network_share_interaction_with_net.yml b/removed/detections/windows_network_share_interaction_with_net.yml
similarity index 100%
rename from deprecated/detections/windows_network_share_interaction_with_net.yml
rename to removed/detections/windows_network_share_interaction_with_net.yml
diff --git a/deprecated/detections/windows_office_product_spawning_msdt.yml b/removed/detections/windows_office_product_spawning_msdt.yml
similarity index 100%
rename from deprecated/detections/windows_office_product_spawning_msdt.yml
rename to removed/detections/windows_office_product_spawning_msdt.yml
diff --git a/deprecated/detections/windows_query_registry_reg_save.yml b/removed/detections/windows_query_registry_reg_save.yml
similarity index 100%
rename from deprecated/detections/windows_query_registry_reg_save.yml
rename to removed/detections/windows_query_registry_reg_save.yml
diff --git a/deprecated/detections/windows_service_stop_via_net__and_sc_application.yml b/removed/detections/windows_service_stop_via_net__and_sc_application.yml
similarity index 100%
rename from deprecated/detections/windows_service_stop_via_net__and_sc_application.yml
rename to removed/detections/windows_service_stop_via_net__and_sc_application.yml
diff --git a/deprecated/detections/windows_valid_account_with_never_expires_password.yml b/removed/detections/windows_valid_account_with_never_expires_password.yml
similarity index 100%
rename from deprecated/detections/windows_valid_account_with_never_expires_password.yml
rename to removed/detections/windows_valid_account_with_never_expires_password.yml
diff --git a/deprecated/detections/winword_spawning_cmd.yml b/removed/detections/winword_spawning_cmd.yml
similarity index 100%
rename from deprecated/detections/winword_spawning_cmd.yml
rename to removed/detections/winword_spawning_cmd.yml
diff --git a/deprecated/detections/winword_spawning_powershell.yml b/removed/detections/winword_spawning_powershell.yml
similarity index 100%
rename from deprecated/detections/winword_spawning_powershell.yml
rename to removed/detections/winword_spawning_powershell.yml
diff --git a/deprecated/detections/winword_spawning_windows_script_host.yml b/removed/detections/winword_spawning_windows_script_host.yml
similarity index 100%
rename from deprecated/detections/winword_spawning_windows_script_host.yml
rename to removed/detections/winword_spawning_windows_script_host.yml
diff --git a/deprecated/investigations/all_backup_logs_for_host.yml b/removed/investigations/all_backup_logs_for_host.yml
similarity index 100%
rename from deprecated/investigations/all_backup_logs_for_host.yml
rename to removed/investigations/all_backup_logs_for_host.yml
diff --git a/deprecated/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml b/removed/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml
similarity index 100%
rename from deprecated/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml
rename to removed/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml
diff --git a/deprecated/investigations/aws_investigate_security_hub_alerts_by_dest.yml b/removed/investigations/aws_investigate_security_hub_alerts_by_dest.yml
similarity index 100%
rename from deprecated/investigations/aws_investigate_security_hub_alerts_by_dest.yml
rename to removed/investigations/aws_investigate_security_hub_alerts_by_dest.yml
diff --git a/deprecated/investigations/aws_investigate_user_activities_by_accesskeyid.yml b/removed/investigations/aws_investigate_user_activities_by_accesskeyid.yml
similarity index 100%
rename from deprecated/investigations/aws_investigate_user_activities_by_accesskeyid.yml
rename to removed/investigations/aws_investigate_user_activities_by_accesskeyid.yml
diff --git a/deprecated/investigations/aws_investigate_user_activities_by_arn.yml b/removed/investigations/aws_investigate_user_activities_by_arn.yml
similarity index 100%
rename from deprecated/investigations/aws_investigate_user_activities_by_arn.yml
rename to removed/investigations/aws_investigate_user_activities_by_arn.yml
diff --git a/deprecated/investigations/aws_network_acl_details_from_id.yml b/removed/investigations/aws_network_acl_details_from_id.yml
similarity index 100%
rename from deprecated/investigations/aws_network_acl_details_from_id.yml
rename to removed/investigations/aws_network_acl_details_from_id.yml
diff --git a/deprecated/investigations/aws_network_interface_details_via_resourceid.yml b/removed/investigations/aws_network_interface_details_via_resourceid.yml
similarity index 100%
rename from deprecated/investigations/aws_network_interface_details_via_resourceid.yml
rename to removed/investigations/aws_network_interface_details_via_resourceid.yml
diff --git a/deprecated/investigations/aws_s3_bucket_details_via_bucketname.yml b/removed/investigations/aws_s3_bucket_details_via_bucketname.yml
similarity index 100%
rename from deprecated/investigations/aws_s3_bucket_details_via_bucketname.yml
rename to removed/investigations/aws_s3_bucket_details_via_bucketname.yml
diff --git a/deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml b/removed/investigations/gcp_kubernetes_activity_by_src_ip.yml
similarity index 100%
rename from deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml
rename to removed/investigations/gcp_kubernetes_activity_by_src_ip.yml
diff --git a/deprecated/investigations/get_all_aws_activity_from_city.yml b/removed/investigations/get_all_aws_activity_from_city.yml
similarity index 100%
rename from deprecated/investigations/get_all_aws_activity_from_city.yml
rename to removed/investigations/get_all_aws_activity_from_city.yml
diff --git a/deprecated/investigations/get_all_aws_activity_from_country.yml b/removed/investigations/get_all_aws_activity_from_country.yml
similarity index 100%
rename from deprecated/investigations/get_all_aws_activity_from_country.yml
rename to removed/investigations/get_all_aws_activity_from_country.yml
diff --git a/deprecated/investigations/get_all_aws_activity_from_ip_address.yml b/removed/investigations/get_all_aws_activity_from_ip_address.yml
similarity index 100%
rename from deprecated/investigations/get_all_aws_activity_from_ip_address.yml
rename to removed/investigations/get_all_aws_activity_from_ip_address.yml
diff --git a/deprecated/investigations/get_all_aws_activity_from_region.yml b/removed/investigations/get_all_aws_activity_from_region.yml
similarity index 100%
rename from deprecated/investigations/get_all_aws_activity_from_region.yml
rename to removed/investigations/get_all_aws_activity_from_region.yml
diff --git a/deprecated/investigations/get_backup_logs_for_endpoint.yml b/removed/investigations/get_backup_logs_for_endpoint.yml
similarity index 100%
rename from deprecated/investigations/get_backup_logs_for_endpoint.yml
rename to removed/investigations/get_backup_logs_for_endpoint.yml
diff --git a/deprecated/investigations/get_certificate_logs_for_a_domain.yml b/removed/investigations/get_certificate_logs_for_a_domain.yml
similarity index 100%
rename from deprecated/investigations/get_certificate_logs_for_a_domain.yml
rename to removed/investigations/get_certificate_logs_for_a_domain.yml
diff --git a/deprecated/investigations/get_dns_server_history_for_a_host.yml b/removed/investigations/get_dns_server_history_for_a_host.yml
similarity index 100%
rename from deprecated/investigations/get_dns_server_history_for_a_host.yml
rename to removed/investigations/get_dns_server_history_for_a_host.yml
diff --git a/deprecated/investigations/get_dns_traffic_ratio.yml b/removed/investigations/get_dns_traffic_ratio.yml
similarity index 100%
rename from deprecated/investigations/get_dns_traffic_ratio.yml
rename to removed/investigations/get_dns_traffic_ratio.yml
diff --git a/deprecated/investigations/get_ec2_instance_details_by_instanceid.yml b/removed/investigations/get_ec2_instance_details_by_instanceid.yml
similarity index 100%
rename from deprecated/investigations/get_ec2_instance_details_by_instanceid.yml
rename to removed/investigations/get_ec2_instance_details_by_instanceid.yml
diff --git a/deprecated/investigations/get_ec2_launch_details.yml b/removed/investigations/get_ec2_launch_details.yml
similarity index 100%
rename from deprecated/investigations/get_ec2_launch_details.yml
rename to removed/investigations/get_ec2_launch_details.yml
diff --git a/deprecated/investigations/get_email_info.yml b/removed/investigations/get_email_info.yml
similarity index 100%
rename from deprecated/investigations/get_email_info.yml
rename to removed/investigations/get_email_info.yml
diff --git a/deprecated/investigations/get_emails_from_specific_sender.yml b/removed/investigations/get_emails_from_specific_sender.yml
similarity index 100%
rename from deprecated/investigations/get_emails_from_specific_sender.yml
rename to removed/investigations/get_emails_from_specific_sender.yml
diff --git a/deprecated/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml b/removed/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml
similarity index 100%
rename from deprecated/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml
rename to removed/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml
diff --git a/deprecated/investigations/get_history_of_email_sources.yml b/removed/investigations/get_history_of_email_sources.yml
similarity index 100%
rename from deprecated/investigations/get_history_of_email_sources.yml
rename to removed/investigations/get_history_of_email_sources.yml
diff --git a/deprecated/investigations/get_logon_rights_modifications_for_endpoint.yml b/removed/investigations/get_logon_rights_modifications_for_endpoint.yml
similarity index 100%
rename from deprecated/investigations/get_logon_rights_modifications_for_endpoint.yml
rename to removed/investigations/get_logon_rights_modifications_for_endpoint.yml
diff --git a/deprecated/investigations/get_logon_rights_modifications_for_user.yml b/removed/investigations/get_logon_rights_modifications_for_user.yml
similarity index 100%
rename from deprecated/investigations/get_logon_rights_modifications_for_user.yml
rename to removed/investigations/get_logon_rights_modifications_for_user.yml
diff --git a/deprecated/investigations/get_notable_history.yml b/removed/investigations/get_notable_history.yml
similarity index 100%
rename from deprecated/investigations/get_notable_history.yml
rename to removed/investigations/get_notable_history.yml
diff --git a/deprecated/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml b/removed/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml
similarity index 100%
rename from deprecated/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml
rename to removed/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml
diff --git a/deprecated/investigations/get_parent_process_info.yml b/removed/investigations/get_parent_process_info.yml
similarity index 100%
rename from deprecated/investigations/get_parent_process_info.yml
rename to removed/investigations/get_parent_process_info.yml
diff --git a/deprecated/investigations/get_process_file_activity.yml b/removed/investigations/get_process_file_activity.yml
similarity index 100%
rename from deprecated/investigations/get_process_file_activity.yml
rename to removed/investigations/get_process_file_activity.yml
diff --git a/deprecated/investigations/get_process_info.yml b/removed/investigations/get_process_info.yml
similarity index 100%
rename from deprecated/investigations/get_process_info.yml
rename to removed/investigations/get_process_info.yml
diff --git a/deprecated/investigations/get_process_information_for_port_activity.yml b/removed/investigations/get_process_information_for_port_activity.yml
similarity index 100%
rename from deprecated/investigations/get_process_information_for_port_activity.yml
rename to removed/investigations/get_process_information_for_port_activity.yml
diff --git a/deprecated/investigations/get_process_responsible_for_the_dns_traffic.yml b/removed/investigations/get_process_responsible_for_the_dns_traffic.yml
similarity index 100%
rename from deprecated/investigations/get_process_responsible_for_the_dns_traffic.yml
rename to removed/investigations/get_process_responsible_for_the_dns_traffic.yml
diff --git a/deprecated/investigations/get_sysmon_wmi_activity_for_host.yml b/removed/investigations/get_sysmon_wmi_activity_for_host.yml
similarity index 100%
rename from deprecated/investigations/get_sysmon_wmi_activity_for_host.yml
rename to removed/investigations/get_sysmon_wmi_activity_for_host.yml
diff --git a/deprecated/investigations/get_web_session_information_via_session_id.yml b/removed/investigations/get_web_session_information_via_session_id.yml
similarity index 100%
rename from deprecated/investigations/get_web_session_information_via_session_id.yml
rename to removed/investigations/get_web_session_information_via_session_id.yml
diff --git a/deprecated/investigations/investigate_aws_activities_via_region_name.yml b/removed/investigations/investigate_aws_activities_via_region_name.yml
similarity index 100%
rename from deprecated/investigations/investigate_aws_activities_via_region_name.yml
rename to removed/investigations/investigate_aws_activities_via_region_name.yml
diff --git a/deprecated/investigations/investigate_aws_user_activities_by_user_field.yml b/removed/investigations/investigate_aws_user_activities_by_user_field.yml
similarity index 100%
rename from deprecated/investigations/investigate_aws_user_activities_by_user_field.yml
rename to removed/investigations/investigate_aws_user_activities_by_user_field.yml
diff --git a/deprecated/investigations/investigate_failed_logins_for_multiple_destinations.yml b/removed/investigations/investigate_failed_logins_for_multiple_destinations.yml
similarity index 100%
rename from deprecated/investigations/investigate_failed_logins_for_multiple_destinations.yml
rename to removed/investigations/investigate_failed_logins_for_multiple_destinations.yml
diff --git a/deprecated/investigations/investigate_network_traffic_from_src_ip.yml b/removed/investigations/investigate_network_traffic_from_src_ip.yml
similarity index 100%
rename from deprecated/investigations/investigate_network_traffic_from_src_ip.yml
rename to removed/investigations/investigate_network_traffic_from_src_ip.yml
diff --git a/deprecated/investigations/investigate_okta_activity_by_app.yml b/removed/investigations/investigate_okta_activity_by_app.yml
similarity index 100%
rename from deprecated/investigations/investigate_okta_activity_by_app.yml
rename to removed/investigations/investigate_okta_activity_by_app.yml
diff --git a/deprecated/investigations/investigate_okta_activity_by_ip_address.yml b/removed/investigations/investigate_okta_activity_by_ip_address.yml
similarity index 100%
rename from deprecated/investigations/investigate_okta_activity_by_ip_address.yml
rename to removed/investigations/investigate_okta_activity_by_ip_address.yml
diff --git a/deprecated/investigations/investigate_pass_the_hash_attempts.yml b/removed/investigations/investigate_pass_the_hash_attempts.yml
similarity index 100%
rename from deprecated/investigations/investigate_pass_the_hash_attempts.yml
rename to removed/investigations/investigate_pass_the_hash_attempts.yml
diff --git a/deprecated/investigations/investigate_pass_the_ticket_attempts.yml b/removed/investigations/investigate_pass_the_ticket_attempts.yml
similarity index 100%
rename from deprecated/investigations/investigate_pass_the_ticket_attempts.yml
rename to removed/investigations/investigate_pass_the_ticket_attempts.yml
diff --git a/deprecated/investigations/investigate_previous_unseen_user.yml b/removed/investigations/investigate_previous_unseen_user.yml
similarity index 100%
rename from deprecated/investigations/investigate_previous_unseen_user.yml
rename to removed/investigations/investigate_previous_unseen_user.yml
diff --git a/deprecated/investigations/investigate_successful_remote_desktop_authentications.yml b/removed/investigations/investigate_successful_remote_desktop_authentications.yml
similarity index 100%
rename from deprecated/investigations/investigate_successful_remote_desktop_authentications.yml
rename to removed/investigations/investigate_successful_remote_desktop_authentications.yml
diff --git a/deprecated/investigations/investigate_suspicious_strings_in_http_header.yml b/removed/investigations/investigate_suspicious_strings_in_http_header.yml
similarity index 100%
rename from deprecated/investigations/investigate_suspicious_strings_in_http_header.yml
rename to removed/investigations/investigate_suspicious_strings_in_http_header.yml
diff --git a/deprecated/investigations/investigate_user_activities_in_okta.yml b/removed/investigations/investigate_user_activities_in_okta.yml
similarity index 100%
rename from deprecated/investigations/investigate_user_activities_in_okta.yml
rename to removed/investigations/investigate_user_activities_in_okta.yml
diff --git a/deprecated/investigations/investigate_web_posts_from_src.yml b/removed/investigations/investigate_web_posts_from_src.yml
similarity index 100%
rename from deprecated/investigations/investigate_web_posts_from_src.yml
rename to removed/investigations/investigate_web_posts_from_src.yml
diff --git a/deprecated/stories/aws_cryptomining.yml b/removed/stories/aws_cryptomining.yml
similarity index 100%
rename from deprecated/stories/aws_cryptomining.yml
rename to removed/stories/aws_cryptomining.yml
diff --git a/deprecated/stories/aws_suspicious_provisioning_activities.yml b/removed/stories/aws_suspicious_provisioning_activities.yml
similarity index 100%
rename from deprecated/stories/aws_suspicious_provisioning_activities.yml
rename to removed/stories/aws_suspicious_provisioning_activities.yml
diff --git a/deprecated/stories/common_phishing_frameworks.yml b/removed/stories/common_phishing_frameworks.yml
similarity index 100%
rename from deprecated/stories/common_phishing_frameworks.yml
rename to removed/stories/common_phishing_frameworks.yml
diff --git a/deprecated/stories/container_implantation_monitoring_and_investigation.yml b/removed/stories/container_implantation_monitoring_and_investigation.yml
similarity index 100%
rename from deprecated/stories/container_implantation_monitoring_and_investigation.yml
rename to removed/stories/container_implantation_monitoring_and_investigation.yml
diff --git a/deprecated/stories/host_redirection.yml b/removed/stories/host_redirection.yml
similarity index 100%
rename from deprecated/stories/host_redirection.yml
rename to removed/stories/host_redirection.yml
diff --git a/deprecated/stories/kubernetes_sensitive_role_activity.yml b/removed/stories/kubernetes_sensitive_role_activity.yml
similarity index 100%
rename from deprecated/stories/kubernetes_sensitive_role_activity.yml
rename to removed/stories/kubernetes_sensitive_role_activity.yml
diff --git a/deprecated/stories/lateral_movement.yml b/removed/stories/lateral_movement.yml
similarity index 100%
rename from deprecated/stories/lateral_movement.yml
rename to removed/stories/lateral_movement.yml
diff --git a/deprecated/stories/monitor_backup_solution.yml b/removed/stories/monitor_backup_solution.yml
similarity index 100%
rename from deprecated/stories/monitor_backup_solution.yml
rename to removed/stories/monitor_backup_solution.yml
diff --git a/deprecated/stories/monitor_for_unauthorized_software.yml b/removed/stories/monitor_for_unauthorized_software.yml
similarity index 100%
rename from deprecated/stories/monitor_for_unauthorized_software.yml
rename to removed/stories/monitor_for_unauthorized_software.yml
diff --git a/deprecated/stories/office_365_detections.yml b/removed/stories/office_365_detections.yml
similarity index 100%
rename from deprecated/stories/office_365_detections.yml
rename to removed/stories/office_365_detections.yml
diff --git a/deprecated/stories/spectre_and_meltdown_vulnerabilities.yml b/removed/stories/spectre_and_meltdown_vulnerabilities.yml
similarity index 100%
rename from deprecated/stories/spectre_and_meltdown_vulnerabilities.yml
rename to removed/stories/spectre_and_meltdown_vulnerabilities.yml
diff --git a/deprecated/stories/suspicious_aws_ec2_activities.yml b/removed/stories/suspicious_aws_ec2_activities.yml
similarity index 100%
rename from deprecated/stories/suspicious_aws_ec2_activities.yml
rename to removed/stories/suspicious_aws_ec2_activities.yml
diff --git a/deprecated/stories/unusual_aws_ec2_modifications.yml b/removed/stories/unusual_aws_ec2_modifications.yml
similarity index 100%
rename from deprecated/stories/unusual_aws_ec2_modifications.yml
rename to removed/stories/unusual_aws_ec2_modifications.yml
diff --git a/deprecated/stories/web_fraud_detection.yml b/removed/stories/web_fraud_detection.yml
similarity index 100%
rename from deprecated/stories/web_fraud_detection.yml
rename to removed/stories/web_fraud_detection.yml
From f096d77d6f7485cc6b235ffc2e72298c99b21386 Mon Sep 17 00:00:00 2001
From: Eric
Date: Tue, 18 Mar 2025 14:25:56 -0700
Subject: [PATCH 64/67] Changed the names of some fields due to the use of both
deprecated and removed to refer to content in different stages of removal
---
removed/deprecation_mapping.YML | 1004 +++++++++++++++----------------
1 file changed, 502 insertions(+), 502 deletions(-)
diff --git a/removed/deprecation_mapping.YML b/removed/deprecation_mapping.YML
index e070b62001..73220d59fb 100644
--- a/removed/deprecation_mapping.YML
+++ b/removed/deprecation_mapping.YML
@@ -1,248 +1,248 @@
detections:
- - deprecated_content: Open Redirect in Splunk Web
- deprecated_in_version: 5.2.0
+ - content: Open Redirect in Splunk Web
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Splunk Enterprise Information Disclosure
- deprecated_in_version: 5.2.0
+ - content: Splunk Enterprise Information Disclosure
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: ASL AWS Excessive Security Scanning
- deprecated_in_version: 5.2.0
+ - content: ASL AWS Excessive Security Scanning
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: AWS Cloud Provisioning From Previously Unseen Region
- deprecated_in_version: 5.2.0
+ - content: AWS Cloud Provisioning From Previously Unseen Region
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Provisioning Activity From Previously Unseen Region
- - deprecated_content: First time seen command line argument
- deprecated_in_version: 5.2.0
+ - content: First time seen command line argument
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Windows connhost exe started forcefully
- deprecated_in_version: 5.2.0
+ - content: Windows connhost exe started forcefully
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Detect Mimikatz Using Loaded Images
- deprecated_in_version: 5.2.0
+ - content: Detect Mimikatz Using Loaded Images
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Kubernetes Azure detect sensitive role access
- deprecated_in_version: 5.2.0
+ - content: Kubernetes Azure detect sensitive role access
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Web Fraud - Anomalous User Clickspeed
- deprecated_in_version: 5.2.0
+ - content: Web Fraud - Anomalous User Clickspeed
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: EC2 Instance Started With Previously Unseen Instance Type
- deprecated_in_version: 5.2.0
+ - content: EC2 Instance Started With Previously Unseen Instance Type
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Compute Instance Created With Previously Unseen Instance Type
- - deprecated_content: EC2 Instance Started With Previously Unseen AMI
- deprecated_in_version: 5.2.0
+ - content: EC2 Instance Started With Previously Unseen AMI
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Compute Instance Created With Previously Unseen Image
- - deprecated_content: Domain Group Discovery With Net
- deprecated_in_version: 5.2.0
+ - content: Domain Group Discovery With Net
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Group Discovery Via Net
- - deprecated_content: Kubernetes AWS detect sensitive role access
- deprecated_in_version: 5.2.0
+ - content: Kubernetes AWS detect sensitive role access
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Winword Spawning Windows Script Host
- deprecated_in_version: 5.2.0
+ - content: Winword Spawning Windows Script Host
+ removed_in_version: 5.2.0
reason: "The following analytics was deprecated in favour of a more generic approach.
Where instead of creating specific analytic for every potentially suspicious child
of an office product. We group them by threat level.\nThis would ease management
and false positives tuning."
replacement_content:
- Windows Office Product Spawned Uncommon Process
- - deprecated_content: Winword Spawning PowerShell
- deprecated_in_version: 5.2.0
+ - content: Winword Spawning PowerShell
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- - deprecated_content: Attempted Credential Dump From Registry via Reg exe
- deprecated_in_version: 5.2.0
+ - content: Attempted Credential Dump From Registry via Reg exe
+ removed_in_version: 5.2.0
reason: This analytic had some overlap with another one, hence the deprecation.
It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry
Hive Dump Via CommandLine
replacement_content:
- Windows Sensitive Registry Hive Dump Via CommandLine
- - deprecated_content: Detect processes used for System Network Configuration Discovery
- deprecated_in_version: 5.2.0
+ - content: Detect processes used for System Network Configuration Discovery
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Potential System Network Configuration Discovery Activity
- - deprecated_content: Execution of File With Spaces Before Extension
- deprecated_in_version: 5.2.0
+ - content: Execution of File With Spaces Before Extension
+ removed_in_version: 5.2.0
reason: Updated to a new detection name
replacement_content:
- Execution of File with Multiple Extensions
- - deprecated_content: EC2 Instance Started In Previously Unseen Region
- deprecated_in_version: 5.2.0
+ - content: EC2 Instance Started In Previously Unseen Region
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Compute Instance Created In Previously Unused Region
- - deprecated_content: Office Document Spawned Child Process To Download
- deprecated_in_version: 5.2.0
+ - content: Office Document Spawned Child Process To Download
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Spawned Child Process For Download
- - deprecated_content: Detect new API calls from user roles
- deprecated_in_version: 5.2.0
+ - content: Detect new API calls from user roles
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud API Calls From Previously Unseen User Roles
- - deprecated_content: Cmdline Tool Not Executed In CMD Shell
- deprecated_in_version: 5.2.0
+ - content: Cmdline Tool Not Executed In CMD Shell
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Cmdline Tool Execution From Non-Shell Process
- - deprecated_content: Linux Auditd Find Private Keys
- deprecated_in_version: 5.2.0
+ - content: Linux Auditd Find Private Keys
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Linux Auditd Private Keys and Certificate Enumeration
- - deprecated_content: Detect AWS API Activities From Unapproved Accounts
- deprecated_in_version: 5.2.0
+ - content: Detect AWS API Activities From Unapproved Accounts
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Monitor DNS For Brand Abuse
- deprecated_in_version: 5.2.0
+ - content: Monitor DNS For Brand Abuse
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Kubernetes GCP detect sensitive object access
- deprecated_in_version: 5.2.0
+ - content: Kubernetes GCP detect sensitive object access
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Kubernetes Azure scan fingerprint
- deprecated_in_version: 5.2.0
+ - content: Kubernetes Azure scan fingerprint
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: ASL AWS Password Policy Changes
- deprecated_in_version: 5.2.0
+ - content: ASL AWS Password Policy Changes
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: O365 Suspicious Admin Email Forwarding
- deprecated_in_version: 5.2.0
+ - content: O365 Suspicious Admin Email Forwarding
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- O365 Mailbox Email Forwarding Enabled
- - deprecated_content: AWS Cloud Provisioning From Previously Unseen City
- deprecated_in_version: 5.2.0
+ - content: AWS Cloud Provisioning From Previously Unseen City
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Provisioning Activity From Previously Unseen City
- - deprecated_content: Kubernetes AWS detect service accounts forbidden failure access
- deprecated_in_version: 5.2.0
+ - content: Kubernetes AWS detect service accounts forbidden failure access
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Osquery pack - ColdRoot detection
- deprecated_in_version: 5.2.0
+ - content: Osquery pack - ColdRoot detection
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Windows Modify Registry Reg Restore
- deprecated_in_version: 5.2.0
+ - content: Windows Modify Registry Reg Restore
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Registry Entries Restored Via Reg
- - deprecated_content: Kubernetes GCP detect most active service accounts by pod
- deprecated_in_version: 5.2.0
+ - content: Kubernetes GCP detect most active service accounts by pod
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Scheduled tasks used in BadRabbit ransomware
- deprecated_in_version: 5.2.0
+ - content: Scheduled tasks used in BadRabbit ransomware
+ removed_in_version: 5.2.0
reason: Updated to a new detection name
replacement_content:
- Scheduled Task Deleted Or Created via CMD
- - deprecated_content: Suspicious Rundll32 Rename
- deprecated_in_version: 5.2.0
+ - content: Suspicious Rundll32 Rename
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Remote System Discovery with Net
- deprecated_in_version: 5.2.0
+ - content: Remote System Discovery with Net
+ removed_in_version: 5.2.0
reason: "This analytic was focusing on 2 separate and unrelated type of threats
or actions. PLease use the replacement content"
replacement_content:
- Windows Sensitive Group Discovery With Net
- - deprecated_content: DNS Query Requests Resolved by Unauthorized DNS Servers
- deprecated_in_version: 5.2.0
+ - content: DNS Query Requests Resolved by Unauthorized DNS Servers
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Suspicious Changes to File Associations
- deprecated_in_version: 5.2.0
+ - content: Suspicious Changes to File Associations
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: GCP Detect high risk permissions by resource and account
- deprecated_in_version: 5.2.0
+ - content: GCP Detect high risk permissions by resource and account
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Office Product Writing cab or inf
- deprecated_in_version: 5.2.0
+ - content: Office Product Writing cab or inf
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Dropped Cab or Inf File
- - deprecated_content: Identify New User Accounts
- deprecated_in_version: 5.2.0
+ - content: Identify New User Accounts
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Office Product Spawn CMD Process
- deprecated_in_version: 5.2.0
+ - content: Office Product Spawn CMD Process
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- - deprecated_content: Windows DLL Search Order Hijacking Hunt
- deprecated_in_version: 5.2.0
+ - content: Windows DLL Search Order Hijacking Hunt
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Windows DLL Search Order Hijacking Hunt with Sysmon
- - deprecated_content: ASL AWS CreateAccessKey
- deprecated_in_version: 5.2.0
+ - content: ASL AWS CreateAccessKey
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- ASL AWS Create Access Key
- - deprecated_content: Okta ThreatInsight Login Failure with High Unknown users
- deprecated_in_version: 5.2.0
+ - content: Okta ThreatInsight Login Failure with High Unknown users
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Detect Spike in Security Group Activity
- deprecated_in_version: 5.2.0
+ - content: Detect Spike in Security Group Activity
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Abnormally High Number Of Cloud Security Group API Calls
- - deprecated_content: Office Product Spawning BITSAdmin
- deprecated_in_version: 5.2.0
+ - content: Office Product Spawning BITSAdmin
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- - deprecated_content: Create local admin accounts using net exe
- deprecated_in_version: 5.2.0
+ - content: Create local admin accounts using net exe
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Create Local Administrator Account Via Net
- - deprecated_content: Abnormally High AWS Instances Terminated by User - MLTK
- deprecated_in_version: 5.2.0
+ - content: Abnormally High AWS Instances Terminated by User - MLTK
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Windows Office Product Spawning MSDT
- deprecated_in_version: 5.2.0
+ - content: Windows Office Product Spawning MSDT
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Spawned MSDT
- - deprecated_content: Detect Spike in AWS API Activity
- deprecated_in_version: 5.2.0
+ - content: Detect Spike in AWS API Activity
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Office Product Spawning Windows Script Host
- deprecated_in_version: 5.2.0
+ - content: Office Product Spawning Windows Script Host
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- - deprecated_content: Prohibited Software On Endpoint
- deprecated_in_version: 5.2.0
+ - content: Prohibited Software On Endpoint
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Attacker Tools On Endpoint
- - deprecated_content: AWS Cloud Provisioning From Previously Unseen Country
- deprecated_in_version: 5.2.0
+ - content: AWS Cloud Provisioning From Previously Unseen Country
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Provisioning Activity From Previously Unseen Country
- - deprecated_content: Detect Critical Alerts from Security Tools
- deprecated_in_version: 5.2.0
+ - content: Detect Critical Alerts from Security Tools
+ removed_in_version: 5.2.0
reason: As discussed internally, this analytic was too generic for an analyst to
do anything with it. It was deprecated in favor of the more specific approach
provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender
@@ -250,759 +250,759 @@ detections:
have their specific analytics.
replacement_content:
- Microsoft Defender ATP Alerts
- - deprecated_content: Detect Critical Alerts from Security Tools
- deprecated_in_version: 5.2.0
+ - content: Detect Critical Alerts from Security Tools
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Microsoft Defender Incident Alerts
- - deprecated_content: Excel Spawning PowerShell
- deprecated_in_version: 5.2.0
+ - content: Excel Spawning PowerShell
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- - deprecated_content: Office Application Spawn rundll32 process
- deprecated_in_version: 5.2.0
+ - content: Office Application Spawn rundll32 process
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- - deprecated_content: Excessive Usage Of Net App
- deprecated_in_version: 5.2.0
+ - content: Excessive Usage Of Net App
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Excessive Usage Of Net App
- - deprecated_content: Elevated Group Discovery With Net
- deprecated_in_version: 5.2.0
+ - content: Elevated Group Discovery With Net
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Sensitive Group Discovery With Net
- - deprecated_content: Local Account Discovery with Net
- deprecated_in_version: 5.2.0
+ - content: Local Account Discovery with Net
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows User Discovery Via Net
- - deprecated_content: Windows Command Shell Fetch Env Variables
- deprecated_in_version: 5.2.0
+ - content: Windows Command Shell Fetch Env Variables
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows List ENV Variables Via SET Command From Uncommon Parent
- - deprecated_content: Suspicious Email - UBA Anomaly
- deprecated_in_version: 5.2.0
+ - content: Suspicious Email - UBA Anomaly
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Detect web traffic to dynamic domain providers
- deprecated_in_version: 5.2.0
+ - content: Detect web traffic to dynamic domain providers
+ removed_in_version: 5.2.0
reason: Updated to use a different log source
replacement_content:
- Detect hosts connecting to dynamic domain providers
- - deprecated_content: Okta Failed SSO Attempts
- deprecated_in_version: 5.2.0
+ - content: Okta Failed SSO Attempts
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Unauthorized Access to Application
- - deprecated_content: Kubernetes AWS detect RBAC authorization by account
- deprecated_in_version: 5.2.0
+ - content: Kubernetes AWS detect RBAC authorization by account
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Kubernetes Azure detect service accounts forbidden failure access
- deprecated_in_version: 5.2.0
+ - content: Kubernetes Azure detect service accounts forbidden failure access
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Remote Registry Key modifications
- deprecated_in_version: 5.2.0
+ - content: Remote Registry Key modifications
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: O365 Suspicious User Email Forwarding
- deprecated_in_version: 5.2.0
+ - content: O365 Suspicious User Email Forwarding
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- O365 Mailbox Email Forwarding Enabled
- - deprecated_content: Office Product Spawning MSHTA
- deprecated_in_version: 5.2.0
+ - content: Office Product Spawning MSHTA
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- - deprecated_content: Kubernetes AWS detect most active service accounts by pod
- deprecated_in_version: 5.2.0
+ - content: Kubernetes AWS detect most active service accounts by pod
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Correlation by Repository and Risk
- deprecated_in_version: 5.2.0
+ - content: Correlation by Repository and Risk
+ removed_in_version: 5.2.0
reason: Detections updated to use the datamodel
replacement_content:
- Risk Rule for Dev Sec Ops by Repository
- - deprecated_content: Kubernetes Azure detect RBAC authorization by account
- deprecated_in_version: 5.2.0
+ - content: Kubernetes Azure detect RBAC authorization by account
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Clients Connecting to Multiple DNS Servers
- deprecated_in_version: 5.2.0
+ - content: Clients Connecting to Multiple DNS Servers
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Excessive Service Stop Attempt
- deprecated_in_version: 5.2.0
+ - content: Excessive Service Stop Attempt
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Excessive Service Stop Attempt
- - deprecated_content: Multiple Okta Users With Invalid Credentials From The Same IP
- deprecated_in_version: 5.2.0
+ - content: Multiple Okta Users With Invalid Credentials From The Same IP
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Multiple Users Failing To Authenticate From Ip
- - deprecated_content: Suspicious writes to System Volume Information
- deprecated_in_version: 5.2.0
+ - content: Suspicious writes to System Volume Information
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Detect new user AWS Console Login
- deprecated_in_version: 5.2.0
+ - content: Detect new user AWS Console Login
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Detect AWS Console Login by New User
- - deprecated_content: Domain Account Discovery With Net App
- deprecated_in_version: 5.2.0
+ - content: Domain Account Discovery With Net App
+ removed_in_version: 5.2.0
reason: "This analytic was a TTP that looked only for commands that tries to query
info about the users via net user /do. This had a couple of issues, such as triggering
on creation of users via the /add flag etc..\nIt was deprecated in favor of a
more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122"
replacement_content:
- Windows User Discovery Via Net
- - deprecated_content: Detection of DNS Tunnels
- deprecated_in_version: 5.2.0
+ - content: Detection of DNS Tunnels
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Detect DNS requests to Phishing Sites leveraging EvilGinx2
- deprecated_in_version: 5.2.0
+ - content: Detect DNS requests to Phishing Sites leveraging EvilGinx2
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Office Document Creating Schedule Task
- deprecated_in_version: 5.2.0
+ - content: Office Document Creating Schedule Task
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Loading Taskschd DLL
- - deprecated_content: Okta Account Locked Out
- deprecated_in_version: 5.2.0
+ - content: Okta Account Locked Out
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Multiple Accounts Locked Out
- - deprecated_content: Unsuccessful Netbackup backups
- deprecated_in_version: 5.2.0
+ - content: Unsuccessful Netbackup backups
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Detect Mimikatz Via PowerShell And EventCode 4703
- deprecated_in_version: 5.2.0
+ - content: Detect Mimikatz Via PowerShell And EventCode 4703
+ removed_in_version: 5.2.0
reason: Updated to a new detection name
replacement_content:
- Detect Mimikatz With PowerShell Script Block Logging
- - deprecated_content: Winword Spawning Cmd
- deprecated_in_version: 5.2.0
+ - content: Winword Spawning Cmd
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- - deprecated_content: GCP Kubernetes cluster scan detection
- deprecated_in_version: 5.2.0
+ - content: GCP Kubernetes cluster scan detection
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Kubernetes Scanning by Unauthenticated IP Address
- - deprecated_content: Kubernetes GCP detect suspicious kubectl calls
- deprecated_in_version: 5.2.0
+ - content: Kubernetes GCP detect suspicious kubectl calls
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: gcp detect oauth token abuse
- deprecated_in_version: 5.2.0
+ - content: gcp detect oauth token abuse
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Correlation by User and Risk
- deprecated_in_version: 5.2.0
+ - content: Correlation by User and Risk
+ removed_in_version: 5.2.0
reason: Detections updated to use the datamodel
replacement_content:
- Risk Rule for Dev Sec Ops by Repository
- - deprecated_content: Processes created by netsh
- deprecated_in_version: 5.2.0
+ - content: Processes created by netsh
+ removed_in_version: 5.2.0
reason: Updated to a new detection name
replacement_content:
- Processes launching netsh
- - deprecated_content: Office Product Spawning Wmic
- deprecated_in_version: 5.2.0
+ - content: Office Product Spawning Wmic
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- - deprecated_content: Extraction of Registry Hives
- deprecated_in_version: 5.2.0
+ - content: Extraction of Registry Hives
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Sensitive Registry Hive Dump Via CommandLine
- - deprecated_content: Attempt To Stop Security Service
- deprecated_in_version: 5.2.0
+ - content: Attempt To Stop Security Service
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Attempt To Stop Security Service
- - deprecated_content: Windows MSIExec With Network Connections
- deprecated_in_version: 5.2.0
+ - content: Windows MSIExec With Network Connections
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows HTTP Network Communication From MSIExec
- - deprecated_content: Windows Query Registry Reg Save
- deprecated_in_version: 5.2.0
+ - content: Windows Query Registry Reg Save
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Registry Entries Exported Via Reg
- - deprecated_content: Cloud Network Access Control List Deleted
- deprecated_in_version: 5.2.0
+ - content: Cloud Network Access Control List Deleted
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- AWS Network Access Control List Deleted
- - deprecated_content: O365 Suspicious Rights Delegation
- deprecated_in_version: 5.2.0
+ - content: O365 Suspicious Rights Delegation
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- O365 Elevated Mailbox Permission Assigned
- - deprecated_content: Abnormally High AWS Instances Launched by User - MLTK
- deprecated_in_version: 5.2.0
+ - content: Abnormally High AWS Instances Launched by User - MLTK
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Reg exe used to hide files directories via registry keys
- deprecated_in_version: 5.2.0
+ - content: Reg exe used to hide files directories via registry keys
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Detect Long DNS TXT Record Response
- deprecated_in_version: 5.2.0
+ - content: Detect Long DNS TXT Record Response
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Password Policy Discovery with Net
- deprecated_in_version: 5.2.0
+ - content: Password Policy Discovery with Net
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Password Policy Discovery with Net
- - deprecated_content: AWS Cloud Provisioning From Previously Unseen IP Address
- deprecated_in_version: 5.2.0
+ - content: AWS Cloud Provisioning From Previously Unseen IP Address
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Provisioning Activity From Previously Unseen IP Address
- - deprecated_content: Network Connection Discovery With Net
- deprecated_in_version: 5.2.0
+ - content: Network Connection Discovery With Net
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Network Connection Discovery Via Net
- - deprecated_content: Kubernetes Azure detect suspicious kubectl calls
- deprecated_in_version: 5.2.0
+ - content: Kubernetes Azure detect suspicious kubectl calls
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Kubernetes GCP detect sensitive role access
- deprecated_in_version: 5.2.0
+ - content: Kubernetes GCP detect sensitive role access
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Detect Webshell Exploit Behavior
- deprecated_in_version: 5.2.0
+ - content: Detect Webshell Exploit Behavior
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Suspicious Child Process Spawned From WebServer
- - deprecated_content: DNS record changed
- deprecated_in_version: 5.2.0
+ - content: DNS record changed
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Unsigned Image Loaded by LSASS
- deprecated_in_version: 5.2.0
+ - content: Unsigned Image Loaded by LSASS
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Detect USB device insertion
- deprecated_in_version: 5.2.0
+ - content: Detect USB device insertion
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Windows Network Share Interaction With Net
- deprecated_in_version: 5.2.0
+ - content: Windows Network Share Interaction With Net
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Network Share Interaction Via Net
- - deprecated_content: Account Discovery With Net App
- deprecated_in_version: 5.2.0
+ - content: Account Discovery With Net App
+ removed_in_version: 5.2.0
reason: This analytic was a TTP that focused on unrelated things and called account
discovery. Since there were other detection that overlapped with it. I choose
to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122
/ Windows Excessive Usage Of Net App.
replacement_content:
- Windows Excessive Usage Of Net App
- - deprecated_content: Change Default File Association
- deprecated_in_version: 5.2.0
+ - content: Change Default File Association
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows New Default File Association Value Set
- - deprecated_content: Windows Lateral Tool Transfer RemCom
- deprecated_in_version: 5.2.0
+ - content: Windows Lateral Tool Transfer RemCom
+ removed_in_version: 5.2.0
reason: Updated to a new detection name
replacement_content:
- Windows Service Execution RemCom
- - deprecated_content: Office Document Executing Macro Code
- deprecated_in_version: 5.2.0
+ - content: Office Document Executing Macro Code
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Loading VBE7 DLL
- - deprecated_content: Okta Account Lockout Events
- deprecated_in_version: 5.2.0
+ - content: Okta Account Lockout Events
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Multiple Accounts Locked Out
- - deprecated_content: Abnormally High AWS Instances Launched by User
- deprecated_in_version: 5.2.0
+ - content: Abnormally High AWS Instances Launched by User
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Abnormally High Number Of Cloud Instances Launched
- - deprecated_content: EC2 Instance Modified With Previously Unseen User
- deprecated_in_version: 5.2.0
+ - content: EC2 Instance Modified With Previously Unseen User
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud API Calls From Previously Unseen User Roles
- - deprecated_content: Windows Valid Account With Never Expires Password
- deprecated_in_version: 5.2.0
+ - content: Windows Valid Account With Never Expires Password
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Set Account Password Policy To Unlimited Via Net
- - deprecated_content: Windows hosts file modification
- deprecated_in_version: 5.2.0
+ - content: Windows hosts file modification
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: MSHTML Module Load in Office Product
- deprecated_in_version: 5.2.0
+ - content: MSHTML Module Load in Office Product
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Loaded MSHTML Module
- - deprecated_content: Abnormally High AWS Instances Terminated by User
- deprecated_in_version: 5.2.0
+ - content: Abnormally High AWS Instances Terminated by User
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Abnormally High Number Of Cloud Instances Destroyed
- - deprecated_content: Web Fraud - Account Harvesting
- deprecated_in_version: 5.2.0
+ - content: Web Fraud - Account Harvesting
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Office Spawning Control
- deprecated_in_version: 5.2.0
+ - content: Office Spawning Control
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Spawned Control
- - deprecated_content: Detect Activity Related to Pass the Hash Attacks
- deprecated_in_version: 5.2.0
+ - content: Detect Activity Related to Pass the Hash Attacks
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Deleting Of Net Users
- deprecated_in_version: 5.2.0
+ - content: Deleting Of Net Users
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows User Deletion Via Net
- - deprecated_content: Suspicious File Write
- deprecated_in_version: 5.2.0
+ - content: Suspicious File Write
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: AWS EKS Kubernetes cluster sensitive object access
- deprecated_in_version: 5.2.0
+ - content: AWS EKS Kubernetes cluster sensitive object access
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Kubernetes Abuse of Secret by Unusual Location
- - deprecated_content: Spectre and Meltdown Vulnerable Systems
- deprecated_in_version: 5.2.0
+ - content: Spectre and Meltdown Vulnerable Systems
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: EC2 Instance Started With Previously Unseen User
- deprecated_in_version: 5.2.0
+ - content: EC2 Instance Started With Previously Unseen User
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Compute Instance Created By Previously Unseen User
- - deprecated_content: Office Product Spawning CertUtil
- deprecated_in_version: 5.2.0
+ - content: Office Product Spawning CertUtil
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- - deprecated_content: Kubernetes GCP detect RBAC authorizations by account
- deprecated_in_version: 5.2.0
+ - content: Kubernetes GCP detect RBAC authorizations by account
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Office Application Drop Executable
- deprecated_in_version: 5.2.0
+ - content: Office Application Drop Executable
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Dropped Uncommon File
- - deprecated_content: Kubernetes Azure active service accounts by pod namespace
- deprecated_in_version: 5.2.0
+ - content: Kubernetes Azure active service accounts by pod namespace
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Kubernetes Azure pod scan fingerprint
- deprecated_in_version: 5.2.0
+ - content: Kubernetes Azure pod scan fingerprint
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Detect Spike in Network ACL Activity
- deprecated_in_version: 5.2.0
+ - content: Detect Spike in Network ACL Activity
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Abnormally High Number Of Cloud Infrastructure API Calls
- - deprecated_content: Suspicious Powershell Command-Line Arguments
- deprecated_in_version: 5.2.0
+ - content: Suspicious Powershell Command-Line Arguments
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Malicious PowerShell Process - Encoded Command
- - deprecated_content: Office Application Spawn Regsvr32 process
- deprecated_in_version: 5.2.0
+ - content: Office Application Spawn Regsvr32 process
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- - deprecated_content: Detect API activity from users without MFA
- deprecated_in_version: 5.2.0
+ - content: Detect API activity from users without MFA
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- AWS Successful Single-Factor Authentication
- - deprecated_content: Kubernetes Azure detect sensitive object access
- deprecated_in_version: 5.2.0
+ - content: Kubernetes Azure detect sensitive object access
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Web Fraud - Password Sharing Across Accounts
- deprecated_in_version: 5.2.0
+ - content: Web Fraud - Password Sharing Across Accounts
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Disabling Net User Account
- deprecated_in_version: 5.2.0
+ - content: Disabling Net User Account
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows User Disabled Via Net
- - deprecated_content: GCP Detect accounts with high risk roles by project
- deprecated_in_version: 5.2.0
+ - content: GCP Detect accounts with high risk roles by project
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Kubernetes GCP detect service accounts forbidden failure access
- deprecated_in_version: 5.2.0
+ - content: Kubernetes GCP detect service accounts forbidden failure access
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Extended Period Without Successful Netbackup Backups
- deprecated_in_version: 5.2.0
+ - content: Extended Period Without Successful Netbackup Backups
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Office Product Spawning Rundll32 with no DLL
- deprecated_in_version: 5.2.0
+ - content: Office Product Spawning Rundll32 with no DLL
+ removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Spawned Rundll32 With No DLL
- - deprecated_content: Okta ThreatInsight Suspected PasswordSpray Attack
- deprecated_in_version: 5.2.0
+ - content: Okta ThreatInsight Suspected PasswordSpray Attack
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta ThreatInsight Threat Detected
- - deprecated_content: Net Localgroup Discovery
- deprecated_in_version: 5.2.0
+ - content: Net Localgroup Discovery
+ removed_in_version: 5.2.0
reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44
/ Windows Group Discovery Via Net
replacement_content:
- Windows Group Discovery Via Net
- - deprecated_content: Uncommon Processes On Endpoint
- deprecated_in_version: 5.2.0
+ - content: Uncommon Processes On Endpoint
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Attacker Tools On Endpoint
- - deprecated_content: Dump LSASS via procdump Rename
- deprecated_in_version: 5.2.0
+ - content: Dump LSASS via procdump Rename
+ removed_in_version: 5.2.0
reason: Updated to a new detection name
replacement_content:
- Dump LSASS via procdump
- - deprecated_content: Okta Two or More Rejected Okta Pushes
- deprecated_in_version: 5.2.0
+ - content: Okta Two or More Rejected Okta Pushes
+ removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Multiple Failed MFA Requests For User
- - deprecated_content: Windows Service Stop Via Net and SC Application
- deprecated_in_version: 5.2.0
+ - content: Windows Service Stop Via Net and SC Application
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Excel Spawning Windows Script Host
- deprecated_in_version: 5.2.0
+ - content: Excel Spawning Windows Script Host
+ removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: GitHub Actions Disable Security Workflow
- deprecated_in_version: 5.4.0
+ - content: GitHub Actions Disable Security Workflow
+ removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Github Commit Changes In Master
- deprecated_in_version: 5.4.0
+ - content: Github Commit Changes In Master
+ removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Github Commit In Develop
- deprecated_in_version: 5.4.0
+ - content: Github Commit In Develop
+ removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: GitHub Dependabot Alert
- deprecated_in_version: 5.4.0
+ - content: GitHub Dependabot Alert
+ removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: GitHub Pull Request from Unknown User
- deprecated_in_version: 5.4.0
+ - content: GitHub Pull Request from Unknown User
+ removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Known Services Killed by Ransomware
- deprecated_in_version: 5.4.0
+ - content: Known Services Killed by Ransomware
+ removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Remote Desktop Network Bruteforce
- deprecated_in_version: 5.4.0
+ - content: Remote Desktop Network Bruteforce
+ removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Suspicious Driver Loaded Path
- deprecated_in_version: 5.4.0
+ - content: Suspicious Driver Loaded Path
+ removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Suspicious Event Log Service Behavior
- deprecated_in_version: 5.4.0
+ - content: Suspicious Event Log Service Behavior
+ removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Suspicious Process File Path
- deprecated_in_version: 5.4.0
+ - content: Suspicious Process File Path
+ removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: AWS Cross Account Activity From Previously Unseen Account
- deprecated_in_version: 5.4.0
+ - content: AWS Cross Account Activity From Previously Unseen Account
+ removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: aws detect attach to role policy
- deprecated_in_version: 5.4.0
+ - content: aws detect attach to role policy
+ removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: aws detect permanent key creation
- deprecated_in_version: 5.4.0
+ - content: aws detect permanent key creation
+ removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: aws detect role creation
- deprecated_in_version: 5.4.0
+ - content: aws detect role creation
+ removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: aws detect sts assume role abuse
- deprecated_in_version: 5.4.0
+ - content: aws detect sts assume role abuse
+ removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: aws detect sts get session token abuse
- deprecated_in_version: 5.4.0
+ - content: aws detect sts get session token abuse
+ removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: AWS SAML Access by Provider User and Principal
- deprecated_in_version: 5.4.0
+ - content: AWS SAML Access by Provider User and Principal
+ removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
baselines:
- - deprecated_content: Add Prohibited Processes to Enterprise Security
- deprecated_in_version: 5.2.0
+ - content: Add Prohibited Processes to Enterprise Security
+ removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- - deprecated_content: Baseline of API Calls per User ARN
- deprecated_in_version: 5.2.0
+ - content: Baseline of API Calls per User ARN
+ removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- - deprecated_content: Baseline of Excessive AWS Instances Launched by User - MLTK
- deprecated_in_version: 5.2.0
+ - content: Baseline of Excessive AWS Instances Launched by User - MLTK
+ removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- - deprecated_content: Baseline of Excessive AWS Instances Terminated by User - MLTK
- deprecated_in_version: 5.2.0
+ - content: Baseline of Excessive AWS Instances Terminated by User - MLTK
+ removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- - deprecated_content: Previously seen API call per user roles in CloudTrail
- deprecated_in_version: 5.2.0
+ - content: Previously seen API call per user roles in CloudTrail
+ removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- - deprecated_content: Previously Seen AWS Provisioning Activity Sources
- deprecated_in_version: 5.2.0
+ - content: Previously Seen AWS Provisioning Activity Sources
+ removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- - deprecated_content: Previously Seen EC2 AMIs
- deprecated_in_version: 5.2.0
+ - content: Previously Seen EC2 AMIs
+ removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- - deprecated_content: Previously Seen EC2 Instance Types
- deprecated_in_version: 5.2.0
+ - content: Previously Seen EC2 Instance Types
+ removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- - deprecated_content: Previously Seen EC2 Launches By User
- deprecated_in_version: 5.2.0
+ - content: Previously Seen EC2 Launches By User
+ removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- - deprecated_content: Previously seen users in CloudTrail
- deprecated_in_version: 5.2.0
+ - content: Previously seen users in CloudTrail
+ removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- - deprecated_content: Update previously seen users in CloudTrail
- deprecated_in_version: 5.2.0
+ - content: Update previously seen users in CloudTrail
+ removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- - deprecated_content: Monitor Successful Backups
- deprecated_in_version: 5.2.0
+ - content: Monitor Successful Backups
+ removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- - deprecated_content: Monitor Unsuccessful Backups
- deprecated_in_version: 5.2.0
+ - content: Monitor Unsuccessful Backups
+ removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- - deprecated_content: Previously Seen AWS Regions
- deprecated_in_version: 5.2.0
+ - content: Previously Seen AWS Regions
+ removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- - deprecated_content: Previously Seen EC2 Modifications By User
- deprecated_in_version: 5.2.0
+ - content: Previously Seen EC2 Modifications By User
+ removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- - deprecated_content: Systems Ready for Spectre-Meltdown Windows Patch
- deprecated_in_version: 5.2.0
+ - content: Systems Ready for Spectre-Meltdown Windows Patch
+ removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- - deprecated_content: Previously Seen AWS Cross Account Activity - Initial
- deprecated_in_version: 5.4.0
+ - content: Previously Seen AWS Cross Account Activity - Initial
+ removed_in_version: 5.4.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- - deprecated_content: Previously Seen AWS Cross Account Activity - Update
- deprecated_in_version: 5.4.0
+ - content: Previously Seen AWS Cross Account Activity - Update
+ removed_in_version: 5.4.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
investigations:
- - deprecated_content: All backup logs for host
- deprecated_in_version: 5.2.0
+ - content: All backup logs for host
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Amazon EKS Kubernetes activity by src ip
- deprecated_in_version: 5.2.0
+ - content: Amazon EKS Kubernetes activity by src ip
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: AWS Investigate Security Hub alerts by dest
- deprecated_in_version: 5.2.0
+ - content: AWS Investigate Security Hub alerts by dest
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: AWS Investigate User Activities By AccessKeyId
- deprecated_in_version: 5.2.0
+ - content: AWS Investigate User Activities By AccessKeyId
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: AWS Investigate User Activities By ARN
- deprecated_in_version: 5.2.0
+ - content: AWS Investigate User Activities By ARN
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: AWS Network ACL Details from ID
- deprecated_in_version: 5.2.0
+ - content: AWS Network ACL Details from ID
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: AWS Network Interface details via resourceId
- deprecated_in_version: 5.2.0
+ - content: AWS Network Interface details via resourceId
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: AWS S3 Bucket details via bucketName
- deprecated_in_version: 5.2.0
+ - content: AWS S3 Bucket details via bucketName
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: GCP Kubernetes activity by src ip
- deprecated_in_version: 5.2.0
+ - content: GCP Kubernetes activity by src ip
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get All AWS Activity From City
- deprecated_in_version: 5.2.0
+ - content: Get All AWS Activity From City
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get All AWS Activity From Country
- deprecated_in_version: 5.2.0
+ - content: Get All AWS Activity From Country
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get All AWS Activity From IP Address
- deprecated_in_version: 5.2.0
+ - content: Get All AWS Activity From IP Address
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get All AWS Activity From Region
- deprecated_in_version: 5.2.0
+ - content: Get All AWS Activity From Region
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get Backup Logs For Endpoint
- deprecated_in_version: 5.2.0
+ - content: Get Backup Logs For Endpoint
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get Certificate logs for a domain
- deprecated_in_version: 5.2.0
+ - content: Get Certificate logs for a domain
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get DNS Server History for a host
- deprecated_in_version: 5.2.0
+ - content: Get DNS Server History for a host
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get DNS traffic ratio
- deprecated_in_version: 5.2.0
+ - content: Get DNS traffic ratio
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get EC2 Instance Details by instanceId
- deprecated_in_version: 5.2.0
+ - content: Get EC2 Instance Details by instanceId
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get EC2 Launch Details
- deprecated_in_version: 5.2.0
+ - content: Get EC2 Launch Details
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get Email Info
- deprecated_in_version: 5.2.0
+ - content: Get Email Info
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get Emails From Specific Sender
- deprecated_in_version: 5.2.0
+ - content: Get Emails From Specific Sender
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get First Occurrence and Last Occurrence of a MAC Address
- deprecated_in_version: 5.2.0
+ - content: Get First Occurrence and Last Occurrence of a MAC Address
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get History Of Email Sources
- deprecated_in_version: 5.2.0
+ - content: Get History Of Email Sources
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get Logon Rights Modifications For Endpoint
- deprecated_in_version: 5.2.0
+ - content: Get Logon Rights Modifications For Endpoint
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get Logon Rights Modifications For User
- deprecated_in_version: 5.2.0
+ - content: Get Logon Rights Modifications For User
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get Notable History
- deprecated_in_version: 5.2.0
+ - content: Get Notable History
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get Outbound Emails to Hidden Cobra Threat Actors
- deprecated_in_version: 5.2.0
+ - content: Get Outbound Emails to Hidden Cobra Threat Actors
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get Parent Process Info
- deprecated_in_version: 5.2.0
+ - content: Get Parent Process Info
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get Process File Activity
- deprecated_in_version: 5.2.0
+ - content: Get Process File Activity
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get Process Info
- deprecated_in_version: 5.2.0
+ - content: Get Process Info
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get Process Information For Port Activity
- deprecated_in_version: 5.2.0
+ - content: Get Process Information For Port Activity
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get Process Responsible For The DNS Traffic
- deprecated_in_version: 5.2.0
+ - content: Get Process Responsible For The DNS Traffic
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get Sysmon WMI Activity for Host
- deprecated_in_version: 5.2.0
+ - content: Get Sysmon WMI Activity for Host
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Get Web Session Information via session id
- deprecated_in_version: 5.2.0
+ - content: Get Web Session Information via session id
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Investigate AWS activities via region name
- deprecated_in_version: 5.2.0
+ - content: Investigate AWS activities via region name
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Investigate AWS User Activities by user field
- deprecated_in_version: 5.2.0
+ - content: Investigate AWS User Activities by user field
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Investigate Failed Logins for Multiple Destinations
- deprecated_in_version: 5.2.0
+ - content: Investigate Failed Logins for Multiple Destinations
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Investigate Network Traffic From src ip
- deprecated_in_version: 5.2.0
+ - content: Investigate Network Traffic From src ip
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Investigate Okta Activity by app
- deprecated_in_version: 5.2.0
+ - content: Investigate Okta Activity by app
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Investigate Okta Activity by IP Address
- deprecated_in_version: 5.2.0
+ - content: Investigate Okta Activity by IP Address
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Investigate Pass the Hash Attempts
- deprecated_in_version: 5.2.0
+ - content: Investigate Pass the Hash Attempts
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Investigate Pass the Ticket Attempts
- deprecated_in_version: 5.2.0
+ - content: Investigate Pass the Ticket Attempts
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Investigate Previous Unseen User
- deprecated_in_version: 5.2.0
+ - content: Investigate Previous Unseen User
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Investigate Successful Remote Desktop Authentications
- deprecated_in_version: 5.2.0
+ - content: Investigate Successful Remote Desktop Authentications
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Investigate Suspicious Strings in HTTP Header
- deprecated_in_version: 5.2.0
+ - content: Investigate Suspicious Strings in HTTP Header
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Investigate User Activities In Okta
- deprecated_in_version: 5.2.0
+ - content: Investigate User Activities In Okta
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- - deprecated_content: Investigate Web POSTs From src
- deprecated_in_version: 5.2.0
+ - content: Investigate Web POSTs From src
+ removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
stories:
- - deprecated_content: AWS Cryptomining
- deprecated_in_version: 5.2.0
+ - content: AWS Cryptomining
+ removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Cloud Cryptomining
- - deprecated_content: AWS Suspicious Provisioning Activities
- deprecated_in_version: 5.2.0
+ - content: AWS Suspicious Provisioning Activities
+ removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Suspicious Cloud Provisioning Activities
- - deprecated_content: Common Phishing Frameworks
- deprecated_in_version: 5.2.0
+ - content: Common Phishing Frameworks
+ removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Container Implantation Monitoring and Investigation
- deprecated_in_version: 5.2.0
+ - content: Container Implantation Monitoring and Investigation
+ removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Kubernetes Security
- - deprecated_content: Host Redirection
- deprecated_in_version: 5.2.0
+ - content: Host Redirection
+ removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Kubernetes Sensitive Role Activity
- deprecated_in_version: 5.2.0
+ - content: Kubernetes Sensitive Role Activity
+ removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Kubernetes Security
- - deprecated_content: Lateral Movement
- deprecated_in_version: 5.2.0
+ - content: Lateral Movement
+ removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Compromised User Account
- - deprecated_content: Monitor Backup Solution
- deprecated_in_version: 5.2.0
+ - content: Monitor Backup Solution
+ removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Monitor for Unauthorized Software
- deprecated_in_version: 5.2.0
+ - content: Monitor for Unauthorized Software
+ removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Office 365 Detections
- deprecated_in_version: 5.2.0
+ - content: Office 365 Detections
+ removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Office 365 Account Takeover
- - deprecated_content: Spectre And Meltdown Vulnerabilities
- deprecated_in_version: 5.2.0
+ - content: Spectre And Meltdown Vulnerabilities
+ removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Suspicious AWS EC2 Activities
- deprecated_in_version: 5.2.0
+ - content: Suspicious AWS EC2 Activities
+ removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Suspicious Cloud Instance Activities
- - deprecated_content: Unusual AWS EC2 Modifications
- deprecated_in_version: 5.2.0
+ - content: Unusual AWS EC2 Modifications
+ removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Suspicious Cloud Instance Activities
- - deprecated_content: Web Fraud Detection
- deprecated_in_version: 5.2.0
+ - content: Web Fraud Detection
+ removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- - deprecated_content: Nexus APT Threat Activity
- deprecated_in_version: 5.4.0
+ - content: Nexus APT Threat Activity
+ removed_in_version: 5.4.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- China-Nexus Threat Activity
\ No newline at end of file
From 6488af7c57740c0e39da9bcb968b6c822c087f61 Mon Sep 17 00:00:00 2001
From: delgado-jacob <29643013+delgado-jacob@users.noreply.github.com>
Date: Tue, 18 Mar 2025 14:29:30 -0700
Subject: [PATCH 65/67] Add Zeek TA, fix detection source list
---
data_sources/bro_conn.yml | 5 ++++-
data_sources/bro_dns.yml | 6 +++++-
data_sources/bro_files.yml | 5 ++++-
data_sources/bro_http.yml | 5 ++++-
data_sources/bro_loaded_scripts.yml | 5 ++++-
data_sources/bro_ntp.yml | 5 ++++-
data_sources/bro_ocsp.yml | 5 ++++-
data_sources/bro_ssl.yml | 5 ++++-
data_sources/bro_weird.yml | 5 ++++-
data_sources/bro_x509.yml | 5 ++++-
detections/network/detect_outbound_ldap_traffic.yml | 3 ---
11 files changed, 41 insertions(+), 13 deletions(-)
diff --git a/data_sources/bro_conn.yml b/data_sources/bro_conn.yml
index 1d8e4110c3..2344d857d7 100644
--- a/data_sources/bro_conn.yml
+++ b/data_sources/bro_conn.yml
@@ -12,4 +12,7 @@ mitre_components:
- Application Log Content
source: bro:conn:json
sourcetype: bro:conn:json
-supported_TA: []
+supported_TA:
+- name: TA for Zeek
+ url: https://splunkbase.splunk.com/app/5466
+ version: 1.0.8
diff --git a/data_sources/bro_dns.yml b/data_sources/bro_dns.yml
index b4deae7a6c..a87a59819a 100644
--- a/data_sources/bro_dns.yml
+++ b/data_sources/bro_dns.yml
@@ -13,4 +13,8 @@ mitre_components:
- Response Metadata
source: bro:dns:json
sourcetype: bro:dns:json
-supported_TA: []
+supported_TA:
+- name: TA for Zeek
+ url: https://splunkbase.splunk.com/app/5466
+ version: 1.0.8
+
diff --git a/data_sources/bro_files.yml b/data_sources/bro_files.yml
index 20121d2067..6185e27c8f 100644
--- a/data_sources/bro_files.yml
+++ b/data_sources/bro_files.yml
@@ -14,4 +14,7 @@ mitre_components:
- Application Log Content
source: bro:files:json
sourcetype: bro:files:json
-supported_TA: []
+supported_TA:
+- name: TA for Zeek
+ url: https://splunkbase.splunk.com/app/5466
+ version: 1.0.8
diff --git a/data_sources/bro_http.yml b/data_sources/bro_http.yml
index e8e25150dc..02c2647022 100644
--- a/data_sources/bro_http.yml
+++ b/data_sources/bro_http.yml
@@ -13,4 +13,7 @@ mitre_components:
- Application Log Content
source: bro:http:json
sourcetype: bro:http:json
-supported_TA: []
+supported_TA:
+- name: TA for Zeek
+ url: https://splunkbase.splunk.com/app/5466
+ version: 1.0.8
diff --git a/data_sources/bro_loaded_scripts.yml b/data_sources/bro_loaded_scripts.yml
index 2b9669bac3..016c7beb38 100644
--- a/data_sources/bro_loaded_scripts.yml
+++ b/data_sources/bro_loaded_scripts.yml
@@ -12,4 +12,7 @@ mitre_components:
- OS API Execution
source: bro:loaded_scripts:json
sourcetype: bro:loaded_scripts:json
-supported_TA: []
+supported_TA:
+- name: TA for Zeek
+ url: https://splunkbase.splunk.com/app/5466
+ version: 1.0.8
diff --git a/data_sources/bro_ntp.yml b/data_sources/bro_ntp.yml
index 727dfc5bfa..f76e65c2ae 100644
--- a/data_sources/bro_ntp.yml
+++ b/data_sources/bro_ntp.yml
@@ -12,4 +12,7 @@ mitre_components:
- Application Log Content
source: bro:ntp:json
sourcetype: bro:ntp:json
-supported_TA: []
+supported_TA:
+- name: TA for Zeek
+ url: https://splunkbase.splunk.com/app/5466
+ version: 1.0.8
diff --git a/data_sources/bro_ocsp.yml b/data_sources/bro_ocsp.yml
index 316e75d352..fc3bd136a9 100644
--- a/data_sources/bro_ocsp.yml
+++ b/data_sources/bro_ocsp.yml
@@ -13,4 +13,7 @@ mitre_components:
- Application Log Content
source: bro:ocsp:json
sourcetype: bro:ocsp:json
-supported_TA: []
+supported_TA:
+- name: TA for Zeek
+ url: https://splunkbase.splunk.com/app/5466
+ version: 1.0.8
diff --git a/data_sources/bro_ssl.yml b/data_sources/bro_ssl.yml
index b138786a0f..42a8a59910 100644
--- a/data_sources/bro_ssl.yml
+++ b/data_sources/bro_ssl.yml
@@ -13,4 +13,7 @@ mitre_components:
- Application Log Content
source: bro:ssl:json
sourcetype: bro:ssl:json
-supported_TA: []
+supported_TA:
+- name: TA for Zeek
+ url: https://splunkbase.splunk.com/app/5466
+ version: 1.0.8
diff --git a/data_sources/bro_weird.yml b/data_sources/bro_weird.yml
index 4d46c68d74..fe5a01ce05 100644
--- a/data_sources/bro_weird.yml
+++ b/data_sources/bro_weird.yml
@@ -13,4 +13,7 @@ mitre_components:
- Host Status
source: bro:weird:json
sourcetype: bro:weird:json
-supported_TA: []
+supported_TA:
+- name: TA for Zeek
+ url: https://splunkbase.splunk.com/app/5466
+ version: 1.0.8
diff --git a/data_sources/bro_x509.yml b/data_sources/bro_x509.yml
index 3f23109ebd..a5d7370c9e 100644
--- a/data_sources/bro_x509.yml
+++ b/data_sources/bro_x509.yml
@@ -13,4 +13,7 @@ mitre_components:
- Host Status
source: bro:x509:json
sourcetype: bro:x509:json
-supported_TA: []
+supported_TA:
+- name: TA for Zeek
+ url: https://splunkbase.splunk.com/app/5466
+ version: 1.0.8
diff --git a/detections/network/detect_outbound_ldap_traffic.yml b/detections/network/detect_outbound_ldap_traffic.yml
index 43c8417a22..03e2420676 100644
--- a/detections/network/detect_outbound_ldap_traffic.yml
+++ b/detections/network/detect_outbound_ldap_traffic.yml
@@ -13,10 +13,7 @@ description: The following analytic identifies outbound LDAP traffic to external
this to access sensitive directory information, leading to data breaches or further
network compromise.
data_source:
-- Bro conn
- Palo Alto Network Traffic
-- Splunk Stream TCP
-- Splunk Stream IP
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime values(All_Traffic.dest_ip) as dest_ip from datamodel=Network_Traffic.All_Traffic
where All_Traffic.dest_port = 389 OR All_Traffic.dest_port = 636 AND NOT (All_Traffic.dest_ip
From ea3fa4daf6eabcbdd9f3625b37b6f3837083794a Mon Sep 17 00:00:00 2001
From: Bhavin Patel
Date: Tue, 18 Mar 2025 14:52:30 -0700
Subject: [PATCH 66/67] updating search
---
detections/cloud/aws_saml_update_identity_provider.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/detections/cloud/aws_saml_update_identity_provider.yml b/detections/cloud/aws_saml_update_identity_provider.yml
index 1cbc4848f6..b75e51fa8b 100644
--- a/detections/cloud/aws_saml_update_identity_provider.yml
+++ b/detections/cloud/aws_saml_update_identity_provider.yml
@@ -17,7 +17,7 @@ data_source:
- AWS CloudTrail UpdateSAMLProvider
search: '`cloudtrail` eventName=UpdateSAMLProvider
| rename user_name as user
- | stats count min(_time) as firstTime max(_time) as lastTime values(request_parameters) as request_parameters by signature dest user user_agent src vendor_account vendor_region vendor_product
+ | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.sAMLProviderArn) as request_parameters by signature dest user user_agent src vendor_account vendor_region vendor_product
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|`aws_saml_update_identity_provider_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
From 58aca7db99704d6a877714031870c9e37e2bc2e1 Mon Sep 17 00:00:00 2001
From: Eric
Date: Tue, 18 Mar 2025 15:41:21 -0700
Subject: [PATCH 67/67] Update the deprecation_info.csv file, manually
generated with a version of contentctl that has not yet been merged or
released in main branch.
---
lookups/deprecation_info.csv | 400 ++++++++++++++++++-----------------
1 file changed, 206 insertions(+), 194 deletions(-)
diff --git a/lookups/deprecation_info.csv b/lookups/deprecation_info.csv
index ca41e89981..743562a38e 100644
--- a/lookups/deprecation_info.csv
+++ b/lookups/deprecation_info.csv
@@ -1,195 +1,207 @@
-Name,Content Type,Deprecated in Version,Reason,Migration Guide,Replacement Content
-ESCU - ASL AWS Excessive Security Scanning - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - AWS Cloud Provisioning From Previously Unseen Region - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5aba1860-9617-4af9-b19d-aecac16fe4f2
-ESCU - First time seen command line argument - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Windows connhost exe started forcefully - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Detect Mimikatz Using Loaded Images - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Kubernetes Azure detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Web Fraud - Anomalous User Clickspeed - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - EC2 Instance Started With Previously Unseen Instance Type - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c6ddbf53-9715-49f3-bb4c-fb2e8a309cda
-ESCU - EC2 Instance Started With Previously Unseen AMI - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/bc24922d-987c-4645-b288-f8c73ec194c4
-ESCU - Domain Group Discovery With Net - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c5c8e0f3-147a-43da-bf04-4cfaec27dc44
-ESCU - Kubernetes AWS detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Winword Spawning Windows Script Host - Rule,Detection,5.2.0,"The following analytics was deprecated in favour of a more generic approach. Where instead of creating specific analytic for every potentially suspicious child of an office product. We group them by threat level.
-This would ease management and false positives tuning.",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
-ESCU - Winword Spawning PowerShell - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
-ESCU - Attempted Credential Dump From Registry via Reg exe - Rule,Detection,5.2.0,"This analytic had some overlap with another one, hence the deprecation. It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry Hive Dump Via CommandLine",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5aaff29d-0cce-405b-9ee8-5d06b49d045e
-ESCU - Detect processes used for System Network Configuration Discovery - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/3f0b95e3-3195-46ac-bea3-84fb59e7fac5
-ESCU - Execution of File With Spaces Before Extension - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b06a555e-dce0-417d-a2eb-28a5d8d66ef7
-ESCU - EC2 Instance Started In Previously Unseen Region - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/fa4089e2-50e3-40f7-8469-d2cc1564ca59
-ESCU - Office Document Spawned Child Process To Download - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f02b64b8-cbea-4f75-bf77-7a05111566b1
-ESCU - Detect new API calls from user roles - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2181ad1f-1e73-4d0c-9780-e8880482a08f
-ESCU - Cmdline Tool Not Executed In CMD Shell - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2afa393f-b88d-41b7-9793-623c93a2dfde
-ESCU - Linux Auditd Find Private Keys - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/892eb674-3344-4143-8e52-4775b1daf3f1
-ESCU - Detect AWS API Activities From Unapproved Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Monitor DNS For Brand Abuse - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Kubernetes GCP detect sensitive object access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Kubernetes Azure scan fingerprint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - ASL AWS Password Policy Changes - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - O365 Suspicious Admin Email Forwarding - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/0b6bc75c-05d1-4101-9fc3-97e706168f24
-ESCU - AWS Cloud Provisioning From Previously Unseen City - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/e7ecc5e0-88df-48b9-91af-51104c68f02f
-ESCU - Kubernetes AWS detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Osquery pack - ColdRoot detection - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Windows Modify Registry Reg Restore - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a17af481-e2ad-494c-9da6-afb4d243a019
-ESCU - Kubernetes GCP detect most active service accounts by pod - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Scheduled tasks used in BadRabbit ransomware - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d5af132c-7c17-439c-9d31-13d55340f36c
-ESCU - Suspicious Rundll32 Rename - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Remote System Discovery with Net - Rule,Detection,5.2.0,"This analytic was focusing on 2 separate and unrelated type of threats or actions. It was split into other analytics, namely:
-
-Windows Network Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277
-Windows Sensitive Group Discovery With Net / a23a0e20-0b1b-4a07-82e5-ec5f70811e7a",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/4dc3951f-b3f8-4f46-b412-76a483f72277
-ESCU - Remote System Discovery with Net - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d9eb7cda-5622-4722-bc88-7f2442f4b5af
-ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Suspicious Changes to File Associations - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - GCP Detect high risk permissions by resource and account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Office Product Writing cab or inf - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/dbdd251e-dd45-4ec9-a555-f5e151391746
-ESCU - Identify New User Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Office Product Spawn CMD Process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
-ESCU - Windows DLL Search Order Hijacking Hunt - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/79c7d1fc-64c7-91be-a616-ccda752efe81
-ESCU - ASL AWS CreateAccessKey - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/81a9f2fe-1697-473c-af1d-086b0d8b63c8
-ESCU - Okta ThreatInsight Login Failure with High Unknown users - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Detect Spike in Security Group Activity - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d4dfb7f3-7a37-498a-b5df-f19334e871af
-ESCU - Office Product Spawning BITSAdmin - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
-ESCU - Create local admin accounts using net exe - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2c568c34-bb57-4b43-9d75-19c605b98e70
-ESCU - Abnormally High AWS Instances Terminated by User - MLTK - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Windows Office Product Spawning MSDT - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a3148fad-3734-4b7f-9a71-62f08d39fab1
-ESCU - Detect Spike in AWS API Activity - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Office Product Spawning Windows Script Host - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
-ESCU - Prohibited Software On Endpoint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a51bfe1a-94f0-48cc-b4e4-16a110145893
-ESCU - AWS Cloud Provisioning From Previously Unseen Country - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/94994255-3acf-4213-9b3f-0494df03bb31
-ESCU - Detect Critical Alerts from Security Tools - Rule,Detection,5.2.0,"As discussed internally, this analytic was too generic for an analyst to do anything with it. It was deprecated in favor of the more specific approach provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender Incident Alerts. Going forward analytics from leveraging alerts from vendors will have their specific analytics.",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/38f034ed-1598-46c8-95e8-14edf05fdf5d
-ESCU - Detect Critical Alerts from Security Tools - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/13435b55-afd8-46d4-9045-7d5457f430a5
-ESCU - Excel Spawning PowerShell - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
-ESCU - Office Application Spawn rundll32 process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
-ESCU - Excessive Usage Of Net App - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/355ba810-0a20-4215-8485-9ce3f87f2e38
-ESCU - Elevated Group Discovery With Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d9eb7cda-5622-4722-bc88-7f2442f4b5af
-ESCU - Local Account Discovery with Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7742987e-88c1-476b-a626-a869e088ab72
-ESCU - Windows Command Shell Fetch Env Variables - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/aec157f4-8783-4584-aca6-754c4dc7fba9
-ESCU - Suspicious Email - UBA Anomaly - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Detect web traffic to dynamic domain providers - Rule,Detection,5.2.0,Updated to use a different log source,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a1e761ac-1344-4dbd-88b2-3f34c912d359
-ESCU - Okta Failed SSO Attempts - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5f661629-9750-4cb9-897c-1f05d6db8727
-ESCU - Kubernetes AWS detect RBAC authorization by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Kubernetes Azure detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Remote Registry Key modifications - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - O365 Suspicious User Email Forwarding - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/0b6bc75c-05d1-4101-9fc3-97e706168f24
-ESCU - Office Product Spawning MSHTA - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
-ESCU - Kubernetes AWS detect most active service accounts by pod - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Correlation by Repository and Risk - Rule,Detection,5.2.0,Detections updated to use the datamodel,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/161bc0ca-4651-4c13-9c27-27770660cf67
-ESCU - Kubernetes Azure detect RBAC authorization by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Clients Connecting to Multiple DNS Servers - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Excessive Service Stop Attempt - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/8f3a614f-6b98-4f7d-82dd-d0df38452a8b
-ESCU - Multiple Okta Users With Invalid Credentials From The Same IP - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/de365ffa-42f5-46b5-b43f-fa72290b8218
-ESCU - Suspicious writes to System Volume Information - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Detect new user AWS Console Login - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/bc91a8cd-35e7-4bb2-6140-e756cc46fd71
+Name,Content Type,Removed in Version,Reason,Replacement Content,Replacement Content Link
+ESCU - Previously Seen AWS Cross Account Activity - Initial,Baseline,5.4.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available
+ESCU - Previously Seen AWS Cross Account Activity - Update,Baseline,5.4.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available
+ESCU - AWS Cross Account Activity From Previously Unseen Account - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - AWS SAML Access by Provider User and Principal - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - GitHub Actions Disable Security Workflow - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - GitHub Dependabot Alert - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - GitHub Pull Request from Unknown User - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Github Commit Changes In Master - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Github Commit In Develop - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Known Services Killed by Ransomware - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Remote Desktop Network Bruteforce - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Suspicious Driver Loaded Path - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Suspicious Event Log Service Behavior - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Suspicious Process File Path - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - aws detect attach to role policy - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - aws detect permanent key creation - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - aws detect role creation - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - aws detect sts assume role abuse - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - aws detect sts get session token abuse - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+Nexus APT Threat Activity,Story,5.4.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,China-Nexus Threat Activity,https://research.splunk.com/stories/china_nexus_threat_activity
+ESCU - Add Prohibited Processes to Enterprise Security,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available
+ESCU - Baseline of API Calls per User ARN,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available
+ESCU - Baseline of Excessive AWS Instances Launched by User - MLTK,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available
+ESCU - Baseline of Excessive AWS Instances Terminated by User - MLTK,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available
+ESCU - Monitor Successful Backups,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available
+ESCU - Monitor Unsuccessful Backups,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available
+ESCU - Previously Seen AWS Provisioning Activity Sources,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available
+ESCU - Previously Seen AWS Regions,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available
+ESCU - Previously Seen EC2 AMIs,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available
+ESCU - Previously Seen EC2 Instance Types,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available
+ESCU - Previously Seen EC2 Launches By User,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available
+ESCU - Previously Seen EC2 Modifications By User,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available
+ESCU - Previously seen API call per user roles in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available
+ESCU - Previously seen users in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available
+ESCU - Systems Ready for Spectre-Meltdown Windows Patch,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available
+ESCU - Update previously seen users in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available
+ESCU - ASL AWS CreateAccessKey - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - ASL AWS Create Access Key - Rule,https://research.splunk.com/cloud/81a9f2fe-1697-473c-af1d-086b0d8b63c8
+ESCU - ASL AWS Excessive Security Scanning - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - ASL AWS Password Policy Changes - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - AWS Cloud Provisioning From Previously Unseen City - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud Provisioning Activity From Previously Unseen City - Rule,https://research.splunk.com/cloud/e7ecc5e0-88df-48b9-91af-51104c68f02f
+ESCU - AWS Cloud Provisioning From Previously Unseen Country - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud Provisioning Activity From Previously Unseen Country - Rule,https://research.splunk.com/cloud/94994255-3acf-4213-9b3f-0494df03bb31
+ESCU - AWS Cloud Provisioning From Previously Unseen IP Address - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud Provisioning Activity From Previously Unseen IP Address - Rule,https://research.splunk.com/cloud/f86a8ec9-b042-45eb-92f4-e9ed1d781078
+ESCU - AWS Cloud Provisioning From Previously Unseen Region - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud Provisioning Activity From Previously Unseen Region - Rule,https://research.splunk.com/cloud/5aba1860-9617-4af9-b19d-aecac16fe4f2
+ESCU - AWS EKS Kubernetes cluster sensitive object access - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Kubernetes Abuse of Secret by Unusual Location - Rule,https://research.splunk.com/cloud/40a064c1-4ec1-4381-9e35-61192ba8ef82
+ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Abnormally High AWS Instances Launched by User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Abnormally High Number Of Cloud Instances Launched - Rule,https://research.splunk.com/cloud/f2361e9f-3928-496c-a556-120cd4223a65
+ESCU - Abnormally High AWS Instances Terminated by User - MLTK - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Abnormally High AWS Instances Terminated by User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Abnormally High Number Of Cloud Instances Destroyed - Rule,https://research.splunk.com/cloud/ef629fc9-1583-4590-b62a-f2247fbf7bbf
+ESCU - Account Discovery With Net App - Rule,Detection,5.2.0,"This analytic was a TTP that focused on unrelated things and called account discovery. Since there were other detection that overlapped with it. I choose to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 / Windows Excessive Usage Of Net App.",ESCU - Windows Excessive Usage Of Net App - Rule,https://research.splunk.com/endpoint/355ba810-0a20-4215-8485-9ce3f87f2e38
+ESCU - Attempt To Stop Security Service - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Attempt To Stop Security Service - Rule,https://research.splunk.com/endpoint/9ed27cea-4e27-4eff-b2c6-aac9e78a7517
+ESCU - Attempted Credential Dump From Registry via Reg exe - Rule,Detection,5.2.0,"This analytic had some overlap with another one, hence the deprecation. It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry Hive Dump Via CommandLine",ESCU - Windows Sensitive Registry Hive Dump Via CommandLine - Rule,https://research.splunk.com/endpoint/5aaff29d-0cce-405b-9ee8-5d06b49d045e
+ESCU - Change Default File Association - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows New Default File Association Value Set - Rule,https://research.splunk.com/endpoint/7d1f031f-f1c9-43be-8b0b-c4e3e8a8928a
+ESCU - Clients Connecting to Multiple DNS Servers - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Cloud Network Access Control List Deleted - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - AWS Network Access Control List Deleted - Rule,https://research.splunk.com/cloud/ada0f478-84a8-4641-a3f1-d82362d6fd75
+ESCU - Cmdline Tool Not Executed In CMD Shell - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Cmdline Tool Execution From Non-Shell Process - Rule,https://research.splunk.com/endpoint/2afa393f-b88d-41b7-9793-623c93a2dfde
+ESCU - Correlation by Repository and Risk - Rule,Detection,5.2.0,Detections updated to use the datamodel,ESCU - Risk Rule for Dev Sec Ops by Repository - Rule,https://research.splunk.com/cloud/161bc0ca-4651-4c13-9c27-27770660cf67
+ESCU - Correlation by User and Risk - Rule,Detection,5.2.0,Detections updated to use the datamodel,ESCU - Risk Rule for Dev Sec Ops by Repository - Rule,https://research.splunk.com/cloud/161bc0ca-4651-4c13-9c27-27770660cf67
+ESCU - Create local admin accounts using net exe - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Create Local Administrator Account Via Net - Rule,https://research.splunk.com/endpoint/2c568c34-bb57-4b43-9d75-19c605b98e70
+ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - DNS record changed - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Deleting Of Net Users - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows User Deletion Via Net - Rule,https://research.splunk.com/endpoint/b0b6fd2c-8953-4d1b-8f7b-56075ea6ab3e
+ESCU - Detect API activity from users without MFA - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - AWS Successful Single-Factor Authentication - Rule,https://research.splunk.com/cloud/a520b1fe-cc9e-4f56-b762-18354594c52f
+ESCU - Detect AWS API Activities From Unapproved Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Detect Activity Related to Pass the Hash Attacks - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Detect Critical Alerts from Security Tools - Rule,Detection,5.2.0,"As discussed internally, this analytic was too generic for an analyst to do anything with it. It was deprecated in favor of the more specific approach provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender Incident Alerts. Going forward analytics from leveraging alerts from vendors will have their specific analytics.",ESCU - Microsoft Defender ATP Alerts - Rule,https://research.splunk.com/endpoint/38f034ed-1598-46c8-95e8-14edf05fdf5d
+ESCU - Detect Critical Alerts from Security Tools - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Microsoft Defender Incident Alerts - Rule,https://research.splunk.com/endpoint/13435b55-afd8-46d4-9045-7d5457f430a5
+ESCU - Detect DNS requests to Phishing Sites leveraging EvilGinx2 - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Detect Long DNS TXT Record Response - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Detect Mimikatz Using Loaded Images - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Detect Mimikatz Via PowerShell And EventCode 4703 - Rule,Detection,5.2.0,Updated to a new detection name,ESCU - Detect Mimikatz With PowerShell Script Block Logging - Rule,https://research.splunk.com/endpoint/8148c29c-c952-11eb-9255-acde48001122
+ESCU - Detect Spike in AWS API Activity - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Detect Spike in Network ACL Activity - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Abnormally High Number Of Cloud Infrastructure API Calls - Rule,https://research.splunk.com/cloud/0840ddf1-8c89-46ff-b730-c8d6722478c0
+ESCU - Detect Spike in Security Group Activity - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Abnormally High Number Of Cloud Security Group API Calls - Rule,https://research.splunk.com/cloud/d4dfb7f3-7a37-498a-b5df-f19334e871af
+ESCU - Detect USB device insertion - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Detect Webshell Exploit Behavior - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Suspicious Child Process Spawned From WebServer - Rule,https://research.splunk.com/endpoint/2d4470ef-7158-4b47-b68b-1f7f16382156
+ESCU - Detect new API calls from user roles - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud API Calls From Previously Unseen User Roles - Rule,https://research.splunk.com/cloud/2181ad1f-1e73-4d0c-9780-e8880482a08f
+ESCU - Detect new user AWS Console Login - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Detect AWS Console Login by New User - Rule,https://research.splunk.com/cloud/bc91a8cd-35e7-4bb2-6140-e756cc46fd71
+ESCU - Detect processes used for System Network Configuration Discovery - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Potential System Network Configuration Discovery Activity - Rule,https://research.splunk.com/endpoint/3f0b95e3-3195-46ac-bea3-84fb59e7fac5
+ESCU - Detect web traffic to dynamic domain providers - Rule,Detection,5.2.0,Updated to use a different log source,ESCU - Detect hosts connecting to dynamic domain providers - Rule,https://research.splunk.com/network/a1e761ac-1344-4dbd-88b2-3f34c912d359
+ESCU - Detection of DNS Tunnels - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Disabling Net User Account - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows User Disabled Via Net - Rule,https://research.splunk.com/endpoint/b0359e05-c87b-4354-83d8-aee0d890243f
ESCU - Domain Account Discovery With Net App - Rule,Detection,5.2.0,"This analytic was a TTP that looked only for commands that tries to query info about the users via net user /do. This had a couple of issues, such as triggering on creation of users via the /add flag etc..
-It was deprecated in favor of a more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7742987e-88c1-476b-a626-a869e088ab72
-ESCU - Detection of DNS Tunnels - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Detect DNS requests to Phishing Sites leveraging EvilGinx2 - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Office Document Creating Schedule Task - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d7297cfa-1f04-4714-bfbe-3679e0666959
-ESCU - Okta Account Locked Out - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a511426e-184f-4de6-8711-cfd2af29d1e1
-ESCU - Unsuccessful Netbackup backups - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Detect Mimikatz Via PowerShell And EventCode 4703 - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/8148c29c-c952-11eb-9255-acde48001122
-ESCU - Winword Spawning Cmd - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
-ESCU - GCP Kubernetes cluster scan detection - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f9cadf4e-df22-4f4e-a08f-9d3344c2165d
-ESCU - Kubernetes GCP detect suspicious kubectl calls - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - gcp detect oauth token abuse - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Correlation by User and Risk - Rule,Detection,5.2.0,Detections updated to use the datamodel,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/161bc0ca-4651-4c13-9c27-27770660cf67
-ESCU - Processes created by netsh - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b89919ed-fe5f-492c-b139-95dbb162040e
-ESCU - Office Product Spawning Wmic - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
-ESCU - Extraction of Registry Hives - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5aaff29d-0cce-405b-9ee8-5d06b49d045e
-ESCU - Attempt To Stop Security Service - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/9ed27cea-4e27-4eff-b2c6-aac9e78a7517
-ESCU - Windows MSIExec With Network Connections - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b0fd38c7-f71a-43a2-870e-f3ca06bcdd99
-ESCU - Windows Query Registry Reg Save - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/466379bc-0f47-476c-8202-16ef38112e0d
-ESCU - Cloud Network Access Control List Deleted - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/ada0f478-84a8-4641-a3f1-d82362d6fd75
-ESCU - O365 Suspicious Rights Delegation - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2246c142-a678-45f8-8546-aaed7e0efd30
-ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Reg exe used to hide files directories via registry keys - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Detect Long DNS TXT Record Response - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Password Policy Discovery with Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/e52f7865-be78-46bf-b7ed-150fbe447613
-ESCU - AWS Cloud Provisioning From Previously Unseen IP Address - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f86a8ec9-b042-45eb-92f4-e9ed1d781078
-ESCU - Network Connection Discovery With Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/86a5b949-679b-4197-8d4c-9c180a818c45
-ESCU - Kubernetes Azure detect suspicious kubectl calls - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Kubernetes GCP detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Detect Webshell Exploit Behavior - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2d4470ef-7158-4b47-b68b-1f7f16382156
-ESCU - DNS record changed - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Unsigned Image Loaded by LSASS - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Detect USB device insertion - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Windows Network Share Interaction With Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/e51fbdb0-0be0-474f-92ea-d289f71a695e
-ESCU - Account Discovery With Net App - Rule,Detection,5.2.0,"This analytic was a TTP that focused on unrelated things and called account discovery. Since there were other detection that overlapped with it. I choose to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 / Windows Excessive Usage Of Net App.",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/355ba810-0a20-4215-8485-9ce3f87f2e38
-ESCU - Change Default File Association - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7d1f031f-f1c9-43be-8b0b-c4e3e8a8928a
-ESCU - Windows Lateral Tool Transfer RemCom - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7e3d68db-ea4d-419b-adbd-e14a525ecf09
-ESCU - Office Document Executing Macro Code - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7cfec906-2697-43f7-898b-83634a051d9a
-ESCU - Okta Account Lockout Events - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a511426e-184f-4de6-8711-cfd2af29d1e1
-ESCU - Abnormally High AWS Instances Launched by User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f2361e9f-3928-496c-a556-120cd4223a65
-ESCU - EC2 Instance Modified With Previously Unseen User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2181ad1f-1e73-4d0c-9780-e8880482a08f
-ESCU - Windows Valid Account With Never Expires Password - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/11f93009-8083-43fd-82a7-821fcbdc8342
-ESCU - Windows hosts file modification - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - MSHTML Module Load in Office Product - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/4cc015c9-687c-40d2-adcc-46350f66e10c
-ESCU - Abnormally High AWS Instances Terminated by User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/ef629fc9-1583-4590-b62a-f2247fbf7bbf
-ESCU - Web Fraud - Account Harvesting - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Office Spawning Control - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/081c485d-ac8d-4bee-ad4c-525772fead4d
-ESCU - Detect Activity Related to Pass the Hash Attacks - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Deleting Of Net Users - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b0b6fd2c-8953-4d1b-8f7b-56075ea6ab3e
-ESCU - Suspicious File Write - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - AWS EKS Kubernetes cluster sensitive object access - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/40a064c1-4ec1-4381-9e35-61192ba8ef82
-ESCU - Spectre and Meltdown Vulnerable Systems - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - EC2 Instance Started With Previously Unseen User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/37a0ec8d-827e-4d6d-8025-cedf31f3a149
-ESCU - Office Product Spawning CertUtil - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
-ESCU - Kubernetes GCP detect RBAC authorizations by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Office Application Drop Executable - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7ac0fced-9eae-4381-a748-90dcd1aa9393
-ESCU - Kubernetes Azure active service accounts by pod namespace - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Kubernetes Azure pod scan fingerprint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Detect Spike in Network ACL Activity - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/0840ddf1-8c89-46ff-b730-c8d6722478c0
-ESCU - Suspicious Powershell Command-Line Arguments - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c4db14d9-7909-48b4-a054-aa14d89dbb19
-ESCU - Office Application Spawn Regsvr32 process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
-ESCU - Detect API activity from users without MFA - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a520b1fe-cc9e-4f56-b762-18354594c52f
-ESCU - Kubernetes Azure detect sensitive object access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Web Fraud - Password Sharing Across Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Disabling Net User Account - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b0359e05-c87b-4354-83d8-aee0d890243f
-ESCU - GCP Detect accounts with high risk roles by project - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Kubernetes GCP detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Extended Period Without Successful Netbackup Backups - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Office Product Spawning Rundll32 with no DLL - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f28e787e-69ca-480e-9f98-ab970e6d4bcc
-ESCU - Okta ThreatInsight Suspected PasswordSpray Attack - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/140504ae-5fe2-4d65-b2bc-a211813fbca6
-ESCU - Net Localgroup Discovery - Rule,Detection,5.2.0,Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 / Windows Group Discovery Via Net,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c5c8e0f3-147a-43da-bf04-4cfaec27dc44
-ESCU - Uncommon Processes On Endpoint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a51bfe1a-94f0-48cc-b4e4-16a110145893
-ESCU - Dump LSASS via procdump Rename - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/3742ebfe-64c2-11eb-ae93-0242ac130002
-ESCU - Okta Two or More Rejected Okta Pushes - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/826dbaae-a1e6-4c8c-b384-d16898956e73
-ESCU - Excel Spawning Windows Script Host - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - GitHub Actions Disable Security Workflow - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Github Commit Changes In Master - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Github Commit In Develop - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - GitHub Dependabot Alert - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - GitHub Pull Request from Unknown User - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Known Services Killed by Ransomware - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Remote Desktop Network Bruteforce - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Suspicious Driver Loaded Path - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Suspicious Event Log Service Behavior - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Suspicious Process File Path - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Windows Service Stop Via Net and SC Application - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-ESCU - Add Prohibited Processes to Enterprise Security,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
-ESCU - Baseline of API Calls per User ARN,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
-ESCU - Baseline of Excessive AWS Instances Launched by User - MLTK,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
-ESCU - Baseline of Excessive AWS Instances Terminated by User - MLTK,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
-ESCU - Previously seen API call per user roles in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
-ESCU - Previously Seen AWS Provisioning Activity Sources,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
-ESCU - Previously Seen EC2 AMIs,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
-ESCU - Previously Seen EC2 Instance Types,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
-ESCU - Previously Seen EC2 Launches By User,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
-ESCU - Previously seen users in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
-ESCU - Update previously seen users in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
-AWS Cryptomining,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-AWS Suspicious Provisioning Activities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-Common Phishing Frameworks,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-Container Implantation Monitoring and Investigation,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-Host Redirection,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-Kubernetes Sensitive Role Activity,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-Lateral Movement,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-Monitor Backup Solution,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-Monitor for Unauthorized Software,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-Office 365 Detections,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-Spectre And Meltdown Vulnerabilities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-Suspicious AWS EC2 Activities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-Unusual AWS EC2 Modifications,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-Web Fraud Detection,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
-Nexus APT Threat Activity,Story,5.4.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
+It was deprecated in favor of a more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122",ESCU - Windows User Discovery Via Net - Rule,https://research.splunk.com/endpoint/7742987e-88c1-476b-a626-a869e088ab72
+ESCU - Domain Group Discovery With Net - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Group Discovery Via Net - Rule,https://research.splunk.com/endpoint/c5c8e0f3-147a-43da-bf04-4cfaec27dc44
+ESCU - Dump LSASS via procdump Rename - Rule,Detection,5.2.0,Updated to a new detection name,ESCU - Dump LSASS via procdump - Rule,https://research.splunk.com/endpoint/3742ebfe-64c2-11eb-ae93-0242ac130002
+ESCU - EC2 Instance Modified With Previously Unseen User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud API Calls From Previously Unseen User Roles - Rule,https://research.splunk.com/cloud/2181ad1f-1e73-4d0c-9780-e8880482a08f
+ESCU - EC2 Instance Started In Previously Unseen Region - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud Compute Instance Created In Previously Unused Region - Rule,https://research.splunk.com/cloud/fa4089e2-50e3-40f7-8469-d2cc1564ca59
+ESCU - EC2 Instance Started With Previously Unseen AMI - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud Compute Instance Created With Previously Unseen Image - Rule,https://research.splunk.com/cloud/bc24922d-987c-4645-b288-f8c73ec194c4
+ESCU - EC2 Instance Started With Previously Unseen Instance Type - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud Compute Instance Created With Previously Unseen Instance Type - Rule,https://research.splunk.com/cloud/c6ddbf53-9715-49f3-bb4c-fb2e8a309cda
+ESCU - EC2 Instance Started With Previously Unseen User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud Compute Instance Created By Previously Unseen User - Rule,https://research.splunk.com/cloud/37a0ec8d-827e-4d6d-8025-cedf31f3a149
+ESCU - Elevated Group Discovery With Net - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Sensitive Group Discovery With Net - Rule,https://research.splunk.com/endpoint/d9eb7cda-5622-4722-bc88-7f2442f4b5af
+ESCU - Excel Spawning PowerShell - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Excel Spawning Windows Script Host - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Excessive Service Stop Attempt - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Excessive Service Stop Attempt - Rule,https://research.splunk.com/endpoint/8f3a614f-6b98-4f7d-82dd-d0df38452a8b
+ESCU - Excessive Usage Of Net App - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Excessive Usage Of Net App - Rule,https://research.splunk.com/endpoint/355ba810-0a20-4215-8485-9ce3f87f2e38
+ESCU - Execution of File With Spaces Before Extension - Rule,Detection,5.2.0,Updated to a new detection name,ESCU - Execution of File with Multiple Extensions - Rule,https://research.splunk.com/endpoint/b06a555e-dce0-417d-a2eb-28a5d8d66ef7
+ESCU - Extended Period Without Successful Netbackup Backups - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Extraction of Registry Hives - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Sensitive Registry Hive Dump Via CommandLine - Rule,https://research.splunk.com/endpoint/5aaff29d-0cce-405b-9ee8-5d06b49d045e
+ESCU - First time seen command line argument - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - GCP Detect accounts with high risk roles by project - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - GCP Detect high risk permissions by resource and account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - GCP Kubernetes cluster scan detection - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Kubernetes Scanning by Unauthenticated IP Address - Rule,https://research.splunk.com/cloud/f9cadf4e-df22-4f4e-a08f-9d3344c2165d
+ESCU - Identify New User Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Kubernetes AWS detect RBAC authorization by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Kubernetes AWS detect most active service accounts by pod - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Kubernetes AWS detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Kubernetes AWS detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Kubernetes Azure active service accounts by pod namespace - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Kubernetes Azure detect RBAC authorization by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Kubernetes Azure detect sensitive object access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Kubernetes Azure detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Kubernetes Azure detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Kubernetes Azure detect suspicious kubectl calls - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Kubernetes Azure pod scan fingerprint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Kubernetes Azure scan fingerprint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Kubernetes GCP detect RBAC authorizations by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Kubernetes GCP detect most active service accounts by pod - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Kubernetes GCP detect sensitive object access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Kubernetes GCP detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Kubernetes GCP detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Kubernetes GCP detect suspicious kubectl calls - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Linux Auditd Find Private Keys - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Linux Auditd Private Keys and Certificate Enumeration - Rule,https://research.splunk.com/endpoint/892eb674-3344-4143-8e52-4775b1daf3f1
+ESCU - Local Account Discovery with Net - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows User Discovery Via Net - Rule,https://research.splunk.com/endpoint/7742987e-88c1-476b-a626-a869e088ab72
+ESCU - MSHTML Module Load in Office Product - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Office Product Loaded MSHTML Module - Rule,https://research.splunk.com/endpoint/4cc015c9-687c-40d2-adcc-46350f66e10c
+ESCU - Monitor DNS For Brand Abuse - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Multiple Okta Users With Invalid Credentials From The Same IP - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Okta Multiple Users Failing To Authenticate From Ip - Rule,https://research.splunk.com/application/de365ffa-42f5-46b5-b43f-fa72290b8218
+ESCU - Net Localgroup Discovery - Rule,Detection,5.2.0,Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 / Windows Group Discovery Via Net,ESCU - Windows Group Discovery Via Net - Rule,https://research.splunk.com/endpoint/c5c8e0f3-147a-43da-bf04-4cfaec27dc44
+ESCU - Network Connection Discovery With Net - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Network Connection Discovery Via Net - Rule,https://research.splunk.com/endpoint/86a5b949-679b-4197-8d4c-9c180a818c45
+ESCU - O365 Suspicious Admin Email Forwarding - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - O365 Mailbox Email Forwarding Enabled - Rule,https://research.splunk.com/cloud/0b6bc75c-05d1-4101-9fc3-97e706168f24
+ESCU - O365 Suspicious Rights Delegation - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - O365 Elevated Mailbox Permission Assigned - Rule,https://research.splunk.com/cloud/2246c142-a678-45f8-8546-aaed7e0efd30
+ESCU - O365 Suspicious User Email Forwarding - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - O365 Mailbox Email Forwarding Enabled - Rule,https://research.splunk.com/cloud/0b6bc75c-05d1-4101-9fc3-97e706168f24
+ESCU - Office Application Drop Executable - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Office Product Dropped Uncommon File - Rule,https://research.splunk.com/endpoint/7ac0fced-9eae-4381-a748-90dcd1aa9393
+ESCU - Office Application Spawn Regsvr32 process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Office Application Spawn rundll32 process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Office Document Creating Schedule Task - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Office Product Loading Taskschd DLL - Rule,https://research.splunk.com/endpoint/d7297cfa-1f04-4714-bfbe-3679e0666959
+ESCU - Office Document Executing Macro Code - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Office Product Loading VBE7 DLL - Rule,https://research.splunk.com/endpoint/7cfec906-2697-43f7-898b-83634a051d9a
+ESCU - Office Document Spawned Child Process To Download - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Office Product Spawned Child Process For Download - Rule,https://research.splunk.com/endpoint/f02b64b8-cbea-4f75-bf77-7a05111566b1
+ESCU - Office Product Spawn CMD Process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Office Product Spawning BITSAdmin - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Office Product Spawning CertUtil - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Office Product Spawning MSHTA - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Office Product Spawning Rundll32 with no DLL - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Office Product Spawned Rundll32 With No DLL - Rule,https://research.splunk.com/endpoint/f28e787e-69ca-480e-9f98-ab970e6d4bcc
+ESCU - Office Product Spawning Windows Script Host - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Office Product Spawning Wmic - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Office Product Writing cab or inf - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Office Product Dropped Cab or Inf File - Rule,https://research.splunk.com/endpoint/dbdd251e-dd45-4ec9-a555-f5e151391746
+ESCU - Office Spawning Control - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Office Product Spawned Control - Rule,https://research.splunk.com/endpoint/081c485d-ac8d-4bee-ad4c-525772fead4d
+ESCU - Okta Account Locked Out - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Okta Multiple Accounts Locked Out - Rule,https://research.splunk.com/application/a511426e-184f-4de6-8711-cfd2af29d1e1
+ESCU - Okta Account Lockout Events - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Okta Multiple Accounts Locked Out - Rule,https://research.splunk.com/application/a511426e-184f-4de6-8711-cfd2af29d1e1
+ESCU - Okta Failed SSO Attempts - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Okta Unauthorized Access to Application - Rule,https://research.splunk.com/application/5f661629-9750-4cb9-897c-1f05d6db8727
+ESCU - Okta ThreatInsight Login Failure with High Unknown users - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Okta ThreatInsight Suspected PasswordSpray Attack - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Okta ThreatInsight Threat Detected - Rule,https://research.splunk.com/application/140504ae-5fe2-4d65-b2bc-a211813fbca6
+ESCU - Okta Two or More Rejected Okta Pushes - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Okta Multiple Failed MFA Requests For User - Rule,https://research.splunk.com/application/826dbaae-a1e6-4c8c-b384-d16898956e73
+ESCU - Open Redirect in Splunk Web - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Osquery pack - ColdRoot detection - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Password Policy Discovery with Net - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Password Policy Discovery with Net - Rule,https://research.splunk.com/endpoint/e52f7865-be78-46bf-b7ed-150fbe447613
+ESCU - Processes created by netsh - Rule,Detection,5.2.0,Updated to a new detection name,ESCU - Processes launching netsh - Rule,https://research.splunk.com/endpoint/b89919ed-fe5f-492c-b139-95dbb162040e
+ESCU - Prohibited Software On Endpoint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Attacker Tools On Endpoint - Rule,https://research.splunk.com/endpoint/a51bfe1a-94f0-48cc-b4e4-16a110145893
+ESCU - Reg exe used to hide files directories via registry keys - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Remote Registry Key modifications - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Remote System Discovery with Net - Rule,Detection,5.2.0,This analytic was focusing on 2 separate and unrelated type of threats or actions. PLease use the replacement content,ESCU - Windows Sensitive Group Discovery With Net - Rule,https://research.splunk.com/endpoint/d9eb7cda-5622-4722-bc88-7f2442f4b5af
+ESCU - Scheduled tasks used in BadRabbit ransomware - Rule,Detection,5.2.0,Updated to a new detection name,ESCU - Scheduled Task Deleted Or Created via CMD - Rule,https://research.splunk.com/endpoint/d5af132c-7c17-439c-9d31-13d55340f36c
+ESCU - Spectre and Meltdown Vulnerable Systems - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Splunk Enterprise Information Disclosure - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Suspicious Changes to File Associations - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Suspicious Email - UBA Anomaly - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Suspicious File Write - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Suspicious Powershell Command-Line Arguments - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Malicious PowerShell Process - Encoded Command - Rule,https://research.splunk.com/endpoint/c4db14d9-7909-48b4-a054-aa14d89dbb19
+ESCU - Suspicious Rundll32 Rename - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Suspicious writes to System Volume Information - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Uncommon Processes On Endpoint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Attacker Tools On Endpoint - Rule,https://research.splunk.com/endpoint/a51bfe1a-94f0-48cc-b4e4-16a110145893
+ESCU - Unsigned Image Loaded by LSASS - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Unsuccessful Netbackup backups - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Web Fraud - Account Harvesting - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Web Fraud - Anomalous User Clickspeed - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Web Fraud - Password Sharing Across Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Windows Command Shell Fetch Env Variables - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows List ENV Variables Via SET Command From Uncommon Parent - Rule,https://research.splunk.com/endpoint/aec157f4-8783-4584-aca6-754c4dc7fba9
+ESCU - Windows DLL Search Order Hijacking Hunt - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Windows DLL Search Order Hijacking Hunt with Sysmon - Rule,https://research.splunk.com/endpoint/79c7d1fc-64c7-91be-a616-ccda752efe81
+ESCU - Windows Lateral Tool Transfer RemCom - Rule,Detection,5.2.0,Updated to a new detection name,ESCU - Windows Service Execution RemCom - Rule,https://research.splunk.com/endpoint/7e3d68db-ea4d-419b-adbd-e14a525ecf09
+ESCU - Windows MSIExec With Network Connections - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows HTTP Network Communication From MSIExec - Rule,https://research.splunk.com/endpoint/b0fd38c7-f71a-43a2-870e-f3ca06bcdd99
+ESCU - Windows Modify Registry Reg Restore - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Registry Entries Restored Via Reg - Rule,https://research.splunk.com/endpoint/a17af481-e2ad-494c-9da6-afb4d243a019
+ESCU - Windows Network Share Interaction With Net - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Network Share Interaction Via Net - Rule,https://research.splunk.com/endpoint/e51fbdb0-0be0-474f-92ea-d289f71a695e
+ESCU - Windows Office Product Spawning MSDT - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Office Product Spawned MSDT - Rule,https://research.splunk.com/endpoint/a3148fad-3734-4b7f-9a71-62f08d39fab1
+ESCU - Windows Query Registry Reg Save - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Registry Entries Exported Via Reg - Rule,https://research.splunk.com/endpoint/466379bc-0f47-476c-8202-16ef38112e0d
+ESCU - Windows Service Stop Via Net and SC Application - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Windows Valid Account With Never Expires Password - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Set Account Password Policy To Unlimited Via Net - Rule,https://research.splunk.com/endpoint/11f93009-8083-43fd-82a7-821fcbdc8342
+ESCU - Windows connhost exe started forcefully - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Windows hosts file modification - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+ESCU - Winword Spawning Cmd - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Winword Spawning PowerShell - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - Winword Spawning Windows Script Host - Rule,Detection,5.2.0,"The following analytics was deprecated in favour of a more generic approach. Where instead of creating specific analytic for every potentially suspicious child of an office product. We group them by threat level.
+This would ease management and false positives tuning.",ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8
+ESCU - gcp detect oauth token abuse - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+AWS Cryptomining,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,Cloud Cryptomining,https://research.splunk.com/stories/cloud_cryptomining
+AWS Suspicious Provisioning Activities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,Suspicious Cloud Provisioning Activities,https://research.splunk.com/stories/suspicious_cloud_provisioning_activities
+Common Phishing Frameworks,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+Container Implantation Monitoring and Investigation,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,Kubernetes Security,https://research.splunk.com/stories/kubernetes_security
+Host Redirection,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+Kubernetes Sensitive Role Activity,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,Kubernetes Security,https://research.splunk.com/stories/kubernetes_security
+Lateral Movement,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,Compromised User Account,https://research.splunk.com/stories/compromised_user_account
+Monitor Backup Solution,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+Monitor for Unauthorized Software,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+Office 365 Detections,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,Office 365 Account Takeover,https://research.splunk.com/stories/office_365_account_takeover
+Spectre And Meltdown Vulnerabilities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available
+Suspicious AWS EC2 Activities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,Suspicious Cloud Instance Activities,https://research.splunk.com/stories/suspicious_cloud_instance_activities
+Unusual AWS EC2 Modifications,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,Suspicious Cloud Instance Activities,https://research.splunk.com/stories/suspicious_cloud_instance_activities
+Web Fraud Detection,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available